Avatar billede ingelo Praktikant
11. januar 2008 - 17:56 Der er 17 kommentarer og
1 løsning

måske en virus

jeg kan komme ind i kontrolpanelet, men kan ikke åbne nogen af mapperne, og kan så heller ikke tilføje eller fjerne programmer. i et af mine spil får jeg at vide, at det ikke kan åbnes p.g.a. defekte filer, og i det andet kommer spillet godt nok op i fuld skærm, men cursoren er der ikke. jeg kan komme på nettet, men en opdatering af windows mislykkedes. jeg mener jeg har automatisk opdatering, -men åbenbart ikke fuldstændig. som en udvej ville jeg køre en systemgendannelse, -jeg kan vælge at gøre det, men så sker der ikke mere.
jeg håber, der er nogen, der kan hjælpe mig.
11. januar 2008 - 18:32 #1
... for en go' ordens skyld; stik os/mig en HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)
Avatar billede ingelo Praktikant
11. januar 2008 - 20:03 #2
:)-det har jeg vist også fået,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:58:28, on 11-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Programmer\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Spyware Doctor\svcntaux.exe
C:\Programmer\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
c:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
C:\Programmer\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmer\IBM\Messages By IBM\ibmmessages.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YTBSDK.exe
C:\Programmer\Fælles filer\Logitech\KhalShared\KHALMNPR.EXE
C:\Documents and Settings\Inge Andersen\Dokumenter\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Programmer\Java\jre1.5.0_06\bin\jucheck.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\Programmer\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Programmer\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SDTray] "C:\Programmer\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [FiksDinPC] C:\Programmer\FiksDinPC\SysRep.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Hope Draw Obj Funk] C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\BAT COMP.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [acid platform] C:\DOCUME~1\INGEAN~1\APPLIC~1\GRIDAN~1\bone default blah.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ibmmessages] C:\Programmer\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [RomeSetup.exe] C:\DOWNLO~1\ROMESE~1.EXE /r
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142627531296
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: Microsoft Agent - Unknown owner - C:\WINDOWS\system32\dllcache\freewin.exe (file missing)
O23 - Service: Microsoft Media - Unknown owner - C:\WINDOWS\system32\dllcache\Rtsecar.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Programmer\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Programmer\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 10171 bytes
Avatar billede ingelo Praktikant
11. januar 2008 - 21:26 #3
ps: det var min mening at gi 100 point for et brugbart svar, men så skal vist stille spørgsmålet igen, ik?
12. januar 2008 - 00:17 #4
SUK - du har vist 'leget' med bla. BEARSHARE
Og blevet lokket til at install [FiksDinPC] ...
Samt en masse andet skrammel / 'snavs'


Afinstaller
* BearShare (hvis det er der?)
* FiksDinPC
via
[Start][Indstilninger][Kontrolpanel][Tilføj/fjern programmer]

Genstart for at fuldføre afinstalationen...

---------------------------------------

Så gennemfør proceduren herfra -> http://www.eksperten.dk/artikler/1123
Avatar billede ingelo Praktikant
12. januar 2008 - 18:18 #5
Jeg kan jo ikke komme ind i kontrolpanel, men har fjernet FiksDinPC med Ccleaner. Desuden vedlægger jeg så en bunke logfiler fra artikel 1123

rootlog:
******************************** ROOTCHK-(28-12-07)-LOG, by ejvindh
12-01-2008 16:27:34,62

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-12 16:27:37
Windows 5.1.2600 Service Pack 2
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...

detected NTDLL code modification:
ZwOpenFile
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Programmer\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:00,32,fc,9e,c2,a9,c0,6d,0e,3a,c6,51,83,0a,0b,21,bf,24,35,85,6b,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,a9,eb,0c,d3,66,d2,3a,ed,49,8d,40,88,17,1e,c4,ee,9f,..
"khjeh"=hex:e9,11,ec,81,16,72,b5,8f,4f,b9,ff,6e,eb,f3,5a,3b,83,1d,0d,e5,c7,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:b8,00,5a,32,69,83,f4,a8,e1,9c,7e,5e,59,6b,a1,db,e7,a1,42,e7,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Programmer\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:00,32,fc,9e,c2,a9,c0,6d,0e,3a,c6,51,83,0a,0b,21,bf,24,35,85,6b,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,a9,eb,0c,d3,66,d2,3a,ed,49,8d,40,88,17,1e,c4,ee,9f,..
"khjeh"=hex:e9,11,ec,81,16,72,b5,8f,4f,b9,ff,6e,eb,f3,5a,3b,83,1d,0d,e5,c7,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:b8,00,5a,32,69,83,f4,a8,e1,9c,7e,5e,59,6b,a1,db,e7,a1,42,e7,01,..

detected NTDLL code modification:
ZwOpenFile
scanning hidden registry entries ...

detected NTDLL code modification:
ZwOpenFile
scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0

combofix:
ComboFix 08-01-11.1 - Inge Andersen 2008-01-12 17:15:26.1 - NTFSx86
Running from: C:\Documents and Settings\Inge Andersen\Dokumenter\virus osv\ComboFix.exe
.
The following files were disabled during the run:
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat


(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\Inge Andersen\Application Data\setup_dk[1].exe

.
(((((((((((((((((((((((((  Files Created from 2007-12-12 to 2008-01-12  )))))))))))))))))))))))))))))))
.

2008-01-12 17:09 . 2000-08-31 08:00    60,928    --a------    C:\WINDOWS\NirCmd.exe
2008-01-12 14:17 . 2008-01-12 14:17    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-12 14:16 . 2008-01-12 16:39    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-01-12 14:16 . 2008-01-12 14:16    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\SUPERAntiSpyware.com
2008-01-12 14:15 .     <DIR>        C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-11 22:42 . 2008-01-11 22:42    <DIR>    d--------    C:\Programmer\CCleaner
2008-01-11 15:42 . 2008-01-11 15:44    <DIR>    d--------    C:\e1c1e80afe1d6b18ce6b
2008-01-10 22:40 . 2008-01-10 22:40    4,096    --a------    C:\WINDOWS\d3dx.dat
2008-01-07 15:09 . 2008-01-07 15:09    <DIR>    d--------    C:\Programmer\Grid Ante
2007-12-30 21:08 . 2007-12-30 21:08    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\Logitech
2007-12-30 21:07 .     <DIR>        C:\Programmer\Fælles filer\LogiShared
2007-12-30 21:07 . 2007-12-30 21:07    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\Leadertech
2007-12-30 21:04 . 2007-12-30 21:04    0    --ah-----    C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-30 21:04 . 2007-12-30 21:04    0    --ah-----    C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-12-30 21:03 . 2007-12-30 21:03    <DIR>    d----c---    C:\WINDOWS\system32\DRVSTORE
2007-12-30 21:03 . 2007-04-11 15:33    1,419,024    --a------    C:\WINDOWS\system32\WdfCoInstaller01005.dll
2007-12-30 21:03 . 2007-04-11 15:33    79,376    --a------    C:\WINDOWS\system32\drivers\LMouKE.Sys
2007-12-30 21:03 . 2007-04-11 15:32    63,248    --a------    C:\WINDOWS\system32\drivers\L8042mou.Sys
2007-12-30 21:03 . 2007-04-11 15:32    56,080    --a------    C:\WINDOWS\KHALMNPR.Exe
2007-12-30 21:03 . 2007-04-11 15:32    36,112    --a------    C:\WINDOWS\system32\drivers\LMouFilt.Sys
2007-12-30 21:03 . 2007-04-11 15:32    34,832    --a------    C:\WINDOWS\system32\drivers\LHidFilt.Sys
2007-12-30 21:03 . 2007-04-11 15:32    20,496    --a------    C:\WINDOWS\system32\drivers\L8042Kbd.sys
2007-12-30 21:02 . 2007-12-30 21:02    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Logitech
2007-12-30 21:02 . 2007-04-23 04:00    163,840    --a------    C:\WINDOWS\system32\kemutb.dll
2007-12-30 21:02 . 2007-04-23 04:00    135,168    --a------    C:\WINDOWS\system32\KemUtil.dll
2007-12-30 21:02 . 2007-04-23 04:00    110,592    --a------    C:\WINDOWS\system32\KemWnd.dll
2007-12-30 21:02 . 2007-04-23 04:00    69,632    --a------    C:\WINDOWS\system32\KemXML.dll
2007-12-30 21:01 . 2007-12-30 21:01    <DIR>    d--------    C:\Programmer\Logitech
2007-12-30 21:01 .     <DIR>        C:\Programmer\Fælles filer\Logitech
2007-12-30 21:01 . 2007-12-30 21:01    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\InstallShield
2007-12-30 21:01 . 2007-12-30 21:01    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\LogiShrd
2007-12-29 16:37 . 2007-12-29 16:37    111    --a------    C:\WINDOWS\system32\data.bat
2007-12-29 16:37 . 2007-12-29 16:37    83    --a------    C:\WINDOWS\system32\data.vbs
2007-12-27 21:21 . 2007-12-27 21:33    69,456    --a------    C:\WINDOWS\hpoins05.dat
2007-12-27 21:21 . 2004-12-14 19:35    19,696    ---------    C:\WINDOWS\hpomdl05.dat
2007-12-25 00:46 . 2004-08-26 17:53    21,504    --a------    C:\WINDOWS\system32\hidserv.dll
2007-12-25 00:46 . 2004-08-26 17:53    21,504    --a------    C:\WINDOWS\system32\dllcache\hidserv.dll
2007-12-25 00:46 . 2001-10-04 16:35    12,160    --a------    C:\WINDOWS\system32\drivers\mouhid.sys
2007-12-25 00:46 . 2001-10-04 16:35    12,160    --a------    C:\WINDOWS\system32\dllcache\mouhid.sys

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 16:22    ---------    d-----w    C:\Programmer\Spyware Doctor
2008-01-12 16:21    8,419,360    --sha-w    C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-12 16:20    99,716    --sha-w    C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-12 13:08    ---------    d-----w    C:\Programmer\Fælles filer\Symantec Shared
2008-01-12 13:07    ---------    d-----w    C:\Programmer\Yahoo!
2008-01-12 12:50    ---------    d-----w    C:\Programmer\Symantec
2008-01-11 22:50    ---------    d-----w    C:\Programmer\5star Free Lines
2008-01-11 22:13    ---------    d-----w    C:\Programmer\Norton AntiVirus
2008-01-11 22:13    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-11 21:56    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-07 14:09    ---------    d-----w    C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante
2008-01-07 14:09    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2007-12-30 20:01    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2007-12-27 20:31    ---------    d-----w    C:\Programmer\HP
2007-12-07 21:30    ---------    d-----w    C:\Programmer\Mario Forever
2007-12-07 14:19    ---------    d-----w    C:\Programmer\PiX Juegos
2007-12-07 14:19    ---------    d-----w    C:\Documents and Settings\Inge Andersen\Application Data\.PiXJuegos
2007-11-23 21:18    ---------    d-----w    C:\Programmer\FiksDinPC
2007-11-23 21:18    ---------    d-----w    C:\Programmer\Fælles filer\FiksDinPC
2007-11-23 20:53    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-11-23 19:58    ---------    d-----w    C:\Programmer\Broadcom
2007-11-23 15:53    ---------    d-----w    C:\Programmer\Agnitum
2007-11-22 20:55    ---------    d-----w    C:\Documents and Settings\Inge Andersen\Application Data\fiksdinpc
2007-11-22 20:50    ---------    d-----r    C:\Documents and Settings\All Users\Application Data\fiksdinpc
2007-11-13 10:25    20,480    ----a-w    C:\WINDOWS\system32\drivers\secdrv.sys
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 02:53 25088]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-15 21:49 68856]
"acid platform"="C:\DOCUME~1\INGEAN~1\APPLIC~1\GRIDAN~1\bone default blah.exe" [2008-01-07 15:08 484352]
"DAEMON Tools"="C:\Programmer\DAEMON Tools\daemon.exe" [2007-04-03 23:29 165784]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46 1330416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-04-20 19:47 167936]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-04-20 19:43 131072]
"UC_Start"="C:\Programmer\IBM\Updater\\ucstartup.exe" [2003-10-01 00:39 49152]
"UC_SMB"="" []
"IBMPRC"="C:\IBMTOOLS\UTILS\ibmprc.exe" [2004-03-19 21:12 102400]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 49263]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-09-01 14:57 294912]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 14:49 61440]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"SDTray"="C:\Programmer\Spyware Doctor\SDTrayApp.exe" [2007-05-18 08:54 810576]
"ZoneAlarm Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Hope Draw Obj Funk"="C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\BAT COMP.exe" [2008-01-12 17:23 790016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 02:53 25088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

.
Contents of the 'Scheduled Tasks' folder
"2008-01-12 16:00:01 C:\WINDOWS\Tasks\AD31C18E918A7502.job"
- c:\docume~1\ingean~1\applic~1\gridan~1\SIZE FRAG JUMP.exe
"2008-01-12 15:12:46 C:\WINDOWS\Tasks\HPpromotions psc 1600 series.job"
- C:\Programmer\HP\Digital Imaging\bin\HP Promotions\AiOMVC\HPpromo.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-12 17:24:24
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-12 17:27:10 - machine was rebooted
ComboFix-quarantined-files.txt  2008-01-12 16:27:05
.
2008-01-12 15:39:09    --- E O F --- 

superspyware:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/12/2008 at 03:26 PM

Application Version : 3.7.1018

Core Rules Database Version : 3379
Trace Rules Database Version: 1373

Scan type      : Complete Scan
Total Scan Time : 00:59:36

Memory items scanned      : 221
Memory threats detected  : 0
Registry items scanned    : 6127
Registry threats detected : 0
File items scanned        : 27765
File threats detected    : 67

Adware.Tracking Cookie
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@1072572700[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@aa[3].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@elitehost[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@qxl.adservinginternational[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@clickbank[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@banner.cdpoker[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@710092432412044[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@click4foto[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@1066230470[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ad1.clickhype[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@www.adserver5[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@qxl.banneradministration[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@eas4.emediate[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ads1.partnerlogic[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@pacificpoker[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@005.free-counters.co[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@banners.casino[3].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@eas.apm.emediate[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ad.yieldmanager[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@hbxtracking.sueddeutsche[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ad.hbv[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ad.ofir[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@e2.emediate[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@date.ventivmedia[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ads.dk-kogebogen[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@amlocalhost.trymedia[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@cgi-bin[3].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ads2.jubii[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ad.adnet[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@clickaider[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@clicktorrent[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@mediavantage[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@adfair[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@adv.surinter[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ads.e-planning[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@bannere.fyens[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@banner.fynskemedier[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@evolnetmedia[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@partner2profit[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@1067704117[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@ad.exent[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@1070791529[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@new-pcp[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@redirect.clickshield[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@www.findalt[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@stats24[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@phpmv2[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@media.mtvnservices[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@stat.postdanmark[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@usenext[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@rambler[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@partypoker[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@shop.zanox[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@www.clash-media[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@stat.inleadmedia[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@tracking.notabenestats[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@richmedia.yahoo[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@www.torrent-finder[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@yourmedia[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@torrent-finder[1].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@adsense[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@adsense[3].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@banner.fynskemedier[2].txt
    C:\Documents and Settings\Inge Andersen\Cookies\inge andersen@banner.fynskemedier[3].txt

Malware.LocusSoftware Inc/Gen
    C:\PROGRAMMER\FIKSDINPC\UCOOKW.EXE

Adware.IWinGames
    C:\PROGRAMMER\IWIN GAMES\IWINGAMESHOOKIE.DLL

hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:58:28, on 11-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Programmer\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Spyware Doctor\svcntaux.exe
C:\Programmer\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
c:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
C:\Programmer\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmer\IBM\Messages By IBM\ibmmessages.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YTBSDK.exe
C:\Programmer\Fælles filer\Logitech\KhalShared\KHALMNPR.EXE
C:\Documents and Settings\Inge Andersen\Dokumenter\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Programmer\Java\jre1.5.0_06\bin\jucheck.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\Programmer\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Programmer\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SDTray] "C:\Programmer\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [FiksDinPC] C:\Programmer\FiksDinPC\SysRep.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Hope Draw Obj Funk] C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\BAT COMP.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [acid platform] C:\DOCUME~1\INGEAN~1\APPLIC~1\GRIDAN~1\bone default blah.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ibmmessages] C:\Programmer\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [RomeSetup.exe] C:\DOWNLO~1\ROMESE~1.EXE /r
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142627531296
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: Microsoft Agent - Unknown owner - C:\WINDOWS\system32\dllcache\freewin.exe (file missing)
O23 - Service: Microsoft Media - Unknown owner - C:\WINDOWS\system32\dllcache\Rtsecar.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Programmer\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Programmer\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 10171 bytes
Avatar billede ingelo Praktikant
12. januar 2008 - 20:05 #6
30 point er alt for lidt, for at se alt det her igennem, så den der kan hjælpe mig får et nyt og let spørgsmål, der giver 150 point!!!
Avatar billede fromsej Praktikant
12. januar 2008 - 21:09 #7
30 point eller 200, det betyder ikke et hammerslag. :-)

Derimod vil vi gerne se et par tekster mere, du har en Lop infektion.
Hent Schtasks her:
http://fromsej.dk/download/schtasks.exe
Den skal ligge i C:\windows\system32\
Hvis du bliver spurgt om den skal overskrives, så annuller download, så har du filen

allerede.

Klik på Start->Kør skriv CMD og klik OK.
I "DOS"vinduet skriver du følgende: (tryk på <Enter> efter hver linie)

schtasks /query>C:\tasks.txt
notepad C:\tasks.txt

Kopier indholdet herind.

Hent fl.zip, pak den ud og kør fl.bat - programmet laver en lille tekst fil, som du også skal kopiere herind:
http://www.ctrlaltdel.dk/Programmer/fl.zip
Avatar billede ingelo Praktikant
12. januar 2008 - 21:29 #8
Jeg håber dette er det rigtige. Du kan i hvert fald få et kæmpe tak, hvis det lykkes, det her
Opgavenavn                          N‘ste k›rsel            Status       
==================================== ======================== ===============
AD31C18E918A7502                    22:00:00, 12-01-2008                   
HPpromotions psc 1600 series        00:00:00, 13-01-2008 

Disken i drev C er IBM_PRELOAD
Diskens serienummer er 8CBC-F992

Indhold af C:\Documents and Settings\Administrator\Application Data

06-03-2003  16:25    <DIR>          Identities
25-10-2004  13:31    <DIR>          Symantec
              0 fil(er)                0 byte
              2 mappe(r)  16.820.629.504 byte ledig
Disken i drev C er IBM_PRELOAD
Diskens serienummer er 8CBC-F992

Indhold af C:\Documents and Settings\All Users\Application Data

14-12-2006  23:01    <DIR>          Adobe
14-10-2006  15:33    <DIR>          Apple Computer
18-08-2007  14:12    <DIR>          Face error funk license
22-11-2007  21:50    <DIR>          fiksdinpc
20-05-2007  21:04    <DIR>          FloodLightGames
17-10-2006  23:27    <DIR>          Google
31-03-2006  13:22    <DIR>          HP
27-12-2007  21:33            38.488 hpzinstall.log
25-10-2004  13:29    <DIR>          IBM
18-05-2007  12:58    <DIR>          iWin Games
07-01-2008  15:09    <DIR>          LICENSE FORD HOPE DRAW
30-12-2007  21:01    <DIR>          LogiShrd
30-12-2007  21:02    <DIR>          Logitech
23-11-2007  21:53    <DIR>          MailFrontier
28-03-2006  20:29    <DIR>          MSN6
23-06-2006  21:16    <DIR>          PopCap
14-10-2006  15:48            1.749 QTSBandwidthCache
11-01-2008  22:56    <DIR>          Spybot - Search & Destroy
12-01-2008  14:17    <DIR>          SUPERAntiSpyware.com
11-01-2008  23:13    <DIR>          Symantec
05-08-2007  19:52    <DIR>          TEMP
07-01-2007  20:22    <DIR>          Trymedia
03-08-2007  11:26    <DIR>          user hole send camp
10-11-2006  00:51    <DIR>          Windows Genuine Advantage
04-06-2007  13:43    <DIR>          Yahoo!
31-07-2006  12:16    <DIR>          Yahoo! Companion
              2 fil(er)          40.237 byte
              24 mappe(r)  16.820.625.408 byte ledig
Disken i drev C er IBM_PRELOAD
Diskens serienummer er 8CBC-F992

Indhold af C:\Documents and Settings\Inge Andersen\Application Data

07-12-2007  15:19    <DIR>          .PiXJuegos
26-12-2007  15:42    <DIR>          Adobe
14-12-2006  23:01    <DIR>          AdobeUM
20-08-2007  21:03    <DIR>          Apple Computer
21-10-2007  21:33    <DIR>          Azureus
22-11-2007  21:55    <DIR>          fiksdinpc
20-05-2007  21:04    <DIR>          FloodLightGames
16-04-2006  16:04            5.863 GdiplusUpgrade_MSIApproach_Wrapper.log
09-05-2007  21:14    <DIR>          GetRightToGo
23-10-2006  18:32    <DIR>          Google
07-01-2008  15:09    <DIR>          Grid Ante
23-03-2006  20:53    <DIR>          Help
23-03-2006  17:16    <DIR>          IBM
06-03-2003  16:25    <DIR>          Identities
11-09-2007  15:09    <DIR>          Image Zone Express
30-12-2007  21:01    <DIR>          InstallShield
11-11-2006  18:31    <DIR>          InterVideo
23-03-2006  17:29    <DIR>          Lavasoft
30-12-2007  21:07    <DIR>          Leadertech
29-06-2006  19:17    <DIR>          LG Electronics
21-10-2007  20:53    <DIR>          LimeWire
30-12-2007  21:08    <DIR>          Logitech
10-08-2006  10:19    <DIR>          Macromedia
23-11-2006  17:28    <DIR>          MGI
01-04-2006  22:17    <DIR>          Mozilla
28-03-2006  20:32    <DIR>          MSN6
29-12-2006  22:03    <DIR>          PC Tools
11-09-2007  15:09    <DIR>          Printer Info Cache
28-06-2007  22:21    <DIR>          Pro Cycling Manager 2007
20-04-2006  21:22    <DIR>          Sun
12-01-2008  14:16    <DIR>          SUPERAntiSpyware.com
25-10-2004  13:31    <DIR>          Symantec
22-08-2007  19:10    <DIR>          TVU Networks
09-10-2006  20:50    <DIR>          vlc
              1 fil(er)            5.863 byte
              33 mappe(r)  16.820.625.408 byte ledig
Disken i drev C er IBM_PRELOAD
Diskens serienummer er 8CBC-F992

Indhold af C:\Documents and Settings\Default User\Application Data

17-03-2006  21:30    <DIR>          .
17-03-2006  21:30    <DIR>          ..
06-03-2003  16:09                62 desktop.ini
              1 fil(er)              62 byte
              2 mappe(r)  16.820.625.408 byte ledig
Disken i drev C er IBM_PRELOAD
Diskens serienummer er 8CBC-F992

Indhold af C:\Documents and Settings\LocalService\Application Data

Disken i drev C er IBM_PRELOAD
Diskens serienummer er 8CBC-F992

Indhold af C:\Documents and Settings\NetworkService\Application Data
Avatar billede fromsej Praktikant
12. januar 2008 - 21:43 #9
Nu ved jeg godt, at det er Karise_Larry der er påbegyndt, men "Lop/C2Media" og jeg har et helt specielt forhold til hinanden, så jeg tillader mig at blande mig. :-)
Avatar billede fromsej Praktikant
12. januar 2008 - 21:59 #10
Hent Ccleaner her:
http://www.filehippo.com/download_ccleaner/
Installer Ccleaner, husk at fjerne fluebenet udfor installation af Yahoo toolbar.
Start programmet, fjern fluebenet i cookies.
Klik på kør Cleaner og lad den fjerne hvad den finder.
Klik så på Register ovre i venstre side (den blå terning), klik på Skan efter problemer, når den er færdig, klik på Udbedre valgte problemer, lav evt. en backup af registreringsdatabasen, klik så på udbedre alle valgte problemer.
Klik på OK, klik på Luk når den er færdig.
Genstart.
---------------------------------------
Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [FiksDinPC] C:\Programmer\FiksDinPC\SysRep.exe

---------------------------------------
Kopiér indholdet mellem de bølgede linier ind i Notesblok, og gem dokumentet i samme mappe, som Combofix ligger med navnet CFScript.txt.
Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

Killall::

File::
C:\WINDOWS\Tasks\AD31C18E918A7502.job

Folder::
"C:\Programmer\Grid Ante"
"C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante"
"C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW"
C:\Programmer\FiksDinPC
"C:\Programmer\Fælles filer\FiksDinPC"
"C:\Documents and Settings\Inge Andersen\Application Data\fiksdinpc"
"C:\Documents and Settings\All Users\Application Data\fiksdinpc"
"C:\Documents and Settings\All Users\Application Data\Face error funk license"
"C:\Documents and Settings\All Users\Application Data\user hole send camp"
"C:\Documents and Settings\Inge Andersen\Application Data\Azureus"
"C:\Documents and Settings\Inge Andersen\Application Data\LimeWire"

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"acid platform"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hope Draw Obj Funk"=-

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
---------------------------------------
Vi skal se en frisk hijackthislog, samt den nye combofixlog.
Avatar billede ingelo Praktikant
12. januar 2008 - 23:46 #11
ComboFix 08-01-11.1 - Inge Andersen 2008-01-12 23:25:05.2 - NTFSx86
Running from: C:\Documents and Settings\Inge Andersen\Dokumenter\virus osv\ComboFix.exe
Command switches used :: C:\Documents and Settings\Inge Andersen\Dokumenter\virus osv\CFScript.txt C:\Documents and Settings\Inge Andersen\Dokumenter\virus osv\CFScript.txt

FILE
C:\WINDOWS\Tasks\AD31C18E918A7502.job
.
The following files were disabled during the run:
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat
C:\Programmer\Spyware Doctor\klg.dat


(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Face error funk license
C:\Documents and Settings\All Users\Application Data\fiksdinpc
C:\Documents and Settings\All Users\Application Data\fiksdinpc\Data\ac
C:\Documents and Settings\All Users\Application Data\fiksdinpc\Data\em
C:\Documents and Settings\All Users\Application Data\fiksdinpc\Data\oid
C:\Documents and Settings\All Users\Application Data\fiksdinpc\Data\user
C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\BAT COMP.exe
C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\Stop Acid.exe
C:\Documents and Settings\All Users\Application Data\user hole send camp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\.certs
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\.keystore
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\.lock
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\active\31E11A79CC1777A2D2D8E72F879015B9F54CBBCF.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\active\31E11A79CC1777A2D2D8E72F879015B9F54CBBCF.dat.bak
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\active\73DB973F43A3E4C80D8B5DCEC594454B497D276C.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\active\73DB973F43A3E4C80D8B5DCEC594454B497D276C.dat.bak
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\active\75CC3837D4444B097B36D9811F2CB0E397F5E625.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\active\75CC3837D4444B097B36D9811F2CB0E397F5E625.dat.bak
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\active\cache.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\azureus.config
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\azureus.config.bak
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\azureus.statistics
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\azureus.statistics.bak
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\banips.config
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\dht\addresses.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\dht\contacts.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\dht\diverse.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\dht\general.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\dht\version.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\downloads.config
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\downloads.config.bak
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\ipfilter.cache
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\logs\alerts_1.log
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\logs\debug_1.log
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\logs\seltrace_1.log
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\logs\SpeedMan_1.log
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\logs\thread_1.log
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\logs\thread_2.log
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\net\pm_1257.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\net\pm_default.dat
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.jar
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.zip
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\plugins\azupnpav\plugin.properties
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.3
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tmp\AZU47901.tmp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tmp\AZU47902.tmp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tmp\AZU47903.tmp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tmp\AZU47904.tmp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tmp\AZU47905.tmp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tmp\AZU47906.tmp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tmp\AZU47907.tmp
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tracker.config
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\tracker.config.bak
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\update.log
C:\Documents and Settings\Inge Andersen\Application Data\Azureus\update.properties
C:\Documents and Settings\Inge Andersen\Application Data\fiksdinpc
C:\Documents and Settings\Inge Andersen\Application Data\fiksdinpc\Logs\update.log
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\0
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\bgdzmosm.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\bone default blah.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\dhhupfjn.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\dkdtvgrn.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\giqqozqa.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\gplelwgz.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\ijugpofd.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\jebvpinm.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\oarnlvio.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\pzzqfgvf.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\SIZE FRAG JUMP.exe
C:\Documents and Settings\Inge Andersen\Application Data\Grid Ante\ywbtbier.exe
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\412splashfree.png
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\414splashfree.png
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\data.ser
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\filters.props
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\gnutella.net
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\installation.props
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\library.dat
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\mojito.props
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\pub1.key
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\public.key
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\questions.props
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\responses.cache
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\secureMessage.key
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\spam.dat
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\tables.props
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\01_star.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\02_star.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\03_star.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\04_star.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\05_star.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\notsearching.png
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\splash.png
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\splashpro.png
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\update.xml
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\version.key
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\version.xml
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\data\delete_me
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\data\video.sxml
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\misc\application.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\misc\audio.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\misc\document.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\misc\image.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\misc\video.gif
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\schemas\application.xsd
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\schemas\audio.xsd
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\schemas\document.xsd
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\schemas\image.xsd
C:\Documents and Settings\Inge Andersen\Application Data\LimeWire\xml\schemas\video.xsd
C:\Programmer\Fælles filer\FiksDinPC
C:\Programmer\FiksDinPC
C:\Programmer\FiksDinPC\atl71.dll
C:\Programmer\FiksDinPC\mfc71.dll
C:\Programmer\FiksDinPC\msvcp71.dll
C:\Programmer\FiksDinPC\msvcr71.dll
C:\Programmer\FiksDinPC\Res\Main.ico
C:\Programmer\FiksDinPC\Res\RecycleBin.ico
C:\Programmer\FiksDinPC\swupd.log
C:\Programmer\FiksDinPC\SysRep.exe.Log
C:\Programmer\FiksDinPC\transpaid.exe
C:\Programmer\FiksDinPC\unins000.exe
C:\Programmer\FiksDinPC\urls.ini
C:\Programmer\Grid Ante
C:\WINDOWS\system32\m80017.exe
C:\WINDOWS\Tasks\AD31C18E918A7502.job
C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW

.
(((((((((((((((((((((((((  Files Created from 2007-12-12 to 2008-01-12  )))))))))))))))))))))))))))))))
.

2008-01-12 20:41 . 2008-01-12 22:52    323    --a------    C:\WINDOWS\system32\eq
2008-01-12 17:09 . 2000-08-31 08:00    60,928    --a------    C:\WINDOWS\NirCmd.exe
2008-01-12 14:17 . 2008-01-12 14:17    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-12 14:16 . 2008-01-12 16:39    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-01-12 14:16 . 2008-01-12 14:16    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\SUPERAntiSpyware.com
2008-01-12 14:15 .     <DIR>        C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-11 22:42 . 2008-01-11 22:42    <DIR>    d--------    C:\Programmer\CCleaner
2008-01-11 15:42 . 2008-01-11 15:44    <DIR>    d--------    C:\e1c1e80afe1d6b18ce6b
2008-01-10 22:40 . 2008-01-10 22:40    4,096    --a------    C:\WINDOWS\d3dx.dat
2007-12-30 21:08 . 2007-12-30 21:08    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\Logitech
2007-12-30 21:07 .     <DIR>        C:\Programmer\Fælles filer\LogiShared
2007-12-30 21:07 . 2007-12-30 21:07    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\Leadertech
2007-12-30 21:04 . 2007-12-30 21:04    0    --ah-----    C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-30 21:04 . 2007-12-30 21:04    0    --ah-----    C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-12-30 21:03 . 2007-12-30 21:03    <DIR>    d----c---    C:\WINDOWS\system32\DRVSTORE
2007-12-30 21:03 . 2007-04-11 15:33    1,419,024    --a------    C:\WINDOWS\system32\WdfCoInstaller01005.dll
2007-12-30 21:03 . 2007-04-11 15:33    79,376    --a------    C:\WINDOWS\system32\drivers\LMouKE.Sys
2007-12-30 21:03 . 2007-04-11 15:32    63,248    --a------    C:\WINDOWS\system32\drivers\L8042mou.Sys
2007-12-30 21:03 . 2007-04-11 15:32    56,080    --a------    C:\WINDOWS\KHALMNPR.Exe
2007-12-30 21:03 . 2007-04-11 15:32    36,112    --a------    C:\WINDOWS\system32\drivers\LMouFilt.Sys
2007-12-30 21:03 . 2007-04-11 15:32    34,832    --a------    C:\WINDOWS\system32\drivers\LHidFilt.Sys
2007-12-30 21:03 . 2007-04-11 15:32    20,496    --a------    C:\WINDOWS\system32\drivers\L8042Kbd.sys
2007-12-30 21:02 . 2007-12-30 21:02    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Logitech
2007-12-30 21:02 . 2007-04-23 04:00    163,840    --a------    C:\WINDOWS\system32\kemutb.dll
2007-12-30 21:02 . 2007-04-23 04:00    135,168    --a------    C:\WINDOWS\system32\KemUtil.dll
2007-12-30 21:02 . 2007-04-23 04:00    110,592    --a------    C:\WINDOWS\system32\KemWnd.dll
2007-12-30 21:02 . 2007-04-23 04:00    69,632    --a------    C:\WINDOWS\system32\KemXML.dll
2007-12-30 21:01 . 2007-12-30 21:01    <DIR>    d--------    C:\Programmer\Logitech
2007-12-30 21:01 .     <DIR>        C:\Programmer\Fælles filer\Logitech
2007-12-30 21:01 . 2007-12-30 21:01    <DIR>    d--------    C:\Documents and Settings\Inge Andersen\Application Data\InstallShield
2007-12-30 21:01 . 2007-12-30 21:01    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\LogiShrd
2007-12-29 16:37 . 2007-12-29 16:37    111    --a------    C:\WINDOWS\system32\data.bat
2007-12-29 16:37 . 2007-12-29 16:37    83    --a------    C:\WINDOWS\system32\data.vbs
2007-12-27 21:21 . 2007-12-27 21:33    69,456    --a------    C:\WINDOWS\hpoins05.dat
2007-12-27 21:21 . 2004-12-14 19:35    19,696    ---------    C:\WINDOWS\hpomdl05.dat
2007-12-25 00:46 . 2004-08-26 17:53    21,504    --a------    C:\WINDOWS\system32\hidserv.dll
2007-12-25 00:46 . 2004-08-26 17:53    21,504    --a------    C:\WINDOWS\system32\dllcache\hidserv.dll
2007-12-25 00:46 . 2001-10-04 16:35    12,160    --a------    C:\WINDOWS\system32\drivers\mouhid.sys
2007-12-25 00:46 . 2001-10-04 16:35    12,160    --a------    C:\WINDOWS\system32\dllcache\mouhid.sys

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 22:33    8,562,720    --sha-w    C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-12 22:32    ---------    d-----w    C:\Programmer\Spyware Doctor
2008-01-12 22:31    ---------    d-----w    C:\Programmer\5star Free Lines
2008-01-12 22:30    101,372    --sha-w    C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-12 18:45    ---------    d-----w    C:\Programmer\PiX Juegos
2008-01-12 13:08    ---------    d-----w    C:\Programmer\Fælles filer\Symantec Shared
2008-01-12 13:07    ---------    d-----w    C:\Programmer\Yahoo!
2008-01-12 12:50    ---------    d-----w    C:\Programmer\Symantec
2008-01-11 22:13    ---------    d-----w    C:\Programmer\Norton AntiVirus
2008-01-11 22:13    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-11 21:56    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-30 20:01    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2007-12-27 20:31    ---------    d-----w    C:\Programmer\HP
2007-12-07 21:30    ---------    d-----w    C:\Programmer\Mario Forever
2007-12-07 14:19    ---------    d-----w    C:\Documents and Settings\Inge Andersen\Application Data\.PiXJuegos
2007-11-23 20:53    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-11-23 19:58    ---------    d-----w    C:\Programmer\Broadcom
2007-11-23 15:53    ---------    d-----w    C:\Programmer\Agnitum
2007-11-13 10:25    20,480    ----a-w    C:\WINDOWS\system32\drivers\secdrv.sys
.

(((((((((((((((((((((((((((((  snapshot@2008-01-12_17.26.43.37  )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-12 16:13:53    233,472    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-12 22:24:43    233,472    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-12 16:13:53    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-12 22:24:43    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-12 16:13:54    233,472    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-12 22:24:43    233,472    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-12 16:13:54    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-12 22:24:44    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-12 16:13:54    4,235,264    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-12 22:24:44    4,235,264    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-12 16:13:54    102,400    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-12 22:24:44    102,400    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-12 16:20:53    16,384    ----a-w    C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-12 22:31:14    16,384    ----a-w    C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-01-12 16:20:53    32,768    ----a-w    C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\index.dat
+ 2008-01-12 22:31:14    32,768    ----a-w    C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\index.dat
- 2008-01-12 16:20:53    32,768    ----a-w    C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-12 22:31:14    32,768    ----a-w    C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-12 22:31:32    16,384    ----atw    C:\WINDOWS\Temp\Perflib_Perfdata_f4.dat
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 02:53 25088]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-15 21:49 68856]
"DAEMON Tools"="C:\Programmer\DAEMON Tools\daemon.exe" [2007-04-03 23:29 165784]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46 1330416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-04-20 19:47 167936]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-04-20 19:43 131072]
"UC_Start"="C:\Programmer\IBM\Updater\\ucstartup.exe" [2003-10-01 00:39 49152]
"UC_SMB"="" []
"IBMPRC"="C:\IBMTOOLS\UTILS\ibmprc.exe" [2004-03-19 21:12 102400]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 49263]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-09-01 14:57 294912]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 14:49 61440]
"SDTray"="C:\Programmer\Spyware Doctor\SDTrayApp.exe" [2007-05-18 08:54 810576]
"ZoneAlarm Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 02:53 25088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

.
Contents of the 'Scheduled Tasks' folder
"2008-01-12 19:00:00 C:\WINDOWS\Tasks\HPpromotions psc 1600 series.job"
- C:\Programmer\HP\Digital Imaging\bin\HP Promotions\AiOMVC\HPpromo.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-12 23:34:32
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-12 23:37:52 - machine was rebooted
ComboFix-quarantined-files.txt  2008-01-12 22:37:47
ComboFix2.txt  2008-01-12 16:27:10
.
2008-01-12 15:39:09    --- E O F --- 

-og hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:42:15, on 12-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Programmer\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Programmer\Spyware Doctor\svcntaux.exe
C:\Programmer\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\Spyware Doctor\SDTrayApp.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\Programmer\Fælles filer\Logitech\KhalShared\KHALMNPR.EXE
C:\Programmer\internet explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YTBSDK.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Documents and Settings\Inge Andersen\Dokumenter\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\Programmer\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Programmer\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142627531296
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: Microsoft Agent - Unknown owner - C:\WINDOWS\system32\dllcache\freewin.exe (file missing)
O23 - Service: Microsoft Media - Unknown owner - C:\WINDOWS\system32\dllcache\Rtsecar.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Programmer\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Programmer\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7470 bytes

denne her O4 - HKLM\..\Run: [FiksDinPC] C:\Programmer\FiksDinPC\SysRep.exe, kunne jeg ikke finde på min liste. Jeg er selvlærd amatør-bruger, så er lidt spændt på, om jeg stadig får gjort, det du ber om ;-)
Avatar billede fromsej Praktikant
13. januar 2008 - 10:00 #12
Amatør i ordets positive betydning er nu ikke det værste der findes.
Titanic blev bygget af eksperter, Noahs ark af en glad amatør. ;-)

Så er din log ren, vi behøver ikke se flere.
Se her hvordan du "nulstiller" systemgendannelse.
http://spywarefri.dk/virusscannere.htm#alle - Systemgendannelse.

For at holde den ren kan du kigge på vores pakke til formålet.
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm
Som minimum anbefaler jeg Spywareguard, Spywareblaster, Zoned-out og IE Privacy Keeper.
Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
http://fromsej.dk/html/avoid.html
Mvh:
Fromsej/Team Spywarefri.
Avatar billede ingelo Praktikant
13. januar 2008 - 13:50 #13
Mange tak for hjælpen Fromsej. Og så kan jeg jo se på disse logs, at selvom man afinstallerer mistænkelige downloads, så bliver der altid gemt et eller andet, som holder døren på klem, så "katten" stadig kan komme ind
Mvh. Inge
Avatar billede fromsej Praktikant
13. januar 2008 - 14:15 #14
Velbekomme. :-)

Ja banditterne bliver bedre og bedre til at skjule sig, heldigvis bliver vi også bedre til at finde dem, takket være de mennesker der udvikler på renseværktøjerne.

Karise_Larry skal lige komme med et svar, så skal du markere begge navne i boksen og klikke på accepter, så er spørgsmålet her afsluttet korrekt.
Avatar billede ingelo Praktikant
13. januar 2008 - 15:30 #15
Jeg troede alt nu var i orden, men kan stadig ikke åbne mapper i kontrolpanelet og heller ikke åbne egenskaber i "Denne computer" så.....
Avatar billede fromsej Praktikant
13. januar 2008 - 16:57 #16
Prøv dette:
Klik på Start->Kør skriv SFC /scannow (bemærk mellemrum), klik OK.
Din XP-CD skal sidde i drevet.
Genstart, se om det hjalp.
13. januar 2008 - 17:21 #17
Så er jeg (lidt) tilbage...

PS: Har du NERO instaleret ?

Så pas dog på med disse P2P programmer alá BEARSHARE !!!
Avatar billede ingelo Praktikant
28. januar 2008 - 20:08 #18
Undskyld jeg ikke har fået spørgsmålet afsluttet, men min XP-CD er væk!! -har ikke fået en anden endnu. Jeg giver fromsej mine point, da jeg i hvert fald har fået fjernet en del irriterende hændelser.
Når CD´en kommer, stiller jeg et nyt spørgsmål, hvis ikke forslaget om scannow virker,
Mvh Inge
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester