Avatar billede Slettet bruger
18. januar 2008 - 17:43 Der er 10 kommentarer og
1 løsning

Har fået noget via MSN

Hej eksperter

Min datter fik en fil på MSN. Det var en zip-fil. Den åbnede hun. Der var et billede i. Det åbnede hun. Og siden har maskinen gjort ting, vi ikke kan lide. Vi har Avast-antivirus.

Avast e-postskanner-ikonet står jævnt hen og blafrer nede i programbakken. Men vi kan ikke nå at læse, hvad det er, den sender eller modtager.

Filen, hun modtog hed img_397-jpeg.zip (108 KB).

Efter at have fulgt vejledningen i fromsejs 'SuperAntiSpyware (kombineret med Dr.Web)'-artikel http://www.eksperten.dk/artikler/954 har jeg startet maskinen i normal tilstand. Og nu er der ro. Avast står ikke hele tiden og viser at der sendes post. Puha!

Men jeg står nu med tre logfiler. Er der nogen, der godt vil kigge dem igennem og hjælpe mig med at fjerne eventuelle overlevende virus, adware og orme?

På forhånd tak for det store arbejde, I udfører her på siden.

mvh
Jørn Hansen

*** Kørsel af DrWeb
******************************

Process.exe;C:\Documents and Settings\Marie\Skrivebord\MSNFix\incl;Tool.Prockill;Renamed.;
POSTOOBE.NEC;C:\DRIVERS;VBS.Generic.278;Deleted.;
CTMDEngU.dll;C:\Programmer\Creative\ZENcast Organizer;Adware.BookedSpace.origin;Renamed.;
A0039965.exe;C:\System Volume Information\_restore{4D25720C-D913-4297-878B-534CFAB8E819}\RP263;Tool.Prockill;Renamed.;
A0039966.dll;C:\System Volume Information\_restore{4D25720C-D913-4297-878B-534CFAB8E819}\RP263;Adware.BookedSpace.origin;Renamed.;

*** Kørsel af SuperAntiSpyware
******************************

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/18/2008 at 07:19 AM

Application Version : 3.9.1008

Core Rules Database Version : 3380
Trace Rules Database Version: 1374

Scan type      : Complete Scan
Total Scan Time : 01:12:13

Memory items scanned      : 222
Memory threats detected  : 0
Registry items scanned    : 6131
Registry threats detected : 0
File items scanned        : 40348
File threats detected    : 129

Adware.Tracking Cookie
    C:\Documents and Settings\Marie\Cookies\marie@fastclick[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.googleadservices[5].txt
    C:\Documents and Settings\Marie\Cookies\marie@statse.webtrendslive[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@stat.inleadmedia[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@media.mtvnservices[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@hit.stat[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@m1.webstats.motigo[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@mybannercreator[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@atwola[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@specificclick[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@ad.adocean[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@revsci[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.googleadservices[3].txt
    C:\Documents and Settings\Marie\Cookies\marie@mediaplex[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ads.pointroll[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@questionmarket[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@spamfighter.112.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@bs.serving-sys[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ads[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@adtech[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@precisionclick[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@advertising[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@imrworldwide[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@track.adform[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@shinystat[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@doubleclick[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@list[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@statcounter[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@burstnet[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.googleadservices[6].txt
    C:\Documents and Settings\Marie\Cookies\marie@gamefinder.disney.go[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@eyewonder[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@clickbank[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ehg-bskyb.hitbox[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@telmore.112.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@atdmt[3].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.burstnet[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ehg-twi.hitbox[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@eas4.emediate[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.googleadservices[4].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.zanox-affiliate[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@saxocom.112.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@hitbox[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@ad.yieldmanager[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@ads.myyearbook[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ad1.emediate[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@www5.addfreestats[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@tradedoubler[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@track.webgains[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@toplist[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@serving-sys[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@tacoda[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@eas.apm.emediate[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@saxoomis.122.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@overture[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ehg-oreilly.hitbox[2].txt
    C:\Documents and Settings\Hanne\Cookies\hanne@imrworldwide[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@2o7[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@ad.yieldmanager[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@ad1.emediate[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@adbrite[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@adopt.specificclick[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@ads.adbrite[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@adserver.banneradministration[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@advertising[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@as-eu.falkag[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@as1.falkag[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@atdmt[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@banner.fynskemedier[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@bluestreak[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@bs.serving-sys[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@casalemedia[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@cbs.112.2o7[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@counter.hitslink[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@eas.apm.emediate[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@eas4.emediate[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@edsa.122.2o7[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@ehg-techtarget.hitbox[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@ehg-ti.hitbox[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@fastclick[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@fortunecity[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@hitbox[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@ilead.itrack[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@imrworldwide[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@indextools[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@jobzonen.112.2o7[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@mediaplex[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@ncom.banneradministration[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@questionmarket[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@revenue[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@revsci[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@saxobfdk.122.2o7[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@serving-sys[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@specificclick[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@statcounter[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@tacoda[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@track.adform[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@tracking.notabenestats[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@tradedoubler[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@tribalfusion[1].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@www.googleadservices[2].txt
    C:\Documents and Settings\Jorn\Cookies\jorn@www.jobfinder[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@3.adbrite[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@4.adbrite[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@ad.uk.tangozebra[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ad.zanox[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ads.aol.co[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@ads.cartoonnetwork[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ads2.jubii[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@as1.falkag[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@atdmt[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@casalemedia[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@cbs.112.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@dhs.click2dial[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@e2.emediate[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@edsa.122.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@imrworldwide[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@lenovo.112.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@m1.webstats4u[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@media.adrevolver[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@ncom.banneradministration[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@saxobfdk.122.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@smileycentral[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@tribalfusion[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.googleadservices[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@www.googleadservices[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@zedo[1].txt

*** HiJackThis
***********************

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:29:36, on 18-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Intel\Wireless\Bin\OProtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Programmer\TortoiseSVN\bin\TSVNCache.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Apps\Powercinema\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Intel\Wireless\Bin\EOUWiz.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Picasa2\PicasaMediaDetector.exe
C:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Programmer\Fælles filer\Teleca Shared\CapabilityManager.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\entvnvaqmu.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
C:\drweb\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programmer\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Programmer\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Programmer\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Programmer\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Genvej til egenskabsside for High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Programmer\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YeppStudioAgent] C:\Programmer\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [vfdccgnsc] C:\WINDOWS\system32\vfdccgnsc.exe
O4 - HKLM\..\Run: [entvnvaqmu] C:\WINDOWS\system32\entvnvaqmu.exe
O4 - HKLM\..\RunServices: [entvnvaqmu] C:\WINDOWS\system32\entvnvaqmu.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Programmer\OpenOffice.org 2.1\program\quickstart.exe
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: HP Klipsamling - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart markering - {700259D7-1666-479a-93B1-3250410481E8} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\dan.htm
O16 - DPF: LearnKey LTF Applet - file:///C:/WINDOWS/system32/lktest.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171562397098
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://tst.klubif.dk/admin/Editors/Upload/XUpload.ocx
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Print Spooler Service (o4u8koeanywoa) - Unknown owner - C:\WINDOWS\system32\vfdccgnsc.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\Programmer\xampp\service.exe (file missing)

--
End of file - 12235 bytes
18. januar 2008 - 22:33 #1
Yffer Pyffer...

... der er stadig 'snavs' tilbage - så gennemfør proceduren herfra -> http://www.eksperten.dk/artikler/1123
Avatar billede Slettet bruger
19. januar 2008 - 00:54 #2
Hej Karise_larry

Jeg opdagede artikel http://www.eksperten.dk/artikler/1124 og http://www.eksperten.dk/artikler/1123 bagefter jeg havde sendt spørgsmålet. Jeg tror at det lykkedes at fjerne skidtet ved at køre MSNFIX.BAT fra http://sosvirus.changelog.fr/MSNFix.zip

Jeg har ikke fået lavet logfiler. Men når jeg kigger i Comodo firewall er der nu ikke længere kontaktforsøg på port 25.

Hvis den begynder at lave mærkelige ting, opretter jeg et nyt spørgsmål, hvor jeg følger artikel 1124 og 1123 og uploader logfiler.

Tak for hjælpen. Læg et svar. Jeg vil gerne af med mine point :-)

mvh
Jørn Hansen
19. januar 2008 - 08:29 #3
... ifølge Logggen [17:29:36, on 18-01-2008] ER der 'snavs' så du bør (=skal) rulle proceduren i http://www.eksperten.dk/artikler/1123 - og jeg vil se/læse logfilerne ...
Ellers ingen garanti...
Avatar billede Slettet bruger
19. januar 2008 - 23:15 #4
Hej Karise_larry.

Jeg får lige gjort det i løbet af weekenden. Så håber jeg at du kan se på det først i næste uge.
20. januar 2008 - 08:32 #5
OK ...
Avatar billede Slettet bruger
20. januar 2008 - 19:42 #6
Hej igen

Så har jeg fået gennemført artikel 1123. Jeg håber at du (karise_larry) vil se logfiler igennem og hjælpe mig af med det evt. sidste.

mvh
Jørn Hansen

*** Logfil fra SAS
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/20/2008 at 03:05 PM

Application Version : 3.7.1018

Core Rules Database Version : 3384
Trace Rules Database Version: 1378

Scan type      : Complete Scan
Total Scan Time : 01:08:00

Memory items scanned      : 192
Memory threats detected  : 0
Registry items scanned    : 6107
Registry threats detected : 0
File items scanned        : 38546
File threats detected    : 14

Adware.Tracking Cookie
    C:\Documents and Settings\Marie\Cookies\marie@ad1.emediate[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@adtech[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@adtech[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@atdmt[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@bs.serving-sys[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@doubleclick[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@imrworldwide[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@mediaplex[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@saxoomis.122.2o7[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@serving-sys[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@statcounter[2].txt
    C:\Documents and Settings\Marie\Cookies\marie@track.adform[1].txt
    C:\Documents and Settings\Marie\Cookies\marie@track.adform[3].txt
    C:\Documents and Settings\Marie\Cookies\marie@tribalfusion[1].txt

*** HiJackThis

Logfile of HijackThis v1.99.1
Scan saved at 18:13:32, on 20-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Programmer\Comodo\Firewall\cmdagent.exe
C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\OProtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Apps\Powercinema\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Intel\Wireless\Bin\EOUWiz.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Picasa2\PicasaMediaDetector.exe
C:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\Fælles filer\Teleca Shared\CapabilityManager.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
C:\Programmer\MSN Messenger\usnsvc.exe
C:\Programmer\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\drweb\alternativ.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programmer\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Programmer\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Programmer\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Programmer\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Genvej til egenskabsside for High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Programmer\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programmer\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\RunServices: [entvnvaqmu] C:\WINDOWS\system32\entvnvaqmu.exe
O4 - HKLM\..\RunServices: [vfdccgnsc] C:\WINDOWS\system32\vfdccgnsc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: HP Klipsamling - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart markering - {700259D7-1666-479a-93B1-3250410481E8} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\dan.htm
O16 - DPF: LearnKey LTF Applet - file:///C:/WINDOWS/system32/lktest.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171562397098
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://tst.klubif.dk/admin/Editors/Upload/XUpload.ocx
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programmer\Comodo\Firewall\cmdagent.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\Programmer\xampp\service.exe (file missing)

*** rootchk
(Når rootchk kører råber Avast op om trojanere i ...lokale)********************************* ROOTCHK-(28-12-07)-LOG, by ejvindh
20-01-2008 18:17:54,80

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 18:18:04
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
IPC error: 2 Den angivne fil blev ikke fundet.

scanning hidden services & system hive ...
IPC error: 2 Den angivne fil blev ikke fundet.

scanning hidden registry entries ...

scanning hidden files ...
IPC error: 2 Den angivne fil blev ikke fundet.

hidden processes: 0
hidden services: 0
hidden files: 0

*** combofix
(Når combofix starter får jeg en meddelelse: Swreg.cfexe – Programfejl
Instruktionen ved ”0x7c9111de” refererede hukommelse ved ”0x4ffffe49”. Hukommelsen kunne ikke ”read”.)

Men combofix k'rer derefter uden at finde noget. Der sker ingen genstart. Programmet slutter bare.

ComboFix 08-01-20.1 - Marie 2008-01-20 18:48:37.3 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.1411 [GMT 1:00]
Running from: C:\drweb\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\AutoRun.inf

.
(((((((((((((((((((((((((  Files Created from 2007-12-20 to 2008-01-20  )))))))))))))))))))))))))))))))
.

2008-01-20 18:19 . 2000-08-31 08:00    51,200    --a------    C:\WINDOWS\NirCmd.exe
2008-01-19 00:39 . 2008-01-19 00:39    <DIR>    d--------    C:\Programmer\MSN Messenger
2008-01-18 22:53 . 2008-01-18 22:53    <DIR>    d--------    C:\Documents and Settings\Marie\Application Data\Comodo
2008-01-18 22:53 . 2008-01-18 22:53    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Comodo
2008-01-18 22:43 . 2008-01-18 22:43    <DIR>    d--------    C:\Programmer\Comodo
2008-01-18 22:43 . 2007-01-05 22:45    288    --a------    C:\boot.ini.comodofirewall
2008-01-18 17:57 . 2008-01-18 17:57    <DIR>    d--------    C:\Programmer\CCleaner
2008-01-18 17:56 . 2008-01-18 17:56    <DIR>    d--------    C:\Documents and Settings\Marie\Application Data\HP
2008-01-17 20:09 . 2008-01-17 20:09    <DIR>    d--------    C:\Documents and Settings\Marie\DoctorWeb
2008-01-17 00:37 . 2008-01-20 18:17    <DIR>    d--------    C:\drweb
2008-01-17 00:37 . 2008-01-17 00:37    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-17 00:36 . 2008-01-20 13:57    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-01-17 00:36 . 2008-01-20 13:49    <DIR>    d--------    C:\Documents and Settings\Marie\Application Data\SUPERAntiSpyware.com
2008-01-16 22:44 . 2008-01-16 22:59    <DIR>    d--------    C:\Programmer\Windows Live Safety Center
2008-01-16 22:26 . 2008-01-16 22:59    <DIR>    d--------    C:\Programmer\NoAdware5.0
2008-01-16 18:32 . 2008-01-16 18:32    <DIR>    d--------    C:\Programmer\Lavasoft
2008-01-16 18:32 . 2008-01-16 18:33    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 17:43    ---------    d-----w    C:\Documents and Settings\Marie\Application Data\OpenOffice.org2
2008-01-20 12:48    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-18 22:39    ---------    d-----w    C:\Programmer\eMule
2008-01-18 21:46    ---------    d-----w    C:\Programmer\manuals
2008-01-16 22:51    ---------    d-----w    C:\Programmer\Fælles filer\Microsoft Shared
2008-01-15 19:33    ---------    d-----w    C:\Documents and Settings\Marie\Application Data\HPAppData
2008-01-12 23:13    ---------    d-----w    C:\Documents and Settings\Jorn\Application Data\OpenOffice.org2
2007-12-14 10:32    12,632    ----a-w    C:\WINDOWS\system32\lsdelete.exe
2007-12-13 21:13    ---------    d-----w    C:\Programmer\WorldCommunityGrid
2007-12-13 21:08    ---------    d-----w    C:\Programmer\Mozilla Thunderbird
2007-12-13 18:57    ---------    d-----w    C:\Programmer\Java
2007-12-08 19:33    ---------    d-----w    C:\Programmer\DetGodeProgram
2007-12-04 14:56    93,264    ----a-w    C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55    94,544    ----a-w    C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53    23,152    ----a-w    C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51    42,912    ----a-w    C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49    26,624    ----a-w    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04    837,496    ----a-w    C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54    95,608    ----a-w    C:\WINDOWS\system32\AVASTSS.scr
2007-11-07 09:28    723,456    ----a-w    C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:28    723,456    ------w    C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:26    3,590,656    ----a-w    C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20    360,064    ------w    C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:44    1,291,776    ----a-w    C:\WINDOWS\system32\quartz.dll
2007-10-29 22:44    1,291,776    ------w    C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-25 16:43    8,472,064    ----a-w    C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 08:28    222,720    ----a-w    C:\WINDOWS\system32\wmasf.dll
2007-10-25 08:28    222,720    ----a-w    C:\WINDOWS\system32\dllcache\wmasf.dll
.

(((((((((((((((((((((((((((((  snapshot@2008-01-20_18.26.19,12  )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-20 17:40:14    16,384    ----atw    C:\WINDOWS\Temp\Perflib_Perfdata_79c.dat
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
2007-03-02 16:52    1298024    -ra------    C:\Programmer\HP\Smart Web Printing\hpswp_printenhancer.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
2007-03-02 16:52    177768    -ra------    C:\Programmer\HP\Smart Web Printing\hpswp_framework.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00 15360]
"msnmsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55 5674352]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46 1318128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 13:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00 455168]
"Genvej til egenskabsside for High Definition Audio"="HDAShCut.exe" [2005-01-07 16:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-05-25 14:37 14477312 C:\WINDOWS\RTHDCPL.EXE]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2005-06-20 10:50 729178]
"AGRSMMSG"="AGRSMMSG.exe" [2005-05-11 12:12 88204 C:\WINDOWS\AGRSMMSG.exe]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 12:48 127118]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"IntelWireless"="C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 10:27 385024]
"EOUApp"="C:\Programmer\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 10:31 356352]
"Sony Ericsson PC Suite"="C:\Programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17 159744]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-12-25 12:57 155648]
"Picasa Media Detector"="C:\Programmer\Picasa2\PicasaMediaDetector.exe" [2007-06-16 00:15 366400]
"VirtualCloneDrive"="C:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 14:21 94208]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-01-13 09:47 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-01-13 09:47 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-01-13 09:46 135168]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"COMODO Firewall Pro"="C:\Programmer\Comodo\Firewall\CPF.exe" [2008-01-18 22:43 1115728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"entvnvaqmu"="C:\WINDOWS\system32\entvnvaqmu.exe" [ ]
"vfdccgnsc"="C:\WINDOWS\system32\vfdccgnsc.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 13:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FÆLLES~1\MICROS~1\DW\dwtrig20.exe" [ ]

C:\Documents and Settings\Jorn\Menuen Start\Programmer\Start\
BgInfo.lnk - C:\Programmer\utils\Bginfo.exe [2006-10-26 19:20:46 741421]
OpenOffice.org 2.2.lnk - C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe [2007-03-22 02:53:44 393216]
World Community Grid Agent.lnk - C:\Programmer\WorldCommunityGrid\UD.EXE [2005-04-29 14:12:42 482816]

C:\Documents and Settings\Marie\Menuen Start\Programmer\Start\
OpenOffice.org 2.2.lnk - C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe [2007-03-22 02:53:44 393216]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
HP Digital Imaging Monitor.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Programmer\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 10:27 110592 C:\Programmer\Intel\Wireless\Bin\LgNotify.dll

R0 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 22:07]
R2 HPSLPSVC;HP Network Devices Support;C:\WINDOWS\system32\svchost.exe [2004-08-27 13:00]
S3 SE2Cbus;Sony Ericsson Device 044 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cbus.sys [2006-05-15 14:56]
S3 SE2Cmdfl;Sony Ericsson Device 044 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Cmdfl.sys [2006-05-15 14:56]
S3 SE2Cmdm;Sony Ericsson Device 044 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Cmdm.sys [2006-05-15 14:56]
S3 SE2Cmgmt;Sony Ericsson Device 044 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cmgmt.sys [2006-05-15 14:56]
S3 se2Cnd5;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se2Cnd5.sys [2006-05-15 14:56]
S3 SE2Cobex;Sony Ericsson Device 044 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Cobex.sys [2006-05-15 14:56]
S3 se2Cunic;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se2Cunic.sys [2006-05-15 14:56]
S3 WmaCDriverV32;WmaCDriverV32;C:\WINDOWS\system32\drivers\WmaCDriverV32.sys [2007-06-04 12:17]
S3 XAMPP;XAMPP Service;C:\Programmer\xampp\service.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12    REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt    REG_MULTI_SZ      hpqcxs08 hpqddsvc
HPService    REG_MULTI_SZ      HPSLPSVC

.
Contents of the 'Scheduled Tasks' folder
"2008-01-20 17:43:31 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Programmer\Windows Defender\MpCmdRun.exe
"2008-01-07 17:30:00 C:\WINDOWS\Tasks\Packard Bell Data Secure for Jorn.job"
- C:\APPS\DataSecure\PBBackup.exe
"2006-10-21 13:15:36 C:\WINDOWS\Tasks\Registreringspåmindelse 3.job"
20. januar 2008 - 21:54 #7
Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\RunServices: [entvnvaqmu] C:\WINDOWS\system32\entvnvaqmu.exe
O4 - HKLM\..\RunServices: [vfdccgnsc] C:\WINDOWS\system32\vfdccgnsc.exe

O9 - Extra button: HP Klipsamling - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart markering - {700259D7-1666-479a-93B1-3250410481E8} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\Programmer\xampp\service.exe (file missing)

Genstart normalt

Slet følgende filer/mapper - hvis de stadig findes:

PS: For at kunne se alle filer og mapper, så følg denne vejledning:
http://www.spywareinfo.dk/tip-og-tricks/mappeindstillinger.htm

C:\Programmer\eMule <- Hele mappen *SUK* http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=40284
C:\WINDOWS\system32\entvnvaqmu.exe
C:\WINDOWS\system32\vfdccgnsc.exe

Kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

------------------------------------------------------------------------

Tag en omgang med CCleaner - som du allerede har - specielt punktet [Problemer/Register] ...
20. januar 2008 - 21:56 #8
Hovsa - dette skal lige køres først ->

Klik på Start->Kør skriv Services.msc og klik OK.
Find Tjenesten
* entvnvaqmu
* vfdccgnsc
stop den hvis den kører, højreklik på den og vælg Starttype Deaktiveret.
Avatar billede Slettet bruger
21. januar 2008 - 18:22 #9
Her er en ny omgang hijackthis.

mvh
Jørn Hansen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:20, on 2008-01-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Programmer\Comodo\Firewall\cmdagent.exe
C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\OProtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Apps\Powercinema\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Intel\Wireless\Bin\EOUWiz.exe
C:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmer\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Fælles filer\Teleca Shared\CapabilityManager.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
C:\Programmer\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\drweb\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programmer\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Programmer\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Programmer\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Programmer\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Genvej til egenskabsside for High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Programmer\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programmer\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\dan.htm
O16 - DPF: LearnKey LTF Applet - file:///C:/WINDOWS/system32/lktest.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171562397098
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://tst.klubif.dk/admin/Editors/Upload/XUpload.ocx
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programmer\Comodo\Firewall\cmdagent.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\Programmer\xampp\service.exe (file missing)

--
End of file - 10677 bytes
21. januar 2008 - 20:05 #10
Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...
Avatar billede Slettet bruger
22. januar 2008 - 15:05 #11
Tak for hjælpen. Og tak for de sidste tips.

mvh
Jørn Hansen
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester