Avatar billede ahv Nybegynder
20. januar 2008 - 13:48 Der er 10 kommentarer og
1 løsning

MSN Virus: Hjælp til logfiler

Hej Eksperter,

En af mine venner har desværre fået en MSN virus, hvilket jeg nu prøver at hjælpe hende af med.

Hun har fulgt følgende vejledning:
http://www.eksperten.dk/artikler/1021

Hvilket resulterede i følgende logfiler som jeg behøver hjælp til, hvad der skal renses i bl.a. HiJackThis.

- - - - -  - - - - - - EWIDO LOGFIL - - - - - - - - - - -
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            01:40:49, 20-01-2008
+ Report-Checksum:        B5385D87

+ Scan result:

    C:\Documents and Settings\Pernille\Cookies\pernille@ads10.bpath[1].txt -> Spyware.Cookie.Bpath : Cleaned with backup
    C:\Documents and Settings\Pernille\Cookies\pernille@ads14.bpath[1].txt -> Spyware.Cookie.Bpath : Cleaned with backup
    C:\Documents and Settings\Pernille\Cookies\pernille@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\Pernille\Cookies\pernille@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
    C:\Documents and Settings\Pernille\Cookies\pernille@trafic[1].txt -> Spyware.Cookie.Trafic : Cleaned with backup
    C:\Documents and Settings\Pernille\Cookies\pernille@www.myaffiliateprogram[2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup

::Report End


- - - - -  - - - - - - SAS LOGFIL - - - - - - - - - - -

SUPERAntiSpyware Scan Log
Generated 01/19/2008 at 11:22 PM

Application Version : 3.5.1016

Core Rules Database Version : 3384
Trace Rules Database Version: 1378

Scan type      : Complete Scan
Total Scan Time : 01:13:51

Memory items scanned      : 183
Memory threats detected  : 0
Registry items scanned    : 6372
Registry threats detected : 0
File items scanned        : 33074
File threats detected    : 127

Adware.Tracking Cookie
    C:\Documents and Settings\Pernille\Cookies\pernille@mediaonenetwork[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@rambler[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@smartadserver[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@specificclick[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.vg.basefarm[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@tracking.dc-storm[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@microsoftwllivemkt.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@questionmarket[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@perf.overture[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@warnerbrothersrecords.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@xiti[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@login.tracking101[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.adsag[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@anad.tacoda[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@s[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@serving-sys[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@server.iad.liveperson[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adtech[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ad[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@eas.apm.emediate[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@pulz.banneradministration[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@mb[3].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@stat.katalysatormedia[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@bonnier.banneradministration[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@realmedia[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.l-word[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.contactmusic[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@cbs.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@mtg.banneradministration[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@web-stat[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ad1.emediate[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@6658999[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@tacoda[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@trafficmp[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@tripod[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@oasc02.247realmedia[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@picturetheloan[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@www.burstbeacon[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@belnk[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adserver[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adopt.specificclick[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@tunefind[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.pointroll[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adfair[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@atdmt[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@m1.webstats4u[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@track.adform[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.adbrite[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@eas4.emediate[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@dist.belnk[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adopt.euroclick[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@advertising[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adcentriconline[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@cgi-bin[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@overture[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@vialogoonline.112.2o7[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ad.ofir[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@mediablvd.us.intellitxt[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@1072674847[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@bs.serving-sys[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@a[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@tribalfusion[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adbrite[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@atwola[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@revsci[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@banner.bolddk[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adinterax[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@brightcove.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@1070527576[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@e2.emediate[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@saxoomis.122.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@members.tripod[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adserver.banneradministration[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@tscounter[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@as1.falkag[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@wrigley.122.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@viacomedycentralrl.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@247realmedia[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@list[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@4.adbrite[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@track.webgains[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adserve.v-store.co[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@monstersandcritics.advertserve[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@mediablvd[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@www.mediablvd[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@neocounter.neoworx-blog-tools[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@findbolig[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@windowsmedia[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.lookery[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads2.jubii[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@1070926688[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ad.adtoma[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@tracking.notabenestats[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@jobzonen.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@keywordmax[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.guardian.co[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@www.searchenginetracking[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ad.zanox[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@audit.median[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@m1.webstats.motigo[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@rocku.adbureau[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@politiken.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ad.directanetworks[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@date.ventivmedia[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@cbsdigitalmedia.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@www.findbolig[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@adfarm1.adition[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@stat.onestat[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@data3.perf.overture[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@edsa.122.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@videoegg.adbureau[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@saxobfdk.122.2o7[2].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@acvs.mediaonenetwork[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.lookery[3].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@ads.softure[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@lastminute.112.2o7[1].txt
    C:\Documents and Settings\Pernille\Cookies\pernille@counter[2].txt
    C:\Documents and Settings\Pernille\Lokale indstillinger\Temp\Cookies\pernille@advertising[1].txt
    C:\Documents and Settings\Pernille\Lokale indstillinger\Temp\Cookies\pernille@atdmt[2].txt
    C:\Documents and Settings\Pernille\Lokale indstillinger\Temp\Cookies\pernille@msnportal.112.2o7[1].txt
    C:\WINDOWS\Temp\Cookies\pernille@adserver.banneradministration[1].txt
    C:\WINDOWS\Temp\Cookies\pernille@mtg.banneradministration[1].txt
    C:\WINDOWS\Temp\Cookies\pernille@track.adform[1].txt
    C:\WINDOWS\Temp\Cookies\pernille@tradedoubler[1].txt


- - - - -  - - - - - - HIJACKTHIS LOGFIL - - - - - - - - - - -

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:36:27, on 20-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Network Associates\Common Framework\FrameworkService.exe
C:\Programmer\Network Associates\VirusScan\Mcshield.exe
C:\Programmer\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Mindjet\MindManager 6\MMReminderService.exe
C:\Programmer\Network Associates\VirusScan\SHSTAT.EXE
C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe
C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe
C:\Programmer\QuickTime\QTTask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe
C:\Programmer\KNet Utility\KNet Utility.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\HPQ\SHARED\HPQWMI.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\OpenOffice.org 2.0\program\soffice.exe
C:\Programmer\OpenOffice.org 2.0\program\soffice.BIN
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Pernille\Skrivebord\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O2 - BHO: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Programmer\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [MMReminderService] C:\Programmer\Mindjet\MindManager 6\MMReminderService.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Programmer\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [xri] C:\WINDOWS\system32\xri.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [pdfSaver3] "C:\Programmer\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [K-Net Utility] "C:\Programmer\KNet Utility\KNet Utility.exe" -winstart
O4 - HKCU\..\Run: [updateMgr] C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Programmer\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Programmer\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://intern.diplom-is.dk/msrdp.cab
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\Player\__CDS2.DLL (file missing)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Programmer\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Print Spooler Service (ybaie7ica2radu) - Unknown owner - C:\WINDOWS\system32\xri.exe

--
End of file - 11662 bytes


Der blev vist ikke fundet nogle problemer, da hun kørte Dr.Web og derfor er der ingen logfil derfra.
Kan i hjælpe med at rense det sidste ud via hijackthis, hvis der skulle være noget tilbage?

Tak for hjælpen,
Alexander Holm Viborg
Avatar billede fromsej Praktikant
20. januar 2008 - 14:14 #1
Desværre er den artikel håbløst uddateret, jeg tager lige fat i forfatteren, så han kan få den skrevet om.
Der mangler en meget vigtig log.

Hent Combofix, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

-- Kør så combofix.exe, og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.
Avatar billede ahv Nybegynder
20. januar 2008 - 15:15 #2
Her er logfilen fra combofix;

ComboFix 08-01-20.1 - Pernille 2008-01-20 14:58:47.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.177 [GMT 1:00]
Running from: C:\Documents and Settings\Pernille\Lokale indstillinger\Temporary Internet Files\Content.IE5\GJUJZRV8\ComboFix[1].exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((  Files Created from 2007-12-20 to 2008-01-20  )))))))))))))))))))))))))))))))
.

2008-01-20 14:56 . 2000-08-31 08:00    51,200    --a------    C:\WINDOWS\NirCmd.exe
2008-01-19 17:41 . 2008-01-19 17:41    <DIR>    d--------    C:\Documents and Settings\Pernille\DoctorWeb
2008-01-19 17:07 . 2008-01-20 12:57    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-01-19 17:07 . 2008-01-19 17:07    <DIR>    d--------    C:\Documents and Settings\Pernille\Application Data\SUPERAntiSpyware.com
2008-01-19 17:07 . 2008-01-19 17:07    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-19 17:06 .     <DIR>        C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-16 22:11 . 2008-01-16 22:14    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-16 21:49 . 2006-11-29 13:06    3,426,072    --a------    C:\WINDOWS\system32\d3dx9_32.dll
2008-01-16 21:48 . 2008-01-16 21:48    <DIR>    d--------    C:\Programmer\Microsoft SQL Server Compact Edition
2008-01-15 20:26 . 2008-01-15 20:24    131,072    --a------    C:\WINDOWS\system32\xri.exe
2008-01-04 21:28 . 2007-10-11 00:52    6,065,664    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-04 21:28 . 2007-07-01 04:31    2,455,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-04 21:28 . 2007-07-01 04:36    1,015,808    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-04 21:28 . 2007-10-11 00:52    459,264    ---------    C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-04 21:28 . 2007-10-11 00:52    383,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-04 21:28 . 2007-10-11 00:52    267,776    ---------    C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-04 21:28 . 2007-10-11 00:52    63,488    ---------    C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-04 21:28 . 2007-10-11 00:52    52,224    ---------    C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-04 21:28 . 2007-10-10 11:59    13,824    ---------    C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-04 21:25 . 2008-01-04 21:29    <DIR>    d--------    C:\WINDOWS\system32\da-dk

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 13:51    ---------    d-----w    C:\Documents and Settings\Pernille\Application Data\OpenOffice.org2
2008-01-19 16:12    ---------    d-----w    C:\Programmer\Windows Live Toolbar
2008-01-19 16:06    ---------    d-----w    C:\Programmer\Fælles filer
2008-01-19 15:55    ---------    d-----w    C:\Programmer\Windows Live
2008-01-19 15:50    ---------    d-----w    C:\Programmer\Fælles filer\Microsoft Shared
2008-01-17 20:49    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-14 06:13    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-05 13:48    ---------    dcsh--w    C:\Programmer\Fælles filer\WindowsLiveInstaller
2007-11-30 19:12    ---------    d-----w    C:\Programmer\Java
2007-11-26 21:27    ---------    d-----w    C:\Documents and Settings\Pernille\Application Data\Apple Computer
2007-11-26 18:52    ---------    d-----w    C:\Programmer\Fælles filer\System
2007-11-26 18:45    ---------    d-----w    C:\Programmer\MSBuild
2007-11-26 18:45    ---------    d-----w    C:\Programmer\Microsoft Works
2007-11-26 18:44    ---------    d-----w    C:\Programmer\Fælles filer\DESIGNER
2007-11-26 18:42    ---------    d-----w    C:\Programmer\Microsoft.NET
2007-11-07 09:28    723,456    ----a-w    C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:28    723,456    ------w    C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-31 03:56    3,590,656    ------w    C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20    360,064    ------w    C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:44    1,291,776    ----a-w    C:\WINDOWS\system32\quartz.dll
2007-10-29 22:44    1,291,776    ------w    C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-25 16:43    8,472,064    ----a-w    C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 08:28    222,720    ----a-w    C:\WINDOWS\system32\wmasf.dll
2007-10-25 08:28    222,720    ----a-w    C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-23 16:49    586,240    ----a-w    C:\WINDOWS\WLXPGSS.SCR
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 09:00 15360]
"MsnMsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.exe" [ ]
"pdfSaver3"="C:\Programmer\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" [2004-09-05 17:20 380928]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" [ ]
"K-Net Utility"="C:\Programmer\KNet Utility\KNet Utility.exe" [2004-12-07 13:56 495678]
"updateMgr"="C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-17 14:33 68856]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-01-10 15:14 1310720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-01-22 19:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-22 19:31 126976]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"HP Software Update"="C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"eabconfg.cpl"="C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24 290816]
"Cpqset"="C:\Programmer\HPQ\Default Settings\cpqset.exe" [2004-11-05 12:52 233534]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54 253952]
"hpWirelessAssistant"="C:\Programmer\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-01-21 12:40 790528]
"DAEMON Tools-1033"="C:\Programmer\D-Tools\daemon.exe" [2004-08-22 16:05 81920]
"pdfSaver3"="" []
"MMReminderService"="C:\Programmer\Mindjet\MindManager 6\MMReminderService.exe" [2005-09-13 02:02 28672]
"ShStatEXE"="C:\Programmer\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 08:00 94208]
"McAfeeUpdaterUI"="C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 03:55 131072]
"Network Associates Error Reporting Service"="C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe" [ ]
"QuickTime Task"="C:\Programmer\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2007-07-10 08:18 270648]
"GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"xri"="C:\WINDOWS\system32\xri.exe" [2008-01-15 20:24 131072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 09:00 15360]

C:\Documents and Settings\Pernille\Menuen Start\Programmer\Start\
OpenOffice.org 2.0.lnk - C:\Programmer\OpenOffice.org 2.0\program\quickstart.exe [2005-10-15 02:02:32 61440]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2006-10-19 09:12 258048 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R1 ewido security suite driver;ewido security suite driver;C:\Programmer\ewido\security suite\guard.sys [2004-11-22 15:15]
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2006-04-18 15:45]
S2 ybaie7ica2radu;Print Spooler Service;C:\WINDOWS\system32\xri.exe [2008-01-15 20:24]

*Newly Created Service* - ENTDRV51
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-11-30 19:30:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 15:07:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Programmer\HPQ\Default Settings\cpqset.exe???????????0?3?1?4??P???? ?,?B????????? ???hLC????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 15:08:22
.
2008-01-20 12:00:59    --- E O F ---
Avatar billede fromsej Praktikant
20. januar 2008 - 15:50 #3
Hent Ccleaner her:
http://www.filehippo.com/download_ccleaner/
Installer Ccleaner, husk at fjerne fluebenet udfor installation af Yahoo toolbar.
Start programmet, fjern fluebenet i cookies.
Klik på kør Cleaner og lad den fjerne hvad den finder.
Klik så på Register ovre i venstre side (den blå terning), klik på Skan efter problemer, når den er færdig, klik på Udbedre valgte problemer, lav evt. en backup af registreringsdatabasen, klik så på udbedre alle valgte problemer.
Klik på OK, klik på Luk når den er færdig.
Genstart.
---------------------------------------
Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [xri] C:\WINDOWS\system32\xri.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe (file missing)

---------------------------------------
Kopiér indholdet mellem de bølgede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt. Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

Killall::

File::
C:\WINDOWS\system32\xri.exe

Service::
ybaie7ica2radu

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
---------------------------------------
Vi skal se en frisk hijackthislog, samt den nye combofixlog.
Avatar billede ahv Nybegynder
20. januar 2008 - 17:11 #4
Her er friske logfiler;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:05:15, on 20-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Network Associates\Common Framework\FrameworkService.exe
C:\Programmer\Network Associates\VirusScan\Mcshield.exe
C:\Programmer\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Mindjet\MindManager 6\MMReminderService.exe
C:\Programmer\Network Associates\VirusScan\SHSTAT.EXE
C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe
C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe
C:\Programmer\QuickTime\QTTask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe
C:\Programmer\KNet Utility\KNet Utility.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\HPQ\SHARED\HPQWMI.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\OpenOffice.org 2.0\program\soffice.exe
C:\Programmer\OpenOffice.org 2.0\program\soffice.BIN
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\Microsoft Office\Office12\WINWORD.EXE
C:\Documents and Settings\Pernille\Skrivebord\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O2 - BHO: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Programmer\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [MMReminderService] C:\Programmer\Mindjet\MindManager 6\MMReminderService.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Programmer\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\RunServices: [xri] C:\WINDOWS\system32\xri.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pdfSaver3] "C:\Programmer\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [K-Net Utility] "C:\Programmer\KNet Utility\KNet Utility.exe" -winstart
O4 - HKCU\..\Run: [updateMgr] C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Programmer\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Programmer\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://intern.diplom-is.dk/msrdp.cab
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\Player\__CDS2.DLL (file missing)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Programmer\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Print Spooler Service (ybaie7ica2radu) - Unknown owner - C:\WINDOWS\system32\xri.exe (file missing)

--
End of file - 11387 bytes




ComboFix 08-01-20.1 - Pernille 2008-01-20 16:44:44.2 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.202 [GMT 1:00]
Running from: C:\Documents and Settings\Pernille\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Pernille\Skrivebord\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\xri.exe
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\xri.exe

.
(((((((((((((((((((((((((  Files Created from 2007-12-20 to 2008-01-20  )))))))))))))))))))))))))))))))
.

2008-01-20 16:14 . 2008-01-20 16:14    <DIR>    d--------    C:\Programmer\CCleaner
2008-01-20 14:56 . 2000-08-31 08:00    51,200    --a------    C:\WINDOWS\NirCmd.exe
2008-01-19 17:41 . 2008-01-19 17:41    <DIR>    d--------    C:\Documents and Settings\Pernille\DoctorWeb
2008-01-19 17:07 . 2008-01-20 12:57    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-01-19 17:07 . 2008-01-19 17:07    <DIR>    d--------    C:\Documents and Settings\Pernille\Application Data\SUPERAntiSpyware.com
2008-01-19 17:07 . 2008-01-19 17:07    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-19 17:06 .     <DIR>        C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-16 22:11 . 2008-01-16 22:14    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-16 21:49 . 2006-11-29 13:06    3,426,072    --a------    C:\WINDOWS\system32\d3dx9_32.dll
2008-01-16 21:48 . 2008-01-16 21:48    <DIR>    d--------    C:\Programmer\Microsoft SQL Server Compact Edition
2008-01-04 21:28 . 2007-10-11 00:52    6,065,664    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-04 21:28 . 2007-07-01 04:31    2,455,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-04 21:28 . 2007-07-01 04:36    1,015,808    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-04 21:28 . 2007-10-11 00:52    459,264    ---------    C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-04 21:28 . 2007-10-11 00:52    383,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-04 21:28 . 2007-10-11 00:52    267,776    ---------    C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-04 21:28 . 2007-10-11 00:52    63,488    ---------    C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-04 21:28 . 2007-10-11 00:52    52,224    ---------    C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-04 21:28 . 2007-10-10 11:59    13,824    ---------    C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-04 21:25 . 2008-01-04 21:29    <DIR>    d--------    C:\WINDOWS\system32\da-dk

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 15:25    ---------    d-----w    C:\Documents and Settings\Pernille\Application Data\OpenOffice.org2
2008-01-19 16:12    ---------    d-----w    C:\Programmer\Windows Live Toolbar
2008-01-19 16:06    ---------    d-----w    C:\Programmer\Fælles filer
2008-01-19 15:55    ---------    d-----w    C:\Programmer\Windows Live
2008-01-19 15:50    ---------    d-----w    C:\Programmer\Fælles filer\Microsoft Shared
2008-01-17 20:49    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-14 06:13    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-05 13:48    ---------    dcsh--w    C:\Programmer\Fælles filer\WindowsLiveInstaller
2007-11-30 19:12    ---------    d-----w    C:\Programmer\Java
2007-11-26 21:27    ---------    d-----w    C:\Documents and Settings\Pernille\Application Data\Apple Computer
2007-11-26 18:52    ---------    d-----w    C:\Programmer\Fælles filer\System
2007-11-26 18:45    ---------    d-----w    C:\Programmer\MSBuild
2007-11-26 18:45    ---------    d-----w    C:\Programmer\Microsoft Works
2007-11-26 18:44    ---------    d-----w    C:\Programmer\Fælles filer\DESIGNER
2007-11-26 18:42    ---------    d-----w    C:\Programmer\Microsoft.NET
2007-10-23 16:49    586,240    ----a-w    C:\WINDOWS\WLXPGSS.SCR
.

(((((((((((((((((((((((((((((  snapshot@2008-01-20_15.07.24,96  )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 13:58:01    1,413,120    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 15:44:19    1,413,120    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 13:58:01    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 15:44:19    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 13:58:01    1,417,216    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 15:44:19    1,417,216    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 13:58:02    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 15:44:20    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 13:58:02    5,734,400    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 15:44:20    5,734,400    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-20 13:58:02    151,552    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 15:44:20    151,552    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 09:00 15360]
"pdfSaver3"="C:\Programmer\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" [2004-09-05 17:20 380928]
"K-Net Utility"="C:\Programmer\KNet Utility\KNet Utility.exe" [2004-12-07 13:56 495678]
"updateMgr"="C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-17 14:33 68856]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-01-10 15:14 1310720]
"MsnMsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-01-22 19:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-22 19:31 126976]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"HP Software Update"="C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"eabconfg.cpl"="C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24 290816]
"Cpqset"="C:\Programmer\HPQ\Default Settings\cpqset.exe" [2004-11-05 12:52 233534]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54 253952]
"hpWirelessAssistant"="C:\Programmer\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-01-21 12:40 790528]
"DAEMON Tools-1033"="C:\Programmer\D-Tools\daemon.exe" [2004-08-22 16:05 81920]
"pdfSaver3"="" []
"MMReminderService"="C:\Programmer\Mindjet\MindManager 6\MMReminderService.exe" [2005-09-13 02:02 28672]
"ShStatEXE"="C:\Programmer\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 08:00 94208]
"McAfeeUpdaterUI"="C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 03:55 131072]
"Network Associates Error Reporting Service"="C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe" [ ]
"QuickTime Task"="C:\Programmer\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2007-07-10 08:18 270648]
"GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"xri"="C:\WINDOWS\system32\xri.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 09:00 15360]

C:\Documents and Settings\Pernille\Menuen Start\Programmer\Start\
OpenOffice.org 2.0.lnk - C:\Programmer\OpenOffice.org 2.0\program\quickstart.exe [2005-10-15 02:02:32 61440]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2006-10-19 09:12 258048 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R1 ewido security suite driver;ewido security suite driver;C:\Programmer\ewido\security suite\guard.sys [2004-11-22 15:15]
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2006-04-18 15:45]
S2 ybaie7ica2radu;Print Spooler Service;C:\WINDOWS\system32\xri.exe []

.
Contents of the 'Scheduled Tasks' folder
"2007-11-30 19:30:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 16:53:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Programmer\HPQ\Default Settings\cpqset.exe???????????0?3?1?4??????? ?,?B????????? ???hLC????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 17:01:51 - machine was rebooted
ComboFix-quarantined-files.txt  2008-01-20 16:01:38
ComboFix2.txt  2008-01-20 14:08:24
.
2008-01-20 12:00:59    --- E O F ---
Avatar billede fromsej Praktikant
20. januar 2008 - 19:33 #5
Kopiér indholdet mellem de bølgede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt. Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

File::
C:\WINDOWS\system32\xri.exe

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"xri"=-

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Vi skal se den nye Combofixlog.
Avatar billede fromsej Praktikant
20. januar 2008 - 19:34 #6
Bummer, denne her er rigtig.

Kopiér indholdet mellem de bølgede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt. Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

Killall::

File::
C:\WINDOWS\system32\xri.exe

Rootkit::
ybaie7ica2radu

Driver::
ybaie7ica2radu

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"xri"=-

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Avatar billede ahv Nybegynder
20. januar 2008 - 20:11 #7
Combofix log;


ComboFix 08-01-20.1 - Pernille 2008-01-20 19:52:09.3 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.192 [GMT 1:00]
Running from: C:\Documents and Settings\Pernille\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Pernille\Skrivebord\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\xri.exe
.

(((((((((((((((((((((((((  Files Created from 2007-12-20 to 2008-01-20  )))))))))))))))))))))))))))))))
.

2008-01-20 16:14 . 2008-01-20 16:14    <DIR>    d--------    C:\Programmer\CCleaner
2008-01-20 14:56 . 2000-08-31 08:00    51,200    --a------    C:\WINDOWS\NirCmd.exe
2008-01-19 17:41 . 2008-01-19 17:41    <DIR>    d--------    C:\Documents and Settings\Pernille\DoctorWeb
2008-01-19 17:07 . 2008-01-20 12:57    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-01-19 17:07 . 2008-01-19 17:07    <DIR>    d--------    C:\Documents and Settings\Pernille\Application Data\SUPERAntiSpyware.com
2008-01-19 17:07 . 2008-01-19 17:07    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-19 17:06 .     <DIR>        C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-16 22:11 . 2008-01-16 22:14    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-16 21:49 . 2006-11-29 13:06    3,426,072    --a------    C:\WINDOWS\system32\d3dx9_32.dll
2008-01-16 21:48 . 2008-01-16 21:48    <DIR>    d--------    C:\Programmer\Microsoft SQL Server Compact Edition
2008-01-04 21:28 . 2007-10-11 00:52    6,065,664    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-04 21:28 . 2007-07-01 04:31    2,455,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-04 21:28 . 2007-07-01 04:36    1,015,808    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-04 21:28 . 2007-10-11 00:52    459,264    ---------    C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-04 21:28 . 2007-10-11 00:52    383,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-04 21:28 . 2007-10-11 00:52    267,776    ---------    C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-04 21:28 . 2007-10-11 00:52    63,488    ---------    C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-04 21:28 . 2007-10-11 00:52    52,224    ---------    C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-04 21:28 . 2007-10-10 11:59    13,824    ---------    C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-04 21:25 . 2008-01-04 21:29    <DIR>    d--------    C:\WINDOWS\system32\da-dk

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 18:43    ---------    d-----w    C:\Documents and Settings\Pernille\Application Data\OpenOffice.org2
2008-01-19 16:12    ---------    d-----w    C:\Programmer\Windows Live Toolbar
2008-01-19 15:55    ---------    d-----w    C:\Programmer\Windows Live
2008-01-17 20:49    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-14 06:13    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-05 13:48    ---------    dcsh--w    C:\Programmer\Fælles filer\WindowsLiveInstaller
2007-11-30 19:12    ---------    d-----w    C:\Programmer\Java
2007-11-26 21:27    ---------    d-----w    C:\Documents and Settings\Pernille\Application Data\Apple Computer
2007-11-26 18:45    ---------    d-----w    C:\Programmer\MSBuild
2007-11-26 18:45    ---------    d-----w    C:\Programmer\Microsoft Works
2007-11-26 18:42    ---------    d-----w    C:\Programmer\Microsoft.NET
2007-10-23 16:49    586,240    ----a-w    C:\WINDOWS\WLXPGSS.SCR
.

(((((((((((((((((((((((((((((  snapshot@2008-01-20_15.07.24,96  )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 13:58:01    1,413,120    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 18:51:39    1,413,120    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 13:58:01    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 18:51:39    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 13:58:01    1,417,216    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 18:51:39    1,417,216    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 13:58:02    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 18:51:40    8,192    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 13:58:02    5,734,400    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 18:51:40    5,734,400    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-20 13:58:02    151,552    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 18:51:40    151,552    ----a-w    C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2000-08-31 07:00:00    163,328    ----a-w    C:\WINDOWS\erdnt\subs\ERDNT.EXE
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 09:00 15360]
"pdfSaver3"="C:\Programmer\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" [2004-09-05 17:20 380928]
"K-Net Utility"="C:\Programmer\KNet Utility\KNet Utility.exe" [2004-12-07 13:56 495678]
"updateMgr"="C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-17 14:33 68856]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-01-10 15:14 1310720]
"MsnMsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-01-22 19:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-22 19:31 126976]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"HP Software Update"="C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"eabconfg.cpl"="C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24 290816]
"Cpqset"="C:\Programmer\HPQ\Default Settings\cpqset.exe" [2004-11-05 12:52 233534]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54 253952]
"hpWirelessAssistant"="C:\Programmer\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-01-21 12:40 790528]
"DAEMON Tools-1033"="C:\Programmer\D-Tools\daemon.exe" [2004-08-22 16:05 81920]
"pdfSaver3"="" []
"MMReminderService"="C:\Programmer\Mindjet\MindManager 6\MMReminderService.exe" [2005-09-13 02:02 28672]
"ShStatEXE"="C:\Programmer\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 08:00 94208]
"McAfeeUpdaterUI"="C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 03:55 131072]
"Network Associates Error Reporting Service"="C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe" [ ]
"QuickTime Task"="C:\Programmer\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2007-07-10 08:18 270648]
"GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 09:00 15360]

C:\Documents and Settings\Pernille\Menuen Start\Programmer\Start\
OpenOffice.org 2.0.lnk - C:\Programmer\OpenOffice.org 2.0\program\quickstart.exe [2005-10-15 02:02:32 61440]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2006-10-19 09:12 258048 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R1 ewido security suite driver;ewido security suite driver;C:\Programmer\ewido\security suite\guard.sys [2004-11-22 15:15]
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2006-04-18 15:45]

*Newly Created Service* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder
"2007-11-30 19:30:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 20:01:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Programmer\HPQ\Default Settings\cpqset.exe???????????0?3?1?4??????? ?,?B????????? ???hLC????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 20:07:08 - machine was rebooted
ComboFix-quarantined-files.txt  2008-01-20 19:06:59
ComboFix2.txt  2008-01-20 16:01:53
ComboFix3.txt  2008-01-20 14:08:24
.
2008-01-20 12:00:59    --- E O F ---
Avatar billede ahv Nybegynder
21. januar 2008 - 15:13 #8
Ser logfilen ok ud nu?
Avatar billede fromsej Praktikant
21. januar 2008 - 18:13 #9
Ja, loggen er ren.
Er problemet løst?
Avatar billede ahv Nybegynder
21. januar 2008 - 20:13 #10
Alt er i skønneste orden, tak for hjælpen.
Avatar billede fromsej Praktikant
21. januar 2008 - 20:31 #11
Velbekomme, tak for point.*S*
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester