Avatar billede vejmand Juniormester
03. maj 2008 - 05:55 Der er 10 kommentarer og
1 løsning

Kan ikke fjerne trojan helt.

Startsiden vil ændres til dbsarticles.com

Har fulgt http://www.eksperten.dk/artikler/1123

Logfile of HijackThis v1.99.1
Scan saved at 18:30:47, on 02-05-2008
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\wuaclt.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Winamp Remote\bin\OrbTray.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\LVComS.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Ditte K\Dokumenter\Rensning\Hja\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {DA86175F-BF2F-4354-AA26-167BB8684D6C} - (no file)
O2 - BHO: {39a8eae4-406b-6898-fe94-e6141c3afc1f} - {f1cfa3c1-416e-49ef-8986-b6044eae8a93} - C:\WINDOWS\System32\thknimhl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Networking Monitoring] C:\WINDOWS\System32\mdm.exe
O4 - HKLM\..\Run: [Modifiet Amateur HTPB] C:\WINDOWS\System32\wuaclt.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Orb] "C:\Programmer\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Modifiet Amateur HTPB] C:\WINDOWS\System32\wuaclt.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm147YYDK
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15-3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194438919077
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/02/2008 at 06:22 PM

Application Version : 4.0.1154

Core Rules Database Version : 3451
Trace Rules Database Version: 1443

Scan type      : Complete Scan
Total Scan Time : 00:18:14

Memory items scanned      : 160
Memory threats detected  : 2
Registry items scanned    : 3352
Registry threats detected : 10
File items scanned        : 8100
File threats detected    : 110

Trojan.Vundo-Variant/F
    C:\WINDOWS\SYSTEM32\OPNMFVOG.DLL
    C:\WINDOWS\SYSTEM32\OPNMFVOG.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F3EA905-DE65-4D00-BC1F-FF3A77F8CA30}
    HKCR\CLSID\{7F3EA905-DE65-4D00-BC1F-FF3A77F8CA30}
    HKCR\CLSID\{7F3EA905-DE65-4D00-BC1F-FF3A77F8CA30}\InprocServer32
    HKCR\CLSID\{7F3EA905-DE65-4D00-BC1F-FF3A77F8CA30}\InprocServer32#ThreadingModel
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{7F3EA905-DE65-4D00-BC1F-FF3A77F8CA30}
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\opnMFVOG
    C:\WINDOWS\SYSTEM32\DDCBRJJY.DLL
    C:\WINDOWS\SYSTEM32\FCCBRQIJ.DLL
    C:\WINDOWS\SYSTEM32\FCCCYWXQ.DLL
    C:\WINDOWS\SYSTEM32\HGGWMLCU.DLL
    C:\WINDOWS\SYSTEM32\IIFEDBAX.DLL
    C:\WINDOWS\SYSTEM32\RQRJAATK.DLL
    C:\WINDOWS\SYSTEM32\TUDKMCES.DLL

Adware.Vundo Variant/Resident
    C:\WINDOWS\SYSTEM32\NNNNLBXR.DLL
    C:\WINDOWS\SYSTEM32\NNNNLBXR.DLL

Adware.Vundo-Variant
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7587FA0E-09C5-4EFC-BBF1-58CF6491B726}
    HKCR\CLSID\{7587FA0E-09C5-4EFC-BBF1-58CF6491B726}
    HKCR\CLSID\{7587FA0E-09C5-4EFC-BBF1-58CF6491B726}\InprocServer32
    HKCR\CLSID\{7587FA0E-09C5-4EFC-BBF1-58CF6491B726}\InprocServer32#ThreadingModel

Adware.Tracking Cookie
    C:\Documents and Settings\Ditte K\Cookies\ditte k@banner.joylandcasino[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@atwola[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@bluestreak[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@eas4.emediate[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@tribalfusion[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@mediaplex[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ads.addynamix[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@azjmp[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@cassava[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@19238[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ad[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@e2.emediate[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@pacificpoker[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@serving-sys[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adopt.specificclick[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@windowsmedia[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adnetserver[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ads.gamershell[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@3.adbrite[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@apmebf[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@qxl.adservinginternational[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@bestsexworld[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@zedo[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@metacafe.122.2o7[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@qxl.banneradministration[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@tacoda[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@banner.eurogrand[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@server.cpmstar[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@date.ventivmedia[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@bs.serving-sys[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@akira[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ad1.emediate[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@anad.tacoda[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@statse.webtrendslive[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@xiti[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adfair[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@casalemedia[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@www.zanox-affiliate[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@atdmt[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@hitbox[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@statcounter[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adopt.euroclick[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ad.yieldmanager[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@media.adrevolver[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ads.planetactive[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adserver.adservinginternational[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@www.clickmanage[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@revenue[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@track.adform[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@advertising[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@888[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@eas.apm.emediate[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ehg-hollywood.hitbox[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@1070847646[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@doubleclick[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@indextools[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adserver.banneradministration[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@clicktorrent[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@revsci[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ads.pointroll[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ads2.jubii[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@shopping.112.2o7[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@stat.dealtime[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@tradedoubler[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ads.adbrite[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@fastclick[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@mywebsearch[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ads.zam[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@2o7[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adserver[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@1066821213[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@nordea.112.2o7[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@specificclick[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@tracking.vindicosuite[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adtech[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@www.windowsmedia[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@smartadserver[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@edsa.122.2o7[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@new-pcp[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ad.zanox[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@maxserving[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@partygaming.122.2o7[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@cgi-bin[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@partypoker[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@ehg-nokiafin.hitbox[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@adbrite[2].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@traffictracker[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@www.burstnet[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@accounts[1].txt
    C:\Documents and Settings\Ditte K\Cookies\ditte k@burstnet[1].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@adopt.euroclick[2].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@atdmt[2].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@date.ventivmedia[1].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@ads.zam[2].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@fastclick[2].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@ad.yieldmanager[1].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@track.adform[1].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@tribalfusion[2].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@mywebsearch[2].txt
    C:\Documents and Settings\Ditte K\Lokale indstillinger\Temp\Cookies\ditte k@advertising[1].txt
Avatar billede vejmand Juniormester
03. maj 2008 - 06:01 #1
ComboFix 08-05-01.1 - Ditte K 2008-05-02 18:32:43.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.0.1252.1.1030.18.664 [GMT 2:00]
Running from: C:\Documents and Settings\Ditte K\Dokumenter\Rensning\Combofix\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\kkqjkhpe.dll
C:\WINDOWS\system32\nvqvmqbr.dll
C:\WINDOWS\system32\omwfiskr.ini
C:\WINDOWS\system32\rXbLnnnn.ini
C:\WINDOWS\system32\rXbLnnnn.ini2
C:\WINDOWS\system32\rxfbbjtd.ini
C:\WINDOWS\system32\secmkdut.ini
C:\WINDOWS\system32\thknimhl.dll

.
(((((((((((((((((((((((((  Files Created from 2008-04-02 to 2008-05-02  )))))))))))))))))))))))))))))))
.

2008-05-02 17:51 . 2008-05-02 17:51    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-05-02 17:51 . 2008-05-02 17:51    <DIR>    d--------    C:\Documents and Settings\Ditte K\Application Data\SUPERAntiSpyware.com
2008-05-02 17:51 . 2008-05-02 17:51    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-02 17:43 . 2008-05-02 17:43    <DIR>    d--------    C:\Programmer\CCleaner
2008-04-30 22:23 . 2008-04-30 22:23    36,463    ---hs----    C:\WINDOWS\system32\wuaclt.exe
2008-04-08 15:21 . 2008-05-02 17:46    <DIR>    dr-h-----    C:\$VAULT$.AVG

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 15:51    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-05-02 15:25    ---------    d-----w    C:\Documents and Settings\Ditte K\Application Data\AVG7
2008-03-16 21:04    2,829    ----a-w    C:\WINDOWS\War3Unin.pif
2008-03-16 21:04    139,264    ----a-w    C:\WINDOWS\War3Unin.exe
2008-03-07 07:15    ---------    d-----w    C:\Documents and Settings\Ditte K\Application Data\uTorrent
2008-02-18 16:34    499,712    ----a-w    C:\WINDOWS\system32\msvcp71.dll
2008-02-18 16:34    348,160    ----a-w    C:\WINDOWS\system32\msvcr71.dll
2008-02-04 17:32    21,840    ----atw    C:\WINDOWS\system32\SIntfNT.dll
2008-02-04 17:32    17,212    ----atw    C:\WINDOWS\system32\SIntf32.dll
2008-02-04 17:32    12,067    ----atw    C:\WINDOWS\system32\SIntf16.dll
2008-02-04 15:28    94,208    ----a-w    C:\WINDOWS\DIIUnin.exe
2008-02-04 15:28    2,829    ----a-w    C:\WINDOWS\DIIUnin.pif
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55 5674352]
"DAEMON Tools"="C:\Programmer\DAEMON Tools\daemon.exe" [2007-08-29 17:09 171464]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2001-08-02 08:14 1077277]
"Orb"="C:\Programmer\Winamp Remote\bin\OrbTray.exe" [2008-01-07 22:02 495616]
"Modifiet Amateur HTPB"="C:\WINDOWS\System32\wuaclt.exe" [2008-04-30 22:23 36463]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-10-04 18:14 8491008]
"nwiz"="nwiz.exe" [2007-10-04 18:14 1626112 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 06:12 577536 C:\WINDOWS\soundman.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-10-04 18:14 81920]
"LogitechVideoRepair"="C:\Programmer\Logitech\Video\ISStart.exe" [2003-12-16 23:37 188416]
"LogitechVideoTray"="C:\Programmer\Logitech\Video\LogiTray.exe" [2003-12-16 23:39 77824]
"WinampAgent"="C:\Programmer\Winamp\winampa.exe" [2007-12-20 17:16 37376]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-19 08:23 579584]
"Windows Networking Monitoring"="C:\WINDOWS\System32\mdm.exe" [ ]
"Modifiet Amateur HTPB"="C:\WINDOWS\System32\wuaclt.exe" [2008-04-30 22:23 36463]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-09 14:00 13312]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-18 18:34 219136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm

S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\System32\DRIVERS\wg111v2.sys []

*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-02 18:35:58
Windows 5.1.2600  NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\LVComS.exe
C:\DOCUME~1\DITTEK~1\LOKALE~1\temp\SSUPDATE.EXE
C:\WINDOWS\system32\rasautou.exe
.
**************************************************************************
.
Completion time: 2008-05-02 18:36:56 - machine was rebooted
ComboFix-quarantined-files.txt  2008-05-02 16:36:52

Pre-Run: 4,890,664,960 byte ledig
Post-Run: 6,176,165,888 byte ledig

104
Avatar billede vejmand Juniormester
03. maj 2008 - 06:40 #2
Har lige kørt SDFix.


SDFix: Version 1.178
Run by Ditte K on 03-05-2008 at 06:28

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



                                Final Check :

catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-03 06:32:38
Windows 5.1.2600  NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Programmer\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:09,10,d3,d6,b6,a5,07,a3,72,3d,d6,af,ae,bc,b9,94,7e,d4,ee,f4,ad,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,7c,53,71,83,0d,4f,b3,df,dc,66,69,cd,60,36,cf,52,92,..
"khjeh"=hex:fa,23,ea,3f,fb,81,26,c2,d9,b2,9d,39,64,c9,5c,c5,4c,bd,d1,9a,42,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:28,23,13,75,c6,46,0a,df,cc,9d,7e,10,60,5e,9c,22,42,0f,f6,bf,3d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Programmer\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:09,10,d3,d6,b6,a5,07,a3,72,3d,d6,af,ae,bc,b9,94,7e,d4,ee,f4,ad,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,7c,53,71,83,0d,4f,b3,df,dc,66,69,cd,60,36,cf,52,92,..
"khjeh"=hex:fa,23,ea,3f,fb,81,26,c2,d9,b2,9d,39,64,c9,5c,c5,4c,bd,d1,9a,42,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:28,23,13,75,c6,46,0a,df,cc,9d,7e,10,60,5e,9c,22,42,0f,f6,bf,3d,..

scanning hidden registry entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 30 Apr 2008        36,463 ..SH. --- "C:\WINDOWS\system32\wuaclt.exe"

Finished!
03. maj 2008 - 07:55 #3
Du burde da vide bedre *S*

Afinstaller
* µTorrent - Fildelingsprogram
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=40284
via
[Start][Indstilninger][Kontrolpanel][Tilføj/fjern programmer]

Genstart for at fuldføre afinstalationen...

---------------------------------------

*** Det er du selv ude om !!! ***

Du har ikke opdateret dit Windows XP til ServicePack2 (SP2) + efterfølgende >100 opdateringer fra WindowsUpdate.
"Ubeskyttede pc’er holder i 20 minutter]":
http://www.comon.dk/index.php/news/show/id=18812       

Det er ikke så godt, for så er du ikke sikret mod mange af de vira, der suser rundt på nettet og kigger efter uopdaterede maskiner. Som du er et godt eksempel på !!!

DET ER EN OMMER !!!

http://www.eksperten.dk/artikler/1104
Avatar billede vejmand Juniormester
03. maj 2008 - 08:07 #4
karise_larry >> Jeg ved bedre, det er ikke min PC. Jeg prøver at hjælpe min kæreste's datter, hun skal ha' ny PC inden for overskuelig fremtid.
Skulle bare gerne ha' denne til at virke nogenlunde indtil da.  :-)

Lige nu kører jeg Drweb på den, det ser ud som om den finder noget, melder tilbage senere.

Jeg har fuld forståelse for, hvis du ikke vil bruge tid på dette, jeg forsøger alligevel om jeg kan få fjernet den trojan.  (Trojan horse generic10)
Avatar billede vejmand Juniormester
03. maj 2008 - 08:22 #5
Log fra Drweb:

00137171.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
00139375.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
00177078.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
00321656.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
00323343.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
00636203.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.based;Incurable.Moved.;
01033218.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
01033359.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
01243343.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
01243390.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
01243468.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
01243515.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.based;Incurable.Moved.;
02500890.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.based;Incurable.Moved.;
13324484.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
14777906.FIL;C:\$VAULT$.AVG;Trojan.Virtumod.240;Deleted.;
kkqjkhpe.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Incurable.Moved.;
nvqvmqbr.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Incurable.Moved.;
thknimhl.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Incurable.Moved.;
Process.exe;C:\SDFix\apps;Tool.Prockill;;
Avatar billede vejmand Juniormester
03. maj 2008 - 08:29 #6
Hmmm, den prøver stadig at ændre startsiden til dbsarticles.com, men det har jeg blokeret med SUPERAntiSpyware.

Det må hun så måske bare leve med, indtil hun får købt ny PC.
03. maj 2008 - 11:56 #7
Så længe at der ikke er noget som helst WindowsUpdate vil det bare komme igen og igen og igen og ...

Og når der samtidig bliver 'leget' med µTorrent -> *SUK*

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O2 - BHO: {39a8eae4-406b-6898-fe94-e6141c3afc1f} - {f1cfa3c1-416e-49ef-8986-b6044eae8a93} - C:\WINDOWS\System32\thknimhl.dll
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [Modifiet Amateur HTPB] C:\WINDOWS\System32\wuaclt.exe
O4 - HKCU\..\Run: [Orb] "C:\Programmer\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Modifiet Amateur HTPB] C:\WINDOWS\System32\wuaclt.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm147YYDK
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15-3.cab

Genstart normalt, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

------------------------------------------------------------------------

Registreringsdatabase oprydning kan anbefales ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Register]...)
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller NEJ til den.

------------------------------------------------------------------------
Avatar billede vejmand Juniormester
03. maj 2008 - 14:16 #8
Logfile of HijackThis v1.99.1
Scan saved at 14:12:39, on 03-05-2008
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\LVComS.exe
D:\Internet\Mobile Connect.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Ditte K\Dokumenter\Rensning\Hja\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194438919077
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
Avatar billede vejmand Juniormester
03. maj 2008 - 15:25 #9
karise_larry >> Send et svar, det ser ud til problemet er løst.

Tusind tak for hjælpen, på trods af en ubeskyttet maskine.
03. maj 2008 - 15:26 #10
FORELØBIG 'ren' - ifølge det som en HiJackThis ka' vise ...

Bemærk der vil være en del programmer (=spil!) som ikke vil køre pga. manglende SP2 ...
03. maj 2008 - 15:27 #11
Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...

--------------
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester