Avatar billede Erantis1 Nybegynder
03. maj 2009 - 15:36 Der er 7 kommentarer

win32 trojan

Hej eksperter

Jeg har desværre fået en genstridig virus af typen win32_trojan.
Norton antivirus og programmerne i guiden "sådan fjerner du virus og malware" http://www.eksperten.dk/guide/1232 formåede desværre ikke at udbedre alt. Jeg endte op med ikke at kunne komme på internettet og virussen viste sig igen, når jeg satte en CD rom i.

Derfor valgte jeg at formatere harddisken/installere windows XP mv.

For at være helt sikker på at alt virus nu er slettet, vil jeg gerne bede en ekspert om at se vedhæftede logfiler igennem:

Malwarebytes

Malwarebytes' Anti-Malware 1.36
Database version: 2069
Windows 5.1.2600 Service Pack 3

03-05-2009 14:11:55
mbam-log-2009-05-03 (14-11-55).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 139242
Tid tilbagelagt: 38 minute(s), 10 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)


Combofix

ComboFix 09-05-02.4 - Vivian Thomsen 03-05-2009 14:19.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.45.1030.18.511.212 [GMT 2:00]
Kører fra: c:\documents and settings\Vivian Thomsen\Skrivebord\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated)
FW: Norton 360 *enabled*
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\patchw32.dll
c:\windows\pw32a.dll
c:\windows\system32\AutoRun.inf

.
(((((((((((((((((((((((((((((  Filer skabt fra 2009-04-03 til 2009-05-03  )))))))))))))))))))))))))))))))))))
.

2009-05-03 11:28 . 2009-05-03 11:28    --------    d-----w    c:\documents and settings\Vivian Thomsen\Application Data\Malwarebytes
2009-05-03 11:28 . 2009-04-06 13:32    15504    ----a-w    c:\windows\system32\drivers\mbam.sys
2009-05-03 11:28 . 2009-04-06 13:32    38496    ----a-w    c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-03 11:28 . 2009-05-03 11:28    --------    d-----w    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-03 11:28 . 2009-05-03 11:28    --------    d-----w    c:\programmer\Malwarebytes' Anti-Malware
2009-05-02 19:00 . 2009-05-02 19:00    --------    d-----w    c:\documents and settings\Vivian Thomsen\Application Data\Symantec
2009-05-02 17:04 . 2008-10-16 12:06    268648    ----a-w    c:\windows\system32\mucltui.dll
2009-05-02 16:20 . 2009-05-02 16:20    --------    d-----w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Symantec_Corporation
2009-05-02 15:55 . 2008-01-19 18:12    128104    ----a-w    c:\windows\system32\drivers\WimFltr.sys
2009-05-02 15:55 . 2008-01-19 17:40    15088    ----a-w    c:\windows\system32\drivers\vproeventmonitor.sys
2009-05-02 15:55 . 2008-08-13 15:07    38112    ----a-w    c:\windows\system32\drivers\v2imount.sys
2009-05-02 15:55 . 2008-08-07 15:31    138080    ----a-w    c:\windows\system32\drivers\symsnap.sys
2009-05-02 15:54 . 2009-05-02 15:54    --------    d-----w    c:\programmer\Norton Ghost
2009-05-02 11:42 . 2003-06-25 14:05    266360    ----a-w    c:\windows\system32\TweakUI.exe
2009-05-02 10:22 . 2008-04-14 06:42    14720    -c--a-w    c:\windows\system32\dllcache\kbdhid.sys
2009-05-02 10:22 . 2008-04-14 06:42    14720    ----a-w    c:\windows\system32\drivers\kbdhid.sys
2009-05-02 10:22 . 2008-04-13 09:45    10368    -c--a-w    c:\windows\system32\dllcache\hidusb.sys
2009-05-02 10:22 . 2008-04-13 09:45    10368    ----a-w    c:\windows\system32\drivers\hidusb.sys
2009-05-02 10:10 . 2009-05-02 10:10    --------    d-----w    c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-02 09:50 . 2009-05-02 09:50    --------    d-----w    C:\WEBBANK
2009-05-02 09:14 . 2007-03-13 02:35    476416    ----a-w    c:\windows\system32\drivers\rt2870.sys
2009-05-02 09:14 . 2009-05-02 09:14    --------    d-----w    c:\programmer\D-Link
2009-05-02 09:13 . 2009-05-02 09:13    --------    d-----w    c:\documents and settings\Vivian Thomsen\Application Data\InstallShield
2009-05-02 09:04 . 2009-05-02 09:04    --------    d-sh--w    c:\documents and settings\Administrator\IETldCache
2009-05-02 08:47 . 2009-05-02 08:48    --------    d-----w    c:\programmer\Paint.NET
2009-05-02 08:47 . 2009-05-02 11:49    --------    d-----w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Paint.NET
2009-05-02 08:04 . 2009-05-02 08:04    --------    d-----w    c:\documents and settings\Vivian Thomsen\Application Data\r2 Studios
2009-05-02 08:04 . 2009-05-02 08:04    --------    d-----w    c:\documents and settings\All Users\Application Data\r2 Studios
2009-05-02 08:04 . 2009-05-02 08:04    --------    d-----w    c:\programmer\r2 Studios
2009-05-02 08:00 . 2009-05-02 08:00    --------    d-----w    c:\documents and settings\NetworkService\Lokale indstillinger\Application Data\Google
2009-05-01 23:07 . 2009-05-01 23:07    --------    d-----w    c:\windows\ie8updates
2009-05-01 23:02 . 2009-05-01 23:02    143    ----a-w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\fusioncache.dat
2009-05-01 23:02 . 2009-05-01 23:03    --------    d-----w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\ApplicationHistory
2009-05-01 22:59 . 2009-02-28 04:55    105984    -c----w    c:\windows\system32\dllcache\iecompat.dll
2009-05-01 22:57 . 2009-05-02 08:38    --------    d-----w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Adobe
2009-05-01 22:56 . 2009-05-01 22:57    --------    d-----w    c:\programmer\Fælles filer\Adobe
2009-05-01 22:52 . 2009-05-01 22:52    --------    d-----w    c:\documents and settings\LocalService\Lokale indstillinger\Application Data\Google
2009-05-01 22:50 . 2009-05-02 10:08    --------    d-----w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Google
2009-05-01 22:49 . 2009-05-03 09:02    --------    d-----w    c:\documents and settings\All Users\Application Data\Google Updater
2009-05-01 22:49 . 2009-05-01 22:54    --------    d-----w    c:\programmer\Google
2009-05-01 22:44 . 2009-05-01 22:44    --------    d--h--w    c:\windows\PIF
2009-05-01 22:44 . 2009-05-01 22:44    --------    d-----w    c:\documents and settings\Vivian Thomsen\Application Data\Windows Search
2009-05-01 22:41 . 2009-05-01 22:41    --------    d-----w    c:\windows\nvidia icons
2009-05-01 22:40 . 2009-05-01 22:40    --------    d-----w    c:\windows\nview
2009-05-01 22:40 . 2008-05-03 03:46    442368    ----a-w    c:\windows\system32\nvudisp.exe
2009-05-01 22:40 . 2008-04-30 15:27    442368    ----a-w    c:\windows\system32\NVUNINST.EXE
2009-05-01 22:39 . 2009-05-01 22:39    --------    d-----w    C:\NVIDIA
2009-05-01 22:39 . 2009-05-01 22:39    --------    d-----w    c:\windows\system32\Adobe
2009-05-01 22:36 . 2009-05-01 22:36    --------    d-----w    c:\programmer\SystemRequirementsLab
2009-05-01 22:34 . 2009-05-01 22:34    --------    d-sh--w    c:\documents and settings\Vivian Thomsen\IECompatCache
2009-05-01 22:33 . 2009-05-01 22:33    --------    d-sh--w    c:\documents and settings\Vivian Thomsen\PrivacIE
2009-05-01 22:30 . 2009-05-01 22:30    --------    d-sh--w    c:\documents and settings\LocalService\IETldCache
2009-05-01 22:21 . 2009-05-01 22:21    --------    d-sh--w    c:\documents and settings\NetworkService\IETldCache
2009-05-01 22:21 . 2009-05-01 22:21    --------    d-sh--w    c:\documents and settings\Vivian Thomsen\IETldCache
2009-05-01 22:15 . 2009-05-01 22:18    --------    dc-h--w    c:\windows\ie8
2009-05-01 22:13 . 2009-05-01 22:13    --------    d-----w    c:\programmer\MSXML 4.0
2009-05-01 22:10 . 2009-05-01 22:10    --------    d-----w    c:\programmer\Fælles filer\Windows Live
2009-05-01 22:08 . 2009-05-01 22:08    --------    d-----w    c:\programmer\Microsoft Silverlight
2009-05-01 22:08 . 2006-06-29 11:07    14048    ------w    c:\windows\system32\spmsg2.dll
2009-05-01 21:58 . 2009-05-01 22:07    --------    d-----w    c:\windows\system32\XPSViewer
2009-05-01 21:58 . 2009-05-01 21:58    --------    d-----w    c:\programmer\MSBuild
2009-05-01 21:58 . 2009-05-01 21:58    --------    d-----w    c:\programmer\Reference Assemblies
2009-05-01 21:57 . 2008-07-06 12:06    117760    ------w    c:\windows\system32\prntvpt.dll
2009-05-01 21:57 . 2008-07-06 12:06    89088    -c----w    c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-01 21:57 . 2008-07-06 10:50    597504    -c----w    c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-01 21:57 . 2008-07-06 12:06    575488    -c----w    c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-01 21:57 . 2008-07-06 12:06    575488    ------w    c:\windows\system32\xpsshhdr.dll
2009-05-01 21:57 . 2008-07-06 12:06    1676288    -c----w    c:\windows\system32\dllcache\xpssvcs.dll
2009-05-01 21:57 . 2008-07-06 12:06    1676288    ------w    c:\windows\system32\xpssvcs.dll
2009-05-01 21:57 . 2009-05-01 21:57    --------    d-----w    C:\97a06b72b156b99c0f83a44fb3640cc0
2009-05-01 21:51 . 2009-05-01 21:51    --------    d-----w    c:\programmer\Microsoft
2009-05-01 21:50 . 2009-05-01 21:50    --------    d-----w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Identities
2009-05-01 21:49 . 2009-05-01 22:48    --------    d-----w    c:\programmer\Windows Desktop Search
2009-05-01 21:49 . 2009-05-01 21:49    --------    d-----w    c:\windows\system32\GroupPolicy
2009-05-01 21:49 . 2008-03-07 17:02    29696    -c----w    c:\windows\system32\dllcache\mimefilt.dll
2009-05-01 21:49 . 2008-03-07 17:02    98304    -c----w    c:\windows\system32\dllcache\nlhtml.dll
2009-05-01 21:49 . 2008-03-07 17:02    192000    -c----w    c:\windows\system32\dllcache\offfilt.dll
2009-05-01 21:47 . 2008-04-14 07:05    221184    ----a-w    c:\windows\system32\wmpns.dll
2009-05-01 21:47 . 2009-05-01 21:47    --------    d-----w    c:\programmer\Windows Media Connect 2
2009-05-01 21:45 . 2009-05-01 21:46    --------    d-----w    c:\windows\system32\drivers\UMDF
2009-05-01 21:45 . 2009-05-01 21:45    --------    d-----w    c:\windows\system32\LogFiles
2009-05-01 21:44 . 2009-05-01 21:44    --------    d-----w    c:\programmer\Microsoft CAPICOM 2.1.0.2
2009-05-01 21:40 . 2009-05-01 21:42    --------    d-----w    c:\windows\system32\URTTemp
2009-05-01 21:28 . 2009-05-01 21:28    --------    d-----w    c:\windows\Sun
2009-05-01 21:28 . 2009-05-01 21:27    410984    ----a-w    c:\windows\system32\deploytk.dll
2009-05-01 21:27 . 2009-05-01 21:27    --------    d-----w    c:\programmer\Java
2009-05-01 21:25 . 2009-05-02 11:42    --------    d-----w    c:\windows\Downloaded Installations
2009-05-01 21:20 . 2009-05-02 11:58    --------    d-----w    C:\System & co
2009-05-01 21:17 . 2009-05-01 21:17    --------    d-----w    c:\documents and settings\All Users\Application Data\WEBREG
2009-05-01 21:16 . 2007-03-08 04:20    16496    ----a-r    c:\windows\system32\drivers\HPZipr12.sys
2009-05-01 21:16 . 2007-03-08 04:20    49920    ----a-r    c:\windows\system32\drivers\HPZid412.sys
2009-05-01 21:16 . 2009-05-01 21:16    --------    d-----w    c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-05-01 21:16 . 2007-05-02 10:03    267864    ----a-r    c:\windows\system32\hpzids01.dll
2009-05-01 21:16 . 2007-03-15 13:32    118272    ----a-w    c:\windows\system32\hpz3l5ha.dll
2009-05-01 21:15 . 2007-03-08 04:20    21568    ----a-r    c:\windows\system32\drivers\HPZius12.sys
2009-05-01 21:15 . 2007-03-08 04:20    309760    ----a-r    c:\windows\system32\difxapi.dll
2009-05-01 21:15 . 2007-03-08 04:20    364544    ----a-r    c:\windows\system32\hppldcoi.dll
2009-05-01 21:15 . 2007-05-02 09:00    303104    ----a-r    c:\windows\system32\hpovst12.dll
2009-05-01 21:15 . 2007-05-02 08:56    954368    ----a-r    c:\windows\system32\hpotiop5.dll
2009-05-01 21:15 . 2007-05-02 09:01    675840    ----a-r    c:\windows\system32\hpowiax5.dll
2009-05-01 21:15 . 2008-04-13 09:45    15104    -c--a-w    c:\windows\system32\dllcache\usbscan.sys
2009-05-01 21:15 . 2008-04-13 09:45    15104    ----a-w    c:\windows\system32\drivers\usbscan.sys
2009-05-01 21:13 . 2009-05-01 21:13    --------    d-----w    c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-05-01 21:13 . 2009-05-01 21:13    --------    d-----w    c:\documents and settings\Vivian Thomsen\Application Data\HPAppData
2009-05-01 21:11 . 2009-05-01 21:11    --------    d-----w    c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-05-01 21:11 . 2009-05-01 21:12    --------    d-----w    c:\documents and settings\All Users\Application Data\HP
2009-05-01 21:11 . 2009-05-01 21:11    --------    d-----w    c:\programmer\Fælles filer\HP
2009-05-01 21:10 . 2009-05-01 21:10    --------    d-----w    c:\programmer\Hewlett-Packard
2009-05-01 21:10 . 2009-05-01 21:10    --------    d-----w    c:\programmer\Fælles filer\Hewlett-Packard
2009-05-01 21:09 . 2009-05-01 21:13    --------    d-----w    c:\programmer\HP
2009-05-01 21:08 . 2008-04-13 09:47    25856    -c--a-w    c:\windows\system32\dllcache\usbprint.sys
2009-05-01 21:08 . 2008-04-13 09:47    25856    ----a-w    c:\windows\system32\drivers\usbprint.sys
2009-05-01 21:07 . 2008-05-01 14:36    331776    -c----w    c:\windows\system32\dllcache\msadce.dll
2009-05-01 21:07 . 2009-05-01 21:17    160539    ----a-w    c:\windows\hpoins21.dat
2009-05-01 21:07 . 2007-09-05 18:26    8138    ------w    c:\windows\hpomdl21.dat
2009-05-01 21:04 . 2009-05-02 16:15    --------    dc----w    c:\windows\system32\DRVSTORE
2009-05-01 21:04 . 2009-05-01 21:04    --------    d-----w    c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-01 21:04 . 2009-05-01 21:04    --------    d-----w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\Downloaded Installations
2009-05-01 21:04 . 2009-05-01 21:04    36400    ----a-r    c:\windows\system32\drivers\SymIM.sys
2009-05-01 21:04 . 2009-05-01 21:04    60808    ----a-w    c:\windows\system32\S32EVNT1.DLL
2009-05-01 21:04 . 2009-05-01 21:04    124464    ----a-w    c:\windows\system32\drivers\SYMEVENT.SYS
2009-05-01 21:04 . 2009-05-02 15:56    --------    d-----w    c:\programmer\Symantec
2009-05-01 21:03 . 2009-05-01 21:03    --------    d-----w    c:\windows\system32\drivers\N360
2009-05-01 21:03 . 2009-05-01 21:03    --------    d-----w    c:\programmer\Norton 360
2009-05-01 21:03 . 2009-05-01 21:03    --------    d-----w    c:\programmer\Windows Sidebar

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-03 12:23 . 2009-05-01 22:52    892    ----a-w    c:\windows\Tasks\GoogleUpdateTaskMachine.job
2009-05-03 12:23 . 2009-05-01 22:49    902    ----a-w    c:\windows\Tasks\Google Software Updater.job
2009-05-03 12:22 . 2009-05-01 17:50    6    ---ha-w    c:\windows\Tasks\SA.DAT
2009-05-02 09:15 . 2009-05-02 09:14    --------    d-----w    c:\programmer\ANI
2009-05-02 09:15 . 2009-05-01 18:12    --------    d--h--w    c:\programmer\InstallShield Installation Information
2009-05-01 23:01 . 2006-03-02 12:00    82286    ----a-w    c:\windows\system32\perfc006.dat
2009-05-01 23:01 . 2006-03-02 12:00    455992    ----a-w    c:\windows\system32\perfh006.dat
2009-05-01 22:40 . 2009-05-01 18:12    --------    d-----w    c:\programmer\Fælles filer\InstallShield
2009-05-01 22:09 . 2009-05-01 18:03    19880    ----a-w    c:\documents and settings\Vivian Thomsen\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 21:04 . 2009-05-01 21:04    805    ----a-w    c:\windows\system32\drivers\SYMEVENT.INF
2009-05-01 21:04 . 2009-05-01 21:04    7386    ----a-w    c:\windows\system32\drivers\SYMEVENT.CAT
2009-05-01 19:50 . 2009-05-01 17:47    76487    ----a-w    c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-01 18:23 . 2009-05-01 18:23    --------    d-----w    c:\programmer\CCleaner
2009-05-01 18:20 . 2009-05-01 18:19    --------    d-----w    c:\programmer\Ahead
2009-05-01 18:15 . 2009-05-01 18:15    --------    d-----w    c:\programmer\Realtek Sound Manager
2009-05-01 18:15 . 2009-05-01 18:15    --------    d-----w    c:\programmer\AvRack
2009-05-01 18:14 . 2009-05-01 18:12    --------    d-----w    c:\programmer\Intel
2009-05-01 18:14 . 2009-05-01 18:14    --------    d-----w    c:\programmer\Gigabyte
2009-05-01 17:48 . 2009-05-01 17:48    --------    d-----w    c:\programmer\microsoft frontpage
2009-05-01 17:47 . 2006-03-02 12:00    67    --sha-w    c:\windows\Fonts\desktop.ini
2009-05-01 17:46 . 2009-05-01 17:46    --------    d-----w    c:\programmer\Onlinetjenester
2009-05-01 17:45 . 2009-05-01 17:45    --------    d-----w    c:\programmer\Fælles filer\Tjenester
2009-05-01 17:45 . 2009-05-01 17:45    21644    ----a-w    c:\windows\system32\emptyregdb.dat
2009-03-08 02:34 . 2006-03-02 12:00    914944    ----a-w    c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2006-03-02 12:00    43008    ----a-w    c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2006-03-02 12:00    18944    ----a-w    c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2006-03-02 12:00    420352    ----a-w    c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2006-03-02 12:00    72704    ----a-w    c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2006-03-02 12:00    71680    ----a-w    c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2006-03-02 12:00    34816    ----a-w    c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2006-03-02 12:00    48128    ----a-w    c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2006-03-02 12:00    45568    ----a-w    c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2006-03-02 12:00    156160    ----a-w    c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2006-03-02 12:00    284672    ----a-w    c:\windows\system32\pdh.dll
2009-02-21 06:25 . 2008-12-31 15:04    691592    ----a-w    c:\windows\system32\OGACheckControl.DLL
2009-02-09 14:07 . 2006-03-02 12:00    1846784    ----a-w    c:\windows\system32\win32k.sys
2009-02-09 11:26 . 2004-08-26 17:50    2026496    ----a-w    c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:25 . 2006-03-02 12:00    2147840    ----a-w    c:\windows\system32\ntoskrnl.exe
2009-02-09 11:25 . 2006-03-02 12:00    110592    ----a-w    c:\windows\system32\services.exe
2009-02-09 10:53 . 2006-03-02 12:00    730624    ----a-w    c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2006-03-02 12:00    719360    ----a-w    c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2006-03-02 12:00    682496    ----a-w    c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2006-03-02 12:00    401408    ----a-w    c:\windows\system32\rpcss.dll
2009-02-06 10:39 . 2006-03-02 12:00    35328    ----a-w    c:\windows\system32\sc.exe
2009-02-03 19:58 . 2006-03-02 12:00    56832    ----a-w    c:\windows\system32\secur32.dll
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-01 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupDelayer"="c:\programmer\r2 Studios\Startup Delayer\Startup Launcher GUI.exe" [2009-03-08 147456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"ANIWZCS2Service"="c:\programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"Norton Ghost 14.0"="c:\programmer\Norton Ghost\Agent\VProTray.exe" [2008-12-11 2245992]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

R2 gupdate1c9caaf83912f6c;Tjenesten Google Update (gupdate1c9caaf83912f6c);c:\programmer\Google\Update\GoogleUpdate.exe [2009-05-01 133104]
R3 EraserUtilDrv10710;EraserUtilDrv10710; [x]
R3 GoogleDesktopManager-110408-113106;Google Desktop-administrator 5.8.811.4345;c:\programmer\Google\Google Desktop Search\GoogleDesktop.exe [2009-05-01 30192]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0300000.087\SYMEFA.SYS [2009-05-01 21:04 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.087\BHDrvx86.sys [2009-05-01 21:04 258608]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.087\ccHPx86.sys [2009-05-01 21:04 482352]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090501.001\IDSxpx86.sys [2009-05-01 276344]
S2 N360;Norton 360;c:\programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [2009-05-01 115560]
S2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2008-04-14 5120]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-01 101936]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2007-03-13 476416]
S3 SymSnapService;SymSnapService;c:\programmer\Norton Ghost\Shared\Drivers\SymSnapService.exe [2008-08-07 1558000]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12    REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt    REG_MULTI_SZ      hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Indhold af mappen 'Planlagte Opgaver'

2009-05-03 c:\windows\Tasks\Google Software Updater.job
- c:\programmer\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-01 22:49]

2009-05-03 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2009-05-01 22:52]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-03 14:24
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'explorer.exe'(3812)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
c:\programmer\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\wscntfy.exe
c:\programmer\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe
c:\windows\system32\TaskSwitch.exe
.
**************************************************************************
.
Gennemført tid: 2009-05-03 14:26 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-05-03 12:26

Pre-Kørsel: 69.573.627.904 byte ledig
Post-Kørsel: 69.513.187.328 byte ledig

WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

301    --- E O F ---    2009-05-02 08:02

Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:28:31, on 03-05-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\Programmer\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Programmer\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\explorer.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programmer\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Programmer\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmer\Norton 360\Engine\3.0.0.135\IPSBHO.DLL
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [StartupDelayer] "C:\Programmer\r2 Studios\Startup Delayer\Startup Launcher GUI.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Norton Ghost 14.0] "C:\Programmer\Norton Ghost\Agent\VProTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: HP Klipsamling - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart markering - {700259D7-1666-479a-93B1-3250410481E8} - C:\Programmer\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1241212776937
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1241213297232&h=0bf2c50e47940aef926652476bdf0065/&filename=jinstall-6u13-windows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Programmer\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Programmer\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Google Desktop-administrator 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Tjenesten Google Update (gupdate1c9caaf83912f6c) (gupdate1c9caaf83912f6c) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Programmer\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programmer\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Programmer\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SymSnapService - Symantec - C:\Programmer\Norton Ghost\Shared\Drivers\SymSnapService.exe

--
End of file - 7351 bytes

På forhånd tak for hjælpen.

Mange hilsner

Erantis1
Avatar billede mjdigital Nybegynder
03. maj 2009 - 23:17 #1
Hej Erantis1 :)

Jeg syntes det ser fint ud herfra..

Dog hvis den skulle vise sig så sørg for at lave en Format C igen. Og brug et program som overskriver Filerne med 0 data. Altså overskriver alle filer med "ingen" filer for at være 100% på de er væk.

Sørg for at have et Opdateret antivirus jeg bruger personligt Noron 360 V3 pt.

Og så har jeg en der scanner for rootkits i ny og næ for at være helt sikker :)


Håber det hjalp dig lidt på vej. Held og lykke :)
Avatar billede Erantis1 Nybegynder
05. maj 2009 - 21:05 #2
Hej

Tak for dit svar.Jeg brugte Windows XP installations CD´en til at formattere harddisken.
Kender du et program som overskriver filerne med 0 data, som du nævner ovenfor? Så vil jeg bruge dette fremover.
PS: Jeg bruger også Norton 360 V3.

På forhånd tak
05. maj 2009 - 21:17 #3
... hvis du bare vælger FULD FORMATERING så er det fint nok med henblik på 100% geninstalation...

Hvis det eksempelvis er fordi du skal af med PC'en / Harddisken så ->
http://www.killdisk.com/downloadfree.htm + http://www.helgec.dk/killdisk.html
Avatar billede Erantis1 Nybegynder
06. maj 2009 - 21:08 #4
tja, normalt. Jeg har tidligere haft den tvivlsomme oplevelse, at vælge fuld formatering, men virus´en var stadig aktiv. Der var tilsyneladende nogle filer, som ikke blev slette ved en fuld formattering.
Men det er måske netop et sådant problem som f.eks. killdisk løser?
06. maj 2009 - 21:35 #5
Hmmm... ja...
Avatar billede Erantis1 Nybegynder
07. maj 2009 - 16:10 #6
Hej Karise_Larry
Tusinde tak for din hjælp.
Jeg er nybegynder i dette her community, så hvis du vil have del i de anførte point, så antager jeg, at du skal angive dine råd som svar.
08. maj 2009 - 17:35 #7
Ping...
(Det var et [svar]...)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester