Avatar billede mester12345 Nybegynder
14. juli 2009 - 23:13 Der er 5 kommentarer og
1 løsning

HiJackThis check

Hej derude, jeg er begyndt at få nogle beskeder fra avast om trojaner og orme, jeg håber i kan hjælpe. Jeg bruger sjældent computeren, da jeg er mac-mand, så denne windows bruges kun til netsurf og spil for hele familien.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:10:52, on 14-07-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Hewlett-Packard\IAM\bin\asghost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Analog Devices\SoundMAX\Smax4.exe
C:\Programmer\Intel\AMT\atchk.exe
C:\Programmer\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programmer\Intel\AMT\atchksrv.exe
C:\WINDOWS\system32\ifxspmgt.exe
C:\WINDOWS\system32\ifxtcs.exe
C:\Programmer\Fælles filer\InterVideo\RegMgr\iviRegMgr.exe
C:\Programmer\Intel\AMT\LMS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\IfxPsdSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\AMT\UNS.exe
C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Documents and Settings\Administrator\Skrivebord\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=74&bd=smb&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Programmer\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmer\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [atchk] "C:\Programmer\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [PTHOSTTR] c:\Programmer\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [SetRefresh] C:\Programmer\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Steam] "c:\programmer\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: rncsys32.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar-søgning - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\da-DK\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214208963218
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: APSHook.dll
O20 - Winlogon Notify: OneCard - C:\Programmer\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Programmer\Intel\AMT\atchksrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - C:\Programmer\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\ifxtcs.exe
O23 - Service: IviRegMgr - InterVideo - C:\Programmer\Fælles filer\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Programmer\Intel\AMT\LMS.exe
O23 - Service: Personal Secure Drive service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Programmer\Intel\AMT\UNS.exe

--
End of file - 8137 bytes
Avatar billede fromsej Praktikant
15. juli 2009 - 06:17 #1
Kør Hijackthis, scan, sæt flueben ved følgende, luk alle vinduer undtaget Hijackthis, klik på fix checked, når den er færdig, genstart.

O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - Startup: rncsys32.exe

---------------------------------------
Hent Combofix, og gem den i en mappe:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Åbn mappen med Combofix, højreklik, vælg Ny->tekstdokument, åbn tekstdokumentet, kopier følgende ind:

Killall::
Snapshot::
File::
C:\WINDOWS\system32\rpcc.exe
C:\Documents and Settings\Administrator\Menuen Start\Programmer\Start\rncsys32.exe

klik på Filer->Gem som, navngiv den CFScript, luk tekstdokumentet.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den fremkomne log herind.
15. juli 2009 - 06:30 #2
Nøøøøøj - <Fromsej> tidligt på den *S* ...
Avatar billede mester12345 Nybegynder
15. juli 2009 - 14:44 #3
Tak for dit svar. Jeg har gjort som du har beskrevet, her er combofix logfilen:

ComboFix 09-07-14.07 - Administrator 15-07-2009 14:29.1.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.2002.1570 [GMT 2:00]
Kører fra: c:\documents and settings\Administrator\Skrivebord\fix bummelum\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Administrator\Skrivebord\fix bummelum\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090714-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!

FILE ::
"c:\documents and settings\Administrator\Menuen Start\Programmer\Start\rncsys32.exe"
"c:\windows\system32\rpcc.exe"
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Application Data\wiaserva.log
c:\recycler\S-1-5-21-102095748-406114455-947924252-500
c:\windows\010112010146118114.dat
c:\windows\0101120101464849.dat
c:\windows\system32\rpcc.exe

.
(((((((((((((((((((((((((((((  Filer skabt fra 2009-06-15 til 2009-07-15  )))))))))))))))))))))))))))))))))))
.

2009-07-14 20:55 . 2009-02-05 20:06    23152    ----a-w-    c:\windows\system32\drivers\aswRdr.sys
2009-07-14 20:55 . 2009-02-05 20:06    51376    ----a-w-    c:\windows\system32\drivers\aswTdi.sys
2009-07-14 20:55 . 2009-02-05 20:05    26944    ----a-w-    c:\windows\system32\drivers\aavmker4.sys
2009-07-14 20:55 . 2009-02-05 20:07    114768    ----a-w-    c:\windows\system32\drivers\aswSP.sys
2009-07-14 20:55 . 2009-02-05 20:07    20560    ----a-w-    c:\windows\system32\drivers\aswFsBlk.sys
2009-07-14 20:55 . 2009-02-05 20:04    97480    ----a-w-    c:\windows\system32\AvastSS.scr
2009-07-14 20:55 . 2009-02-05 20:08    93296    ----a-w-    c:\windows\system32\drivers\aswmon.sys
2009-07-14 20:55 . 2009-02-05 20:08    94032    ----a-w-    c:\windows\system32\drivers\aswmon2.sys
2009-07-14 20:55 . 2009-02-05 20:11    1256296    ----a-w-    c:\windows\system32\aswBoot.exe
2009-07-14 19:03 . 2009-07-14 19:03    --------    d-sh--w-    c:\documents and settings\Administrator\IECompatCache
2009-07-14 19:01 . 2009-07-14 19:01    --------    d-sh--w-    c:\documents and settings\Administrator\PrivacIE
2009-07-13 15:10 . 2009-07-13 15:10    82380    ----a-w-    c:\windows\system32\drivers\AFS2K.SYS
2009-07-13 15:08 . 2008-04-13 18:45    15104    ----a-w-    c:\windows\system32\drivers\usbscan.sys
2009-07-13 15:08 . 2008-04-13 18:45    15104    ----a-w-    c:\windows\system32\dllcache\usbscan.sys
2009-07-13 15:05 . 2009-07-13 15:11    20455    ----a-w-    c:\windows\hpoins01.dat
2009-07-13 15:05 . 2003-04-05 13:45    16622    ------w-    c:\windows\hpomdl01.dat
2009-07-13 14:48 . 2009-07-13 14:48    --------    d-----w-    c:\windows\system32\NtmsData
2009-07-13 14:40 . 2009-07-13 14:40    --------    d-sh--w-    c:\documents and settings\Administrator\IETldCache
2009-07-13 14:36 . 2009-06-02 10:12    102912    ------w-    c:\windows\system32\dllcache\iecompat.dll
2009-07-13 14:35 . 2009-07-13 14:36    --------    d-----w-    c:\windows\ie8updates
2009-07-13 14:35 . 2009-04-30 21:15    12800    ------w-    c:\windows\system32\dllcache\xpshims.dll
2009-07-13 14:35 . 2009-04-30 21:15    246272    ------w-    c:\windows\system32\dllcache\ieproxy.dll
2009-07-13 14:33 . 2009-07-13 14:35    --------    dc-h--w-    c:\windows\ie8
2009-07-13 14:20 . 2009-07-13 14:20    --------    d-----w-    c:\documents and settings\Administrator\Application Data\Hewlett-Packard
2009-07-13 14:18 . 2003-03-09 04:31    65795    ----a-r-    c:\windows\system32\HPZipm12.exe
2009-07-13 14:18 . 2003-03-09 04:31    61699    ----a-r-    c:\windows\system32\HPZinw12.exe
2009-07-13 14:18 . 2003-03-09 04:31    16080    ----a-r-    c:\windows\system32\drivers\HPZipr12.sys
2009-07-13 14:18 . 2003-03-09 04:31    51024    ----a-r-    c:\windows\system32\drivers\hpzid412.sys
2009-07-13 14:14 . 2009-07-13 14:14    --------    d-----w-    c:\programmer\Fælles filer\Hewlett-Packard
2009-07-13 14:10 . 2008-04-13 18:47    25856    ----a-w-    c:\windows\system32\drivers\usbprint.sys
2009-07-13 14:10 . 2008-04-13 18:47    25856    ----a-w-    c:\windows\system32\dllcache\usbprint.sys
2009-07-13 14:09 . 2008-04-13 18:45    32128    ----a-w-    c:\windows\system32\drivers\usbccgp.sys
2009-07-13 14:09 . 2008-04-13 18:45    32128    ----a-w-    c:\windows\system32\dllcache\usbccgp.sys
2009-06-25 10:33 . 2009-06-25 10:33    --------    d-----w-    c:\documents and settings\NetworkService\Lokale indstillinger\Application Data\Apple
2009-06-23 18:41 . 2009-07-14 18:53    --------    d-----w-    c:\programmer\Valve
2009-06-16 14:39 . 2009-06-16 14:39    81920    ------w-    c:\windows\system32\dllcache\fontsub.dll
2009-06-16 14:39 . 2009-06-16 14:39    119808    ------w-    c:\windows\system32\dllcache\t2embed.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 12:34 . 2009-03-28 21:14    --------    d-----w-    c:\programmer\Steam
2009-07-15 12:27 . 2006-05-04 10:10    83484    ----a-w-    c:\windows\system32\perfc006.dat
2009-07-15 12:27 . 2006-05-04 10:10    459330    ----a-w-    c:\windows\system32\perfh006.dat
2009-07-14 20:48 . 2009-04-01 19:52    1    ----a-w-    c:\documents and settings\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-13 15:10 . 2008-06-23 06:11    --------    d-----w-    c:\programmer\Hewlett-Packard
2009-07-13 14:51 . 2008-06-23 06:14    --------    d--h--w-    c:\programmer\InstallShield Installation Information
2009-07-13 14:51 . 2006-05-04 09:57    86327    ----a-w-    c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-20 17:40 . 2008-06-23 06:32    73472    ----a-w-    c:\documents and settings\Administrator\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-06-16 14:39 . 2006-03-02 02:00    81920    ----a-w-    c:\windows\system32\fontsub.dll
2009-06-16 14:39 . 2006-03-02 02:00    119808    ----a-w-    c:\windows\system32\t2embed.dll
2009-06-12 20:39 . 2009-06-12 20:39    --------    d-----w-    c:\programmer\QuickTime
2009-06-12 20:39 . 2009-06-12 20:39    --------    d-----w-    c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-12 20:39 . 2009-06-12 20:39    --------    d-----w-    c:\programmer\Apple Software Update
2009-06-12 20:39 . 2009-06-12 20:39    --------    d-----w-    c:\documents and settings\All Users\Application Data\Apple
2009-06-03 19:11 . 2006-03-02 02:00    1295360    ----a-w-    c:\windows\system32\quartz.dll
2009-05-13 05:05 . 2006-03-02 02:00    915456    ----a-w-    c:\windows\system32\wininet.dll
2009-05-07 15:33 . 2006-03-02 02:00    346624    ----a-w-    c:\windows\system32\localspl.dll
2009-04-19 19:50 . 2006-03-02 02:00    1847168    ----a-w-    c:\windows\system32\win32k.sys
2009-06-12 21:38 . 2009-03-28 22:36    134648    ----a-w-    c:\programmer\mozilla firefox\components\brwsrcmp.dll
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\programmer\steam\steam.exe" [2009-06-10 1217784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-07 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-07 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-07 137752]
"SoundMAXPnP"="c:\programmer\Analog Devices\Core\smax4pnp.exe" [2007-04-26 1015808]
"atchk"="c:\programmer\Intel\AMT\atchk.exe" [2007-06-07 408344]
"PTHOSTTR"="c:\programmer\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2007-01-09 145184]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-05-23 677408]
"SetRefresh"="c:\programmer\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2003-12-22 17920]
"QuickTime Task"="c:\programmer\QuickTime\QTTask.exe" [2009-05-26 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - c:\programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
hp psc 1000 series.lnk - c:\programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2007-02-07 01:30    74240    ----a-r-    c:\programmer\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\APSHook.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages    REG_MULTI_SZ      SbHpNp scecli ASWLNPkg

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1171\Scripts\Logon\0\0]
"Script"=\\aktivkapitaldanmark.local\SysVol\aktivkapitaldanmark.local\scripts\NO-Offlinefolders.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1171\Scripts\Logon\1\0]
"Script"=inventory.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1172\Scripts\Logon\0\0]
"Script"=\\aktivkapitaldanmark.local\SysVol\aktivkapitaldanmark.local\scripts\NO-Offlinefolders.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1172\Scripts\Logon\1\0]
"Script"=inventory.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1178\Scripts\Logon\0\0]
"Script"=\\aktivkapitaldanmark.local\SysVol\aktivkapitaldanmark.local\scripts\NO-Offlinefolders.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1178\Scripts\Logon\1\0]
"Script"=inventory.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1179\Scripts\Logon\0\0]
"Script"=\\aktivkapitaldanmark.local\SysVol\aktivkapitaldanmark.local\scripts\NO-Offlinefolders.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-1179\Scripts\Logon\1\0]
"Script"=inventory.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-500\Scripts\Logon\0\0]
"Script"=\\aktivkapitaldanmark.local\SysVol\aktivkapitaldanmark.local\scripts\NO-Offlinefolders.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2070037969-3333975863-26598437-500\Scripts\Logon\1\0]
"Script"=inventory.bat

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Steam\\SteamApps\\aco410\\day of defeat source\\hl2.exe"=
"c:\\Programmer\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmer\\Steam\\SteamApps\\aco410\\counter-strike\\hl.exe"=
"c:\\Programmer\\Steam\\SteamApps\\aco410\\condition zero\\hl.exe"=

R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [13-06-2007 17:53 101167]
R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [09-10-2006 13:31 44720]
R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [14-06-2007 16:22 13184]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [14-07-2009 22:55 114768]
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [15-02-2007 20:00 26624]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [18-04-2007 19:32 39080]
R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [13-06-2007 17:53 5808]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [02-03-2006 04:00 14336]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [02-03-2006 04:00 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [14-07-2009 22:55 20560]
R2 HpFkCryptService;Drive Encryption Service;c:\programmer\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [09-07-2007 17:03 221184]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\programmer\Intel\AMT\UNS.exe [23-06-2008 08:14 2521880]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [07-02-2007 20:00 3712]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [23-01-2007 22:13 41216]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance    REG_MULTI_SZ      ASBroker ASChannel
HPZ12    REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Indhold af mappen 'Planlagte Opgaver'

2009-07-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-07-13 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8247497865.job
- c:\programmer\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
IE: &AOL Toolbar-søgning - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\da-DK\local\search.html
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3hmd4zlk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 14:34
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-3900716712-1706807462-3262393135-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,de,92,2b,d9,d5,22,2d,44,aa,ce,12,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,de,92,2b,d9,d5,22,2d,44,aa,ce,12,\
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(668)
c:\programmer\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
c:\programmer\Hewlett-Packard\IAM\bin\ItMsg.dll

- - - - - - - > 'lsass.exe'(724)
c:\windows\SbHpNp.dll
c:\programmer\Hewlett-Packard\IAM\bin\ASWLNPkg.dll
c:\programmer\Hewlett-Packard\IAM\bin\ItMsg.dll

- - - - - - - > 'explorer.exe'(3856)
c:\windows\system32\APSHook.dll
c:\progra~1\WINDOW~1\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Alwil Software\Avast4\aswUpdSv.exe
c:\programmer\Alwil Software\Avast4\ashServ.exe
c:\programmer\Intel\AMT\atchksrv.exe
c:\windows\system32\IFXTCS.exe
c:\programmer\Fælles filer\InterVideo\RegMgr\iviRegMgr.exe
c:\programmer\Intel\AMT\LMS.exe
c:\windows\system32\IfxPsdSv.exe
c:\programmer\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\programmer\Alwil Software\Avast4\ashMaiSv.exe
c:\programmer\Alwil Software\Avast4\ashWebSv.exe
c:\programmer\Hewlett-Packard\IAM\Bin\asghost.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\igfxsrvc.exe
c:\programmer\Hewlett-Packard\Embedded Security Software\PSDrt.exe
.
**************************************************************************
.
Gennemført tid: 2009-07-15 14:36 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-07-15 12:36

Pre-Kørsel: 132.730.376.192 byte ledig
Post-Kørsel: 132.792.844.288 byte ledig

235    --- E O F ---    2009-06-09 22:20





Som der også står i filen har computeren (åbenbart) ikke nogen genoprettelseskonsol installeret. Combofix spurgte om jeg ville oprette en, jeg svarede ja, men den kom med en fejl: "kunne ikke finde download sti", eller lign.

Da jeg kørte combofix spurgte den desuden om den måtte opdatere programmet, da der fandtes en nyere version, jeg trykke bare nej og fortsatte, er det ok?

Fedt du gider hjælpe! Tusinde tak :-)
Avatar billede fromsej Praktikant
15. juli 2009 - 18:01 #4
Der er ikke mere at komme efter.

Det med genoprettelseskonsol kan godt drille, hvis du gerne vil have den installeret kan det gøres manuelt.

Læg Windows XP-cd'en i cd-rom-drevet.
Klik på Start, og klik derefter på Kør.
Skriv d:\i386\winnt32.exe /cmdcons, hvor d er drevbogstavet for cd-rom-drevet, i feltet Åbn.
Dialogboksen Windows Installation vises. Denne dialogboks indeholder en beskrivelse af valgmuligheden Genoprettelseskonsol. Klik på Ja for at bekræfte installationen.
Genstart computeren. Næste gang du starter computeren, vises "Microsoft Windows Genoprettelseskonsol" i startmenuen.

Det giver en startmenu, hvor du kan vælge XP eller konsol.
Avatar billede mester12345 Nybegynder
15. juli 2009 - 18:38 #5
Så siger jeg rigtig mange tak for din hjælp. Vil du lægge et svar, så du kan få nogle point? :-)

Et hurtigt lille spørgsmål: Når jeg holder musen over avast ikonet nede i højre hjørne, så står der, at 6 ud af 7 tjenester kører - før jeg rensede computeren stod der 5 ud af 7. Er det normalt, eller bør alle 7 ud af 7 køre?
Avatar billede fromsej Praktikant
15. juli 2009 - 19:48 #6
Det er fuldstændig som det skal være, med 6 ud af 7 tjenester kørende, den syvende er, så vidt jeg husker en mailscanner der tilknyttes Outlook.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester