Avatar billede AnneMCh Juniormester
04. august 2009 - 18:53 Der er 13 kommentarer og
1 løsning

Udskrifter fra diverse log-filer

Hej,

Da min PC er meget langsom specielt mht. internet explorer har jeg kørt følgende og kopieret log-filerne herunder, er der nogen som ved hvad de fortæller:

Ccleaner (ingen log fil)
Malwarebytes
Combofix
Hijackthis

Log-fil fra Malwarebytes:
Malwarebytes' Anti-Malware 1.40
Database version: 2559
Windows 5.1.2600 Service Pack 3

04-08-2009 18:15:23
mbam-log-2009-08-04 (18-15-23).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 153450
Tid tilbagelagt: 1 hour(s), 8 minute(s), 0 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 2
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)


Log-fil fra Combofix:
ComboFix 09-08-03.A2 - Anne-Marie 04-08-2009 18:25.1.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.1535.1155 [GMT 2:00]
Kører fra: c:\eksperten\combofix\ComboFix.exe
Kommandoer benyttet :: c:\eksperten\combofix\cfscript.txt
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Menuen Start\HP Image Zone .lnk
c:\windows\Installer\307db.msi
c:\windows\Installer\30acd.msi
c:\windows\Installer\8c9cc.msi
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\_000014_.tmp.dll

.
(((((((((((((((((((((((((((((  Filer skabt fra 2009-07-04 til 2009-08-04  )))))))))))))))))))))))))))))))))))
.

2009-08-04 15:05 . 2009-07-13 08:00    87888    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\NAVENG.SYS
2009-08-04 15:05 . 2009-07-13 08:00    875728    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\NAVEX15.SYS
2009-08-04 15:05 . 2009-06-09 21:16    177520    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\NAVENG32.DLL
2009-08-04 15:05 . 2009-06-09 21:16    1181040    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\NAVEX32A.DLL
2009-08-04 15:05 . 2009-06-09 21:16    371248    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\EECTRL.SYS
2009-08-04 15:05 . 2009-06-09 21:16    101936    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\ERASER.SYS
2009-08-04 15:05 . 2009-06-09 21:16    259368    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\ECMSVR32.DLL
2009-08-04 15:05 . 2009-06-09 21:16    2414128    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090803.050\CCERASER.DLL
2009-08-04 15:04 . 2009-08-04 15:04    3942048    ----a-w-    c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 15:03 . 2009-08-04 15:03    --------    d-----w-    c:\documents and settings\Anne-Marie\Application Data\Malwarebytes
2009-08-04 15:02 . 2009-08-03 11:36    38160    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 15:02 . 2009-08-04 15:02    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-04 15:02 . 2009-08-03 11:36    19096    ----a-w-    c:\windows\system32\drivers\mbam.sys
2009-08-04 15:02 . 2009-08-04 15:04    --------    d-----w-    c:\programmer\Malwarebytes' Anti-Malware
2009-08-04 14:56 . 2009-08-04 14:56    --------    d-----w-    c:\programmer\CCleaner
2009-08-01 17:05 . 2009-07-11 19:34    276344    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSXpx86.sys
2009-08-01 17:05 . 2009-07-11 19:34    293424    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSvix86.sys
2009-08-01 17:05 . 2009-07-11 19:34    533880    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\Scxpx86.dll
2009-08-01 17:05 . 2009-07-11 19:34    451960    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSxpx86.dll
2009-08-01 17:05 . 2009-07-11 19:34    397360    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSviA64.sys
2009-07-17 17:00 . 2009-07-13 08:00    87888    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVENG.SYS
2009-07-17 17:00 . 2009-07-13 08:00    875728    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVEX15.SYS
2009-07-17 17:00 . 2009-06-09 21:16    177520    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVENG32.DLL
2009-07-17 17:00 . 2009-06-09 21:16    1181040    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVEX32A.DLL
2009-07-17 17:00 . 2009-06-09 21:16    371248    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\EECTRL.SYS
2009-07-17 17:00 . 2009-06-09 21:16    101936    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\ERASER.SYS
2009-07-17 17:00 . 2009-06-09 21:16    259368    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\ECMSVR32.DLL
2009-07-17 17:00 . 2009-06-09 21:16    2414128    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\CCERASER.DLL
2009-07-15 05:13 . 2009-07-15 05:19    --------    d-----w-    C:\eksperten
2009-07-15 03:28 . 2009-07-11 19:34    276344    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSXpx86.sys
2009-07-15 03:28 . 2009-07-11 19:34    533880    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\Scxpx86.dll
2009-07-15 03:28 . 2009-07-11 19:34    451960    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSxpx86.dll
2009-07-15 03:28 . 2009-07-11 19:34    293424    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSvix86.sys
2009-07-15 03:28 . 2009-07-11 19:34    397360    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSviA64.sys
2009-07-13 05:04 . 2009-07-13 05:27    --------    d-----w-    c:\documents and settings\Anne-Marie\Application Data\Skype
2009-07-11 19:34 . 2009-07-11 19:34    276344    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-07-11 19:34 . 2009-07-11 19:34    293424    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-07-11 19:34 . 2009-07-11 19:34    533880    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34    451960    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34    397360    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-07-10 19:13 . 2009-07-10 23:15    --------    d-----w-    c:\documents and settings\Lars\Application Data\Skype
2009-07-10 19:12 . 2009-07-10 19:12    --------    d-----w-    c:\programmer\Fælles filer\Skype
2009-07-10 19:12 . 2009-07-10 19:12    --------    d-----r-    c:\programmer\Skype
2009-07-10 19:11 . 2009-07-10 19:12    --------    d-----w-    c:\documents and settings\All Users\Application Data\Skype

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 15:58 . 2003-04-25 12:00    827392    ----a-w-    c:\windows\system32\wininet.dll
2009-06-29 15:58 . 2006-12-16 15:50    78336    ----a-w-    c:\windows\system32\ieencode.dll
2009-06-29 15:58 . 2003-04-25 12:00    17408    ----a-w-    c:\windows\system32\corpol.dll
2009-06-19 20:10 . 2006-12-27 13:19    --------    d-----w-    c:\programmer\Pixeline
2009-06-16 14:39 . 2003-04-25 12:00    81920    ----a-w-    c:\windows\system32\fontsub.dll
2009-06-16 14:39 . 2003-04-25 12:00    119808    ----a-w-    c:\windows\system32\t2embed.dll
2009-06-13 14:08 . 2009-06-13 14:08    --------    d-----r-    c:\programmer\Norton Support
2009-06-09 21:29 . 2006-12-16 16:03    --------    d-----w-    c:\programmer\Fælles filer\Symantec Shared
2009-06-09 21:17 . 2009-06-09 21:17    --------    d-----w-    c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-09 21:16 . 2009-06-09 21:16    --------    d-----w-    c:\programmer\Symantec
2009-06-09 21:16 . 2009-06-09 21:16    805    ----a-w-    c:\windows\system32\drivers\SYMEVENT.INF
2009-06-09 21:16 . 2009-06-09 21:16    7386    ----a-w-    c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-09 21:16 . 2009-06-09 21:16    60808    ----a-w-    c:\windows\system32\S32EVNT1.DLL
2009-06-09 21:16 . 2009-06-09 21:16    124464    ----a-w-    c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-09 21:16 . 2009-06-09 21:17    36400    ----a-r-    c:\windows\system32\drivers\SymIM.sys
2009-06-09 21:16 . 2009-06-09 21:16    1290592    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-06-09 21:16 . 2009-06-09 21:16    136840    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-06-09 21:16 . 2009-06-09 21:16    796016    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-06-09 21:16 . 2009-06-09 21:15    --------    d-----w-    c:\programmer\Norton 360
2009-06-09 21:15 . 2009-06-09 21:02    --------    d-----w-    c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-09 21:12 . 2008-06-05 13:43    --------    d-----w-    c:\documents and settings\All Users\Application Data\Symantec
2009-06-09 21:12 . 2007-09-10 17:45    --------    d-----w-    c:\documents and settings\Anne-Marie\Application Data\Symantec
2009-06-09 21:04 . 2009-06-09 21:04    --------    d-----w-    c:\documents and settings\All Users\Application Data\PCSettings
2009-06-09 21:03 . 2009-06-09 21:03    --------    d-----w-    c:\documents and settings\All Users\Application Data\Norton
2009-06-09 21:02 . 2009-06-09 21:02    --------    d-----w-    c:\programmer\NortonInstaller
2009-06-03 19:11 . 2003-04-25 12:00    1295360    ----a-w-    c:\windows\system32\quartz.dll
2009-05-07 15:33 . 2003-04-25 12:00    346624    ----a-w-    c:\windows\system32\localspl.dll
2009-05-07 13:51 . 2008-05-16 13:28    120088    ----a-w-    c:\documents and settings\Lars\Application Data\Mozilla\Plugins\npoctoshape.dll
2008-12-22 18:13 . 2007-01-18 17:31    1682    --sha-w-    c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-04-02 17:50    809864    ----a-w-    c:\programmer\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmer\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmer\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-29 68856]
"LDM"="c:\programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2007-01-19 20480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Adobe Photo Downloader"="c:\programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"HP Software Update"="c:\programmer\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"ISUSPM Startup"="c:\programmer\Fælles filer\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Corel Photo Downloader"="c:\programmer\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-11-17 106496]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2008-07-01 413696]
"SunJavaUpdateSched"="c:\programmer\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0300000.086\SymEFA.sys [09-06-2009 23:16 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.086\BHDrvx86.sys [09-06-2009 23:16 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.086\cchpx86.sys [09-06-2009 23:16 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSXpx86.sys [01-08-2009 19:05 276344]
R2 N360;Norton 360;c:\programmer\Norton 360\Engine\3.0.0.134\ccSvcHst.exe [09-06-2009 23:16 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [09-06-2009 23:31 101936]
S3 cpuz131;cpuz131;\??\c:\docume~1\Lars\LOKALE~1\Temp\cpuz131\cpuz_x32.sys --> c:\docume~1\Lars\LOKALE~1\Temp\cpuz131\cpuz_x32.sys [?]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [29-04-2009 17:47 12672]
S3 WN4501HLFZZ;802.11g Wireless USB Adapter;c:\windows\system32\DRIVERS\O4501U.sys --> c:\windows\system32\DRIVERS\O4501U.sys [?]
.
Indhold af mappen 'Planlagte Opgaver'

2009-03-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]

2009-08-04 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programmer\Ask.com\UpdateTask.exe [2009-04-02 17:50]
.
- - - - TOMME GENVEJE FJERNET - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl


.
------- Yderligere scanning -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.djs-netbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-04 18:33
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\programmer\Norton 360\Engine\3.0.0.134\ccSvcHst.exe\" /s \"N360\" /m \"c:\programmer\Norton 360\Engine\3.0.0.134\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'explorer.exe'(3900)
c:\docume~1\ANNE-M~1\LOKALE~1\Temp\IadHide4.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Gennemført tid: 2009-08-04 18:38 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-08-04 16:38

Pre-Kørsel: 111.703.601.152 byte ledig
Post-Kørsel: 111.697.981.440 byte ledig

223    --- E O F ---    2009-08-01 20:52


Log-fil fra Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:40:41, on 04-08-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmer\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
C:\Programmer\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programmer\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Programmer\Java\jre1.5.0_11\bin\jucheck.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Norton 360\Engine\3.0.0.134\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmer\Norton 360\Engine\3.0.0.134\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmer\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmer\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmer\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Norton 360\Engine\3.0.0.134\coIEPlg.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmer\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmer\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Programmer\Fælles filer\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Programmer\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.djs-netbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.4.0) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Programmer\Norton 360\Engine\3.0.0.134\coIEPlg.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Programmer\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Programmer\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Programmer\Fælles filer\Symantec Shared\Support Controls\ssrc.exe

--
End of file - 8074 bytes


Håber I kan hjælpe :-)

mvh Anne-Marie
Avatar billede fromsej Praktikant
04. august 2009 - 20:15 #1
Kør Hijackthis, scan, sæt flueben ved følgende, luk alle vinduer undtaget Hijackthis, klik på fix checked, når den er færdig, genstart.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmer\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmer\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

---------------------------------------
Åbn mappen med Combofix, højreklik, vælg Ny->tekstdokument, åbn tekstdokumentet, kopier følgende ind:

Killall::
Snapshot::
Folder::
C:\Programmer\Ask.com

klik på Filer->Gem som, navngiv den CFScript, luk tekstdokumentet.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den fremkomne log herind.
Avatar billede AnneMCh Juniormester
06. august 2009 - 07:43 #2
Hej fromsej

Nu har jeg gjort ovenstående så her er den nye log-fil fra combofix:

ComboFix 09-08-04.04 - Anne-Marie 06-08-2009  7:25.2.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.1535.1165 [GMT 2:00]
Kører fra: c:\eksperten\combofix\ComboFix.exe
Kommandoer benyttet :: c:\eksperten\combofix\cfscript.txt
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programmer\ask.com
c:\programmer\ask.com\config.xml
c:\programmer\ask.com\mupcfg.xml
c:\programmer\ask.com\UpdateTask.exe

.
(((((((((((((((((((((((((((((  Filer skabt fra 2009-07-06 til 2009-08-06  )))))))))))))))))))))))))))))))))))
.

2009-08-05 12:44 . 2009-07-13 08:00    87888    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\NAVENG.SYS
2009-08-05 12:44 . 2009-07-13 08:00    875728    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\NAVEX15.SYS
2009-08-05 12:44 . 2009-06-09 21:16    177520    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\NAVENG32.DLL
2009-08-05 12:44 . 2009-06-09 21:16    1181040    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\NAVEX32A.DLL
2009-08-05 12:44 . 2009-06-09 21:16    371248    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\EECTRL.SYS
2009-08-05 12:44 . 2009-06-09 21:16    101936    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\ERASER.SYS
2009-08-05 12:44 . 2009-06-09 21:16    259368    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\ECMSVR32.DLL
2009-08-05 12:44 . 2009-06-09 21:16    2414128    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090804.040\CCERASER.DLL
2009-08-04 16:40 . 2009-08-04 16:40    --------    d-----w-    c:\programmer\Trend Micro
2009-08-04 15:04 . 2009-08-04 15:04    3942048    ----a-w-    c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 15:03 . 2009-08-04 15:03    --------    d-----w-    c:\documents and settings\Anne-Marie\Application Data\Malwarebytes
2009-08-04 15:02 . 2009-08-03 11:36    38160    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 15:02 . 2009-08-04 15:02    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-04 15:02 . 2009-08-03 11:36    19096    ----a-w-    c:\windows\system32\drivers\mbam.sys
2009-08-04 15:02 . 2009-08-04 15:04    --------    d-----w-    c:\programmer\Malwarebytes' Anti-Malware
2009-08-04 14:56 . 2009-08-04 14:56    --------    d-----w-    c:\programmer\CCleaner
2009-08-01 17:05 . 2009-07-11 19:34    276344    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSXpx86.sys
2009-08-01 17:05 . 2009-07-11 19:34    293424    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSvix86.sys
2009-08-01 17:05 . 2009-07-11 19:34    533880    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\Scxpx86.dll
2009-08-01 17:05 . 2009-07-11 19:34    451960    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSxpx86.dll
2009-08-01 17:05 . 2009-07-11 19:34    397360    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSviA64.sys
2009-07-17 17:00 . 2009-07-13 08:00    87888    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVENG.SYS
2009-07-17 17:00 . 2009-07-13 08:00    875728    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVEX15.SYS
2009-07-17 17:00 . 2009-06-09 21:16    177520    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVENG32.DLL
2009-07-17 17:00 . 2009-06-09 21:16    1181040    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\NAVEX32A.DLL
2009-07-17 17:00 . 2009-06-09 21:16    371248    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\EECTRL.SYS
2009-07-17 17:00 . 2009-06-09 21:16    101936    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\ERASER.SYS
2009-07-17 17:00 . 2009-06-09 21:16    259368    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\ECMSVR32.DLL
2009-07-17 17:00 . 2009-06-09 21:16    2414128    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090717.006\CCERASER.DLL
2009-07-15 05:13 . 2009-07-15 05:19    --------    d-----w-    C:\eksperten
2009-07-15 03:28 . 2009-07-11 19:34    276344    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSXpx86.sys
2009-07-15 03:28 . 2009-07-11 19:34    533880    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\Scxpx86.dll
2009-07-15 03:28 . 2009-07-11 19:34    451960    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSxpx86.dll
2009-07-15 03:28 . 2009-07-11 19:34    293424    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSvix86.sys
2009-07-15 03:28 . 2009-07-11 19:34    397360    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSviA64.sys
2009-07-13 05:04 . 2009-07-13 05:27    --------    d-----w-    c:\documents and settings\Anne-Marie\Application Data\Skype
2009-07-11 19:34 . 2009-07-11 19:34    276344    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-07-11 19:34 . 2009-07-11 19:34    293424    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-07-11 19:34 . 2009-07-11 19:34    533880    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34    451960    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34    397360    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-07-10 19:13 . 2009-07-10 23:15    --------    d-----w-    c:\documents and settings\Lars\Application Data\Skype
2009-07-10 19:12 . 2009-07-10 19:12    --------    d-----w-    c:\programmer\Fælles filer\Skype
2009-07-10 19:12 . 2009-07-10 19:12    --------    d-----r-    c:\programmer\Skype
2009-07-10 19:11 . 2009-07-10 19:12    --------    d-----w-    c:\documents and settings\All Users\Application Data\Skype

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 15:58 . 2003-04-25 12:00    827392    ----a-w-    c:\windows\system32\wininet.dll
2009-06-29 15:58 . 2006-12-16 15:50    78336    ----a-w-    c:\windows\system32\ieencode.dll
2009-06-29 15:58 . 2003-04-25 12:00    17408    ----a-w-    c:\windows\system32\corpol.dll
2009-06-19 20:10 . 2006-12-27 13:19    --------    d-----w-    c:\programmer\Pixeline
2009-06-16 14:39 . 2003-04-25 12:00    81920    ----a-w-    c:\windows\system32\fontsub.dll
2009-06-16 14:39 . 2003-04-25 12:00    119808    ----a-w-    c:\windows\system32\t2embed.dll
2009-06-13 14:08 . 2009-06-13 14:08    --------    d-----r-    c:\programmer\Norton Support
2009-06-09 21:29 . 2006-12-16 16:03    --------    d-----w-    c:\programmer\Fælles filer\Symantec Shared
2009-06-09 21:17 . 2009-06-09 21:17    --------    d-----w-    c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-09 21:16 . 2009-06-09 21:16    --------    d-----w-    c:\programmer\Symantec
2009-06-09 21:16 . 2009-06-09 21:16    805    ----a-w-    c:\windows\system32\drivers\SYMEVENT.INF
2009-06-09 21:16 . 2009-06-09 21:16    7386    ----a-w-    c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-09 21:16 . 2009-06-09 21:16    60808    ----a-w-    c:\windows\system32\S32EVNT1.DLL
2009-06-09 21:16 . 2009-06-09 21:16    124464    ----a-w-    c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-09 21:16 . 2009-06-09 21:17    36400    ----a-r-    c:\windows\system32\drivers\SymIM.sys
2009-06-09 21:16 . 2009-06-09 21:16    1290592    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-06-09 21:16 . 2009-06-09 21:16    136840    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-06-09 21:16 . 2009-06-09 21:16    796016    ----a-w-    c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-06-09 21:16 . 2009-06-09 21:15    --------    d-----w-    c:\programmer\Norton 360
2009-06-09 21:15 . 2009-06-09 21:02    --------    d-----w-    c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-09 21:12 . 2008-06-05 13:43    --------    d-----w-    c:\documents and settings\All Users\Application Data\Symantec
2009-06-09 21:12 . 2007-09-10 17:45    --------    d-----w-    c:\documents and settings\Anne-Marie\Application Data\Symantec
2009-06-09 21:04 . 2009-06-09 21:04    --------    d-----w-    c:\documents and settings\All Users\Application Data\PCSettings
2009-06-09 21:03 . 2009-06-09 21:03    --------    d-----w-    c:\documents and settings\All Users\Application Data\Norton
2009-06-09 21:02 . 2009-06-09 21:02    --------    d-----w-    c:\programmer\NortonInstaller
2009-06-03 19:11 . 2003-04-25 12:00    1295360    ----a-w-    c:\windows\system32\quartz.dll
2008-12-22 18:13 . 2007-01-18 17:31    1682    --sha-w-    c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-29 68856]
"LDM"="c:\programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2007-01-19 20480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="c:\programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"HP Software Update"="c:\programmer\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"ISUSPM Startup"="c:\programmer\Fælles filer\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Corel Photo Downloader"="c:\programmer\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-11-17 106496]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2008-07-01 413696]
"SunJavaUpdateSched"="c:\programmer\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0300000.086\SymEFA.sys [09-06-2009 23:16 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.086\BHDrvx86.sys [09-06-2009 23:16 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.086\cchpx86.sys [09-06-2009 23:16 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090730.003\IDSXpx86.sys [01-08-2009 19:05 276344]
R2 N360;Norton 360;c:\programmer\Norton 360\Engine\3.0.0.134\ccSvcHst.exe [09-06-2009 23:16 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [09-06-2009 23:31 101936]
S3 cpuz131;cpuz131;\??\c:\docume~1\Lars\LOKALE~1\Temp\cpuz131\cpuz_x32.sys --> c:\docume~1\Lars\LOKALE~1\Temp\cpuz131\cpuz_x32.sys [?]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [29-04-2009 17:47 12672]
S3 WN4501HLFZZ;802.11g Wireless USB Adapter;c:\windows\system32\DRIVERS\O4501U.sys --> c:\windows\system32\DRIVERS\O4501U.sys [?]
.
Indhold af mappen 'Planlagte Opgaver'

2009-03-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
.
- - - - TOMME GENVEJE FJERNET - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)


.
------- Yderligere scanning -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.djs-netbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-06 07:33
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\programmer\Norton 360\Engine\3.0.0.134\ccSvcHst.exe\" /s \"N360\" /m \"c:\programmer\Norton 360\Engine\3.0.0.134\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'explorer.exe'(1044)
c:\docume~1\ANNE-M~1\LOKALE~1\Temp\IadHide4.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Gennemført tid: 2009-08-06  7:38 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-08-06 05:38
ComboFix2.txt  2009-08-04 16:38

Pre-Kørsel: 111.641.059.328 byte ledig
Post-Kørsel: 111.667.695.616 byte ledig

198    --- E O F ---    2009-08-01 20:52


mvh Anne-Marie
Avatar billede fromsej Praktikant
06. august 2009 - 19:44 #3
Det ser fint ud, har det ændret noget?
Avatar billede AnneMCh Juniormester
08. august 2009 - 07:11 #4
Nej det synes jeg ikke, når jeg kigger i tas manager, bruges der meget CPU når jeg feks. åbner internet, så går iexplorer.exe på mindst 90 % med samme, hvad er ccSvcHst.exe for den bruger også meget CPU ? Andre ideer ?
Avatar billede fromsej Praktikant
08. august 2009 - 07:29 #5
ccSvcHst.exe hører til Norton, det er et alment kendt problem, men Symantec(Norton) mener ikke at de behøver gøre noget ved det, folk skal nok købe deres skrammel alligevel.
Var det min maskine røg Norton omgående ud.

Prøv dette:
Klik på Start->Kør skriv SFC /scannow(bemærk mellemrum), klik OK.
Din XP-CD skal sidde i drevet.
Når den er færdig, genstart, se om det hjalp.
Avatar billede AnneMCh Juniormester
08. august 2009 - 08:51 #6
Det har hjulpet nu bruger PC'en a, 90-100 % CPU kraft i ca. 10 sek. når jeg vælger en ny side i explorer og ccSvcHst.exe bruger ikke CPU. Hvad vil du bruge istedet for Norto, Bullguard eller ?

Når vi er "færdig" med denne PC har jeg en mere vi skal have set på det er en DELL laptop
Avatar billede AnneMCh Juniormester
08. august 2009 - 08:53 #7
Yderligere når jeg kigger i task manager så er derhele tiden udsving i Oversigt over CPU brug, før hang den næsten fast på 100 %
Avatar billede fromsej Praktikant
08. august 2009 - 09:14 #8
Jeg ville enten vælge Bullguard eller Eset.
Begge kører her i huset, Bullguard på døtrenes og konens, Eset på min egen.
Avatar billede AnneMCh Juniormester
08. august 2009 - 09:14 #9
Hvordan afinstallerer jeg Norton, så det er HELT væk ?
Avatar billede fromsej Praktikant
08. august 2009 - 18:21 #10
Først og fremmest skal du have en installationsfil til et andet antivirusprogram.
Prøv f.eks. Bullguard, det er gratis i to måneder.
http://www.spywarefri.dk/download/bullguard-internet-security-32-bit/

Når du har den, så gør dette:
Download Norton Removal Tool (SymNRT) til dit skrivebord.
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039

Når du har hentet det, skal du lukke alle åbne browsere og vinduer, fordi det vil kræve en genstart.

Gå så til dit skrivebord og dobbeltklik på værktøjet og klik derefter på Setup.
Klik på Næste.
Accepter licensaftalen, og klik på Næste
skriv de bogstaver og tal, du ser i tekstfeltet og klik derefter på Næste.
Derefter klik på Næste og værktøjet vil begynde at køre.
Når det er færdigt genstart computeren og kør værktøjet igen for at sikre, at alt er blevet fjernet.
Slet Nortonremoval værktøj fra dit skrivebord.
Genstart.

Installer Bullguard.
Avatar billede AnneMCh Juniormester
09. august 2009 - 08:51 #11
Nu har jeg afinstalleret Norton og installeret Bullguard (gratis version 2 mdr), men mellemtiden ca. 14 timer har jeg haft installeret et gratis program avast, som jeg har fjernet igen vha. "Tilføj/fjern programer" kan du forudse nogen problemer med det. Er det feks. nødvendigt at køre ccleaner osv. igen ?

Rækkefølge jeg har foretaget tingene i:
1. hente fil til avast antivrus
2. afinstalleret norton vha. norton removal tool
3. installeret avast
4. ups ingen firewall
5. ca. 14 timer senere hente fil til bullguard
6. fjernet avast (tilføj/fjern programmer)
7. installeret bullguard (version for 2 mdr)

Hvad er din mening om feks. avast og hvilken firewall kan evt. bruges sammen med ?
Avatar billede fromsej Praktikant
09. august 2009 - 09:42 #12
Avast er i mine øjne den bedste gratis løsning i øjeblikket.
Den kører fint sammen med f.eks. Comodo firewall.

Her er en god artikel, skrevet af BjarneA (her på Eksperten hedder han b-and), som beskriver mere indgående hvilke ting man måtte have brug for.
http://www.spywarefri.dk/forum/viewthread/73083/
Avatar billede AnneMCh Juniormester
11. august 2009 - 06:51 #13
Så kan jeg afslutte denne tråd, så giv lige et svar så jeg kan give point. Status er at jeg har installeret 2-mdr. version af bullguard på begge PC'er, Norton er væk. og pt. kører de hurtigere begge to. Mange tak for hjælpen.
Avatar billede fromsej Praktikant
11. august 2009 - 09:36 #14
Velbekomme. :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester