Avatar billede kafka23 Juniormester
25. april 2014 - 11:09 Der er 15 kommentarer

Malware.

Jeg har stadig en rest tilbage af noget malware efter at I hjalp mig sidst.
Hvordan kommer jeg det sidste til livs?
Her følger malwarebytes' log:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.04.25.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16659
bruger :: AKAT-HP013-R04 [administrator]

25-04-2014 08:47:49
mbam-log-2014-04-25 (08-47-49).txt

Skanningstype: Fuldstændig skanning (C:\|)
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 428672
Tid gået: 1 time(e), 44 minut(ter), 25 sekund(er)

Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabaseværdier Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)

Inficerede Mapper: 0
(Ingen skadelige objekter blev fundet)

Inficerede Filer: 5
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptimizerPro.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProGuard.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProReminder.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProSchedule.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProSmartScan.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.

(færdig)
Avatar billede kafka23 Juniormester
25. april 2014 - 11:16 #1
Da jeg kørte scanningen, viste Microsoft forefront client security en fil, der var "farlig".

Filen hed Exploit:Java/CVE-2013-1493 og blev "removed"

Om filen hed det:

Category:
Exploit

Description:
This program is dangerous and exploits the computer on which it is run.

Advice:
Remove this software immediately.

Programs that may compromise your privacy or damage your computer were detected. You can still access the file without removing the threat, although this is not recommended. To do so, select "Always Allow" as the action and click the "Apply Actions" button. If this option is not available, log on as an administrator or ask an administrator for help.

Detected by:
Definition file

Resources:
file:
C:\Users\bruger\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\60997dd4-18eb0f8b->pGZsiey.class

file:
C:\Users\bruger\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\60997dd4-18eb0f8b->OzoHF.class

containerfile:
C:\Users\bruger\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\60997dd4-18eb0f8b

View more information about this item online
Avatar billede 50573433 Nybegynder
25. april 2014 - 11:27 #2
Avatar billede kafka23 Juniormester
25. april 2014 - 12:02 #3
ok,:
# AdwCleaner v3.202 - Report created 25/04/2014 at 11:57:13
# Updated 23/04/2014 by Xplode
# Operating System : Windows 7 Enterprise Service Pack 1 (32 bits)
# Username : bruger - AKAT-HP013-R04
# Running from : C:\Users\bruger\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MMJM85O4\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\bruger\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\optimi~1\optpro~1.dll
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v28.0 (da)

[ File : C:\Users\bruger\AppData\Roaming\Mozilla\Firefox\Profiles\cc4j7efr.default\prefs.js ]


-\\ Google Chrome v33.0.1750.154

[ File : C:\Users\bruger\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh

*************************

AdwCleaner[R0].txt - [2741 octets] - [21/02/2014 14:20:20]
AdwCleaner[R1].txt - [1609 octets] - [25/04/2014 11:46:22]
AdwCleaner[S0].txt - [2848 octets] - [21/02/2014 14:21:32]
AdwCleaner[S1].txt - [1540 octets] - [25/04/2014 11:57:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1600 octets] ##########
Avatar billede kafka23 Juniormester
25. april 2014 - 12:33 #4
hvad nu?
Avatar billede kafka23 Juniormester
25. april 2014 - 12:34 #5
Det virker til at det der optimizer pro skal ad helvede til. Hvordan får jeg til at skride? :-)
25. april 2014 - 12:52 #6
Slet mappen ->

C:\AdwCleaner\Quarantine\
Avatar billede kafka23 Juniormester
25. april 2014 - 14:27 #7
Ok, det har jeg gjort.
Så er den vel renset. Men jeg har lagt mærke til, at min video kører vildt langsomt, når jeg ser streaming video. Det har været et problem i nogen tid. Så jeg lurer på, om virussen tidligere har rodet sig ind i nogle processer, mens jeg kører mine programmer. Kan jeg tjekke det med Hijcakthis, eller hvad?
Avatar billede Slettet bruger
25. april 2014 - 17:04 #8
Inficerede Filer: 5
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptimizerPro.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProGuard.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProReminder.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProSchedule.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.
C:\AdwCleaner\Quarantine\C\Program Files\optimizer pro\OptProSmartScan.exe.vir (PUP.Optional.OptimizerPro) -> Ingen handling valgt.

Er det en gammel udgave af Malwarebytes du bruger, ser den sådan ud som på billed hvis der gør det er den for gammel. Der er Ingen handling valgt !!
http://i.imgur.com/By4tWPJ.png
Avatar billede Slettet bruger
25. april 2014 - 17:08 #9
Okay det læser jeg så nu, at det er en gammel udgave at malwarebytes du bruger. Den ny scanner bedre end den gamle. http://www.eksperten.dk/guide/1605
Avatar billede kafka23 Juniormester
25. april 2014 - 17:14 #10
Ok,eg downloader den nye malwarebytes og scanner og vender tilbage
Avatar billede kafka23 Juniormester
25. april 2014 - 19:30 #11
Ok, Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Dato: 25-04-2014
Scan Tid: 19:04:23
Logfile:
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.04.25.08
Rootkit Database: v2014.03.27.01
Licens: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
Fil system: NTFS
Bruger: bruger

Scan Type: Trussel Scanning
Resultater: Fuldført
Objekter Scannet: 266626
Forløbet Tid: 35 min, 37 sek

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Warn
PUM: Enabled

Processer: 0
(No malicious items detected)

Moduler: 0
(No malicious items detected)

Nøgle Register: 0
(No malicious items detected)

Værdi Register: 0
(No malicious items detected)

Data Register: 0
(No malicious items detected)

Mapper: 0
(No malicious items detected)

Filer: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)
Avatar billede kafka23 Juniormester
25. april 2014 - 19:34 #12
Så det var jo fint. Video og lyd hakker stadig Hijackthislog følger. Kan I gennemskue noget?
Avatar billede kafka23 Juniormester
25. april 2014 - 19:34 #13
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19:33:35, on 25-04-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16521)

FIREFOX: 28.0 (da)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe
C:\Program Files\CapaInstaller\Client\Util\CapaInstaller InfoCenter.exe
C:\Windows\Samsung\PanelMgr\SSMMgr.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
C:\Users\bruger\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\PlotSoft\PDFill\WriterSave.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_77_ActiveX.exe
C:\Windows\System32\MsSpellCheckingFacility.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\FirstClass\fcc32.exe
C:\Users\bruger\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OUQXRVKZ\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.dk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Microsoft Forefront Client Security Antimalware Service] "c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CapaInstaller Info Center] "C:\Program Files\CapaInstaller\Client\Util\CapaInstaller InfoCenter.exe"
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\bruger\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: Dropbox.lnk = bruger\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB
O17 - HKLM\Software\..\Telephony: DomainName = uv.acu.aaa.dk
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CapaInstaller BITS Control Service (CIBITS) - CapaSystems A/S - C:\Program Files\CapaInstaller\Client\Util\ciBITSSvc.exe
O23 - Service: CapaInstaller Service Health Service (ciinstsvc) - CapaSystems A/S - C:\Program Files\CapaInstaller\Services\sis\ciinstsvc.exe
O23 - Service: CapaInstaller Agent Service (CIStub) - CapaSystems A/S - C:\Program Files\CapaInstaller\Services\CiStub\CIStub.exe
O23 - Service: Google Update Tjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 9798 bytes
Avatar billede 220661 Ekspert
01. maj 2014 - 16:07 #14
Ved du hvad dette er?
CapaInstaller Service Health Service
og CapaInstaller Agent Service?
Og så denne McAffe Security Scan har du ikke behov for.
Prøv at køre en scanning med MAlwarebytes hvor scanning efter rootkits er aktiveret.
Avatar billede kafka23 Juniormester
26. august 2014 - 14:57 #15
Kære alle. Den hakken, jeg ovenfor beskriver, var på grund af et for gammelt modem (eller router), og da den blev skiftet ud, forsvandt problemet. Derfor skal Karise-Larry have pointene. Hvordan giver jeg ham dem?
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester