Fjernelse af dll fil
  hvonaal
Antal indlæg: 27

Jeg får konstant en besked om at Bullguard har fundet malware.

fil: qommkii.dll
Sti: C:\WINDOWS\system32
Virus: Trojan.Peed.Gen

Bullguard kan ikke fjerne den.
Fra Bullguard support har jeg fået besked om, at gå ind i C:\WINDOWS\system32 og delete filen, men det kan jeg ikke, kommer besked om den er skrivebeskyttet eller bruges et program.

Jeg får også Popup vinduer som sender mig til mærkelige sider med Antivir og Protection Center.

Hijack ser således ud:

Logfile of HijackThis v1.99.1
Scan saved at 22:43:57, on 14-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\XP Media\Skrivebord\Ny mappe\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe”
O4 - HKLM\..\Run: [Omnipage] C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe” -boot
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe “C:\WINDOWS\system32\amwoqvog.dll”,realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized
O4 - HKCU\..\Run: [MSMSGS] “C:\Programmer\Messenger\msmsgs.exe” /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe”
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160317481614
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Rootchk således:

********************************* ROOTCHK-(02-05-07)-LOG, by ejvindh
14-05-2007 22:46:12,62

Driver Ntio256 (visible) is present. A rootkit scan is recommended.
Driver Ntio256 (visible) is present. A rootkit scan is recommended.

********************************* ROOTCHK-LOG-end


catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-14 22:46:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

Og AVG Anti Spy:

AVG Anti-Spyware - Scan Report
————————————————————————————-

+ Created at: 23:28:09 14-05-2007

+ Scan result:

Nothing found.

::Report end

I har engang for en 3 år siden hjulpet mig, hvilket jeg håber i kan igen.

Mvh.

Henrik

Administrator
Avatar
Antal indlæg: 29613

Hej hvonaal smile


Ja, der har du reddet dig et par grimme tingester, men lad os lige fixe de rootkit du har fået, først -

Hent dette værktøj fra følgende link, og gem det på skrivebordet:
http://www.uploads.ejvindh.net/rustbfix.exe

Dobbeltklik på værktøjet. Hvis værktøjet finder en Rustock-infektion, vil du efter kort tid blive bedt om at genstarte computeren. Dette skal du så acceptere. Genstarten vil muligvis tage et godt stykke tid, og måske skal der 2 genstarter til, men dette vil ske helt automatisk. Når genstarten er færdig vil der åbnes 2 logfiler (%root%\avenger.txt & %root%\rustbfix\pelog.txt), som du skal kopiere ind i tråden.


Dobbeltklik på værktøjet. Hvis værktøjet finder en Rustock-infektion, vil du efter kort tid blive bedt om at genstarte computeren. Dette skal du så acceptere. Genstarten vil muligvis tage et godt stykke tid, og måske skal der 2 genstarter til, men dette vil ske helt automatisk. Når genstarten er færdig vil der åbnes 2 logfiler, som du skal kopiere ind i tråden.

Højreklik på hijackthis exe og omdøb den til hjt exe

Send også en ny hijackthis log herind sammen med de 2 ovenstående logfiler

  hvonaal
Antal indlæg: 27

Her er så de nye log filer

************************* Rustock.b-fix—By ejvindh *************************
15-05-2007 19:09:02,82

No Rustock.b-rootkits found

******************************* End of Logfile ********************************

Logfile of HijackThis v1.99.1
Scan saved at 19:11:34, on 15-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\XP Media\Skrivebord\Ny mappe\hjt.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {539825C7-49B2-404B-B930-058E06465B9D} - C:\WINDOWS\system32\qommkii.dll
O2 - BHO: (no name) - {575385B4-774C-48BF-AA3C-FE2D8706B453} - (no file)
O2 - BHO: (no name) - {8DD23E0A-4AEF-4B06-9E12-B6D90F1F07E2} - C:\WINDOWS\system32\sstqn.dll
O2 - BHO: (no name) - {A5AD95D2-D398-4604-B5E1-FFD09F5443E5} - C:\WINDOWS\system32\sstqn.dll
O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - (no file)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe”
O4 - HKLM\..\Run: [Omnipage] C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe” -boot
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe “C:\WINDOWS\system32\amwoqvog.dll”,realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized
O4 - HKCU\..\Run: [MSMSGS] “C:\Programmer\Messenger\msmsgs.exe” /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe”
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160317481614
O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll (file missing)
O20 - Winlogon Notify: qommkii - C:\WINDOWS\SYSTEM32\qommkii.dll
O20 - Winlogon Notify: sstqn - C:\WINDOWS\system32\sstqn.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6048

Du har et par slemme rootkits på din computer. Jeg overfører derfor tråden til Rootkit-kategorien. Der gælder nogle særlige forhold for supporten i denne kategori, som du kan læse om her:

http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=29320


Hvis du alligevel vælger at fortsætte, så prøv følgende:

—Hent VirtumundoBeGone, gem det på skrivebordet:
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

—Luk alle kørende programmer, også Internetvinduer, dobbeltklik på VirtumundoBeGone.exe på skrivebordet, læs intro-informationen, klik så på Continue, klik på Start.
Når den spørger om du vil fortsætte, klik på Yes for at køre fixet.
Klik så på Save log.

—Det sker sommetider at fixet afslutter med “BSOD”(blå skærm og frosset PC) så skal du bare genstarte på Resetknappen.

—Der kommer en tekstfil på dit skrivebord der hedder VBG.TXT åbn den og kopier teksten herind, sammen med en frisk Hijackthislog.

—Download så Gmer-rootkit scanner, og pak den ud til skrivebordet:
http://www.young-andersen.dk/gamer/gamer.zip
Start med at omdøbe programmet gmer.exe (fx til abc.exe). Kør programmet, klik på fanebladet “Rootkit”, og klik på “Scan”. Imens der scannes, bør du afbryde netforbindelsen, lukke alle åbne programmer, og undlade at bruge computeren til andre ting. Du bør heller ikke klikke på andre ting i Gmer-scanneren. Når scanningen er færdig, skal du klikke på “Copy”. Så dukker et vindue op, som fortæller at resultatet af rootkit-scanningen er blevet lagt ind i udklipsholderen. Du kan herefter gå ind i denne tråd, og kopiere indholdet herind, ved at stille dig i indtastningsfeltet, og trykke ctrl-v.

I nogle tilfælde er logfilen så lang, at den ikke kan være i en enkelt post. Så må du lægge den af flere omgange.

  hvonaal
Antal indlæg: 27

Logfile of HijackThis v1.99.1
Scan saved at 21:53:58, on 15-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\XP Media\Skrivebord\Ny mappe\hjt.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {575385B4-774C-48BF-AA3C-FE2D8706B453} - (no file)
O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - (no file)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe”
O4 - HKLM\..\Run: [Omnipage] C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe” -boot
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe “C:\WINDOWS\system32\amwoqvog.dll”,realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized
O4 - HKCU\..\Run: [MSMSGS] “C:\Programmer\Messenger\msmsgs.exe” /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe”
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160317481614
O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


VBG tekst ser sådan ud

[05/15/2007, 21:17:58] - VirtumundoBeGone v1.5 ( “C:\Documents and Settings\XP Media\Skrivebord\VirtumundoBeGone.exe” )
[05/15/2007, 21:18:16] - Detected System Information:
[05/15/2007, 21:18:16] -  Windows Version: 5.1.2600, Service Pack 2
[05/15/2007, 21:18:16] -  Current Username: XP Media (Admin)
[05/15/2007, 21:18:16] -  Windows is in NORMAL mode.
[05/15/2007, 21:18:16] - Searching for Browser Helper Objects:
[05/15/2007, 21:18:16] -  BHO 1: {05E0F312-656A-43F8-AAD9-A2A95517641D} ()
[05/15/2007, 21:18:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:16] -  Checking for HKLM\...\Winlogon\Notify\sstqn
[05/15/2007, 21:18:16] -  Found: HKLM\...\Winlogon\Notify\sstqn - This is probably Virtumundo.
[05/15/2007, 21:18:16] -  Assigning {05E0F312-656A-43F8-AAD9-A2A95517641D} MSEvents Object
[05/15/2007, 21:18:16] - BHO list has been changed! Starting over…
[05/15/2007, 21:18:16] -  BHO 1: {05E0F312-656A-43F8-AAD9-A2A95517641D} (MSEvents Object)
[05/15/2007, 21:18:16] - ALERT: Found MSEvents Object!
[05/15/2007, 21:18:16] -  BHO 2: {539825C7-49B2-404B-B930-058E06465B9D} ()
[05/15/2007, 21:18:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:16] -  Checking for HKLM\...\Winlogon\Notify\qommkii
[05/15/2007, 21:18:16] -  Found: HKLM\...\Winlogon\Notify\qommkii - This is probably Virtumundo.
[05/15/2007, 21:18:16] -  Assigning {539825C7-49B2-404B-B930-058E06465B9D} MSEvents Object
[05/15/2007, 21:18:16] - BHO list has been changed! Starting over…
[05/15/2007, 21:18:16] -  BHO 1: {05E0F312-656A-43F8-AAD9-A2A95517641D} (MSEvents Object)
[05/15/2007, 21:18:16] - ALERT: Found MSEvents Object!
[05/15/2007, 21:18:16] -  BHO 2: {539825C7-49B2-404B-B930-058E06465B9D} (MSEvents Object)
[05/15/2007, 21:18:16] - ALERT: Found MSEvents Object!
[05/15/2007, 21:18:16] -  BHO 3: {575385B4-774C-48BF-AA3C-FE2D8706B453} ()
[05/15/2007, 21:18:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:16] -  No filename found. Continuing.
[05/15/2007, 21:18:16] -  BHO 4: {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} ()
[05/15/2007, 21:18:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:16] -  No filename found. Continuing.
[05/15/2007, 21:18:16] - Finished Searching Browser Helper Objects
[05/15/2007, 21:18:16] - *** Detected MSEvents Object
[05/15/2007, 21:18:16] - Trying to remove MSEvents Object…
[05/15/2007, 21:18:17] -  Terminating Process: IEXPLORE.EXE
[05/15/2007, 21:18:18] -  Terminating Process: RUNDLL32.EXE
[05/15/2007, 21:18:18] -  Disabling Automatic Shell Restart
[05/15/2007, 21:18:18] -  Terminating Process: EXPLORER.EXE
[05/15/2007, 21:18:18] -  Suspending the NT Session Manager System Service
[05/15/2007, 21:18:18] -  Terminating Windows NT Logon/Logoff Manager
[05/15/2007, 21:18:19] -  Re-enabling Automatic Shell Restart
[05/15/2007, 21:18:19] -  File to disable: C:\WINDOWS\system32\sstqn.dll
[05/15/2007, 21:18:19] -  Renaming C:\WINDOWS\system32\sstqn.dll -> C:\WINDOWS\system32\sstqn.dll.vir
[05/15/2007, 21:18:19] -  File successfully renamed!
[05/15/2007, 21:18:19] -  Removing HKLM\...\Browser Helper Objects\{05E0F312-656A-43F8-AAD9-A2A95517641D}
[05/15/2007, 21:18:19] -  Removing HKCR\CLSID\{05E0F312-656A-43F8-AAD9-A2A95517641D}
[05/15/2007, 21:18:19] -  Adding Kill Bit for ActiveX for GUID: {05E0F312-656A-43F8-AAD9-A2A95517641D}
[05/15/2007, 21:18:19] -  Deleting ATLEvents/MSEvents Registry entries
[05/15/2007, 21:18:19] -  Removing HKLM\...\Winlogon\Notify\sstqn
[05/15/2007, 21:18:19] - Searching for Browser Helper Objects:
[05/15/2007, 21:18:19] -  BHO 1: {539825C7-49B2-404B-B930-058E06465B9D} (MSEvents Object)
[05/15/2007, 21:18:19] - ALERT: Found MSEvents Object!
[05/15/2007, 21:18:19] -  BHO 2: {575385B4-774C-48BF-AA3C-FE2D8706B453} ()
[05/15/2007, 21:18:19] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:19] -  No filename found. Continuing.
[05/15/2007, 21:18:19] -  BHO 3: {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} ()
[05/15/2007, 21:18:19] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:19] -  No filename found. Continuing.
[05/15/2007, 21:18:19] - Finished Searching Browser Helper Objects
[05/15/2007, 21:18:19] - *** Detected MSEvents Object
[05/15/2007, 21:18:19] - Trying to remove MSEvents Object…
[05/15/2007, 21:18:20] -  Terminating Process: IEXPLORE.EXE
[05/15/2007, 21:18:20] -  Terminating Process: RUNDLL32.EXE
[05/15/2007, 21:18:20] -  Disabling Automatic Shell Restart
[05/15/2007, 21:18:20] -  Terminating Process: EXPLORER.EXE
[05/15/2007, 21:18:20] -  Suspending the NT Session Manager System Service
[05/15/2007, 21:18:20] -  Terminating Windows NT Logon/Logoff Manager
[05/15/2007, 21:18:20] -  Re-enabling Automatic Shell Restart
[05/15/2007, 21:18:20] -  File to disable: C:\WINDOWS\system32\qommkii.dll
[05/15/2007, 21:18:20] -  Renaming C:\WINDOWS\system32\qommkii.dll -> C:\WINDOWS\system32\qommkii.dll.vir
[05/15/2007, 21:18:20] - ! File rename was unsucessful.
[05/15/2007, 21:18:20] -  Attempting to Deny Access to C:\WINDOWS\system32\qommkii.dll
[05/15/2007, 21:18:21] - *** IMPORTANT: Delete/Rename/Move on reboot (like Killbox) MAY NOT work.
[05/15/2007, 21:18:21] -  ERROR: Der blev ikke udført nogen afbildning mellem kontonavne og sikkerheds-id.

[05/15/2007, 21:18:21] - *** IMPORTANT: The file is disabled and will need to be deleted by the user.
[05/15/2007, 21:18:21] -  Removing HKLM\...\Browser Helper Objects\{539825C7-49B2-404B-B930-058E06465B9D}
[05/15/2007, 21:18:21] -  Removing HKCR\CLSID\{539825C7-49B2-404B-B930-058E06465B9D}
[05/15/2007, 21:18:21] -  Adding Kill Bit for ActiveX for GUID: {539825C7-49B2-404B-B930-058E06465B9D}
[05/15/2007, 21:18:21] -  Deleting ATLEvents/MSEvents Registry entries
[05/15/2007, 21:18:21] -  Removing HKLM\...\Winlogon\Notify\qommkii
[05/15/2007, 21:18:21] - Searching for Browser Helper Objects:
[05/15/2007, 21:18:21] -  BHO 1: {575385B4-774C-48BF-AA3C-FE2D8706B453} ()
[05/15/2007, 21:18:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:21] -  No filename found. Continuing.
[05/15/2007, 21:18:21] -  BHO 2: {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} ()
[05/15/2007, 21:18:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/15/2007, 21:18:21] -  No filename found. Continuing.
[05/15/2007, 21:18:21] - Finished Searching Browser Helper Objects
[05/15/2007, 21:18:21] - Finishing up…
[05/15/2007, 21:18:21] - A restart is needed.
[05/15/2007, 21:18:41] - Attempting to Restart via STOP error (Blue Screen!)

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6048

Det ser godt ud. Du glemte at lægge en log fra Gmer, men jeg har i mellemtiden fundet ud af, at Combofix nu kan tage det rootkit, som er på din computer. Så prøv følgende:

—Hent Combofix fra et af disse links, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

— Kør så combofix.exe, som du hentede tidligere, og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.

—Læg også en ny log fra Hijackthis herind til gennemsyn.

  hvonaal
Antal indlæg: 27

Combofix ser således ud:

“XP Media” - 2007-05-16 23:23:57   Service Pack 2
ComboFix 07-05.17.V - Running from: “C:\Documents and Settings\XP Media\Skrivebord\”


((((((((((((((((((((((((((((((((((((((((((((((((((  V Log   )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\amwoqvog.dll
C:\WINDOWS\system32\nantjsxf.dll
C:\WINDOWS\system32\tsadxork.dll
C:\WINDOWS\system32\govqowma.ini
C:\WINDOWS\system32\fxsjtnan.ini


* * *  POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


((((((((((((((((((((((((((((((((((((((((((((  Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\XPMEDI~1\SKRIVE~1.\internet explorer.lnk
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~  Purity   ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\XPMEDI~1
C:\qoobox\purity\C\DOCUME~1\XPMEDI~1\DOKUME~1
C:\qoobox\purity\C\DOCUME~1\XPMEDI~1\DOKUME~1\ICROSO~1.NET


(((((((((((((((((((((((((((((((((((((((((((  Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))


———-\LEGACY_NTIO256
———-\ntio256


(((((((((((((((((((((((((((((((  Files Created from 2007-04-05 to 2007-05-16 ))))))))))))))))))))))))))))))))))


2007-05-15 21:18 0—a———C:\WINDOWS\system32\qommkii.dll.vir
2007-05-15 20:57 <DIR> d————C:\!KillBox
2007-05-15 19:09 <DIR> d————C:\Rustbfix
2007-05-14 22:56 666,490—-hs——C:\WINDOWS\system32\nqtss.bak2
2007-05-14 22:13 3,968—a———C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-05-14 21:36 <DIR> d————C:\Programmer\CCleaner
2007-05-14 20:09 76,560—a———C:\WINDOWS\system32\drivers\tmcomm.sys
2007-05-14 18:39 524,288—ah——- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-14 18:39 <DIR> dr———- C:\DOCUME~1\ADMINI~1\Menuen Start
2007-05-14 18:39 <DIR> d—h——- C:\DOCUME~1\ADMINI~1\Skabeloner
2007-05-14 18:39 <DIR> d—h——- C:\DOCUME~1\ADMINI~1\Printere
2007-05-14 18:39 <DIR> d—h——- C:\DOCUME~1\ADMINI~1\Lokale indstillinger
2007-05-14 18:39 <DIR> d—h——- C:\DOCUME~1\ADMINI~1\Andre computere
2007-05-14 18:39 <DIR> d————C:\DOCUME~1\ADMINI~1\Skrivebord
2007-05-14 18:39 <DIR> d————C:\DOCUME~1\ADMINI~1\Foretrukne
2007-05-14 18:39 <DIR> d————C:\DOCUME~1\ADMINI~1\Dokumenter
2007-05-13 22:56 657,788—-hs——C:\WINDOWS\system32\nqtss.bak1
2007-05-13 22:56 285,268—ahs——C:\WINDOWS\system32\sstqn.dll.vir
2007-05-12 22:29 662,824—-hs——C:\WINDOWS\system32\qrutv.ini2
2007-05-12 22:19 <DIR> d————C:\WINDOWS\system32\appmgmt
2007-05-12 21:13 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\BullGuard
2007-05-12 21:13 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\BullGuard
2007-05-12 21:12 50,904—a———C:\WINDOWS\system32\drivers\BdFileSpy.sys
2007-05-12 21:12 <DIR> d————C:\Programmer\BullGuard Software
2007-05-12 20:42 <DIR> d—hs——C:\WINDOWS\CSC
2007-05-12 20:08 657,828—-hs——C:\WINDOWS\system32\qrutv.bak1
2007-05-12 17:09 34,308—a———C:\WINDOWS\system32\Chip.dll
2007-05-12 16:46 <DIR> d————C:\Programmer\Ashampoo
2007-05-12 16:37 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\SlySoft
2007-05-12 16:36 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\SlySoft
2007-05-12 16:34 <DIR> d————C:\Programmer\SlySoft
2007-05-12 16:16 658,174—-hs——C:\WINDOWS\system32\ghkmp.ini2
2007-05-12 16:14 657,788—-hs——C:\WINDOWS\system32\ghkmp.bak1
2007-05-12 16:11 <DIR> d————C:\Programmer\MSXML 4.0
2007-05-12 15:58 1—a———C:\WINDOWS\system32\ps.dat
2007-05-12 15:58 1—a———C:\WINDOWS\system32\cookie.dat
2007-05-12 15:55 <DIR> d————C:\Programmer\DVD Shrink
2007-05-12 15:55 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-05-12 15:39 29,206—a———C:\WINDOWS\system32\qommkii.dll
2007-05-12 15:26 0—a———C:\WINDOWS\system32\CMMGR32.EXE
2007-05-12 15:22 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\SUPERAntiSpyware.com
2007-05-12 15:22 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-05-12 14:58 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\Ahead
2007-05-11 22:49 82,304—a———C:\WINDOWS\system32\drivers\grclass.sys
2007-05-11 22:49 167,936—a———C:\WINDOWS\system32\SetCSP.dll
2007-05-11 22:49 106,496—a———C:\WINDOWS\system32\pluginhostctrl.dll
2007-05-11 22:49 <DIR> d————C:\Programmer\Setec
2007-05-11 22:48 85,034—a———C:\WINDOWS\system32\drivers\GemUsb.sys
2007-05-11 22:48 <DIR> d————C:\PBS
2007-05-11 22:47 305,152—a———C:\WINDOWS\IsUn0406.exe
2007-05-11 22:44 <DIR> d————C:\Programmer\Windows Media Connect 2
2007-05-11 22:42 <DIR> d————C:\WINDOWS\system32\LogFiles
2007-05-11 22:42 <DIR> d————C:\WINDOWS\system32\drivers\UMDF
2007-05-11 22:37 221,184—a———C:\WINDOWS\system32\wmpns.dll
2007-05-11 22:32 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
2007-05-11 22:11 15,104—a———C:\WINDOWS\system32\drivers\usbscan.sys
2007-05-11 21:59 94,208—a———C:\WINDOWS\system32\ippcv11.dll
2007-05-11 21:59 77,824—a———C:\WINDOWS\system32\ippsr11.dll
2007-05-11 21:59 65,536—a———C:\WINDOWS\system32\ippj11.dll
2007-05-11 21:59 466,944—a———C:\WINDOWS\system32\ippcvw711.dll
2007-05-11 21:59 40,960—a———C:\WINDOWS\system32\IPPCPUID.DLL
2007-05-11 21:59 306,688—a———C:\WINDOWS\IsUninst.exe
2007-05-11 21:59 266,240—a———C:\WINDOWS\system32\ippsrw711.dll
2007-05-11 21:59 225,280—a———C:\WINDOWS\system32\ippi11.dll
2007-05-11 21:59 2,592,768—a———C:\WINDOWS\system32\ippiw711.dll
2007-05-11 21:59 176,128—a———C:\WINDOWS\system32\ipps11.dll
2007-05-11 21:59 159,744—a———C:\WINDOWS\system32\ippjw711.dll
2007-05-11 21:59 11,776—a———C:\WINDOWS\system32\pmsbfn32.dll
2007-05-11 21:59 1,589,248—a———C:\WINDOWS\system32\ippsw711.dll
2007-05-11 21:59 <DIR> d————C:\Programmer\NewSoft
2007-05-11 21:59 <DIR> d————C:\DOCUME~1\XPMEDI~1\WINDOWS
2007-05-11 21:59 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\NewSoft
2007-05-11 21:57 <DIR> d————C:\Programmer\ScanSoft
2007-05-11 21:57 <DIR> d————C:\Programmer\F‘lles filer\ScanSoft Shared
2007-05-11 21:57 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\ScanSoft
2007-05-11 21:57 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanWizard
2007-05-11 21:57 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanAppDataDir
2007-05-11 21:52 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\Help
2007-05-11 21:51 <DIR> d—h——- C:\Programmer\InstallShield Installation Information
2007-05-11 21:51 <DIR> d————C:\Programmer\F‘lles filer\InstallShield
2007-05-11 21:51 <DIR> d————C:\Programmer\Canon
2007-05-11 21:50 749,568—a———C:\WINDOWS\system32\CNQA2405.dll
2007-05-11 21:50 40,960—a———C:\WINDOWS\system32\CNQU72.DLL
2007-05-11 21:50 389,180—a———C:\WINDOWS\system32\UCS32P.DLL
2007-05-11 21:50 192,512—a———C:\WINDOWS\system32\CNQL2405.dll
2007-05-11 21:50 <DIR> d—h——- C:\CanoScan
2007-05-11 21:05 <DIR> d————C:\DOCUME~1\XPMEDI~1\APPLIC~1\Google
2007-05-11 21:01 <DIR> d————C:\Programmer\Google
2007-05-11 21:01 <DIR> d————C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-05-11 20:55 <DIR> d————C:\WEBBANK
2007-05-11 19:14 <DIR> d————C:\WINDOWS\system32\da-dk
2007-05-11 19:12 <DIR> d————C:\WINDOWS\network diagnostic
2007-05-11 18:44 <DIR> d—hs——C:\RECYCLER
2007-05-08 12:35 73,928—a———C:\WINDOWS\system32\drivers\AnyDVD.sys


((((((((((((((((((((((((((((((((((((((((((((((((  Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-14 19:30:30————d——-w C:\Programmer\Fælles filer
2007-05-12 19:17:47 14,416——a-w C:\WINDOWS\system32\lccl.dll
2007-05-12 19:17:47 14,416——a-w C:\WINDOWS\system32\client_cc.dll
2007-05-12 19:17:45 20,048——a-w C:\WINDOWS\system32\BgOutlookHook.dll
2007-05-12 19:12:27————d——-w C:\Programmer\Fælles filer\Microsoft Shared
2007-05-11 19:57:47————d——-w C:\Programmer\Fælles filer\ScanSoft Shared
2007-05-11 19:52:00————d——-w C:\Programmer\Microsoft Image Composer
2007-05-11 19:51:16————d——-w C:\Programmer\Fælles filer\InstallShield
2007-05-11 18:43:13————d——-w C:\Programmer\Fælles filer\Symantec Shared
2007-05-11 17:02:24————d——-w C:\Programmer\Fælles filer\System
2007-05-11 16:55:29————d——-w C:\Programmer\Symantec
2007-04-01 12:34:21 86,016——a-w C:\WINDOWS\system32\ElbyCDIO.dll
2007-03-17 13:45:03 292,864——a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:38:16 577,536——a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:38:16 40,960——a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:38:16 281,600——a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:35:19 1,843,584——a-w C:\WINDOWS\system32\win32k.sys
2007-02-05 20:19:14 185,344——a-w C:\WINDOWS\system32\upnphost.dll


((((((((((((((((((((((((((((((((((((((((((  Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2002-11-18 15:15]
“nwiz”=“nwiz.exe” [2002-11-18 15:15 C:\WINDOWS\system32\nwiz.exe]
“SoundMan”=“SOUNDMAN.EXE” []
“SunJavaUpdateSched”=“C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43]
“Omnipage”=“C:\Programmer\ScanSoft\OmniPageSE\opware32.exe” [2002-06-03 11:38]
“SManager”=“smanager.7.exe” []
“BullGuard”=“C:\Programmer\BullGuard Software\BullGuard\bullguard.exe” [2007-05-15 19:00]
“!AVG Anti-Spyware”=“C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-05-14 22:16]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“MSMSGS”=“C:\Programmer\Messenger\msmsgs.exe” [2004-10-13 18:24]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-27 14:00]
“swg”=“C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe” [2007-05-11 21:05]
“BullGuard”=“C:\Programmer\BullGuard Software\BullGuard\bullguard.exe” [2007-05-15 19:00]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
“DisableRegistryTools”=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
“{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2006-09-28 16:13]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkhg]
C:\WINDOWS\system32\pmkhg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winmqx32]
winmqx32.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0
Security Packages kerberos msv1_0 schannel wdigest
Notification Packages scecli

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HTTPFilter HTTPFilter
LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
NetworkService DnsCache
DcomLaunch DcomLaunch TermService
rpcss RpcSs
imgsvc StiSvc
termsvcs TermService
WudfServiceGroup WUDFSvc
BullGuard BgMainSvc BsFileScan BsMailProxy
BullGuardFw BsFwall

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-16 23:26:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-05-16 23:28:20 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-16 23:28


—- E O F—-


HJT ser således ud:

Logfile of HijackThis v1.99.1
Scan saved at 23:31:12, on 16-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\XP Media\Skrivebord\Ny mappe\hjt.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {575385B4-774C-48BF-AA3C-FE2D8706B453} - (no file)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe”
O4 - HKLM\..\Run: [Omnipage] C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe” -boot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized
O4 - HKCU\..\Run: [MSMSGS] “C:\Programmer\Messenger\msmsgs.exe” /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe”
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160317481614
O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

  Ejvindh
Redaktør
Avatar
Antal indlæg: 6048

—Kør Hijackthis, vælg “Do a system scan only”, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.
O2 - BHO: (no name) - {575385B4-774C-48BF-AA3C-FE2D8706B453} - (no file)
O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll (file missing)
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)

—Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

—Du skal nu til at slette. Som indledning hertil skal du have slået “Udvidet filvisning” til:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved “Skjul beskyttede operativsystemfiler”.
Fjern flueben ved “Skjul filtypenavne for kendte filtyper”.
Sæt prik i “Vis skjulte filer og mapper”.

—Slet herefter følgende (hvis du kan finde dem):
C:\WINDOWS\system32\qommkii.dll.vir
C:\WINDOWS\system32\nqtss.bak2
C:\WINDOWS\system32\nqtss.bak1
C:\WINDOWS\system32\sstqn.dll.vir
C:\WINDOWS\system32\qrutv.ini2
C:\WINDOWS\system32\qrutv.bak1
C:\WINDOWS\system32\ghkmp.ini2
C:\WINDOWS\system32\ghkmp.bak1
C:\WINDOWS\system32\qommkii.dll

—Genstart så computeren til normal tilstand, og lav en ny log med Hijackthis, som du lægger herind til gennemsyn.

—Lav også en ny log med rootchk, som du lægger herind.

—Endelig må du også gerne skrive, om det har hjulpet på computeren.

  hvonaal
Antal indlæg: 27

Ny rootchk fil:

********************************* ROOTCHK-(02-05-07)-LOG, by ejvindh
17-05-2007 23:54:04,20

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-17 23:54:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

Ny hjt fil:

Logfile of HijackThis v1.99.1
Scan saved at 23:55:47, on 17-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\XP Media\Skrivebord\Ny mappe\hjt.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe”
O4 - HKLM\..\Run: [Omnipage] C:\Programmer\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe” -boot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] “C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [MSMSGS] “C:\Programmer\Messenger\msmsgs.exe” /background
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BullGuard] “C:\Programmer\BullGuard Software\BullGuard\bullguard.exe”
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160317481614
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


Det ser ud til at problemet er væk.
Så der er snart penge i kaffekassen.

 

  hvonaal
Antal indlæg: 27

jeg lader Bullguard skanne hat jeg lige opdaget at det finder en Trojan ved navn Trojan.Rootkit.Foop.A og Bullguard kan ikke gøre noget ved den.
Alt det andet ser ud som om det er væk.

Redaktør
Avatar
Antal indlæg: 11785

Hvor finder BullGuard denne trojaner?

Signatur

Med venlig hilsen
Resist TeamSpywarefri

Member of: Alliance of Security Analysis Professionals

  hvonaal
Antal indlæg: 27

Virusinficeret fil!
Filantal: 1
Virusnavn: Trojan.Rootkit.Froop.A
Problemstatus: Alvorligt

Bullguard: kan ikke Desinficer, sætte i karantæne eller slette


Hvis man klikker på se filer kommer følgende:

C:\programmer\grisoft\AVG Anti-spyware 7.5\Quarantine\fil526E1529.dat=>(gzip)=REMOVED_NULLS

Redaktør
Avatar
Antal indlæg: 11785

Det ser ud til at BullGuard finder en fil, som allerede er i karantæne hos AVG.

Signatur

Med venlig hilsen
Resist TeamSpywarefri

Member of: Alliance of Security Analysis Professionals

  hvonaal
Antal indlæg: 27

JA sådan har jeg også opfattet det, men hvordan får jeg det væk.
Har du et godt forslag?

Redaktør
Avatar
Antal indlæg: 11785

Slet hvad der er i AVG karantæne - eller afinstaller AVG Antispyware, og når programmet bliver afinstalleret, så rens karantænen.

Signatur

Med venlig hilsen
Resist TeamSpywarefri

Member of: Alliance of Security Analysis Professionals

  hvonaal
Antal indlæg: 27

HAr jeg gjort og nu finder Bullguard ingen virus mere.

Er vi så ved at være i mål.

Var de sidste log filer jeg sendte dig rene.