Virus og trackingcookies
  Hojer88
Antal indlæg: 7

Mit AVG-free har fundet en virus, som hedder Worm/Generic.ASZS. Denne virus har angrebet forskellige vitale dele af computeren, f.eks. kan jeg ikke åbne C-drevet gennem linket, men kun gennem stifinder. Desuden skriver AVG, at filer som services.exe og scene.exe er inficerede. En anden ting er, at filer på mit genoprettelsesdrev også er inficerede, så computeren har taget meget skade.

Jeg har kørt antivirus igennem og fandt adskillige inficerede filer og trackingcookies. Disse filer er blevet fjernet, men computeren er ikke ren. Så hvad skal jeg gøre?

Administrator
Avatar
Antal indlæg: 54708

Velkommen til Spywarefri. smile
Det lyder slet ikke godt, men lad os tage et kig.
Inden du kører nogen scannere, så lav backup af dine vigtige ting, dokumenter og billeder.
Undlad backup af exe filer.

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html


Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til “Kør et fuldstændigt systemscan” - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).

Derefter - Tryk på “Vis resultater” knappen efter scanningen - og herefter tryk på “Fjern det valgte” - nu åbnes log’en og du skal gemme den et sted, hvor du kan finde den igen.

Kopier indholdet herind og fortæl hvordan computeren kører nu ?

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

  Hojer88
Antal indlæg: 7

Så har jeg kørt en malware-test, og logfilen ser således ud:

Malwarebytes’ Anti-Malware 1.44
Database version: 3712
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

09-02-2010 17:18:49
mbam-log-2010-02-09 (17-18-49).txt

Skan type: Fuldstændig skanning (C:\|D:\|)
Objekter skannet: 199522
Tid tilbagelagt: 1 hour(s), 6 minute(s), 35 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 1
Inficerede Registeringsdatabase Filer: 1
Inficerede Mapper: 0
Inficerede Filer: 61

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft windows update client (Worm.AutoRun) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Filer:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (“regedit.exe” “%1”) Good: (regedit.exe “%1”) -> Quarantined and deleted successfully.

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP38\A0010437.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP38\A0010456.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP38\A0011456.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP38\A0011481.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP38\A0011541.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP39\A0011549.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP39\A0011566.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011605.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011640.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011694.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011743.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011767.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011812.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011848.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011878.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP40\A0011909.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP41\A0011924.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP41\A0011950.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0011959.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0012036.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0012057.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0012090.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0013089.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0013111.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0013138.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0013158.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0013189.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP42\A0013217.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP43\A0013223.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP44\A0013228.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP44\A0013259.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP44\A0013279.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP44\A0013313.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP44\A0013336.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0013345.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0013369.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0013387.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0013412.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0013531.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0014529.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0014589.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0014607.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP45\A0014636.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014643.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014665.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014687.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014729.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014835.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014759.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014788.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014820.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014907.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014931.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0014968.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0015002.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0015024.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0016022.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0016044.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP46\A0016062.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP47\A0016075.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CB9ED32-85EF-42F8-9C92-4A0A7F5DB7D8}\RP47\A0016077.exe (Worm.AutoRun) -> Quarantined and deleted successfully.

Computeren kører som før: Alle programmer virker og computeren er kun lidt langsom (det er en ældre computer). Men jeg kan ikke åbne C- eller D-drevet ved de normale links, kun gennem stifinder.

Administrator
Avatar
Antal indlæg: 54708

Hent Combofix, og gem den i en mappe:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Åbn mappen med Combofix, højreklik et tomt sted i mappen, vælg Ny->tekstdokument, åbn tekstdokumentet, kopier følgende ind:

Killall::
Snapshot::

klik på Filer->Gem som, navngiv den CFScript, luk tekstdokumentet.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du “giver slip” med musen.
http://www.fromsej.saknet.dk/billeder/swfcombo.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den fremkomne log herind.

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

  Hojer88
Antal indlæg: 7

ComboFix 10-02-20.04 - Christian 21-02-2010 15:48:23.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.1022.608 [GMT 3:00]
Kører fra: c:\documents and settings\Christian\Skrivebord\ComboFix\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Christian\Skrivebord\ComboFix\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\recycler\S-1-5-21-426712752-788179235-1577476770-1006
D:\Autorun.inf

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-01-21 til 2010-02-21 )))))))))))))))))))))))))))))))))))
.

2010-02-09 13:04 . 2010-02-09 13:04   ————  d——-w-  c:\documents and settings\Christian\Application Data\Malwarebytes
2010-02-09 13:04 . 2010-01-07 13:07   38224   ——a-w-  c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-09 13:04 . 2010-02-09 13:04   ————  d——-w-  c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-09 13:04 . 2010-01-07 13:07   19160   ——a-w-  c:\windows\system32\drivers\mbam.sys
2010-02-09 13:04 . 2010-02-09 13:04   ————  d——-w-  c:\programmer\Malwarebytes’ Anti-Malware
2010-02-07 15:31 . 2010-01-27 08:49   2066200   ——a-w-  c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2010-01-29 17:43 . 2009-11-21 15:58   471552   ———w-  c:\windows\system32\dllcache\aclayers.dll
2010-01-27 09:43 . 2010-01-27 09:43   ————  d——-w-  c:\documents and settings\Christian\Application Data\Hardcore

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-09 12:56 . 2009-08-09 12:25   4580   ——a-w-  c:\documents and settings\Christian\Application Data\wklnhst.dat
2010-02-08 19:11 . 2009-07-23 14:40   ————  d——-w-  c:\documents and settings\Christian\Application Data\Skype
2010-02-08 18:05 . 2009-07-23 14:41   ————  d——-w-  c:\documents and settings\Christian\Application Data\skypePM
2010-01-04 12:26 . 2009-11-07 07:43   ————  d——-w-  c:\documents and settings\Christian\Application Data\gtk-2.0
2009-12-22 05:09 . 2004-08-27 08:00   668672   ——a-w-  c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2004-08-27 08:00   81920   ——a-w-  c:\windows\system32\ieencode.dll
2009-12-10 16:54 . 2004-09-17 10:37   62862   ——a-w-  c:\windows\system32\perfc006.dat
2009-12-10 16:54 . 2004-09-17 10:37   395314   ——a-w-  c:\windows\system32\perfh006.dat
2009-11-30 14:51 . 2009-11-28 17:44   152576   ——a-w-  c:\documents and settings\Christian\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-30 14:45 . 2009-11-28 17:43   79488   ——a-w-  c:\documents and settings\Christian\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2006-07-14 04:05 . 2009-01-12 10:02   22   —sha-w-  c:\windows\SMINST\HPCD.SYS
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ATIPTA”=“c:\programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-11-10 344064]
“SunJavaUpdateSched”=“c:\programmer\Java\jre1.5.0_06\bin\jusched.exe” [2005-11-10 36975]
“HP Software Update”=“c:\programmer\Hp\HP Software Update\HPWuSchd2.exe” [2005-02-16 49152]
“SynTPEnh”=“c:\programmer\Synaptics\SynTP\SynTPEnh.exe” [2005-06-19 729178]
“QPService”=“c:\programmer\HP\QuickPlay\QPService.exe” [2005-12-12 94208]
“eabconfg.cpl”=“c:\programmer\HPQ\Quick Launch Buttons\EabServr.exe” [2005-12-07 409600]
“Cpqset”=“c:\programmer\HPQ\Default Settings\cpqset.exe” [2005-08-01 233534]
“RecGuard”=“c:\windows\SMINST\RecGuard.exe” [2005-10-11 1187840]
“hpWirelessAssistant”=“c:\programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe” [2005-12-13 507904]
“AVG8_TRAY”=“c:\progra~1\AVG\AVG8\avgtray.exe” [2009-12-15 2043160]
“WinampAgent”=“c:\programmer\Winamp\winampa.exe” [2008-08-03 36352]
“Adobe Reader Speed Launcher”=“c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2009-02-27 35696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
HP Photosmart Premier Hurtig start.lnk - c:\programmer\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-08 13:43   11952   ——a-w-  c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\\system32\\sessmgr.exe”=
“c:\\Programmer\\AVG\\AVG8\\avgemc.exe”=
“c:\\Programmer\\AVG\\AVG8\\avgupd.exe”=
“c:\\Programmer\\AVG\\AVG8\\avgnsx.exe”=
“c:\\Programmer\\Messenger\\msmsgs.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“c:\\Programmer\\Mozilla Firefox\\firefox.exe”=
“c:\\Programmer\\Skype\\Phone\\Skype.exe”=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [23-07-2009 22:15 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [23-07-2009 22:15 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [25-04-2009 13:31 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [25-04-2009 13:31 297752]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [22-08-2005 12:06 231424]
S3 musbehco;musbehco;\??\c:\docume~1\CHRIST~1\LOKALE~1\Temp\musbehco.sys—> c:\docume~1\CHRIST~1\LOKALE~1\Temp\musbehco.sys [?]
.
Indhold af mappen ‘Planlagte Opgaver’
.
.
———- Yderligere scanning———-
.
uStart Page = hxxp://www.hp.com
IE: &Google; Search - c:\programmer\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate; English Word - c:\programmer\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\programmer\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\programmer\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\programmer\Google\GoogleToolbar1.dll/cmtrans.html
.
- - - - TOMME GENVEJE FJERNET - - - -

URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-21 15:55
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = c:\programmer\HPQ\Default Settings\cpqset.exe???????????????n??|?@???? ???B????????? ???hLC????????

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-

[HKEY_USERS\S-1-5-21-2143723599-425648659-2600594845-1006\Software\SecuROM\License information*]
“datasecu”=hex:9f,c2,17,92,d2,bc,7b,32,fb,13,7e,c3,95,c9,66,8c,ad,86,98,7e,f2,
  12,3d,be,34,cf,12,6d,68,2c,ee,25,67,5b,3a,1a,d1,1c,41,19,1a,25,bf,b7,55,13,\
“rkeysecu”=hex:97,2a,0b,91,b1,a7,73,f6,ed,f6,bd,b3,1b,7a,4a,fb
.
——————————- DLLs startet under kørende Processer——————————-

- - - - - - - > ‘winlogon.exe’(880)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > ‘explorer.exe’(3760)
c:\progra~1\WINDOW~1\wmpband.dll
.
————————————Andre kørende processer————————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\programmer\Fælles filer\LightScribe\LSSrvc.exe
c:\programmer\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\programmer\AVG\AVG8\avgcsrvx.exe
c:\programmer\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\hpq\Shared\HPQTOA~1.EXE
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Gennemført tid: 2010-02-21 15:58:36 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-02-21 12:58

Pre-Kørsel: 9.317.666.816 byte ledig
Post-Kørsel: 10.420.559.872 byte ledig

WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe

- - End Of File - - 87B4B40663620E507AD5E152318F0C4F

Administrator
Avatar
Antal indlæg: 54708

Åbn mappen med Combofix, højreklik et tomt sted i mappen, vælg Ny->tekstdokument, åbn tekstdokumentet, kopier følgende ind:

Killall::
Snapshot::
File::
c:\docume~1\CHRIST~1\LOKALE~1\Temp\musbehco.sys
Driver::
musbehco

klik på Filer->Gem som, navngiv den CFScript, luk tekstdokumentet.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du “giver slip” med musen.
http://www.fromsej.saknet.dk/billeder/swfcombo.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den fremkomne log herind.

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

  Hojer88
Antal indlæg: 7

ComboFix 10-02-20.04 - Christian 22-02-2010 17:12:25.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.1022.610 [GMT 3:00]
Kører fra: c:\documents and settings\Christian\Skrivebord\ComboFix\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Christian\Skrivebord\ComboFix\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!

FILE ::
“c:\docume~1\CHRIST~1\LOKALE~1\Temp\musbehco.sys”
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet   )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Tjenester   )))))))))))))))))))))))))))))))))))))))))))))))))
.

———-\Legacy_MUSBEHCO
———-\Service_musbehco


(((((((((((((((((((((((((((((  Filer skabt fra 2010-01-22 til 2010-02-22 )))))))))))))))))))))))))))))))))))
.

2010-02-09 13:04 . 2010-02-09 13:04   ————  d——-w-  c:\documents and settings\Christian\Application Data\Malwarebytes
2010-02-09 13:04 . 2010-01-07 13:07   38224   ——a-w-  c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-09 13:04 . 2010-02-09 13:04   ————  d——-w-  c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-09 13:04 . 2010-01-07 13:07   19160   ——a-w-  c:\windows\system32\drivers\mbam.sys
2010-02-09 13:04 . 2010-02-09 13:04   ————  d——-w-  c:\programmer\Malwarebytes’ Anti-Malware
2010-02-07 15:31 . 2010-01-27 08:49   2066200   ——a-w-  c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2010-01-29 17:43 . 2009-11-21 15:58   471552   ———w-  c:\windows\system32\dllcache\aclayers.dll
2010-01-27 09:43 . 2010-01-27 09:43   ————  d——-w-  c:\documents and settings\Christian\Application Data\Hardcore

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-09 12:56 . 2009-08-09 12:25   4580   ——a-w-  c:\documents and settings\Christian\Application Data\wklnhst.dat
2010-02-08 19:11 . 2009-07-23 14:40   ————  d——-w-  c:\documents and settings\Christian\Application Data\Skype
2010-02-08 18:05 . 2009-07-23 14:41   ————  d——-w-  c:\documents and settings\Christian\Application Data\skypePM
2010-01-04 12:26 . 2009-11-07 07:43   ————  d——-w-  c:\documents and settings\Christian\Application Data\gtk-2.0
2009-12-22 05:09 . 2004-08-27 08:00   668672   ———w-  c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2004-08-27 08:00   81920   ——a-w-  c:\windows\system32\ieencode.dll
2009-12-10 16:54 . 2004-09-17 10:37   62862   ——a-w-  c:\windows\system32\perfc006.dat
2009-12-10 16:54 . 2004-09-17 10:37   395314   ——a-w-  c:\windows\system32\perfh006.dat
2009-11-30 14:51 . 2009-11-28 17:44   152576   ——a-w-  c:\documents and settings\Christian\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-30 14:45 . 2009-11-28 17:43   79488   ——a-w-  c:\documents and settings\Christian\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2006-07-14 04:05 . 2009-01-12 10:02   22   —sha-w-  c:\windows\SMINST\HPCD.SYS
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ATIPTA”=“c:\programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-11-10 344064]
“SunJavaUpdateSched”=“c:\programmer\Java\jre1.5.0_06\bin\jusched.exe” [2005-11-10 36975]
“HP Software Update”=“c:\programmer\Hp\HP Software Update\HPWuSchd2.exe” [2005-02-16 49152]
“SynTPEnh”=“c:\programmer\Synaptics\SynTP\SynTPEnh.exe” [2005-06-19 729178]
“QPService”=“c:\programmer\HP\QuickPlay\QPService.exe” [2005-12-12 94208]
“eabconfg.cpl”=“c:\programmer\HPQ\Quick Launch Buttons\EabServr.exe” [2005-12-07 409600]
“Cpqset”=“c:\programmer\HPQ\Default Settings\cpqset.exe” [2005-08-01 233534]
“RecGuard”=“c:\windows\SMINST\RecGuard.exe” [2005-10-11 1187840]
“hpWirelessAssistant”=“c:\programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe” [2005-12-13 507904]
“AVG8_TRAY”=“c:\progra~1\AVG\AVG8\avgtray.exe” [2009-12-15 2043160]
“WinampAgent”=“c:\programmer\Winamp\winampa.exe” [2008-08-03 36352]
“Adobe Reader Speed Launcher”=“c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2009-02-27 35696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
HP Photosmart Premier Hurtig start.lnk - c:\programmer\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-08 13:43   11952   ——a-w-  c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\\system32\\sessmgr.exe”=
“c:\\Programmer\\AVG\\AVG8\\avgemc.exe”=
“c:\\Programmer\\AVG\\AVG8\\avgupd.exe”=
“c:\\Programmer\\AVG\\AVG8\\avgnsx.exe”=
“c:\\Programmer\\Messenger\\msmsgs.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“c:\\Programmer\\Mozilla Firefox\\firefox.exe”=
“c:\\Programmer\\Skype\\Phone\\Skype.exe”=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [23-07-2009 22:15 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [23-07-2009 22:15 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [25-04-2009 13:31 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [25-04-2009 13:31 297752]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [22-08-2005 12:06 231424]
.
.
———- Yderligere scanning———-
.
uStart Page = hxxp://www.hp.com
IE: &Google; Search - c:\programmer\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate; English Word - c:\programmer\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\programmer\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\programmer\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\programmer\Google\GoogleToolbar1.dll/cmtrans.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-22 17:19
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = c:\programmer\HPQ\Default Settings\cpqset.exe???????????????n??|?????? ???B????????? ???hLC????????

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-

[HKEY_USERS\S-1-5-21-2143723599-425648659-2600594845-1006\Software\SecuROM\License information*]
“datasecu”=hex:9f,c2,17,92,d2,bc,7b,32,fb,13,7e,c3,95,c9,66,8c,ad,86,98,7e,f2,
  12,3d,be,34,cf,12,6d,68,2c,ee,25,67,5b,3a,1a,d1,1c,41,19,1a,25,bf,b7,55,13,\
“rkeysecu”=hex:97,2a,0b,91,b1,a7,73,f6,ed,f6,bd,b3,1b,7a,4a,fb
.
——————————- DLLs startet under kørende Processer——————————-

- - - - - - - > ‘winlogon.exe’(856)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > ‘explorer.exe’(3396)
c:\progra~1\WINDOW~1\wmpband.dll
.
————————————Andre kørende processer————————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\programmer\Fælles filer\LightScribe\LSSrvc.exe
c:\programmer\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\programmer\AVG\AVG8\avgcsrvx.exe
c:\programmer\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
c:\progra~1\hpq\Shared\HPQTOA~1.EXE
.
**************************************************************************
.
Gennemført tid: 2010-02-22 17:22:35 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-02-22 14:22
ComboFix2.txt 2010-02-21 12:58

Pre-Kørsel: 10.398.285.824 byte ledig
Post-Kørsel: 10.320.211.968 byte ledig

- - End Of File - - 18A5BD1456EC679A05C218CE702FC844

Redaktør
Antal indlæg: 12994

Det ser godt ud nu


Hent nyeste version af HijackThis ned til skrivebordet Her:
http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html

2. Dobbeltklik på installationsfilen, og følg installationsvejledningen.

3. Dobbeltklik på det nye HijackThis ikon på skrivebordet.

4. På menuen der kommer op, klikker du på: Do a systemscan and save a logfile.

5. Efter et kort øjeblik åbner en logfil i notesblok, gem den.

6. Sådan kopieres loggen ind i et spørgsmål:

Mens loggen er åben, markeres al teksten med tastekombinationen CTRL + A.
For at kopiere den markerede tekst bruges tastekombinationen CTRL + C, som ”fastgør” det i udklipsholderen i Windows. Gå så ind i dit spørgsmål og klik på kommentér knappen. Her indsættes det kopierede i det hvide felt med tastekombinationen CTRL + V.

Send så hijackthis loggen herind

Hvordan kører din pc nu?

  Hojer88
Antal indlæg: 7

Her er hijackthis loggen:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:52:04, on 22-02-2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HP\QuickPlay\QPService.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programmer\AVG\AVG8\avgcsrvx.exe
C:\Programmer\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\explorer.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\Image-Line\FL Studio 9\FL.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] “C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe”
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] “C:\Programmer\HP\QuickPlay\QPService.exe”
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] “C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe”
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: HP Photosmart Premier Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Google; Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate; English Word - res://C:\Programmer\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E51FC8ED-90F4-46A3-98B8-F256F3B2DF62}: NameServer = 196.46.100.2 196.46.104.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe


End of file - 6536 bytes

Min pc kører meget bedre nu. Jeg skrev i starten, at linket til mit C-drev ikke virkede, men nu virker det meget bedre. Programmerne virker som de skal. Ind imellem siger AVG, at der er trackingcokkies, når jeg åbner min Firefox browser. Men efter den sidste combofix scan har den ikke sagt noget.

Redaktør
Antal indlæg: 12994

Ved du selv hvad der kører på denne 017 linje, kører du med ”Open dns”
Hvis du ikke ved så fix den med HijackThis

Kør HijackThis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget HijackThis, klik på fix checked.

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51FC8ED-90F4-46A3-98B8-F256F3B2DF62}: NameServer = 196.46.100.2 196.46.104.2

Genstart din PC og se om du stadig kan komme på nettet.

>>

Hvis du nu ikke kan komme på nettet åbner du HijackThis og går ind under dette >

Open the Misc Tools section > Fanen “Backups” > Marker linjen her og klik på “Restore”

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51FC8ED-90F4-46A3-98B8-F256F3B2DF62}: NameServer = 196.46.100.2 196.46.104.2

Genstart > Det vil gendanne linjen igen.


Din log er ren

Tid til oprydning

Klik på START derefter Kør

Skriv/kopier: Combofix /Uninstall i boxen, og klik OK.

Bemærk mellemrum mellem X og /Uninstall, det skal være der.

Ovennævnte procedure vil:
Slette følgende:
ComboFix og tilhørende filer og mapper.
Nulstille uret indstillinger.
Skjule filtypenavne, hvis det kræves.
Skjule System / Skjulte filer, hvis det kræves.

De andre programmer vi har bedt dig om at installer må du afinstaller manuelt

Du bør oprette et nyt gendannelsespunkt for at fjerne eventuelle infektioner fra et gammelt gendannelsespunkt.
Den nemmeste og sikreste måde at gøre dette på er:

Gå til Start> Alle programmer> Tilbehør> Systemværktøjer> Systemgendannelse
Vælg Opret et gendannelsespunkt, og tryk Ok.

Næste, skal du gå til Start> Kør og skriv cleanmgr
Vælg drev c og lad den søge
Vælg Flere indstillinger, fanen
Vælg Systemgendannelse - Ryd op og tryk OK.
Dette vil fjerne alle gendannelsespunkter, undtagen det nye du lige har oprettet.

God fornøjelse

Kan vi lukke her?

  Hojer88
Antal indlæg: 7

Jeg har hijacket den fil, du nævnte, og der er ingen problemer med at komme på nettet.

Det eneste problem der er nu, er at når jeg åbner firefox, siger AVG at der er trackingcookies. Er det AVG, firefox eller noget helt andet, der er problemet?

Administrator
Avatar
Antal indlæg: 54708

Hvorfor har du ikke opdateret Internet Explorer til mindst version 7?

Du skal indstille IE til ikke at acceptere tredie-parts cookies, det burde løse problemet.
Åbn Internet Explorer, klik på Funktioner->Internetindstillinger->Fanebladet Beskyttelse af personlige oplysninger->Avanceret
Sæt flueben i Tilsidesæt automatisk behandling af cookies, sæt prik i Accepter, under cookies fra oprindeligt websted, og prik i Bloker under Tredjepartscookies.
http://www.fromsej.dk/billeder/3cook.jpg

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

  Hojer88
Antal indlæg: 7

Okay, jeg har indstillet explorer nu, så det vil jeg prøve at se om det virker.

I hvert fald mange tak for hjælpen! Det er lækkert, at I giver sådan en service!

Mvh Christian

Administrator
Avatar
Antal indlæg: 54708

Velbekomme.smile

Jeg låser tråden, du er velkommen en anden gang.

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur