Nej - vent lige lidt!
|
|
|
|
|
|
|
|
|
|
Hej OK |
|
|
|
|
|
Hent Combofix: Hent dette: ——— Så trækker du sidstnævnte hen over Combofix og kopierer loggen herind |
|
|
|
|
|
Hej Jeg kan stadig ikke downloade filerne, så jeg antager at jeg kan hente det på USB. Jeg er ikke sikker på jeg forstår det sidste du skriver, kan du uddybe:_) |
|
|
|
|
|
Prøv bare dette. Hvis du ikke kan komme på nettet med den maskine så må du lægge HijackThis og Combofix på en USB nøgle eller andet medie. Sæt nu det medie som du gemte combofix på (alg.exe) i den syge pc og kør alg.exe direkte fra det medie. (Vistabrugere skal klikke med højre-musetast på filen og vælge (Kør som administrator) Vigtigt-> Deaktiver dit antivirus/antispyware program.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt som ligger her C:\ Combofix txt Hvis logfilen ikke åbnes så finder du den her c:\combofix.txt Vær tålmodig og vent til Combofix ruden lukker ned. |
|
|
|
|
|
Hej Jeg kan ikke downloade den fil fra Microsoft er det nok med combo filen i første omgang? |
|
|
|
|
|
Ja, prøv bare om du ikke kan køre combofix? |
|
|
|
|
|
Hej Nu er combo fix loggen dannet, den er på ca 23 sider, så spørgsmålet er om jeg skal sende den ind som en vedhæftet fil? |
|
|
|
|
|
Ja, vedhæft du bare den fil. |
|
|
|
|
|
Det er ikke muligt så nu får i den i klar tekst:-( ComboFix 10-03-12.04 - Larsen 13-03-2010 13:36:20.1.1 - x86 advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !! ((((((((((((((((((((((((((((((((((((((( Andet, der er slettet ))))))))))))))))))))))))))))))))))))))))))))))))) c:\documents and settings\Larsen\Application Data\Control Manager . ———-\Legacy_APTO6KO
2010-03-11 18:34 . 2010-03-11 18:34 ———— d——-w- c:\documents and settings\Larsen\Application Data\Malwarebytes . ((((((((((((((((((((((((((((((((((( Start steder i reg.basen )))))))))))))))))))))))))))))))))))))))))))))))) c:\documents and settings\Larsen\Menuen Start\Programmer\Start\ c:\documents and settings\All Users\Menuen Start\Programmer\Start\ [HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] R0 stwlfbus;stwlfbus;c:\windows\system32\drivers\stwlfbus.sys [27-04-2003 11:39 8704] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] 2010-03-13 c:\windows\Tasks\AppleSoftwareUpdate.job 2010-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2010-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2010-03-13 c:\windows\Tasks\User_Feed_Synchronization-{8C9678BF-2068-4220-A547-4F5C8A57A2AB}.job 2010-03-13 c:\windows\Tasks\WGASetup.job Notify-TPSvc - TPSvc.dll ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net scanner skjulte processer ... scanner skjulte autostarter ... scanner skjulte filer ... scanning gennemført med succes ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAV] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Data] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Networking] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for Oracle] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for SqlServer] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NETFramework] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Abiosdsk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\abp480n5] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPI] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPIEC] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\adpu160m] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\adxapie] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aec] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AFD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AFS2K] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aha154x] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78u2] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78xx] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Alerter] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALG] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AliIde] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amsint] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Apple Mobile Device] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppMgmt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\apto6ko] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3350p] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3550] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_1.1.4322] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_2.0.50727] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aspi32] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aspnet_state] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AsyncMac] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atdisk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atmarpc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\audstub] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BattC] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Beep] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BHDrvx86] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BITS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Bonjour Service] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Browser] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf2k] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CCALib8] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccHP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cd20xrnt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdaudio] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdrom] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cisvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ClipSrv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\clr_optimization_v2.0.50727_32] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmdIde] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cmpci] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentFilter] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentIndex] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cpqarray] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cpqoko6] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac2w2k] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac960nt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Disk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmboot] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmio] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmload] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmserver] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DMusic] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dnscache] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dot3svc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dpti2o] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drmkaud] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\E100B] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EapHost] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eeCtrl] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EraserUtilRebootDrv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ERSvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fastfat] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCompatibility] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fdc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fips] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Flpydisk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FltMgr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FontCache3.0.0.0] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fs_Rec] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ftdisk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gameenum] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GEARAspiWDM] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GoogleDesktopManager-110309-193829] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Gpc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gupdate] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gusvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\helpsvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidUsb] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hkmsvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpn] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpt3xx] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZid412] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZipr12] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZius12] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omgmt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ialm] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\idsvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IDSxpx86] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ILADFtmi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Imapi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ImapiService] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\inetaccs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ini910u] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Inport] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntelIde] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ip6fw] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpFilterDriver] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpInIp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpNat] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iPod Service] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IPSec] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IRENUM] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\is3srv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISAPISearch] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\isapnp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\JavaQuickStarterService] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Kbdclass] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmixer] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KSecDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanserver] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanworkstation] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lbrtfdc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ldap] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LicenseService] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LmHosts] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MDM] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Messenger] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmdd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Modem] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mouclass] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mouhid] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MountMgr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mraid35x] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxDAV] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxSmb] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDTC] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDTC Bridge 3.0.0.0] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Msfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSIServer] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSKSSRV] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPCLOCK] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPQM] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mssmbios] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mup] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAL] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\napagent] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAV] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVENG] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVEX15] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDIS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisTapi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ndisuio] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisWan] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDProxy] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBIOS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBT] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netlogon] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetSvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetTcpPortSharing] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nmwcd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nmwcdc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nmwcdcm] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Npfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ntfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtLmSsp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Null] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFlt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFwd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ose] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Outlook] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Parport] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PartMgr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ParVdm] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCI] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIDump] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIIde] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pcmcia] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDCOMP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDFRAME] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRELI] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRFRAME] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2hib] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfDisk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfNet] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfOS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfProc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PlugPlay] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pml Driver HPZ12] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PolicyAgent] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PptpMiniport] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Processor] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ProtectedStorage] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSched] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ptilink] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PxHelp20] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1080] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ql10wnt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql12160] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1240] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1280] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAcd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAuto] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rasl2tp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasMan] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasPppoe] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Raspti] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rdbss] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPCDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rdpdr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPNP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPWD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDSessMgr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\redbook] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteAccess] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteRegistry] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcLocator] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcSs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RSVP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SamSs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCardSvr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Schedule] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ScsiPort] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Secdrv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seclogon] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SENS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\serenum] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ServiceModelEndpoint 3.0.0.0] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ServiceModelOperation 3.0.0.0] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ServiceModelService 3.0.0.0] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sfloppy] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ShellHWDetection] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Simbad] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SMSvcHost 3.0.0.0] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sparrow] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\splitter] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Spooler] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srservice] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SRTSP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SRTSPX] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Srv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSDPSRV] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\st3wolf] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\stisvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\stwlfbus] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swenum] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swmidi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SwPrv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swwd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc810] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc8xx] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymDS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymEFA] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymEvent] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymIRON] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_hi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_u3] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sysaudio] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SysmonLog] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\szkg5] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\szkgfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\szserver] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TapiSrv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDPIPE] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDTCP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermService] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Themes] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TlntSvr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TosIde] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TrkWks] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TSDDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Udfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ultra] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Update] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\upnphost] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UPS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\USBAAPL] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbccgp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbehci] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbhub] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbprint] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbscan] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbser] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UsbserFilt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\USBSTOR] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbuhci] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VgaSave] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ViaIde] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VolSnap] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VSS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VXD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\W32Time] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\W3SVC] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wanarp] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WDICA] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wdmaud] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebClient] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Windows Workflow Foundation 3.0.0.0] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\winmgmt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock - Google Desktop Search Backup Before First Install] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock - Google Desktop Search Backup Before Last Install] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinSock2] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before First Install] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinTrust] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmdmPmSN] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wmi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApRpl] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApSrv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WMPNetworkSvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WS2IFSL] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wscsvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wuauserv] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WZCSVC] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xmlprov] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FF1B975E-C701-43A2-A321-A647EE9EBD0A}] Pre-Kørsel: 19.797.450.752 byte ledig - - End Of File - - 816142AFEC2771456AF63EAFBABAA288 |
|
|
|
|
|
Hej Igen Er det helt skidt med min PC’er? |
|
|
|
|
|
Næh, men loggen indholder nogen ting vi aldrig har set før, derfor tager det længere tid end normalt. Download Gmer’s mbr.exe fra http://www2.gmer.net/mbr/mbr.exe Gå til Start - Kør Skriv cmd (og tryk på OK). Ved prompten skriv eller kopier / indsæt følgende, og tryk på Enter efter hver linje: cd \ Derefter skal du skrive exit, og tryk på Enter for at lukke kommando vinduet. Find så C: \ mbr.log. Og kopier indholdet herind. |
|
|
|
|
|
Hej Det var bestemt heller ikke for at jage med jer:-) Her kommer indholdet af MBR.log Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully |
|
|
|
|
|
Der sket en fejl, prøv lige igen der skal være et mellemrum efter mbr.exe > mbr.exe -t Kom med den ny log |
|
|
|
|
|
Den kommer så her ser også lidt anderledes ud Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully |
|
