han læser min gmail
Antal indlæg: 66

Hej Spywareteam.

Jeg havde for 4-5 år siden en affære med en mand i Holland. Han er meget “dygtig” med PC’er. Han placerede engang noget på min PC, så det ud som mit navn, adresse og telefonnummer var placeret på google. Det kom frem når jeg søgte mit eget navn!
Jeg talte med en af mine venner om det, hun søgte på mit navn på google…og intet kom frem. Så “noget” var placeret på min PC der fik det frem når jeg søgte via min PC, for jeg så det stadig. Jeg tog et screenshot af siden, så jeg kunne vise det til de der ikke selv kunne finde det.. og som tvivlede på min forklaring.

For et par måneder siden begyndte mine gmail-konti at logge på via google.nl og google.com når jeg logger ind med navn og pw.
Jeg har så igen talt med venner om det, det sker ikke når de logger på deres egne konti!

Jeg kan lige oplyse, at vort “forhold” var ret turbulent, han truede mig og var ret modbydelig.
Truslerne ophørte dog, da jeg sagde, at jeg på http://www.youtube.com ville uploade hans håndskrevne breve til mig, indeholdende trusler, hvis han fortsatte. DET hjalp, men nu spøger han igen.

Det er irriterende og hamrende ulovligt, men hvordan kan jeg få fysiske beviser ? Mange af mine programmer bliver fra tid til anden ødelagt, så jeg må afinstallere og geninstallere dem. Han er på en eller anden måde inde på min PC.

Malwarebytes viser “ingen inficerede filer”, min PC har heller ikke virus. Min netbank har ikke lidt skade, men han er heller ikke en tyv i den forstand.
Jeg regner ikke med at jeg må oplyse hans navn her? Han er i stort omfang placeret på google, så man kunne få indtryk af, hvem han er.

Kan I hjælpe mig?

Antal indlæg: 66

Jeg har yderligere en oplysning:

Når jeg er på min PC popper der mange vinduer op fra Comodo firewall om jeg vil give tilladelse til at en anden PC forsøger at connecte til min. De kommer ind gennem andre programmer, f.eks Mozilla, svchost og andre.
Jeg svarer konsekvent block og remember this answer, men dagen efter er der nye forespørgsler.

  mfp
Avatar
Antal indlæg: 257

Du kan jo starte med og ændre dit password så skulle han da ikke kunne komme ind mere med mindre han har lagt noget andet ind på din pc som jeg ikke har forstand på men du kan prøve og ændre password-et hvis ikke det hjælper så må en af support erne tage over

Signatur

mfp

http://www.facebook.com/#!/Spywarefri.dk
Spywarefri er til for dig, støt Spywarefri her:
http://www.spywarefri.dk/medarbejderne
Red liv Bliv samarit i røde kors

Antal indlæg: 66

Ja, ja, det med nyt pw har jeg naturligvis prøvet, en del gange.

Men i dette forum er det, så vidt jeg er orienteret, kun supporterne der må svare wink, så dem venter jeg på.

  mfp
Avatar
Antal indlæg: 257

Vi andre må godt komme med gode råd vi må bare ikke læse logs og forskellige andre ting lige som vi ikke kan lukke en tråd men vi må godt deltage i tråden bare vi ikke tager beslutninger

Signatur

mfp

http://www.facebook.com/#!/Spywarefri.dk
Spywarefri er til for dig, støt Spywarefri her:
http://www.spywarefri.dk/medarbejderne
Red liv Bliv samarit i røde kors

Administrator
Avatar
Antal indlæg: 29177

Hej og velkommen   wink


Det lyder som om han har installeret et Remote Control program af en slags, så lad os lige se hvad der egentlig kører på maskinen ->

Hent DDS og gem programmet på dit Skrivebord:
Her
Dobbeltklik på DDS.scr og tillad programmet at køre.
Når programmet er færdig vil det åbne to logs/tekst-filer.

Gem begge filer på dit Skrivebord og kopier indholdet af txt filerne herind i dit næste indlæg.

Da de er forholdsvis lange, kan du blive nødt til at sende dem i flere indlæg.

Antal indlæg: 66

Hej magic.
Her er loggen.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 26-08-2006 14:37:35
System Uptime: 18-03-2010 11:57:52 (2 hours ago)

Motherboard: Acer |  | FC51GM
Processor: AMD Athlon(tm) 64 Processor 3500+ | Socket 939 | 2210/201mhz

==== Disk Partitions =========================

C: is FIXED (FAT32) - 114 GiB total, 101,207 GiB free.
D: is FIXED (NTFS) - 115 GiB total, 48,503 GiB free.
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8185 54M Wireless LAN Network Adapter
Device ID: PCI\VEN_10EC&DEV;_8185&SUBSYS;_818510EC&REV;_20\4&DC268A3;&0&3880;
Manufacturer: Realtek
Name: Realtek RTL8185 54M Wireless LAN Network Adapter
PNP Device ID: PCI\VEN_10EC&DEV;_8185&SUBSYS;_818510EC&REV;_20\4&DC268A3;&0&3880;
Service: rtl8185

==== System Restore Points ===================

RP1: 17-03-2010 11:48:35 - Systemkontrolpunkt
RP2: 17-03-2010 12:07:57 - fjernet rootkit igen…
RP3: 17-03-2010 18:46:03 - Installeret Realtek AC’97 Audio
RP4: 17-03-2010 18:48:34 - Fjernet Athlon 64 Processor Driver
RP5: 17-03-2010 18:55:17 - Installeret Acer eMode Management
RP6: 17-03-2010 18:55:54 - Installeret Acer eConsole
RP7: 17-03-2010 19:03:28 - Installed NTI CD & DVD-Maker

==== Hosts File Hijack ======================

Hosts: 83.140.176.146 thepiratebay.org http://www.thepiratebay.org
Hosts: 83.140.176.148 static.thepiratebay.org
Hosts: 83.140.176.150 upload.thepiratebay.org
Hosts: 83.140.176.149 rss.thepiratebay.org
Hosts: 83.140.176.157 captcha.thepiratebay.org
Hosts: 83.140.176.156 torrents.thepiratebay.org
Hosts: 77.247.176.134 tracker.thepiratebay.org open.tracker.thepiratebay.org
Hosts: 77.247.176.151 tpb.tracker.thepiratebay.org
Hosts: 77.247.176.153 eztv.tracker.thepiratebay.org vtv.tracker.thepiratebay.org a.tracker.thepiratebay.org
Hosts: 77.247.176.154 vip.tracker.thepiratebay.org tv.tracker.thepiratebay.org
Hosts: 88.80.6.166   mx.thepiratebay.org ns1.thepiratebay.org
Hosts: 83.140.176.159 ns0.thepiratebay.org
Hosts: 85.17.40.33   ns2.thepiratebay.org
Hosts: 217.75.120.120 ns3.thepiratebay.org

==== Installed Programs ======================

Acer eConsole
Acer eMode Management
Acrobat.com
Adobe Flash Player 10 Plugin
Adobe Reader 9.3
Agere Systems PCI Soft Modem
Ashampoo Burning Studio 9.05
ATI - Afinstalleringsværktøj for software
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
Audio Transcoder
Auslogics Disk Defrag
AutoUpdate
avast! Free Antivirus
CCleaner
CDBurnerXP
CloneDVD2
COMODO Internet Security
ConvertXtoDVD 3.3.0.96
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
ffdshow [rev 1122] [2007-04-24]
H.264 Decoder
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
InCD
InFlac 1.1.1
Java Auto Updater
Java(TM) 6 Update 18
K-Lite Codec Pack 2.71 Full
LiveReg (Symantec Corporation)
LiveUpdate 1.6 (Symantec Corporation)
Malwarebytes’ Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Danish Language Pack
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DAN
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DAN
Microsoft .NET Framework 3.5 Language Pack SP1 - dan
Microsoft .NET Framework 3.5 SP1
Microsoft Visual C Runtime
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MKV Splitter
Mozilla Firefox (3.6)
NTI Backup NOW! 4
NTI CD & DVD-Maker
NTI HomeVideo-Maker
NVIDIA Drivers
OLYMPUS CAMEDIA Master 4.2
Opdatering til Windows Internet Explorer 8 (KB976662)
Opdatering til Windows Internet Explorer 8 (KB978506)
PhotoNow! 1.0
PowerDirector Express
PowerDVD
QuickTime
Realtek AC’97 Audio
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB937143)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB938127)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB950759)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB953838)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB956390)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB958215)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB960714)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB961260)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB963027)
Sikkerhedsopdatering til Windows Internet Explorer 8 (KB971961)
Sikkerhedsopdatering til Windows Internet Explorer 8 (KB976325)
Sikkerhedsopdatering til Windows Internet Explorer 8 (KB978207)
Sikkerhedsopdatering til Windows XP (KB923789)
SolSuite
Sprogpakke til Microsoft .NET Framework 3.5 SP1 - dansk
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VC80CRTRedist - 8.0.50727.762
WebFldrs XP
Winamp
Winamp Application Detect
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Language Pack 1.0
AAC Decoder

==== End Of File ===========================

Antal indlæg: 66

her er den anden


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 26-08-2006 14:37:35
System Uptime: 18-03-2010 11:57:52 (2 hours ago)

Motherboard: Acer |  | FC51GM
Processor: AMD Athlon(tm) 64 Processor 3500+ | Socket 939 | 2210/201mhz

==== Disk Partitions =========================

C: is FIXED (FAT32) - 114 GiB total, 101,207 GiB free.
D: is FIXED (NTFS) - 115 GiB total, 48,503 GiB free.
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8185 54M Wireless LAN Network Adapter
Device ID: PCI\VEN_10EC&DEV;_8185&SUBSYS;_818510EC&REV;_20\4&DC268A3;&0&3880;
Manufacturer: Realtek
Name: Realtek RTL8185 54M Wireless LAN Network Adapter
PNP Device ID: PCI\VEN_10EC&DEV;_8185&SUBSYS;_818510EC&REV;_20\4&DC268A3;&0&3880;
Service: rtl8185

==== System Restore Points ===================

RP1: 17-03-2010 11:48:35 - Systemkontrolpunkt
RP2: 17-03-2010 12:07:57 - fjernet rootkit igen…
RP3: 17-03-2010 18:46:03 - Installeret Realtek AC’97 Audio
RP4: 17-03-2010 18:48:34 - Fjernet Athlon 64 Processor Driver
RP5: 17-03-2010 18:55:17 - Installeret Acer eMode Management
RP6: 17-03-2010 18:55:54 - Installeret Acer eConsole
RP7: 17-03-2010 19:03:28 - Installed NTI CD & DVD-Maker

==== Hosts File Hijack ======================

Hosts: 83.140.176.146 thepiratebay.org http://www.thepiratebay.org
Hosts: 83.140.176.148 static.thepiratebay.org
Hosts: 83.140.176.150 upload.thepiratebay.org
Hosts: 83.140.176.149 rss.thepiratebay.org
Hosts: 83.140.176.157 captcha.thepiratebay.org
Hosts: 83.140.176.156 torrents.thepiratebay.org
Hosts: 77.247.176.134 tracker.thepiratebay.org open.tracker.thepiratebay.org
Hosts: 77.247.176.151 tpb.tracker.thepiratebay.org
Hosts: 77.247.176.153 eztv.tracker.thepiratebay.org vtv.tracker.thepiratebay.org a.tracker.thepiratebay.org
Hosts: 77.247.176.154 vip.tracker.thepiratebay.org tv.tracker.thepiratebay.org
Hosts: 88.80.6.166   mx.thepiratebay.org ns1.thepiratebay.org
Hosts: 83.140.176.159 ns0.thepiratebay.org
Hosts: 85.17.40.33   ns2.thepiratebay.org
Hosts: 217.75.120.120 ns3.thepiratebay.org

==== Installed Programs ======================

Acer eConsole
Acer eMode Management
Acrobat.com
Adobe Flash Player 10 Plugin
Adobe Reader 9.3
Agere Systems PCI Soft Modem
Ashampoo Burning Studio 9.05
ATI - Afinstalleringsværktøj for software
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
Audio Transcoder
Auslogics Disk Defrag
AutoUpdate
avast! Free Antivirus
CCleaner
CDBurnerXP
CloneDVD2
COMODO Internet Security
ConvertXtoDVD 3.3.0.96
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
ffdshow [rev 1122] [2007-04-24]
H.264 Decoder
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
InCD
InFlac 1.1.1
Java Auto Updater
Java(TM) 6 Update 18
K-Lite Codec Pack 2.71 Full
LiveReg (Symantec Corporation)
LiveUpdate 1.6 (Symantec Corporation)
Malwarebytes’ Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Danish Language Pack
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DAN
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DAN
Microsoft .NET Framework 3.5 Language Pack SP1 - dan
Microsoft .NET Framework 3.5 SP1
Microsoft Visual C Runtime
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MKV Splitter
Mozilla Firefox (3.6)
NTI Backup NOW! 4
NTI CD & DVD-Maker
NTI HomeVideo-Maker
NVIDIA Drivers
OLYMPUS CAMEDIA Master 4.2
Opdatering til Windows Internet Explorer 8 (KB976662)
Opdatering til Windows Internet Explorer 8 (KB978506)
PhotoNow! 1.0
PowerDirector Express
PowerDVD
QuickTime
Realtek AC’97 Audio
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB937143)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB938127)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB950759)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB953838)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB956390)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB958215)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB960714)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB961260)
Sikkerhedsopdatering til Windows Internet Explorer 7 (KB963027)
Sikkerhedsopdatering til Windows Internet Explorer 8 (KB971961)
Sikkerhedsopdatering til Windows Internet Explorer 8 (KB976325)
Sikkerhedsopdatering til Windows Internet Explorer 8 (KB978207)
Sikkerhedsopdatering til Windows XP (KB923789)
SolSuite
Sprogpakke til Microsoft .NET Framework 3.5 SP1 - dansk
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VC80CRTRedist - 8.0.50727.762
WebFldrs XP
Winamp
Winamp Application Detect
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Language Pack 1.0
AAC Decoder

==== End Of File ===========================

Antal indlæg: 66

DDS (Ver_10-03-17.01) - FAT32x86
Run by ego at 13:48:05,62 on 18-03-2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.958.441 [GMT 1:00]

AV: avast! Antivirus *On-access scanning enabled* (Updated)  {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled*  {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\Programmer\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Programmer\Ahead\InCD\InCDsrv.exe
SVCHOST.EXE
SVCHOST.EXE
C:\WINDOWS\Explorer.EXE
C:\Programmer\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmer\Acer\Acer eMode Management\AspireService.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\Malwarebytes’ Anti-Malware\mbamgui.exe
C:\Programmer\Fælles filer\Java\Java Update\jusched.exe
C:\Programmer\COMODO\COMODO Internet Security\cfp.exe
C:\Programmer\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
SVCHOST.EXE
C:\Programmer\Acer\Acer eConsole\MediaServerService.exe
C:\Programmer\AudioTranscoder\updtr.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Malwarebytes’ Anti-Malware\mbamservice.exe
C:\Programmer\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\ego\SKRIVE~1\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://pralerts.zonelabs.com/pralerts/pranalyze.jsp?PN=CLI+Application+(Command+Line+Interface)&VER=1.2.2044.224&FN=CLI.exe&Created=330608ef&Size=61440&MD5=0fa537e4e4729b97676ce68893e72dae&SKIMP=d2fe2873f4aff3290e2163d492c26fcd&&RIPA;=127.0.0.1&RP=1030&Connect=1&Pgmstatus=1&Zone=1&Keycode=j5hvqhisiu3s4he7bhx644bu4g0&Product=ZoneAlarm&ProductVersion=6.1.744.001&HU100=ZLN41191311044106-1023&DTST=56265&QSRC=1&OS=Windows+XP-5.1.2600-Service+Pack+2-SP&LANG=1030&CL=en&LICFLAG=1&OEM=1023&SKU=0&Mode=1
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [LaunchApp] Alaunch
mRun: [IMJPMIG8.1] “c:\windows\ime\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [nwiz] nwiz.exe /install
mRun: [AspireService] c:\programmer\acer\acer emode management\AspireService.exe
mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\Monitor.exe
mRun: [ATICCC] “c:\programmer\ati technologies\ati.ace\cli.exe” runtime
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Malwarebytes’ Anti-Malware] “c:\programmer\malwarebytes’ anti-malware\mbamgui.exe” /starttray
mRun: [Adobe Reader Speed Launcher] “c:\programmer\adobe\reader 9.0\reader\Reader_sl.exe”
mRun: [Adobe ARM] “c:\programmer\fælles filer\adobe\arm\1.0\AdobeARM.exe”
mRun: [SunJavaUpdateSched] “c:\programmer\fælles filer\java\java update\jusched.exe”
mRun: [COMODO Internet Security] “c:\programmer\comodo\comodo internet security\cfp.exe” -h
mRun: [avast5] “c:\programmer\alwil software\avast5\avastUI.exe” /nogui
mRun: [SoundMan] SOUNDMAN.EXE
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} - hxxp://www.ca.com/dk/securityadvisor/virusinfo/webscan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {01F659E5-8033-4259-973F-5D1919EB28D0} = 208.67.222.222,208.67.220.220
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs:    c:\windows\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File
Hosts: 83.140.176.146 thepiratebay.org http://www.thepiratebay.org
Hosts: 83.140.176.148 static.thepiratebay.org
Hosts: 83.140.176.150 upload.thepiratebay.org
Hosts: 83.140.176.149 rss.thepiratebay.org
Hosts: 83.140.176.157 captcha.thepiratebay.org

Note: multiple HOSTS entries found. Please refer to Attach.txt

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ego\applic~1\mozilla\firefox\profiles\pafvnqr7.default\
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\programmer\mozilla firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmer\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

——FIREFOX POLICIES——
c:\programmer\mozilla firefox\greprefs\all.js - pref(“ui.use_native_colors”, true);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“ui.use_native_popup_windows”, false);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.enable_click_image_resizing”, true);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“accessibility.browsewithcaret_shortcut.enabled”, true);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“javascript.options.mem.high_water_mark”, 32);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“javascript.options.mem.gc_frequency”,  1600);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“network.auth.force-generic-ntlm”, false);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“svg.smil.enabled”, false);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“ui.trackpoint_hack.enabled”, -1);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.formfill.debug”,        false);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.formfill.agedWeight”,    2);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.formfill.bucketSize”,    1);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.formfill.maxTimeGroupings”, 25);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.formfill.timeGroupingSize”, 604800);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.formfill.boundaryWeight”,  25);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“browser.formfill.prefixWeight”,    5);
c:\programmer\mozilla firefox\greprefs\all.js - pref(“html5.enable”, false);
c:\programmer\mozilla firefox\greprefs\security-prefs.js - pref(“security.ssl3.rsa_seed_sha”, true);
c:\programmer\mozilla firefox\defaults\pref\firefox-branding.js - pref(“app.update.download.backgroundInterval”, 600);
c:\programmer\mozilla firefox\defaults\pref\firefox-branding.js - pref(“app.update.url.manual”, “http://www.firefox.com”);
c:\programmer\mozilla firefox\defaults\pref\firefox-branding.js - pref(“browser.search.param.yahoo-fr-ja”, “mozff”);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name”, “chrome://browser/locale/browser.properties”);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description”, “chrome://browser/locale/browser.properties”);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“xpinstall.whitelist.add”, “addons.mozilla.org”);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“xpinstall.whitelist.add.36”, “getpersonas.com”);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“lightweightThemes.update.enabled”, true);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“browser.allTabs.previews”, false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“plugins.hide_infobar_for_outdated_plugin”, false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“plugins.update.notifyUser”, false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“toolbar.customization.usesheet”, false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.enable”, false);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.max”, 20);
c:\programmer\mozilla firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.cachetime”, 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-1 162640]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2010-3-1 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-3-1 25160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-1 19024]
R2 avast! Antivirus;avast! Antivirus;c:\programmer\alwil software\avast5\AvastSvc.exe [2010-3-1 40384]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\programmer\comodo\comodo internet security\cmdagent.exe [2010-3-1 723632]
R2 Digital Music Software: Audio Transcoder update permissions manager. 1543.;Digital Music Software: Audio Transcoder update permissions manager. 1543.;c:\programmer\audiotranscoder\updtr.exe -permissionmanagerrun—> c:\programmer\audiotranscoder\updtr.exe -PermissionManagerRun [?]
R2 MBAMService;MBAMService;c:\programmer\malwarebytes’ anti-malware\mbamservice.exe [2010-1-7 236368]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\programmer\alwil software\avast5\AvastSvc.exe [2010-3-1 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\programmer\alwil software\avast5\AvastSvc.exe [2010-3-1 40384]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-1-7 19160]

=============== Created Last 30 ================

2010-03-17 17:46:07   0   d——-w-  c:\programmer\Realtek AC97
2010-03-17 17:43:50   6   ——a-w-  C:\ISACER.ID
2010-03-16 15:48:15   0   d—h—w-  c:\windows\ie8
2010-03-16 14:27:55   0   d——-w-  c:\programmer\Ashampoo
2010-03-14 21:26:20   0   d——-w-  c:\programmer\Auslogics
2010-03-11 21:41:57   0   d——-w-  c:\windows\system32\wbem\Repository
2010-03-11 20:57:30   0   d——-w-  C:\Softpaq
2010-03-10 07:23:22   3558912   ———w-  c:\windows\system32\dllcache\moviemk.exe
2010-03-05 21:11:04   262144   ——a-w-  c:\windows\_detmp.6
2010-03-05 21:11:04   228858   ——a-w-  c:\windows\_detmp.5
2010-03-05 14:59:30   0   d——-w-  C:\WEBBANK
2010-03-03 08:23:51   0   d——-w-  c:\docume~1\alluse~1\applic~1\ashampoo
2010-03-03 08:19:48   0   d——-w-  c:\docume~1\ego\applic~1\Ashampoo
2010-03-03 01:18:38   0   d——-w-  c:\docume~1\alluse~1\applic~1\Elaborate Bytes
2010-03-02 18:48:46   0   d——-w-  c:\docume~1\alluse~1\applic~1\Canneverbe Limited
2010-03-02 18:48:29   7168   ——a-w-  c:\windows\system32\drivers\StarOpen.sys
2010-03-02 18:28:49   0   d——-w-  c:\docume~1\alluse~1\applic~1\page
2010-03-01 14:58:11   157712   ——a-w-  c:\windows\system32\drivers\tmcomm.sys
2010-03-01 14:01:54   28880   ——a-w-  c:\windows\system32\drivers\aavmker4.sys
2010-03-01 10:13:18   0   d——-w-  c:\docume~1\alluse~1\applic~1\Comodo
2010-03-01 10:13:17   25160   ——a-w-  c:\windows\system32\drivers\cmdhlp.sys
2010-03-01 10:13:17   171552   ——a-w-  c:\windows\system32\guard32.dll
2010-03-01 10:13:16   134344   ——a-w-  c:\windows\system32\drivers\cmdguard.sys
2010-03-01 10:13:15   0   d——-w-  c:\programmer\COMODO
2010-03-01 10:09:03   0   d-sh—w-  C:\Recycled
2010-02-21 18:16:01   0   d——-w-  c:\docume~1\alluse~1\applic~1\F-Secure

==================== Find3M ====================

2010-03-17 18:03:26   6144   ——a-w-  c:\windows\system32\drivers\NTIDrvr.sys
2010-03-17 17:52:58   80336   ——a-w-  c:\windows\system32\perfc006.dat
2010-03-17 17:52:58   451196   ——a-w-  c:\windows\system32\perfh006.dat
2010-02-08 12:19:42   95259   ——a-w-  c:\windows\system32\drivers\klick.dat
2010-02-08 12:19:42   108059   ——a-w-  c:\windows\system32\drivers\klin.dat
2010-01-23 18:41:10   411368   ——a-w-  c:\windows\system32\deploytk.dll
2009-12-31 16:50:04   353792   ———w-  c:\windows\system32\dllcache\srv.sys
2009-12-21 19:08:02   916480   ——a-w-  c:\windows\system32\wininet.dll
2009-12-21 19:08:02   916480   ———w-  c:\windows\system32\dllcache\wininet.dll
2009-12-21 19:08:02   12800   ———w-  c:\windows\system32\dllcache\xpshims.dll
2009-12-21 19:08:02   1208832   ———w-  c:\windows\system32\dllcache\urlmon.dll
2009-12-21 19:08:00   5942784   ———w-  c:\windows\system32\dllcache\mshtml.dll
2009-12-21 19:08:00   206848   ———w-  c:\windows\system32\dllcache\occache.dll
2009-12-21 19:07:58   594432   ———w-  c:\windows\system32\dllcache\msfeeds.dll
2009-12-21 19:07:58   55296   ———w-  c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-21 19:07:58   25600   ———w-  c:\windows\system32\dllcache\jsproxy.dll
2009-12-21 19:07:58   1985536   ———w-  c:\windows\system32\dllcache\iertutil.dll
2009-12-21 19:07:56   246272   ———w-  c:\windows\system32\dllcache\ieproxy.dll
2009-12-21 19:07:56   184320   ———w-  c:\windows\system32\dllcache\iepeers.dll
2009-12-21 19:07:56   11070464   ———w-  c:\windows\system32\dllcache\ieframe.dll
2009-12-21 19:07:54   387584   ———w-  c:\windows\system32\dllcache\iedkcs32.dll
2009-12-21 13:18:56   173056   ———w-  c:\windows\system32\dllcache\ie4uinit.exe
2005-10-24 10:13:58   66560   —sha-r-  c:\windows\MOTA113.exe
2005-06-26 14:32:28   616448   —sha-r-  c:\windows\system32\cygwin1.dll
2005-06-21 21:37:42   45568   —sha-r-  c:\windows\system32\cygz.dll
2004-01-24 23:00:00   70656   —sha-r-  c:\windows\system32\i420vfw.dll
2004-01-24 23:00:00   70656   —sha-r-  c:\windows\system32\yv12vfw.dll
2005-02-28 12:16:22   240128   —sha-r-  c:\windows\system32\x.264.exe
2005-07-14 11:31:20   27648   —sha-r-  c:\windows\system32\AVSredirect.dll
2008-08-02 01:41:38   32768   —sha-w-  c:\windows\system32\config\systemprofile\lokale indstillinger\oversigt\history.ie5\mshist012008080220080803\index.dat
2008-04-14 17:05:56   1695232   —sh—w-  c:\windows\servicepackfiles\i386\msmsgs.exe

============= FINISH: 13:48:48,85 ===============

Antal indlæg: 66

hmmm, jeg har ikke torrent, eller pirate bay. Internetudbyderen har spærret for adgangen for laaaang tid siden.

Administrator
Avatar
Antal indlæg: 54701

Hent Combofix, og gem den i en mappe:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Åbn mappen med Combofix, højreklik et tomt sted i mappen, vælg Ny->tekstdokument, åbn tekstdokumentet, kopier følgende ind:

Killall::
Snapshot::
Hosts::

klik på Filer->Gem som, navngiv den CFScript, luk tekstdokumentet.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du “giver slip” med musen.
http://www.fromsej.saknet.dk/billeder/swfcombo.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den fremkomne log herind.

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

Antal indlæg: 66

Hej Fromsej, tak for din meget udførlige anvisning på den der Combofix grin

Her er loggen:

ComboFix 10-03-17.07 - ego 18-03-2010 15:36:05.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.958.499 [GMT 1:00]
Kører fra: c:\documents and settings\ego\Skrivebord\Combofix\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\ego\Skrivebord\Combofix\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\ego\Application Data\ezpinst.log
c:\documents and settings\ego\Application Data\inst.exe
c:\windows\system32\autorun.ini

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-02-18 til 2010-03-18 )))))))))))))))))))))))))))))))))))
.

2010-03-17 17:46 . 2010-03-17 17:46   ————  d——-w-  c:\programmer\Realtek AC97
2010-03-16 15:48 . 2010-03-16 15:48   ————  d—h—w-  c:\windows\ie8
2010-03-16 14:27 . 2010-03-16 14:27   ————  d——-w-  c:\programmer\Ashampoo
2010-03-14 21:26 . 2010-03-14 21:26   ————  d——-w-  c:\programmer\Auslogics
2010-03-11 21:41 . 2010-03-11 21:41   ————  d——-w-  c:\windows\system32\wbem\Repository
2010-03-11 20:57 . 2010-03-11 20:57   ————  d——-w-  C:\Softpaq
2010-03-10 14:34 . 2010-03-10 14:34   ————  d——-w-  c:\documents and settings\All Users\Application Data\NOS
2010-03-10 07:23 . 2009-10-23 15:28   3558912   ———w-  c:\windows\system32\dllcache\moviemk.exe
2010-03-05 14:59 . 2010-03-05 14:59   ————  d——-w-  C:\WEBBANK
2010-03-03 08:23 . 2010-03-03 08:23   ————  d——-w-  c:\documents and settings\ego\Lokale indstillinger\Application Data\ashampoo
2010-03-03 08:23 . 2010-03-03 08:23   ————  d——-w-  c:\documents and settings\All Users\Application Data\ashampoo
2010-03-03 08:19 . 2010-03-03 08:19   ————  d——-w-  c:\documents and settings\ego\Application Data\Ashampoo
2010-03-03 01:18 . 2010-03-03 01:18   ————  d——-w-  c:\documents and settings\All Users\Application Data\Elaborate Bytes
2010-03-02 18:48 . 2010-03-02 18:48   ————  d——-w-  c:\documents and settings\All Users\Application Data\Canneverbe Limited
2010-03-02 18:48 . 2009-11-12 12:48   7168   ——a-w-  c:\windows\system32\drivers\StarOpen.sys
2010-03-02 18:48 . 2010-03-02 18:48   ————  d——-w-  c:\programmer\CDBurnerXP
2010-03-02 18:28 . 2010-03-02 18:28   ————  d——-w-  c:\documents and settings\All Users\Application Data\page
2010-03-01 14:58 . 2009-05-07 07:04   157712   ——a-w-  c:\windows\system32\drivers\tmcomm.sys
2010-03-01 14:01 . 2010-03-09 11:12   162640   ——a-w-  c:\windows\system32\drivers\aswSP.sys
2010-03-01 14:01 . 2010-03-09 11:08   19024   ——a-w-  c:\windows\system32\drivers\aswFsBlk.sys
2010-03-01 14:01 . 2010-03-09 11:12   46672   ——a-w-  c:\windows\system32\drivers\aswTdi.sys
2010-03-01 14:01 . 2010-03-09 11:09   23376   ——a-w-  c:\windows\system32\drivers\aswRdr.sys
2010-03-01 14:01 . 2010-03-09 11:08   100432   ——a-w-  c:\windows\system32\drivers\aswmon2.sys
2010-03-01 14:01 . 2010-03-09 11:08   94800   ——a-w-  c:\windows\system32\drivers\aswmon.sys
2010-03-01 14:01 . 2010-03-09 11:08   28880   ——a-w-  c:\windows\system32\drivers\aavmker4.sys
2010-03-01 14:01 . 2010-03-09 11:24   153184   ——a-w-  c:\windows\system32\aswBoot.exe
2010-03-01 14:01 . 2010-02-11 18:53   38848   ——a-w-  c:\windows\system32\avastSS.scr
2010-03-01 10:19 . 2010-03-01 10:19   ————  d——-w-  c:\programmer\Alwil Software
2010-03-01 10:13 . 2010-03-01 10:13   ————  d——-w-  c:\documents and settings\All Users\Application Data\Comodo
2010-03-01 10:13 . 2010-03-01 10:13   87104   ——a-w-  c:\windows\system32\drivers\inspect.sys
2010-03-01 10:13 . 2010-03-01 10:13   25160   ——a-w-  c:\windows\system32\drivers\cmdhlp.sys
2010-03-01 10:13 . 2010-03-01 10:13   171552   ——a-w-  c:\windows\system32\guard32.dll
2010-03-01 10:13 . 2010-03-01 10:13   134344   ——a-w-  c:\windows\system32\drivers\cmdguard.sys
2010-03-01 10:13 . 2010-03-01 10:13   ————  d——-w-  c:\programmer\COMODO
2010-02-21 18:16 . 2010-02-21 18:16   ————  d——-w-  c:\documents and settings\All Users\Application Data\F-Secure

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-17 18:06 . 2005-01-26 18:34   1024   —-h—r-  c:\windows\system32\NTIBUN4.dll
2010-03-17 18:03 . 2005-01-26 18:33   1024   —-h—r-  c:\windows\system32\NTIMPEG2.dll
2010-03-17 18:03 . 2005-01-26 18:33   1024   —-h—r-  c:\windows\system32\NTIMP3.dll
2010-03-17 18:03 . 2005-01-26 18:33   1024   —-h—r-  c:\windows\system32\NTIFCD3.dll
2010-03-17 18:03 . 2005-01-26 18:33   1024   —-h—r-  c:\windows\system32\NTICDMK7.dll
2010-03-17 18:03 . 2005-01-26 18:33   6144   ——a-w-  c:\windows\system32\drivers\NTIDrvr.sys
2010-03-17 17:52 . 2010-02-06 15:38   80336   ——a-w-  c:\windows\system32\perfc006.dat
2010-03-17 17:52 . 2010-02-06 15:38   451196   ——a-w-  c:\windows\system32\perfh006.dat
2010-02-08 12:19 . 2010-02-08 12:19   95259   ——a-w-  c:\windows\system32\drivers\klick.dat
2010-02-08 12:19 . 2010-02-08 12:19   108059   ——a-w-  c:\windows\system32\drivers\klin.dat
2010-02-08 12:12 . 2010-02-08 12:12   ————  d——-w-  c:\documents and settings\ego\Application Data\TeamViewer
2010-02-07 21:07 . 2010-02-07 21:07   ————  d——-w-  c:\documents and settings\ego\Application Data\Auslogics
2010-01-26 18:20 . 2010-01-26 18:20   ————  d——-w-  c:\programmer\Winamp Detect
2010-01-23 18:41 . 2010-01-23 18:41   503808   ——a-w-  c:\documents and settings\ego\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7569c29a-n\msvcp71.dll
2010-01-23 18:41 . 2010-01-23 18:41   499712   ——a-w-  c:\documents and settings\ego\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7569c29a-n\jmc.dll
2010-01-23 18:41 . 2010-01-23 18:41   348160   ——a-w-  c:\documents and settings\ego\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7569c29a-n\msvcr71.dll
2010-01-23 18:41 . 2010-01-23 18:41   ————  d——-w-  c:\programmer\Fælles filer\Java
2010-01-23 18:41 . 2010-01-23 18:41   61440   ——a-w-  c:\documents and settings\ego\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-68a4431f-n\decora-sse.dll
2010-01-23 18:41 . 2010-01-23 18:41   12800   ——a-w-  c:\documents and settings\ego\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-68a4431f-n\decora-d3d.dll
2010-01-23 18:41 . 2010-01-23 18:41   411368   ——a-w-  c:\windows\system32\deploytk.dll
2010-01-23 18:41 . 2010-01-23 18:41   ————  d——-w-  c:\programmer\Java
2010-01-23 18:08 . 2010-01-23 18:08   ————  d——-w-  c:\documents and settings\All Users\Application Data\Alwil Software
2010-01-23 18:01 . 2010-01-23 18:01   5115824   ——a-w-  c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes’ Anti-Malware\mbam-setup.exe
2010-01-07 15:07 . 2010-01-07 15:07   38224   ——a-w-  c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2010-01-07 15:07   19160   ——a-w-  c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2008-12-11 10:57   353792   ——a-w-  c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2009-12-21 19:08   916480   ——a-w-  c:\windows\system32\wininet.dll
2009-02-24 20:34 . 2009-02-24 20:34   1044480   ——a-w-  c:\programmer\mozilla firefox\plugins\libdivx.dll
2009-02-24 20:34 . 2009-02-24 20:34   200704   ——a-w-  c:\programmer\mozilla firefox\plugins\ssldivx.dll
2005-10-24 10:13 . 2005-10-24 10:13   66560   —sha-r-  c:\windows\MOTA113.exe
2005-06-26 14:32 . 2005-06-26 14:32   616448   —sha-r-  c:\windows\system32\cygwin1.dll
2005-06-21 21:37 . 2005-06-21 21:37   45568   —sha-r-  c:\windows\system32\cygz.dll
2004-01-24 23:00 . 2004-01-24 23:00   70656   —sha-r-  c:\windows\system32\i420vfw.dll
2004-01-24 23:00 . 2004-01-24 23:00   70656   —sha-r-  c:\windows\system32\yv12vfw.dll
2005-02-28 12:16 . 2005-02-28 12:16   240128   —sha-r-  c:\windows\system32\x.264.exe
2005-07-14 11:31 . 2005-07-14 11:31   27648   —sha-r-  c:\windows\system32\AVSredirect.dll
2008-04-14 17:05 . 2008-04-14 17:05   1695232   —sh—w-  c:\windows\ServicePackFiles\i386\msmsgs.exe
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“LaunchApp”=“Alaunch” [X]
“IMJPMIG8.1”=“c:\windows\IME\imjp8_1\IMJPMIG.EXE” [2004-08-27 208952]
“MSPY2002”=“c:\windows\system32\IME\PINTLGNT\ImScInst.exe” [2004-08-27 59392]
“PHIME2002ASync”=“c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE” [2004-08-27 455168]
“PHIME2002A”=“c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE” [2004-08-27 455168]
“AGRSMMSG”=“AGRSMMSG.exe” [2004-04-13 88363]
“nwiz”=“nwiz.exe” [2005-11-11 1519616]
“AspireService”=“c:\programmer\Acer\Acer eMode Management\AspireService.exe” [2005-09-29 114688]
“eRecoveryService”=“c:\acer\Empowering Technology\eRecovery\Monitor.exe” [2005-11-16 397312]
“ATICCC”=“c:\programmer\ATI Technologies\ATI.ACE\cli.exe” [2005-08-06 61440]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2005-11-11 86016]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2005-11-11 7311360]
“Malwarebytes’ Anti-Malware”=“c:\programmer\Malwarebytes’ Anti-Malware\mbamgui.exe” [2010-01-07 429392]
“Adobe Reader Speed Launcher”=“c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2009-12-22 35760]
“Adobe ARM”=“c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe” [2009-12-11 948672]
“SunJavaUpdateSched”=“c:\programmer\Fælles filer\Java\Java Update\jusched.exe” [2010-01-11 246504]
“COMODO Internet Security”=“c:\programmer\COMODO\COMODO Internet Security\cfp.exe” [2010-03-01 1800464]
“avast5”=“c:\programmer\Alwil Software\Avast5\avastUI.exe” [2010-03-09 2769336]
“SoundMan”=“SOUNDMAN.EXE” [2005-09-22 90112]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=c:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes’ Anti-Malware]
2010-01-07 15:07   429392   ——a-w-  c:\programmer\Malwarebytes’ Anti-Malware\mbamgui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaSync]
2005-09-21 12:48   425984   ——a-w-  c:\programmer\Acer\Acer eConsole\MediaSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntiMUI]
2005-05-11 17:15   45056   ——a-w-  c:\programmer\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 19:24   32768   ——a-w-  c:\programmer\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“SpybotSD TeaTimer”=c:\programmer\Spybot - Search & Destroy\TeaTimer.exe
“MSMSGS”=“c:\programmer\Messenger\msmsgs.exe” /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“CloneCDTray”=“c:\programmer\SlySoft\CloneCD\CloneCDTray.exe” /s
“NvCplDaemon”=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
“InCD”=c:\programmer\Ahead\InCD\InCD.exe
“QuickTime Task”=“c:\programmer\QuickTime\qttask.exe” -atboottime
“NeroFilterCheck”=c:\windows\system32\NeroCheck.exe
“RemoteControl”=c:\programmer\CyberLink\PowerDVD\PDVDServ.exe
“VirtualCloneDrive”=“c:\programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe” /s
“WinampAgent”=c:\programmer\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“d:\\PRG.SET’UPS\\PRG-SET-UP’s\\utorrent.exe”=
“c:\\WINDOWS\\system32\\sessmgr.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“%windir%\\system32\\sessmgr.exe”=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [01-03-2010 15:01 162640]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [01-03-2010 11:13 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [01-03-2010 11:13 25160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [01-03-2010 15:01 19024]
R2 Digital Music Software: Audio Transcoder update permissions manager. 1543.;Digital Music Software: Audio Transcoder update permissions manager. 1543.;c:\programmer\AudioTranscoder\updtr.exe -PermissionManagerRun—> c:\programmer\AudioTranscoder\updtr.exe -PermissionManagerRun [?]
R2 MBAMService;MBAMService;c:\programmer\Malwarebytes’ Anti-Malware\mbamservice.exe [07-01-2010 16:07 236368]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [07-01-2010 16:07 19160]
.
Indhold af mappen ‘Planlagte Opgaver’

2010-03-17 c:\windows\Tasks\Malwarebytes’ Scheduled Update for ego.job
- c:\programmer\Malwarebytes’ Anti-Malware\mbam.exe [2010-01-07 15:07]
.
.
———- Yderligere scanning———-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://pralerts.zonelabs.com/pralerts/pranalyze.jsp?PN=CLI+Application+(Command+Line+Interface)&VER=1.2.2044.224&FN=CLI.exe&Created=330608ef&Size=61440&MD5=0fa537e4e4729b97676ce68893e72dae&SKIMP=d2fe2873f4aff3290e2163d492c26fcd&&RIPA;=127.0.0.1&RP=1030&Connect=1&Pgmstatus=1&Zone=1&Keycode=j5hvqhisiu3s4he7bhx644bu4g0&Product=ZoneAlarm&ProductVersion=6.1.744.001&HU100=ZLN41191311044106-1023&DTST=56265&QSRC=1&OS=Windows+XP-5.1.2600-Service+Pack+2-SP&LANG=1030&CL=en&LICFLAG=1&OEM=1023&SKU=0&Mode=1
TCP: {01F659E5-8033-4259-973F-5D1919EB28D0} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\ego\Application Data\Mozilla\Firefox\Profiles\pafvnqr7.default\
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\programmer\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

——FIREFOX POLITIKKER——
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“ui.use_native_colors”, true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“ui.use_native_popup_windows”, false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.enable_click_image_resizing”, true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“accessibility.browsewithcaret_shortcut.enabled”, true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“javascript.options.mem.high_water_mark”, 32);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“javascript.options.mem.gc_frequency”,  1600);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“network.auth.force-generic-ntlm”, false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“svg.smil.enabled”, false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“ui.trackpoint_hack.enabled”, -1);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.debug”,        false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.agedWeight”,    2);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.bucketSize”,    1);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.maxTimeGroupings”, 25);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.timeGroupingSize”, 604800);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.boundaryWeight”,  25);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.prefixWeight”,    5);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“html5.enable”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-branding.js - pref(“app.update.download.backgroundInterval”, 600);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-branding.js - pref(“app.update.url.manual”, “http://www.firefox.com”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-branding.js - pref(“browser.search.param.yahoo-fr-ja”, “mozff”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name”, “chrome://browser/locale/browser.properties”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description”, “chrome://browser/locale/browser.properties”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“xpinstall.whitelist.add”, “addons.mozilla.org”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“xpinstall.whitelist.add.36”, “getpersonas.com”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“lightweightThemes.update.enabled”, true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.allTabs.previews”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“plugins.hide_infobar_for_outdated_plugin”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“plugins.update.notifyUser”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“toolbar.customization.usesheet”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.enable”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.max”, 20);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.cachetime”, 20);
.
- - - - TOMME GENVEJE FJERNET - - - -

ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
MSConfigStartUp-AnyDVD - c:\programmer\SlySoft\AnyDVD\AnyDVD.exe
MSConfigStartUp-NBJ - c:\programmer\Ahead\Nero BackItUp\NBJ.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-18 15:43
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
“ServiceDll”=”%SystemRoot%\System32\dhcpcsvc.dll”

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Digital Music Software: Audio Transcoder update permissions manager. 1543.]
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-

[HKEY_USERS\S-1-5-21-3242847100-2614902147-801667920-1007\Software\Zepter Software\RegLib*1a1a1b96\AnyDVD/1]
“1”=dword:44f06344
“2”=dword:4511be7b

[HKEY_USERS\S-1-5-21-3242847100-2614902147-801667920-1007\Software\Zepter Software\RegLib*1a1a1b96\CloneDVD2/2]
“1”=dword:44f06373
“2”=dword:49316c1d
.
——————————- DLLs startet under kørende Processer——————————-

- - - - - - - > ‘winlogon.exe’(568)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > ‘explorer.exe’(3032)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
————————————Andre kørende processer————————————
.
c:\programmer\Ahead\InCD\InCDsrv.exe
c:\programmer\Alwil Software\Avast5\AvastSvc.exe
c:\windows\AGRSMMSG.exe
c:\windows\SOUNDMAN.EXE
c:\programmer\Acer\Acer eConsole\MediaServerService.exe
c:\programmer\AudioTranscoder\updtr.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\programmer\Alwil Software\Avast5\setup\avast.setup
.
**************************************************************************
.
Gennemført tid: 2010-03-18 15:46:21 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-03-18 14:46

Pre-Kørsel: 108.590.989.312 byte ledig
Post-Kørsel: 108.546.031.616 byte ledig

WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=“Microsoft Windows XP Home Edition” /noexecute=optin /fastdetect

- - End Of File - - D088E6A84AD76B3DCB8C6E5651EB11CE

Antal indlæg: 66

Jeg sidder og læser den log Combofix har lavet, men den siger mig (selvfølgelig) ikke ret meget.

Men jeg undrer mig over 2 låste registreringsnøgler: til programmerne AnyDVD og CloneDVD2.
Jeg har ikke anyDVD mere, det var en prøveversion, og CloneDVD2 har jeg købt for et par uger siden…men hvorfor er de låst? Måske er det uden betydning….

Administrator
Avatar
Antal indlæg: 54701

Vi kigger grundigt på dine logs, så der kan godt gå lidt ekstra tid.
I mellemtiden, hvilken internetudbyder bruger du?

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

Antal indlæg: 66

Det er helt ok, jeg venter gerne.

Jeg har Stofanet.

Antal indlæg: 66

Hov, glemte lige en ting:

Jeg havde Stofanet for nogle år siden, men “han” hackede ind i deres mailprogram, så Stofanet advicerede mig om at bruge gmail.
jeg er flyttet i mellemtiden og skiftede til fullrate, men skiftede tilbage til Stofanet for ½ år siden.