Langsom computer + Firefox lukker heltiden
  Angel
Antal indlæg: 96

Firefox lukker heltiden, ved ikke hvad der er galt. Check pls

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:44:16, on 18-03-2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Programmer\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Programmer\rnamfler\naomf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\msnmsgr.exe
c:\programmer\rnamfler\radprcmp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\netdde.exe
C:\Programmer\rnamfler\naofsvc.exe
C:\Programmer\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Programmer\CCleaner\CCleaner.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Windows Live\Toolbar\wltuser.exe
C:\Documents and Settings\Oem user\Lokale indstillinger\Temporary Internet Files\Content.IE5\7NQKVB7F\HiJackThis[1].exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15204&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct;=&gc=1&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct;=&gc=1&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Programmer\AskSearch\bin\DefaultSearch.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmer\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmer\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows; Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programmer\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Programmer\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [wrna3ls] C:\Programmer\rnamfler\naomf.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] “C:\Programmer\Windows Live\Messenger\msnmsgr.exe” /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘LOKAL TJENESTE’)
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘NETVÆRKSTJENESTE’)
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra ‘Tools’ menuitem: &Blog; det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: *.danskebank.dk
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1226684116375
O23 - Service: Automatisk LiveUpdate-planlægning - Unknown owner - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: RdnaoFlSvc - Unknown owner - C:\Programmer\rnamfler\naofsvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


End of file - 7373 bytes

Administrator
Avatar
Antal indlæg: 54698

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html


Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til “Kør et fuldstændigt systemscan” - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).

Derefter - Tryk på “Vis resultater” knappen efter scanningen - og herefter tryk på “Fjern det valgte” - nu åbnes log’en og du skal gemme den et sted, hvor du kan finde den igen.

Kopier indholdet herind og fortæl hvordan computeren kører nu ?

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

  Angel
Antal indlæg: 96

Tak for svaret!! smile

Jeg scanner computeren imorgen og giver svar fra mig der. smile

Administrator
Avatar
Antal indlæg: 29174

Fint nok.

  Angel
Antal indlæg: 96

Sådan endelig fik jeg den scannet! smile

Malwarebytes’ Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

19-03-2010 17:17:59
mbam-log-2010-03-19 (17-17-59).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 150456
Tid tilbagelagt: 1 hour(s), 2 minute(s), 21 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)

Administrator
Avatar
Antal indlæg: 29174

Ak ja. Du har IKKE opdateret malwarebyte inden du scannede, så gør det lige og send så en ny log herind.

  Angel
Antal indlæg: 96

Her er den nye log smile

Malwarebytes’ Anti-Malware 1.44
Database version: 3890
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

21-03-2010 14:33:38
mbam-log-2010-03-21 (14-33-38).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 162512
Tid tilbagelagt: 48 minute(s), 53 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 1

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
C:\WINDOWS\file_2.exe (Trojan.PWS) -> Quarantined and deleted successfully.

Administrator
Avatar
Antal indlæg: 54698

Hent Combofix, og gem den i en mappe:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Åbn mappen med Combofix, højreklik et tomt sted i mappen, vælg Ny->tekstdokument, åbn tekstdokumentet, kopier følgende ind:

Killall::
Snapshot::

klik på Filer->Gem som, navngiv den CFScript, luk tekstdokumentet.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du “giver slip” med musen.
http://www.fromsej.saknet.dk/billeder/swfcombo.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den fremkomne log herind.

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

  Angel
Antal indlæg: 96

ComboFix 10-03-20.06 - Oem user 21-03-2010 20:36:01.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.502.201 [GMT 1:00]
Kører fra: c:\documents and settings\Oem user\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Oem user\Skrivebord\CFScript.txt.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programmer\rnamfler\radhslib.dll
c:\programmer\rnamfler\radprlib.dll
c:\windows\system32\oem1.inf

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-02-21 til 2010-03-21 )))))))))))))))))))))))))))))))))))
.

2010-03-21 12:38 . 2010-03-21 12:38   ————  d——-w-  C:\found.000
2010-03-18 16:42 . 2010-03-18 16:42   ————  d-sh—w-  c:\documents and settings\Oem user\IECompatCache
2010-03-18 16:38 . 2010-03-18 16:38   ————  d——-w-  c:\documents and settings\Oem user\Lokale indstillinger\Application Data\Threat Expert
2010-03-18 16:32 . 2010-03-18 16:32   ————  d-sh—w-  c:\documents and settings\LocalService\IETldCache
2010-03-18 16:24 . 2010-03-18 16:24   ————  d——-w-  c:\programmer\Defraggler
2010-03-18 16:20 . 2010-03-18 16:20   52224   ——a-w-  c:\documents and settings\Oem user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-18 16:20 . 2010-03-18 16:20   117760   ——a-w-  c:\documents and settings\Oem user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-18 16:19 . 2010-03-18 16:19   ————  d——-w-  c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-18 16:19 . 2010-03-18 16:19   ————  d——-w-  c:\programmer\SUPERAntiSpyware
2010-03-18 16:19 . 2010-03-18 16:19   ————  d——-w-  c:\documents and settings\Oem user\Application Data\SUPERAntiSpyware.com
2010-03-18 16:19 . 2010-03-18 16:19   ————  d——-w-  c:\programmer\Fælles filer\Wise Installation Wizard
2010-03-18 15:20 . 2010-03-18 15:20   ————  d——-w-  c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-03-18 15:20 . 2010-03-18 15:20   ————  d——-w-  c:\documents and settings\Administrator\Lokale indstillinger\Application Data\Mozilla
2010-03-10 17:33 . 2010-03-10 17:56   ————  d——-w-  c:\documents and settings\Oem user\Application Data\Voipwise
2010-03-10 08:23 . 2009-10-23 15:28   3558912   -c——w-  c:\windows\system32\dllcache\moviemk.exe
2010-03-09 19:39 . 2010-03-09 19:39   ————  d-sh—w-  c:\documents and settings\Oem user\PrivacIE
2010-03-09 14:18 . 2010-03-09 11:12   162640   ——a-w-  c:\windows\system32\drivers\aswSP.sys
2010-03-09 14:18 . 2010-03-09 11:09   23376   ——a-w-  c:\windows\system32\drivers\aswRdr.sys
2010-03-09 14:18 . 2010-03-09 11:08   19024   ——a-w-  c:\windows\system32\drivers\aswFsBlk.sys
2010-03-09 14:18 . 2010-03-09 11:12   46672   ——a-w-  c:\windows\system32\drivers\aswTdi.sys
2010-03-09 14:18 . 2010-03-09 11:08   100432   ——a-w-  c:\windows\system32\drivers\aswmon2.sys
2010-03-09 14:18 . 2010-03-09 11:08   94800   ——a-w-  c:\windows\system32\drivers\aswmon.sys
2010-03-09 14:18 . 2010-03-09 11:08   28880   ——a-w-  c:\windows\system32\drivers\aavmker4.sys
2010-03-09 14:18 . 2010-03-09 11:24   153184   ——a-w-  c:\windows\system32\aswBoot.exe
2010-03-09 14:18 . 2010-02-11 18:53   38848   ——a-w-  c:\windows\system32\avastSS.scr
2010-03-09 14:18 . 2010-03-09 14:18   ————  d——-w-  c:\programmer\Alwil Software
2010-03-09 14:18 . 2010-03-09 14:18   ————  d——-w-  c:\documents and settings\All Users\Application Data\Alwil Software
2010-03-09 14:04 . 2010-03-09 14:04   ————  d-sh—w-  c:\documents and settings\Oem user\IETldCache
2010-03-09 13:31 . 2009-12-11 08:38   69120   -c——w-  c:\windows\system32\dllcache\iecompat.dll
2010-03-09 13:30 . 2010-03-10 09:14   ————  d——-w-  c:\windows\ie8updates
2010-03-09 13:28 . 2009-12-21 19:08   12800   -c——w-  c:\windows\system32\dllcache\xpshims.dll
2010-03-09 13:28 . 2009-12-21 19:07   594432   -c——w-  c:\windows\system32\dllcache\msfeeds.dll
2010-03-09 13:28 . 2009-12-21 19:07   55296   -c——w-  c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-09 13:28 . 2009-12-21 19:07   1985536   -c——w-  c:\windows\system32\dllcache\iertutil.dll
2010-03-09 13:28 . 2009-12-21 19:07   246272   -c——w-  c:\windows\system32\dllcache\ieproxy.dll
2010-03-09 13:27 . 2009-12-21 19:07   11070464   -c——w-  c:\windows\system32\dllcache\ieframe.dll
2010-03-09 13:23 . 2010-03-09 13:27   ————  dc-h—w-  c:\windows\ie8
2010-03-09 12:26 . 2010-03-09 12:26   ————  d——-w-  c:\programmer\CCleaner
2010-03-09 11:53 . 2010-03-09 11:53   ————  d——-w-  c:\programmer\AVG
2010-03-09 11:52 . 2010-03-09 11:58   ————  d——-w-  c:\windows\SxsCaPendDel
2010-03-09 11:50 . 2010-03-09 11:50   ————  d——-w-  c:\documents and settings\Oem user\Application Data\Malwarebytes
2010-03-09 11:50 . 2010-01-07 15:07   38224   ——a-w-  c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-09 11:50 . 2010-03-09 11:50   ————  d——-w-  c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-09 11:50 . 2010-01-07 15:07   19160   ——a-w-  c:\windows\system32\drivers\mbam.sys
2010-03-09 11:50 . 2010-03-09 11:50   ————  d——-w-  c:\programmer\Malwarebytes’ Anti-Malware
2010-03-05 19:05 . 2010-03-05 19:05   ————  d——-w-  c:\programmer\Voipwise.com
2010-03-01 14:34 . 2010-03-02 12:06   ————  d——-w-  c:\programmer\Microsoft Silverlight

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-21 19:33 . 2009-01-21 22:14   ————  d—-a-w-  c:\documents and settings\All Users\Application Data\TEMP
2010-03-21 19:29 . 2009-05-23 23:04   ————  d—h—r-  c:\programmer\rnamfler
2010-03-18 16:25 . 2008-11-14 16:46   ————  d——-w-  c:\programmer\Windows Live
2010-03-18 15:13 . 2008-11-15 20:02   ————  d——-w-  c:\documents and settings\Oem user\Application Data\Paltalk
2010-03-18 15:13 . 2008-11-15 20:02   ————  d——-w-  c:\programmer\Paltalk Messenger
2010-03-10 08:18 . 2006-03-02 12:00   79358   ——a-w-  c:\windows\system32\perfc006.dat
2010-03-10 08:18 . 2006-03-02 12:00   450896   ——a-w-  c:\windows\system32\perfh006.dat
2010-03-09 13:14 . 2009-05-24 23:22   ————  d——-w-  c:\programmer\Google
2010-03-09 11:58 . 2008-11-14 16:16   ————  d——-w-  c:\programmer\Fælles filer\Symantec Shared
2010-03-09 11:58 . 2008-11-14 16:18   ————  d——-w-  c:\programmer\Symantec
2010-03-09 11:48 . 2008-11-14 16:18   ————  d——-w-  c:\documents and settings\All Users\Application Data\Symantec
2009-12-31 16:50 . 2006-03-02 12:00   353792   ——a-w-  c:\windows\system32\drivers\srv.sys
2009-04-15 20:24 . 2009-04-15 20:24   1044480   ——a-w-  c:\programmer\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24   200704   ——a-w-  c:\programmer\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“msnmsgr”=“c:\programmer\Windows Live\Messenger\msnmsgr.exe” [2009-07-26 3883856]
“SUPERAntiSpyware”=“c:\programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2010-02-18 2012912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Broadcom Wireless Manager UI”=“c:\windows\system32\WLTRAY.exe” [2008-10-30 1871872]
“IgfxTray”=“c:\windows\system32\igfxtray.exe” [2007-01-13 131072]
“HotKeysCmds”=“c:\windows\system32\hkcmd.exe” [2007-01-13 163840]
“Persistence”=“c:\windows\system32\igfxpers.exe” [2007-01-13 135168]
“avast5”=“c:\progra~1\ALWILS~1\Avast5\avastUI.exe” [2010-03-09 2769336]
“wrna3ls”=“c:\programmer\rnamfler\naomf.exe” [2006-04-01 1253448]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= “c:\programmer\SUPERAntiSpyware\SASSEH.DLL” [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21   548352   ——a-w-  c:\programmer\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^PalTalk.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 01:38   34672   ——a-w-  c:\programmer\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-08-24 10:20   88363   ——a-w-  c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Athan]
2008-08-18 02:03   1069056   ——a-w-  c:\programmer\Athan\Athan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 16:05   1695232   —sh—w-  c:\programmer\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44   3883856   ——a-w-  c:\programmer\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-07-27 12:48   1388544   ——a-w-  c:\programmer\Analog Devices\SoundMAX\SMax4PNP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-11-28 23:01   136600   ——a-w-  c:\programmer\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-11-14 16:33   185872   ——a-w-  c:\programmer\Fælles filer\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster]
2008-11-10 11:22   9017648   ——a-w-  c:\programmer\VoipBuster.com\VoipBuster\VoipBuster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voipwise]
2010-02-16 13:16   9084720   ——a-w-  c:\programmer\Voipwise.com\Voipwise\Voipwise.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wrna3ls]
2006-04-01 08:45   1253448   ——a-w-  c:\programmer\rnamfler\naomf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\\system32\\sessmgr.exe”=
“c:\\Programmer\\VoipBuster.com\\VoipBuster\\VoipBuster.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“c:\\WINDOWS\\system32\\mmc.exe”=
“c:\\Programmer\\Messenger\\msmsgs.exe”=
“c:\\Programmer\\Java\\jre6\\bin\\java.exe”=
“c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe”=
“c:\\Programmer\\Voipwise.com\\Voipwise\\Voipwise.exe”=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [09-03-2010 15:18 162640]
R1 SASDIFSV;SASDIFSV;c:\programmer\SUPERAntiSpyware\sasdifsv.sys [17-02-2010 10:25 12872]
R1 SASKUTIL;SASKUTIL;c:\programmer\SUPERAntiSpyware\SASKUTIL.SYS [17-02-2010 10:15 66632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09-03-2010 15:18 19024]
R3 SASENUM;SASENUM;c:\programmer\SUPERAntiSpyware\SASENUM.SYS [17-02-2010 10:15 12872]
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;“c:\programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe”—> c:\programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe [?]
.
.
———- Yderligere scanning———-
.
uStart Page = hxxp://eu.ask.com?o=15204&l=dis
uInternet Connection Wizard,ShellNext = iexplore
IE: E&ksporter; til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: danskebank.dk
FF - ProfilePath - c:\documents and settings\Oem user\Application Data\Mozilla\Firefox\Profiles\jmk5zzzy.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.pointshop.dk/ep_startpage.asp?userid=181471&tjecksum=327373684&email=G-uniit15@hotmail.com&doAutoLogin=true
FF - prefs.js: keyword.URL -
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmer\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmer\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

——FIREFOX POLITIKKER——
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“ui.use_native_colors”, true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“ui.use_native_popup_windows”, false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.enable_click_image_resizing”, true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“accessibility.browsewithcaret_shortcut.enabled”, true);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“javascript.options.mem.high_water_mark”, 32);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“javascript.options.mem.gc_frequency”,  1600);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“network.auth.force-generic-ntlm”, false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“svg.smil.enabled”, false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“ui.trackpoint_hack.enabled”, -1);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.debug”,        false);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.agedWeight”,    2);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.bucketSize”,    1);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.maxTimeGroupings”, 25);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.timeGroupingSize”, 604800);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.boundaryWeight”,  25);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“browser.formfill.prefixWeight”,    5);
c:\programmer\Mozilla Firefox\greprefs\all.js - pref(“html5.enable”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-branding.js - pref(“app.update.download.backgroundInterval”, 600);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-branding.js - pref(“app.update.url.manual”, “http://www.firefox.com”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-branding.js - pref(“browser.search.param.yahoo-fr-ja”, “mozff”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref(“browser.fixup.alternate.suffix”, “.dk”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name”, “chrome://browser/locale/browser.properties”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description”, “chrome://browser/locale/browser.properties”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“xpinstall.whitelist.add”, “addons.mozilla.org”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“xpinstall.whitelist.add.36”, “getpersonas.com”);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“lightweightThemes.update.enabled”, true);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.allTabs.previews”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“plugins.hide_infobar_for_outdated_plugin”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“plugins.update.notifyUser”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“toolbar.customization.usesheet”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.enable”, false);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.max”, 20);
c:\programmer\Mozilla Firefox\defaults\pref\firefox.js - pref(“browser.taskbar.previews.cachetime”, 20);
.
- - - - TOMME GENVEJE FJERNET - - - -

AddRemove-HijackThis - c:\documents and settings\Oem user\Lokale indstillinger\Temporary Internet Files\Content.IE5\7NQKVB7F\HijackThis.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-21 20:42
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
——————————- DLLs startet under kørende Processer——————————-

- - - - - - - > ‘winlogon.exe’(688)
c:\programmer\SUPERAntiSpyware\SASWINLO.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > ‘explorer.exe’(2940)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
————————————Andre kørende processer————————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\programmer\Alwil Software\Avast5\AvastSvc.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\windows\system32\netdde.exe
c:\programmer\rnamfler\naofsvc.exe
c:\programmer\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmer\Analog Devices\SoundMAX\SMAgent.exe
.
**************************************************************************
.
Gennemført tid: 2010-03-21 20:48:30 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-03-21 19:48

Pre-Kørsel: 86.737.395.712 byte ledig
Post-Kørsel: 86.743.957.504 byte ledig

- - End Of File - - 8A9AD29AC06BC05CF528D973A3690908

Administrator
Avatar
Antal indlæg: 29174

Download GooredFix og gem den på dit skrivebord
http://jpshortstuff.247fixes.com/GooredFix.exe

Luk alle Firefox-vinduer.
Kør værktøjet-
Når du bliver bedt om at køre scanningen, skal du klikke på Ja.
GooredFix vil kontrollere for infektioner, og derefter vises en log.


Send loggen herind i dit næste svar.

  Angel
Antal indlæg: 96

GooredFix by jpshortstuff (08.01.10.1)
Log created at 11:38 on 22/03/2010 (Oem user)
Firefox version 3.6 (da)

========== GooredScan ==========


========== GooredLog ==========

C:\Programmer\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [12:56 09/03/2010]
{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} [23:01 28/11/2008]

C:\Documents and Settings\Oem user\Application Data\Mozilla\Firefox\Profiles\jmk5zzzy.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b} [13:37 09/03/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
“{ABDE892B-13A8-4d1b-88E6-365A6E755758}”=“C:\Program Files\Real\RealPlayer\browserrecord” [16:33 14/11/2008]
“jqs@sun.com”=“C:\Programmer\Java\jre6\lib\deploy\jqs\ff” [23:01 28/11/2008]
“{20a82645-c095-46ed-80e3-08825760534b}”=“c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\” [01:09 24/08/2009]

-=E.O.F=-