Hej.
Jeg kan ikke åbne joblisten og registreringsdatabasen , så jeg har en mistanke om computeren har fået en virusinfektion.
Er der nogle som kan hjælpe mig med at rense den?
|
|
|
|
Hej. Er der nogle som kan hjælpe mig med at rense den? |
|
|
|
|
|
Hej og velkommen Vi kan lige tjekke.
Download random´s system information tool (RSIT) her http://images.malwareremoval.com/random/RSIT.exe
|
|
|
|
|
|
Her er min log: ======Uninstall list====== —>MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF} ======Hosts File====== 127.0.0.1 local ======Security center information====== AV: avast! Antivirus ======System event log====== Computer Name: DK-23537FAC6172 Record Number: 11327 Computer Name: DK-23537FAC6172 Record Number: 11326 Computer Name: DK-23537FAC6172 Record Number: 11325 Computer Name: DK-23537FAC6172 Record Number: 11324 Computer Name: DK-23537FAC6172 Record Number: 11323 =====Application event log===== Computer Name: DK-23537FAC6172 Computer Name: DK-23537FAC6172 Computer Name: DK-23537FAC6172 Computer Name: DK-23537FAC6172 Record Number: 1923 Computer Name: DK-23537FAC6172 ======Environment variables====== “ComSpec”=%SystemRoot%\system32\cmd.exe ————————-EOF————————- |
|
|
|
|
|
ogfile of random’s system information tool 1.09 (written by random/random) HijackThis download failed ======Scheduled tasks folder====== E:\WINDOWS\tasks\Adobe Flash Player Updater.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite] E:\Documents and Settings\All Users\Menuen Start\Programmer\Start [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RelevantKnowledge] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
|
|
|
|
|
|
Det er ikke hele min regedit file , så du får lige en ny kopi af den. |
|
|
|
|
|
Logfile of random’s system information tool 1.09 (written by random/random) HijackThis download failed ======Scheduled tasks folder====== E:\WINDOWS\tasks\Adobe Flash Player Updater.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite] E:\Documents and Settings\All Users\Menuen Start\Programmer\Start [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RelevantKnowledge] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
|
|
|
|
|
|
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe] [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32] ======File associations====== .scr - open - E:\WINDOWS\system32\notepad.exe “%1” ======List of files/folders created in the last 1 month====== 2012-04-08 13:27:58——D——E:\rsit ======List of files/folders modified in the last 1 month====== 2012-04-08 13:14:42——D——E:\WINDOWS\Temp ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 uagp35;Microsoft AGPv3.5-filter; E:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Akamai;Akamai NetSession Interface; E:\WINDOWS\System32\svchost.exe [2008-04-14 14336] ————————-EOF————————- |
|
|
|
|
|
indlæg 3 skal du ignorere , det er indlæg 5 og 6 det er min regedit. |
|
|
|
|
|
Fint
NB -> Deaktiver dit antivirus/antispyware program. Da det/de kan ”forstyrre” og konflikte med combofix, eller fjerne vigtige combofix filer, hvilket kan få computeren til fryse.
Når combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt Den kan også findes her - > C: combofix txt |
|
|
|
|
|
ComboFix 12-04-07.04 - Henrik Jensen 08-04-2012 19:20:57.1.2 - x86 advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
2012-03-30 08:36:41 . 2011-09-26 20:16:39 70304 ——a-w- E:\WINDOWS\system32\FlashPlayerCPLApp.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] E:\Documents and Settings\All Users\Menuen Start\Programmer\Start\ [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avastSvc.exe] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avastUI.exe] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] R1 aswSnx;aswSnx;E:\WINDOWS\system32\drivers\aswSnx.sys [26-09-2011 16:55:32 435032] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Indhold af mappen ‘Planlagte Opgaver’ 2012-04-08 E:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2012-03-04 E:\WINDOWS\Tasks\AppleSoftwareUpdate.job 2011-09-26 E:\WINDOWS\Tasks\DriverNavigator Scheduled Scan.job 2012-04-08 E:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2012-04-08 E:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2012-04-08 E:\WINDOWS\Tasks\User_Feed_Synchronization-{BEA0F2E9-A640-416D-897D-DDED9BA695E4}.job
uStart Page = hxxp://www.signon.stofanet.dk/
.scr=DWGTrueViewScriptFile - - - - TOMME GENVEJE FJERNET - - - - Toolbar-10 - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net scanner skjulte processer ... scanner skjulte autostarter ... scanner skjulte filer ... scanning gennemført med succes ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai] ——————————- DLLs startet under kørende Processer——————————- - - - - - - - > ‘winlogon.exe’(664) - - - - - - - > ‘explorer.exe’(1516) ————————————Andre kørende processer———————————— E:\Programmer\Java\jre6\bin\jqs.exe ************************************************************************** Gennemført tid: 2012-04-08 19:39:13 - maskinen blev genstartet |
|
|
|
|
|
Hvordan opfører computeren sig nu ? |
|