![]() |
|
#1
| |||
| |||
| Jeg har været smittet med en form for spyware / adware, jeg har fulgt flere af de tråde udstationeret her, som havde en lignende ting, men til ingen nytte. Adware: Changed mit skrivebord til en besked mundheld "Spyware trussel er blevet opdaget, klik her for at køre en fuld scanning", også det holder den dukker op med en boble i hjørnet fortæller mig de samme ting. Jeg har prøvet at hente og køre en masse programmer: SmitFraudFix Combofix ATF-Cleaner CCleaner SpyBotSearch & Destroy Men ingen af dem synes at have fastsat noget ... Please help! ![]() Jeg har vedhæftet en masse af de seneste logs. Grøn |
|
#2
| |||
| |||
| Velkommen til CJ Greenhorn ![]() Slet disse filer / mapper, som følger: 1. Gå til Start > Løbe > Type Notepad.exe og klik OK at åbne Notesblok. Det skal være Notesblok ikke WordPad.
Code: Killall:: Folder:: C: \ Programmer \ FLEOK File:: C: \ Programmer \ didduid.ini C: \ Programmer \ system32 \ wmsdkns.exe 4. Klik derefter på Fil > Gemme 5. Navngiv filen CFScript.txt - Gem filen på dit skrivebord 6. Derefter trække CFScript (hold venstre museknap nede, samtidig med at trække filen) og slippe det (release venstre museknap) i ComboFix.exe som du kan se i skærmbilledet nedenunder. Vigtigt: Udfør denne instruktion omhyggeligt! ![]() ComboFix vil begynde at udføre, skal du blot følge instruktionerne. Efter genstart (når den beder om at genstarte), den vil udarbejde en log for dig. Post, at log (Combofix.txt) i dit næste svar. Bemærk: Må ikke mouseclick combofix vindue mens den kører. Det kan forårsage dit system til at fryse ---------- Åbn Hijackthis og vælg Må en systemscanning kun. Anbringe en markering ved siden af følgende poster: (hvis der)
Afslut Hijackthis. ---------- Please download ATF Cleaner ved Atribune. ATF Cleaner.exe Sørg for, at alle browser vinduer er lukket.
---------- Vigtigt: Afinstallere den version af Hijackthis du har. det er den gamle Beta version, og vi skal have den nye version, samt omdøbe det til snigskytte. Først gå HER og gøre disse trin i orden. Trin Tre -- Malwarebytes' Anti-Malware (MBAM) Trin Fire -- Opdatering af Java Trin Seks -- HijackThis Nu køre en ny Hijackthis scanning og post loggen sammen med de andre. ---------- Næste post skal du tilføje Combofix log MBAM log NYE Hijackthis log |
|
#3
| |||
| |||
Hej, tak for den varme velkomst og hurtige svar, også Kudos til dig for råd!Jeg har fulgt alle dine instruktioner, som du sagde, efter at tilføje script til comofix virussen syntes at forsvinde, men jeg fulgte resten af de skridt alligevel at makesure. Jeg gjorde jeg Hijackthis! scanning, men de filer, du bad mig om at slette ikke længere var der, så jeg gætte combofix skal af sluppet af dem. Jeg løb en Malware bytes så godt, og den fandt nogle filer som jeg havde det slette. Synes lige det hele er godt nu, ikke mere Baggrund Ad eller boble popups, har jeg vedlagt logs som ønsket. Var nødt til at komprimere 2 af dem, fordi de var mere end filstørrelsen grænse, komprimeret med Winrar derefter omdøbes. Zip, håber det er ok. Tak igen Evilfantasy. ComboFix 08-04-08.7 - Ashton 2008-04-09 18:21:02.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.682 [GMT 1:00] Running from: C: \ Documents and Settings \ Ashton \ Desktop \ ComboFix.exe Command switches anvendes:: C: \ Documents and Settings \ Ashton \ Desktop \ CFScript.txt * Skabt et nyt gendannelsespunkt * Resident AV er aktiv ADVARSEL-maskinen IKKE HAR RECOVERY CONSOLE INSTALLERET!! FILE:: C: \ Programmer \ didduid.ini C: \ WINDOWS \ system32 \ wmsdkns.exe . ((((((((((((((((((((((((((((((((((((((( Andre Bortfald ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ Programmer \ 180search assistent C: \ Programmer \ 180search assistent \ 180sa.exe C: \ Programmer \ 180search assistent \ sau.exe C: \ Programmer \ 180searchassistant C: \ Programmer \ 180searchassistant \ saap.exe C: \ Programmer \ 180searchassistant \ sac.exe C: \ Programmer \ 180solutions C: \ Programmer \ 180solutions \ sais.exe C: \ Programmer \ seekmo C: \ Programmer \ seekmo \ seekmohook.dll C: \ Programmer \ STC C: \ Programmer \ stc \ csv5p070.exe C: \ Programmer \ Sysmnt C: \ Programmer \ Sysmnt \ Ssmgr.exe C: \ Programmer \ zango C: \ Programmer \ Zango \ zango.exe C: \ Programmer \ 180ax.exe C: \ Programmer \ 2020search.dll C: \ Programmer \ 2020search2.dll C: \ Programmer \ bjam.dll C: \ Programmer \ bokja.exe C: \ Programmer \ cdsm32.dll C: \ WINDOWS \ default.htm C: \ Programmer \ didduid.ini C: \ Programmer \ FLEOK C: \ Programmer \ FLEOK \ 180ax.exe C: \ WINDOWS \ mspphe.dll C: \ WINDOWS \ mssvr.exe C: \ Programmer \ saiemod.dll C: \ Programmer \ salm.exe C: \ Programmer \ stcloader.exe C: \ WINDOWS \ swin32.dll C: \ WINDOWS \ system32 \ msixu.dll C: \ WINDOWS \ system32 \ wer8274.dll C: \ WINDOWS \ system32 \ wmsdkns.exe C: \ Windows \ Temp \ salm.exe C: \ Programmer \ updatetc.exe C: \ WINDOWS \ voiceip.dll . ((((((((((((((((((((((((( Files Created fra 2008-03-09 til 2008-04-09 ))))))))))) )))))))))))))))))))) . 2008-04-09 08:52. 2008-04-09 08:52 <DIR> d -------- C: \ Programmer \ Sun 2008-04-09 08:36. 2008-04-09 08:36 <DIR> d -------- C: \ Programmer \ Trend Micro 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Programmer \ Malwarebytes 'Anti-Malware 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Application Data \ Malwarebytes 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Malwarebytes 2008-04-09 08:31. 2008-04-09 08:31 <DIR> d -------- C: \ Programmer \ Common Files \ Authentium 2008-04-09 08:31. 2008-04-09 18:11 53.192 - a ------ C: \ WINDOWS \ system32 \ drivers \ rp_skt32.sys 2008-04-09 08:31. 2007-04-19 11:36 48.384 - a ------ C: \ WINDOWS \ system32 \ drivers \ rp_pkt32.sys 2008-04-09 08:30. 2008-04-09 08:30 <DIR> d -------- C: \ Programmer \ Raxco 2008-04-09 08:30. 2008-04-09 18:07 <DIR> d -------- C: \ Programmer \ Common Files \ Scanner 2008-04-09 08:30. 2008-04-09 08:30 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Raxco 2008-04-09 08:28. 2008-04-09 08:28 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Application Data \ InstallShield 2008-04-09 08:25. 2008-04-09 08:30 <DIR> d -------- C: \ Programmer \ Virgin Bredbånd 2008-04-09 01:42. 2008-04-09 01:42 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Yahoo! Companion 2008-04-09 01:14. 2008-04-09 01:14 <DIR> d -------- C: \ Programmer \ Yahoo! 2008-04-09 01:13. 2008-04-09 01:15 <DIR> d -------- C: \ Programmer \ CCleaner 2008-04-09 00:43. 2008-04-09 01:52 3.314 - a ------ C: \ WINDOWS \ system32 \ tmp.reg 2008-04-09 00:42. 2007-09-06 00:22 289.144 - a ------ C: \ WINDOWS \ system32 \ VCCLSID.exe 2008-04-09 00:42. 2006-04-27 17:49 288.417 - a ------ C: \ WINDOWS \ system32 \ SrchSTS.exe 2008-04-09 00:42. 2008-03-29 00:19 86.528 - a ------ C: \ WINDOWS \ system32 \ VACFix.exe 2008-04-09 00:42. 2008-04-08 22:44 82.432 - a ------ C: \ WINDOWS \ system32 \ IEDFix.exe 2008-04-09 00:42. 2003-06-05 21:13 53.248 - a ------ C: \ WINDOWS \ system32 \ Process.exe 2008-04-09 00:42. 2004-07-31 18:50 51.200 - a ------ C: \ WINDOWS \ system32 \ dumphive.exe 2008-04-09 00:42. 2007-10-04 00:36 25.600 - a ------ C: \ WINDOWS \ system32 \ WS2Fix.exe 2008-04-09 00:01. 2008-04-09 00:01 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Flexnet 2008-04-08 23:57. 2008-04-08 23:57 <DIR> d -------- C: \ Programmer \ Spybot - Search & Destroy 2008-04-08 23:57. 2008-04-09 00:46 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Spybot - Search & Destroy 2008-04-08 23:50. 2008-04-08 23:50 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ ALM 2008-04-08 23:47. 2008-04-08 23:47 <DIR> d -------- C: \ Programmer \ Bonjour 2008-04-08 23:29. 2008-04-08 23:29 <DIR> d -------- C: \ Programmer \ Common Files \ Macrovision Shared 2008-04-08 22:42. 2008-04-08 22:42 <DIR> d -------- C: \ Programmer \ PowerISO 2008-04-07 01:56. 2008-04-07 01:56 1.110 - a ------ C: \ Programmer \ mozver.dat 2008-04-01 22:42. 2008-04-01 22:42 <DIR> d - h ----- C: \ Documents and Settings \ All Users \ Application Data \ (0E8E33D8-193a-414A-A909-0F101A142D26) 2008-04-01 22:38. 2008-04-01 22:38 <DIR> d -------- C: \ Programmer \ Stardock Games 2008-03-28 18:39. 2008-03-28 18:39 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Application Data \ dvdcss 2008-03-14 07:04. 2008-03-14 07:04 46.652 - a ------ C: \ WINDOWS \ system32 \ drivers \ scdemu.sys 2008-03-13 23:07. 2008-03-13 23:07 <DIR> d -------- C: \ Programmer \ Common Files \ NSV . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-04-09 07:54 --------- d ----- w C: \ Programmer \ Java 2008-04-09 07:30 --------- d ----- w C: \ Programmer \ CA 2008-04-09 07:29 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Virgin Bredbånd 2008-04-09 07:28 --------- d - h - w C: \ Programmer \ InstallShield Installation Information 2008-04-09 01:58 --------- d ----- w C: \ Documents and Settings \ Ashton \ Application Data \ Virgin Bredbånd 2008-04-08 22:47 --------- d ----- w C: \ Programmer \ Common Files \ Adobe 2008-02-26 20:59 --------- d ----- w C: \ Documents and Settings \ Ashton \ Application Data \ ATI 2008-02-26 20:59 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ ATI 2008-02-26 20:50 --------- d ----- w C: \ Programmer \ ATI Technologies 2008-02-26 01:30 --------- d ----- w C: \ Programmer \ Spil-Masters.com 2008-02-25 09:39 --------- d ----- w C: \ Programmer \ Common Files \ INCA Shared 2008-02-25 09:19 --------- d ----- w C: \ Programmer \ GameTribe 2008-02-24 03:18 --------- d ----- w C: \ Programmer \ Temp.p 2008-02-23 22:31 --------- d ----- w C: \ Programmer \ Common Files \ DirectX 2008-02-23 22:26 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Kontiki 2008-02-23 21:42 --------- d ----- w C: \ Programmer \ OGPlanet 2008-02-22 19:06 --------- d ----- w C: \ Documents and Settings \ Ashton \ Application Data \ AdobeUM 2008-02-21 19:33 --------- d ----- w C: \ Programmer \ Three Rings Design 2008-02-20 22:40 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ kanal4 2008-02-15 19:17 --------- d ----- w C: \ Programmer \ Winamp 2008-02-15 18:00 --------- d ----- w C: \ Programmer \ Hidden City Games 2008-02-15 16:55 --------- d ----- w C: \ Programmer \ SealOnlineUSA 2008-02-13 21:44 --------- d ----- w C: \ Programmer \ Funcom 2007-12-23 19:41 32 ---- ar C: \ Documents and Settings \ All Users \ hash.dat 2004-02-02 10:31 236.510-c - aw C: \ Documents and Settings \ Ashton \ DIAG.EXE 2004-01-30 18:21 62.480-c - aw C: \ Documents and Settings \ Ashton \ FETODI.COM 2004-01-09 14:28 51.356-c - aw C: \ Documents and Settings \ Ashton \ FETND3.sys 2004-01-09 14:27 53.136-c - aw C: \ Documents and Settings \ Ashton \ FETND4.sys 2004-01-09 14:24 40.960-c - aw C: \ Documents and Settings \ Ashton \ FETND5A.sys 2004-01-09 14:23 42.496-c - aw C: \ Documents and Settings \ Ashton \ FETND5B.sys 2003-11-27 15:01 57.344-c - aw C: \ Documents and Settings \ Ashton \ winsetup.exe 2002-10-09 16:29 147.456-c - aw C: \ Documents and Settings \ Ashton \ NTUTIL.DLL 2002-02-20 11:04 15.552-c - aw C: \ Documents and Settings \ Ashton \ WINNDI.DLL . ((((((((((((((((((((((((((((( Snapshot @ 2008-04-09_ 1.41.00.14 ))))))))))) )))))))))))))))))))))))))))))) . - 2008-04-08 22:11:46 29.696 ---- aw C: \ Programmer \ apphelp32.dll + 2008-04-09 17:08:03 9.472 ---- aw C: \ Programmer \ apphelp32.dll - 2008-04-08 22:11:46 14.592 ---- aw C: \ Programmer \ asferror32.dll + 2008-04-09 17:08:03 8.448 ---- aw C: \ Programmer \ asferror32.dll - 2008-04-08 22:11:46 29.952 ---- aw C: \ Programmer \ asycfilt32.dll + 2008-04-09 17:08:03 12.800 ---- aw C: \ Programmer \ asycfilt32.dll - 2008-04-08 22:11:46 20.480 ---- aw C: \ Programmer \ athprxy32.dll + 2008-04-09 17:08:03 18.432 ---- aw C: \ Programmer \ athprxy32.dll - 2008-04-08 22:11:46 17.408 ---- aw C: \ Programmer \ ati2dvaa32.dll + 2008-04-09 17:08:03 16.896 ---- aw C: \ Programmer \ ati2dvaa32.dll - 2008-04-08 22:11:46 10.752 ---- aw C: \ Programmer \ ati2dvag32.dll + 2008-04-09 17:08:03 20.480 ---- aw C: \ Programmer \ ati2dvag32.dll - 2008-04-08 22:11:46 22.016 ---- aw C: \ Programmer \ audiosrv32.dll + 2008-04-09 17:08:03 10.496 ---- aw C: \ Programmer \ audiosrv32.dll - 2008-04-08 22:11:47 22.272 ---- aw C: \ Programmer \ autodisc32.dll + 2008-04-09 17:08:03 30.464 ---- aw C: \ Programmer \ autodisc32.dll - 2008-04-08 22:11:47 12.288 ---- aw C: \ Programmer \ avifile32.dll + 2008-04-09 17:08:04 25.856 ---- aw C: \ Programmer \ avifile32.dll - 2008-04-08 22:11:47 27.392 ---- aw C: \ Programmer \ avisynthex32.dll + 2008-04-09 17:08:04 23.296 ---- aw C: \ Programmer \ avisynthex32.dll - 2008-04-08 22:11:47 23.808 ---- aw C: \ Programmer \ aviwrap32.dll + 2008-04-09 17:08:04 11.776 ---- aw C: \ Programmer \ aviwrap32.dll - 2008-04-08 22:11:47 17.920 ---- aw C: \ Programmer \ browserad.dll + 2008-04-09 17:08:04 18.944 ---- aw C: \ Programmer \ browserad.dll - 2008-04-08 22:11:45 31.488 ---- aw C: \ Programmer \ changeurl_30.dll + 2008-04-09 17:08:03 29.696 ---- aw C: \ Programmer \ changeurl_30.dll - 2007-10-10 15:36:22 10.134 ---- ar C: \ Windows \ Installer \ (05BCCF27-DC23-4ED9-87A2-F8D5B244B4C4) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:00 10.134 ---- ar C: \ Windows \ Installer \ (05BCCF27-DC23-4ED9-87A2-F8D5B244B4C4) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:18 26.582 ---- ar C: \ Windows \ Installer \ (212F5777-1190-4DEF-8E4D-6B2F313B45E7) \ PerfectDisk.exe + 2008-04-09 07:30:56 26.582 ---- ar C: \ Windows \ Installer \ (212F5777-1190-4DEF-8E4D-6B2F313B45E7) \ PerfectDisk.exe - 2007-10-10 15:36:46 10.134 ---- ar C: \ Windows \ Installer \ (324D4909-7A7B-45CD-B199-E975DC108249) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:31 10.134 ---- ar C: \ Windows \ Installer \ (324D4909-7A7B-45CD-B199-E975DC108249) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:53 10.134 ---- ar C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:45 10.134 ---- ar C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:53 25.214 ---- ar C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ Sm_En_DiagD_7C6BED816D7E4AD1AEAF5A1A DB6C8676.exe + 2008-04-09 07:31:45 25.214 ---- ar C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ Sm_En_DiagD_7C6BED816D7E4AD1AEAF5A1A DB6C8676.exe - 2007-10-10 15:36:52 10.134 ---- ar C: \ Windows \ Installer \ (3AFF4279-A590-4010-8C8A-3B096A220CFC) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:43 10.134 ---- ar C: \ Windows \ Installer \ (3AFF4279-A590-4010-8C8A-3B096A220CFC) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:59 10.134 ---- ar C: \ Windows \ Installer \ (3C441434-737C-4D54-8EAB-B409BE54E734) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:50 10.134 ---- ar C: \ Windows \ Installer \ (3C441434-737C-4D54-8EAB-B409BE54E734) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:00 10.134 ---- ar C: \ Windows \ Installer \ (53C32728-D434-4143-9C9D-D73D68D00893) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:52 10.134 ---- ar C: \ Windows \ Installer \ (53C32728-D434-4143-9C9D-D73D68D00893) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:02 10.134 ---- ar C: \ Windows \ Installer \ (5E7EBB6D-F44B-4D8B-9C52-F0F9173FD166) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:55 10.134 ---- ar C: \ Windows \ Installer \ (5E7EBB6D-F44B-4D8B-9C52-F0F9173FD166) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:48 10.134 ---- ar C: \ Windows \ Installer \ (6EA0ABC4-172B-48D4-AF26-93322D7FDE72) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:36 10.134 ---- ar C: \ Windows \ Installer \ (6EA0ABC4-172B-48D4-AF26-93322D7FDE72) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:50 10.134 ---- ar C: \ Windows \ Installer \ (A542D695-16D3-4F89-A6F1-091F009B8ABA) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:42 10.134 ---- ar C: \ Windows \ Installer \ (A542D695-16D3-4F89-A6F1-091F009B8ABA) \ ARPPRODUCTICON.exe - 2007-10-10 15:35:46 10.134 ---- ar C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:07 10.134 ---- ar C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ ARPPRODUCTICON.exe - 2007-10-10 15:35:46 25.214 ---- ar C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Desktop_En_Rps_A64EE928C7A645A784CE5 9FBDBDD9D1B.exe + 2008-04-09 07:30:07 25.214 ---- ar C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Desktop_En_Rps_A64EE928C7A645A784CE5 9FBDBDD9D1B.exe - 2007-10-10 15:35:46 25.214 ---- ar C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Sm_En_Rps_A64EE928C7A645A784CE59FBDB DD9D1B.exe + 2008-04-09 07:30:07 25.214 ---- ar C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Sm_En_Rps_A64EE928C7A645A784CE59FBDB DD9D1B.exe - 2007-10-10 15:36:49 10.134 ---- ar C: \ Windows \ Installer \ (B5C0FD16-3A5D-40D5-8B59-4B43279BB5D0) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:41 10.134 ---- ar C: \ Windows \ Installer \ (B5C0FD16-3A5D-40D5-8B59-4B43279BB5D0) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:57 10.134 ---- ar C: \ Windows \ Installer \ (C831972C-3834-4D9D-A095-8350B324AC3C) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:47 10.134 ---- ar C: \ Windows \ Installer \ (C831972C-3834-4D9D-A095-8350B324AC3C) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:07 10.134 ---- ar C: \ Windows \ Installer \ (D8AEA1D1-78FE-4CE1-9405-D7E55E797C4D) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:29 10.134 ---- ar C: \ Windows \ Installer \ (D8AEA1D1-78FE-4CE1-9405-D7E55E797C4D) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:11 10.134 ---- ar C: \ Windows \ Installer \ (DD1C392B-226D-42C9-B8E6-2A9BEF7583B4) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:50 10.134 ---- ar C: \ Windows \ Installer \ (DD1C392B-226D-42C9-B8E6-2A9BEF7583B4) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:32 10.134 ---- ar C: \ Windows \ Installer \ (ECBDDBD7-43CC-417C-B87A-943AFED8EB57) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:10 10.134 ---- ar C: \ Windows \ Installer \ (ECBDDBD7-43CC-417C-B87A-943AFED8EB57) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:09 10.134 ---- ar C: \ Windows \ Installer \ (EE1D5780-AF29-4DC4-A107-3FD5F79AC63A) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:32 10.134 ---- ar C: \ Windows \ Installer \ (EE1D5780-AF29-4DC4-A107-3FD5F79AC63A) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:01 10.134 ---- ar C: \ Windows \ Installer \ (FD2EC356-DB5E-40AE-907A-9A1D38F9396D) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:53 10.134 ---- ar C: \ Windows \ Installer \ (FD2EC356-DB5E-40AE-907A-9A1D38F9396D) \ ARPPRODUCTICON.exe - 1998-10-29 16:45:06 306.688 ---- aw C: \ Programmer \ IsUninst.exe + 1998-10-29 15:45:06 306.688 ---- aw C: \ Programmer \ IsUninst.exe - 2008-04-08 22:11:49 14.080 ---- aw C: \ Programmer \ msa64chk.dll + 2008-04-09 17:08:06 11.776 ---- aw C: \ Programmer \ msa64chk.dll - 2008-04-08 22:11:49 26.368 ---- aw C: \ Programmer \ msapasrc.dll + 2008-04-09 17:08:06 26.624 ---- aw C: \ Programmer \ msapasrc.dll - 2008-04-08 22:11:48 25.344 ---- aw C: \ Programmer \ ntnut.exe + 2008-04-09 17:08:05 8.960 ---- aw C: \ Programmer \ ntnut.exe - 2008-04-08 22:11:47 18.432 ---- aw C: \ Programmer \ shdocpe.dll + 2008-04-09 17:08:05 32.000 ---- aw C: \ Programmer \ shdocpe.dll - 2008-04-08 22:11:48 21.504 ---- aw C: \ Programmer \ shdocpl.dll + 2008-04-09 17:08:05 27.904 ---- aw C: \ Programmer \ shdocpl.dll - 2007-09-24 22:30:28 135.168 ---- aw C: \ WINDOWS \ system32 \ java.exe + 2008-02-22 00:23:35 135.168 ---- aw C: \ WINDOWS \ system32 \ java.exe - 2007-09-24 22:30:30 135.168 ---- aw C: \ WINDOWS \ system32 \ javaw.exe + 2008-02-22 00:23:39 135.168 ---- aw C: \ WINDOWS \ system32 \ javaw.exe - 2007-09-24 23:31:42 139.264 ---- aw C: \ WINDOWS \ system32 \ javaws.exe + 2008-02-22 01:33:32 139.264 ---- aw C: \ WINDOWS \ system32 \ javaws.exe - 2008-04-08 22:11:50 9.984 ---- aw C: \ WINDOWS \ system32 \ MSNSA32.dll + 2008-04-09 17:08:07 14.336 ---- aw C: \ WINDOWS \ system32 \ MSNSA32.dll - 2008-04-08 22:11:48 31.488 ---- aw C: \ WINDOWS \ system32 \ ntnut32.exe + 2008-04-09 17:08:05 28.928 ---- aw C: \ WINDOWS \ system32 \ ntnut32.exe - 2008-04-08 22:11:48 21.760 ---- aw C: \ WINDOWS \ system32 \ shdocpe.dll + 2008-04-09 17:08:05 26.880 ---- aw C: \ WINDOWS \ system32 \ shdocpe.dll - 2008-04-08 22:11:48 19.712 ---- aw C: \ WINDOWS \ system32 \ SIPSPI32.dll + 2008-04-09 17:08:06 30.720 ---- aw C: \ WINDOWS \ system32 \ SIPSPI32.dll - 2008-04-08 22:11:47 12.800 ---- aw C: \ Programmer \ winsb.dll + 2008-04-09 17:08:04 18.432 ---- aw C: \ Programmer \ winsb.dll - 2007-10-10 15:35:42 1.233.920 ---- aw C: \ Programmer \ winsxs \ x86_Microsoft.MSXML2_6bd6b9abf34 5378f_4.20.9818.0_x-ww_8ff50c5d \ msxml4.dll + 2008-04-09 07:30:03 1.233.920 ---- aw C: \ Programmer \ winsxs \ x86_Microsoft.MSXML2_6bd6b9abf34 5378f_4.20.9818.0_x-ww_8ff50c5d \ msxml4.dll - 2007-10-10 15:35:42 82.432 ---- aw C: \ Programmer \ winsxs \ x86_Microsoft.MSXML2R_6bd6b9abf3 45378f_4.1.0.0_x-ww_29c3ad6a \ Msxml4r.dll + 2008-04-09 07:30:03 82.432 ---- aw C: \ Programmer \ winsxs \ x86_Microsoft.MSXML2R_6bd6b9abf3 45378f_4.1.0.0_x-ww_29c3ad6a \ Msxml4r.dll . - Snapshot reset til aktuelle dato -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Note * empty entries & legit default entries er ikke vist REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "CTFMON.EXE" = "C: \ Programmer \ MSN Messenger \ msnmsgr.exe" [2007-01-19 12:54 5674352] "SB Audigy 2 Startup Menu" = "/ L: ENG" [] "ctfmon.exe" = "C: \ WINDOWS \ system32 \ CTFMON.EXE" [2004-08-04 08:56 15360] [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ RunOnce] "IndexCleaner" = "C: \ Programmer \ Virgin Broadband \ PCguard \ IdxClnR.exe" [2007-09-05 14:09 61168] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "dla" = "C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe" [2004-03-15 01:04 122933] "UpdateManager" = "C: \ Programmer \ Common Files \ Sonic \ Update Manager \ sgtray.exe" [2003-08-19 01:01 110592] "CTSysVol" = "C: \ Programmer \ Creative \ SBAudigy2 \ Surround Mixer \ CTSysVol.exe" [2002-10-29 09:18 49152] "CTDVDDet" = "C: \ Programmer \ Creative \ SBAudigy2 \ DVDAudio \ CTDVDDet.EXE" [2002-09-30 01:00 45056] "CTHelper" = "CTHELPER.EXE" [2003-02-20 23:45 28672 C: \ WINDOWS \ system32 \ CTHELPER.EXE] "AsioReg" = "regsvr32.exe" [2004-08-04 08:56 11776 C: \ WINDOWS \ system32 \ regsvr32.exe] "UpdReg" = "C: \ WINDOWS \ UpdReg.EXE" [2000-05-11 01:00 90112] "ITunesHelper" = "C: \ Programmer \ ATI Technologies \ ATI Control Panel \ iTunes \ iTunesHelper.exe" [2004-05-25 22:35 335872] "BJCFD" = "C: \ Programmer \ BroadJump \ Client Foundation \ CFD.exe" [2003-01-27 17:16 376912] "CTFMON.EXE" = "C: \ Programmer \ Winamp \ winampa.exe" [2008-01-15 23:54 37376] "StartCCC" = "C: \ Programmer \ ATI Technologies \ ATI.ACE \ Core-Static \ CLIStart.exe" [2006-11-10 13:35 90112] "PWRISOVM.EXE" = "C: \ Programmer \ PowerISO \ PWRISOVM.EXE" [2008-03-15 00:50 233472] "workflow" = "D: \ installs \ workflow.exe" [] "Broadbandadvisor.exe" = "C: \ Programmer \ Virgin Broadband \ rådgiver \ Broadbandadvisor.exe" [2007-08-07 18:49 2061552] "PCguard" = "C: \ Programmer \ Virgin Broadband \ PCguard \ Rps.exe" [2007-09-05 14:10 310000] "-FreedomNeedsReboot" = "C: \ Programmer \ Virgin Broadband \ PCguard \ ZkRunOnceR.exe" [2007-09-05 14:10 13552] "SunJavaUpdateSched" = "C: \ Programmer \ Java \ jre1.6.0_05 \ bin \ jusched.exe" [2008-02-22 04:25 144784] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ RunOnce] "IndexCleaner" = "C: \ Programmer \ Virgin Broadband \ PCguard \ IdxClnR.exe" [2007-09-05 14:09 61168] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "CTFMON.EXE" = "C: \ WINDOWS \ system32 \ CTFMON.EXE" [2004-08-04 08:56 15360] C: \ Documents and Settings \ All Users \ Menuen Start \ Programmer \ Start \ Adobe Reader Speed Launch.lnk - C: \ Programmer \ Adobe \ Acrobat 7.0 \ Reader \ Reader_sl.exe [2004-12-14 05:44:06 29696] Microsoft Office.lnk - C: \ Programmer \ Microsoft Office \ Office \ OSA9.EXE [2000-01-21 09:15:54 65588] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ drivers32] "VIDC.X264" = x264vfw.dll "msacm.ac3acm" = AC3ACM.acm "msacm.scg726" = scg726.acm "msacm.alf2cd" = alf2cd.acm "vidc.dvsd" = mcdvd_32.dll [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Shared Tools \ msconfig \ startupreg \ Daemon Tools] - a ------ 2007-08-29 16:09 171464 C: \ Programmer \ DAEMON Tools \ daemon.exe [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile] "EnableFirewall" = 0 (0x0) [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile \ AuthorizedApplications \ List] "% windir% \ \ system32 \ \ sessmgr.exe" = "C: \ \ Programmer \ \ Messenger \ \ msmsgs.exe" = "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" = "C: \ \ Programmer \ \ Skype \ \ Phone \ \ Skype.exe" = "C: \ \ Programmer \ \ MSN Messenger \ \ msnmsgr.exe" = "C: \ \ Programmer \ \ MSN Messenger \ \ livecall.exe" = "C: \ \ Programmer \ \ Stardock Games \ \ Sins af en Solar Empire \ \ Sins af en Solar Empire.exe" = "C: \ \ Programmer \ \ Bonjour \ \ mDNSResponder.exe" = [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile \ GloballyOpenPorts \ List] "15808: TCP" = 15808: TCP: BitComet 15808 TCP "15808: UDP" = 15808: UDP: BitComet 15808 UDP "3724: TCP" = 3724: TCP: Blizzard Downloader: 3724 S3 iadusb; GlobespanVirata USB IAD LAN Modem; C: \ WINDOWS \ system32 \ DRIVERS \ glauiad.sys [2004-07-02 09:20] S3 Radialpoint Security Services; Virgin Bredbånd PCguard C: \ WINDOWS \ system32 \ dllhost.exe [2004-08-04 08:56] S3 XDva037; XDva037 C: \ WINDOWS \ system32 \ XDva037.sys [] . Indhold af "Planlagte opgaver" mappe "2008-04-03 19:15:02 C: \ WINDOWS \ Tasks \ AppleSoftwareUpdate.job" - C: \ Programmer \ Apple Software Update \ SoftwareUpdate.exe . ************************************************** ************************ catchme 0.3.1351 W2K/XP/Vista - rootkit / stealth malware detector ved Gmer, http://www.gmer.net Rootkit scan 2008-04-09 18:26:36 Windows 5.1.2600 Service Pack 2 NTFS scanning skjulte processer ... scanning skjulte autostart entries ... scanning skjulte filer ... scanning afsluttet med succes skjulte filer: 0 ************************************************** ************************ . ------------------------ Other Running Processes ----------------------- -- . C: \ WINDOWS \ system32 \ Ati2evxx.exe C: \ Programmer \ Virgin Broadband \ PCguard \ Fws.exe C: \ WINDOWS \ system32 \ Ati2evxx.exe C: \ Programmer \ Bonjour \ mDNSResponder.exe C: \ WINDOWS \ System32 \ CTsvcCDA.exe C: \ Programmer \ Common Files \ Authentium \ AntiVirus \ dvpapi.exe C: \ Programmer \ CA \ PPRT \ bin \ ITMRTSVC.exe C: \ Programmer \ Raxco \ PerfectDisk \ PDAgent.exe C: \ WINDOWS \ system32 \ PnkBstrA.exe C: \ Programmer \ Analog Devices \ SoundMAX \ spkrmon.exe C: \ WINDOWS \ system32 \ wdfmgr.exe C: \ WINDOWS \ System32 \ MsPMSPSv.exe C: \ Programmer \ ATI Technologies \ ATI.ACE \ Core-Static \ MOM.EXE C: \ Programmer \ Raxco \ PerfectDisk \ PDEngine.exe C: \ Programmer \ Virgin Broadband \ rådgiver \ BroadbandadvisorComHandler.exe C: \ Programmer \ Virgin Broadband \ PCguard \ rpsupdaterR.exe C: \ Programmer \ ATI Technologies \ ATI.ACE \ Core-Static \ ccc.exe C: \ Programmer \ MSN Messenger \ usnsvc.exe . ************************************************** ************************ . Completion time: 2008-04-09 18:31:56 - maskinen blev genstartet ComboFix-quarantined-files.txt 2008-04-09 17:31:47 ComboFix2.txt 2008-04-09 00:59:01 ComboFix3.txt 2008-04-09 00:41:25 Pre-Run: 12340674560 bytes fri Post-Run: 12324302848 bytes fri . 2008-03-22 04:20:29 --- EOF --- |
|
#4
| |||
| |||
| Ser godt ud. Nu køre ATF Cleaner igen for at slippe af med de skadelige filer i temp mapper. Jeg satte Combofix logge ind på stillingen. Jeg er sikker på at du kan se dette: ADVARSEL-maskinen IKKE HAR RECOVERY CONSOLE INSTALLERET!! Dette er fælles, og du kan installere genoprettelseskonsollen, hvis du vælger ved at følge anvisningerne HER Tid til at gøre nogle oprydning og sikre det arbejde, du har gjort.
![]() Ovennævnte procedure vil:
1. Dobbeltklik OTMoveIt2.exe at iværksætte den. Vista-brugere højreklikke og vælge Kør som administrator 2. Klik på Ryd op! knappen. 3. OTMoveIt2 vil hente en liste fra internettet, hvis din firewall eller andre defensive programmer advarer dig, give den adgang. 4. Klik på JA på det næste prompt (liste downloades Vil du begynde Tilfældig proces?)
Indstilling af et nyt gendannelsespunkt efter rensning dit system vil gøre det muligt for computeren at roll-back til et rent arbejder tilstand, hvis det er nødvendigt.
Uaktuel software har sikkerhedssvagheder, at malware kan udnytte.
Se også Langsom computer? Den må ikke være Malware gratis rengøring / vedligeholdelse af værktøjer til at hjælpe med at holde din computer kører glat. Lad mig vide, om noget andet dukker op. |
![]() |
|
| Bogmærker |
Lignende Tråde | ||||
| Tråd | Thread Starter | Forum | Svar | Last Post |
| Inficeret computer | duskmon10 | Virus, Spyware & Sikkerhed | 22 | 28 November 2009 12:27 |
| Min computer er inficeret, jeg tror? Kan nogen hjælpe? | lawt555 | Virus, Spyware & Sikkerhed | 5 | 16 marts 2009 04:59 |
| Kids pc inficeret? | redden137 | Virus, Spyware & Sikkerhed | 6 | 4 januar 2009 15:10 |
| Jeg er ikke sikker på, hvis min computer er inficeret eller ej | Rob1 | Virus, Spyware & Sikkerhed | 4 | 4 februar 2008 15:14 |
| Thread Tools | |
| |