scareware/spyware problem / av niklas90

  • 19 svar
scareware/spyware problem
2010-02-10 kl 21:10

hej jag har kämpat med ett scareware som länkar mig vidare ifrån hemsidorna jag tittar på till sånna som påstår att datorn är virus infekterad och att allt blir bra med deras programvara.... väldigt jobbigt om nån kan hjälpa är jag väldigt tacksam!
här är min logg:
Logfile of Trend Micro HijackThis v2.0.2Scan saved at 21:00:30, on 2010-02-10Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\syst
em32\winlogon.exeC:\WINDOWS\system32\services.exeC:\W
INDOWS\system32\lsass.exeC:\WINDOWS\system32\svchos
t.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explor
er.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\syste
m32
undll32.exeC:\Program\Bonjour\mDNSResponder.exeC:\Pro
gram\F-Secure\Anti-Virus\fsgk32st.exeC:\Program\F-S
ecure\Common\FSMA32.EXEC:\Program\F-Secure\Anti-Vir
us\FSGK32.EXEC:\WINDOWS\system32
vsvc32.exeC:\Program\F-Secure\Common\FSMB32.EXEC:\WIN
DOWS\system32\Pen_Tablet.exeC:\WINDOWS\system32\Sea
rchIndexer.exeC:\Program\F-Secure\Common\FCH32.EXEC:\
Program\F-Secure\Common\FAMEH32.EXEC:\Program\F-Sec
ure\Anti-Virus\fsqh.exeC:\Program\Java\jre1.5.0\bin
\jusched.exeC:\Program\Synaptics\SynTP\SynTPLpr.exeC:\ >Program\Synaptics\SynTP\SynTPEnh.exeC:\Program\F-S
ecure\Common\FSM32.EXEC:\WINDOWS\SOUNDMAN.EXEC:\Progr
am\DAEMON Tools\daemon.exeC:\Program\Microsoft Office\Office12\GrooveMonitor.exeC:\Program\iTunes\
iTunesHelper.exeC:\WINDOWS\system32\ctfmon.exeC:\Prog
ram\F-Secure\FSGUI\fsguidll.exeC:\Program\Windows Live\Messenger\msnmsgr.exeC:\Program\Messenger\msms
gs.exeC:\Program\SUPERAntiSpyware\SUPERAntiSpyware.
exeC:\Program\Spybot - Search & Destroy\TeaTimer.exeC:\Program\Windows Desktop Search\WindowsSearch.exeC:\Program\F-Secure\Common\
FNRB32.EXEC:\Program\F-Secure\Anti-Virus\fssm32.exeC:\ >Program\F-Secure\FSAUA\program\fsaua.exeC:\Program
\F-Secure\Common\FIH32.EXEC:\Program\F-Secure\FWES\
Program\fsdfwd.exeC:\Program\iPod\bin\iPodService.e
xeC:\Program\Telia\Telia_Mobilt_bredband\Telia_Mobi
lt_bredband.exeC:\Program\F-Secure\Anti-Virus\fsav3
2.exeC:\WINDOWS\system32\wuauclt.exeC:\Program\Mozilla Firefox\firefox.exeC:\Documents and Settings\Niklas\Application Data\U3\0000167A67730397\LaunchPad.exeC:\Program\Bi
tTorrent\bittorrent.exeC:\Program\VideoLAN\VLC\vlc.
exed:\Documents and Settings\Niklas\Mina dokument\Hämtade filer\HiJackThis.exeC:\WINDOWS\system32\SearchProto
colHost.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\In
ternet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = LänkarO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program\Microsoft Office\Office12\GrooveShellExtensions.dllO2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exeO4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\jre1.5.0\bin\jusched.exeO4 - HKLM\..\Run: [SynTPLpr] C:\Program\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [SynTPEnh] C:\Program\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program\F-Secure\Common\FSM32.EXE" /splashO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSWO4 - HKLM\..\Run: [InstantOn] "C:\Program\CyberLink\PowerCinema Linux\ion_install.exe" /cO4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXEO4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXEO4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXEO4 - HKLM\..\Run: [DAEMON Tools] "C:\Program\DAEMON Tools\daemon.exe" -lang 1033O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.e
xe" -launchedbyloginO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [msnmsgr] "C:\Program\Windows Live\Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exeO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUti
l.exe -pO4 - Startup: Telia Mobilt bredband.lnk = C:\Program\Telia\Telia_Mobilt_bredband\Telia_Mobilt
_bredband.exeO4 - Global Startup: Windows Desktop Search.lnk = C:\Program\Windows Desktop Search\WindowsSearch.exeO8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MI1933~1\Office12\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0\bin
pjpi150.dllO9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0\bin
pjpi150.dllO9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MI1933~1\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MI1933~1\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MI1933~1\Office12\REFIEBAR.DLLO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot - Search & Destroy\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot - Search & Destroy\SDHelper.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exeO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5
Controls/en/x86/client/muweb_site.cab?12500909426
56O16
- DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/g
p.cabO18
- Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program\Microsoft Office\Office12\GrooveSystemServices.dllO20 - AppInit_DLLs: prio.dllO20 - Winlogon Notify: !SASWinLogon - C:\Program\SUPERAntiSpyware\SASWINLO.dllO23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exeO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program\F-Secure\Anti-Virus\fsgk32st.exeO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program\F-Secure\Common\FNRB32.EXEO23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program\F-Secure\FSAUA\program\fsaua.exeO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program\F-Secure\FWES\Program\fsdfwd.exeO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program\F-Secure\Common\FSMA32.EXEO23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program\F-Secure\ORSP Client\fsorsp.exeO23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32
vsvc32.exeO23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe--End of file - 9147 bytes
tack i förhand!

2010-02-11 kl 08:13

funkar google som vanligt?
http://www.malwarebytes.org/mbam/program/mbam-set
up.exeinstallera
programmet och klicka på uppdatera samt scanna när du ser den knappen.klicka på ok >visa resultat >ta bort markerade, posta den loggen som visas automatisk

2010-02-11 kl 13:18

google funkar men ibland när jag klickar på en länk ifrån sökningen så länkas jag till andra sidor. Jag ska installera det när jag kommer hem.

2010-02-11 kl 19:26

här är loggen:
Malwarebytes' Anti-Malware 1.44Databasversion: 3510Windows 5.1.2600 Service Pack 3Internet Explorer 8.0.6001.187022010-02-11 19:29:53mbam-log-2010-02-11 (19-29-53).txtSkanningstyp: Fullständig skanning (C:\|D:\|)Antal skannade objekt: 232140Förfluten tid: 1 hour(s), 31 minute(s), 39 second(s)Infekterade minnesprocesser: 0Infekterade minnesmoduler: 0Infekterade registernycklar: 0Infekterade registervärden: 0Infekterade registerdataposter: 0Infekterade mappar: 0Infekterade filer: 0Infekterade minnesprocesser:(Inga illasinnade poster hittades)Infekterade minnesmoduler:(Inga illasinnade poster hittades)Infekterade registernycklar:(Inga illasinnade poster hittades)Infekterade registervärden:(Inga illasinnade poster hittades)Infekterade registerdataposter:(Inga illasinnade poster hittades)Infekterade mappar:(Inga illasinnade poster hittades)Infekterade filer:(Inga illasinnade poster hittades)

2010-02-11 kl 21:05

uppdatera malwarebytes och gör en snabb scan, posta logg om nåt hittas

2010-02-11 kl 21:49

inget hittades då heller. jag gjorde fullständig scan

2010-02-11 kl 22:55

kör filen och posta txt filen som lägger sig under C: http://support.kaspersky.com/downloads/utils/tdss
killer.zip

2010-02-11 kl 23:52

här är den:
23:55:47:203 0632 TDSS rootkit removing tool 2.2.3 Feb 4 2010 14:34:0023:55:47:203 0632 =================================================
===============================23:55:47:218 0632 SystemInfo:23:55:47:218 0632 OS Version: 5.1.2600 ServicePack: 3.023:55:47:218 0632 Product type: Workstation23:55:47:218 0632 ComputerName: NIKLAS-DATOR23:55:47:218 0632 UserName: Niklas23:55:47:218 0632 Windows directory: C:\WINDOWS23:55:47:218 0632 Processor architecture: Intel x8623:55:47:218 0632 Number of processors: 123:55:47:218 0632 Page size: 0x100023:55:47:218 0632 Boot type: Normal boot23:55:47:218 0632 =================================================
===============================23:55:47:234 0632 UnloadDriverW: NtUnloadDriver error 223:55:47:234 0632 ForceUnloadDriverW: UnloadDriverW(klmd21) error 223:55:47:234 0632 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.s
ys) returned status 0000000023:55:47:265 0632 UtilityInit: KLMD drop and load success23:55:47:265 0632 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)23:55:47:265 0632 UtilityInit: KLMD open success23:55:47:265 0632 UtilityInit: Initialize success23:55:47:265 0632 23:55:47:265 0632 Scanning Services ...23:55:47:265 0632 CreateRegParser: Registry parser init started23:55:47:265 0632 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 12723:55:47:265 0632 CreateRegParser: DisableWow64Redirection error23:55:47:265 0632 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system23:55:47:265 0632 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C000004323:55:47:265 0632 wfopen_ex: MyNtCreateFileW error 32 (C0000043)23:55:47:265 0632 wfopen_ex: Trying to KLMD file open23:55:47:265 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system23:55:47:265 0632 wfopen_ex: File opened ok (Flags 2)23:55:47:265 0632 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 3D4A3023:55:47:265 0632 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software23:55:47:265 0632 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\softwar
e) returned status C000004323:55:47:265 0632 wfopen_ex: MyNtCreateFileW error 32 (C0000043)23:55:47:265 0632 wfopen_ex: Trying to KLMD file open23:55:47:265 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software23:55:47:265 0632 wfopen_ex: File opened ok (Flags 2)23:55:47:265 0632 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 3D4AD823:55:47:265 0632 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 12723:55:47:265 0632 CreateRegParser: EnableWow64Redirection error23:55:47:265 0632 CreateRegParser: RegParser init completed23:55:47:390 0632 GetAdvancedServicesInfo: Raw services enum returned 350 services23:55:47:406 0632 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system23:55:47:406 0632 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software23:55:47:406 0632 23:55:47:406 0632 Scanning Kernel memory ...23:55:47:406 0632 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk23:55:47:406 0632 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 89B7894023:55:47:406 0632 DetectCureTDL3: KLMD_GetDeviceObjectList returned 6 DevObjects23:55:47:406 0632 23:55:47:406 0632 DetectCureTDL3: DEVICE_OBJECT: 889D617023:55:47:406 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 889D617023:55:47:406 0632 KLMD_ReadMem: Trying to ReadMemory 0x889D6170[0x38]23:55:47:406 0632 DetectCureTDL3: DRIVER_OBJECT: 89B7894023:55:47:406 0632 KLMD_ReadMem: Trying to ReadMemory 0x89B78940[0xA8]23:55:47:406 0632 KLMD_ReadMem: Trying to ReadMemory 0xE1015968[0x18]23:55:47:406 0632 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk23:55:47:406 0632 DetectCureTDL3: IrpHandler (0) addr: F765DBB023:55:47:406 0632 DetectCureTDL3: IrpHandler (1) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (2) addr: F765DBB023:55:47:406 0632 DetectCureTDL3: IrpHandler (3) addr: F7657D1F23:55:47:406 0632 DetectCureTDL3: IrpHandler (4) addr: F7657D1F23:55:47:406 0632 DetectCureTDL3: IrpHandler (5) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (6) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (7) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (8) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (9) addr: F76582E223:55:47:406 0632 DetectCureTDL3: IrpHandler (10) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (11) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (12) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (13) addr: 804FA88E23:55:47:406 0632 DetectCureTDL3: IrpHandler (14) addr: F76583BB23:55:47:421 0632 DetectCureTDL3: IrpHandler (15) addr: F765BF2823:55:47:421 0632 DetectCureTDL3: IrpHandler (16) addr: F76582E223:55:47:421 0632 DetectCureTDL3: IrpHandler (17) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (18) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (19) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (20) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (21) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (22) addr: F7659C8223:55:47:421 0632 DetectCureTDL3: IrpHandler (23) addr: F765E99E23:55:47:421 0632 DetectCureTDL3: IrpHandler (24) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (25) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (26) addr: 804FA88E23:55:47:421 0632 TDL3_FileDetect: Processing driver: Disk23:55:47:421 0632 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys23:55:47:421 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys23:55:47:421 0632 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean23:55:47:421 0632 23:55:47:421 0632 DetectCureTDL3: DEVICE_OBJECT: 88A6EAB823:55:47:421 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 88A6EAB823:55:47:421 0632 DetectCureTDL3: DEVICE_OBJECT: 89680BA023:55:47:421 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89680BA023:55:47:421 0632 KLMD_ReadMem: Trying to ReadMemory 0x89680BA0[0x38]23:55:47:421 0632 DetectCureTDL3: DRIVER_OBJECT: 8882CF3823:55:47:421 0632 KLMD_ReadMem: Trying to ReadMemory 0x8882CF38[0xA8]23:55:47:421 0632 KLMD_ReadMem: Trying to ReadMemory 0xE1DF3880[0x1E]23:55:47:421 0632 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR23:55:47:421 0632 DetectCureTDL3: IrpHandler (0) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (1) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (2) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (3) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (4) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (5) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (6) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (7) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (8) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (9) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (10) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (11) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (12) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (13) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (14) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (15) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (16) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (17) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (18) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (19) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (20) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (21) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (22) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (23) addr: 8881750023:55:47:421 0632 DetectCureTDL3: IrpHandler (24) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (25) addr: 804FA88E23:55:47:421 0632 DetectCureTDL3: IrpHandler (26) addr: 804FA88E23:55:47:421 0632 KLMD_ReadMem: Trying to ReadMemory 0xAFEE4F26[0x400]23:55:47:421 0632 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 023:55:47:421 0632 TDL3_FileDetect: Processing driver: USBSTOR23:55:47:421 0632 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS23:55:47:421 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS23:55:47:453 0632 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean23:55:47:453 0632 23:55:47:453 0632 DetectCureTDL3: DEVICE_OBJECT: 89A6B9F023:55:47:453 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89A6B9F023:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0x89A6B9F0[0x38]23:55:47:453 0632 DetectCureTDL3: DRIVER_OBJECT: 89B7894023:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0x89B78940[0xA8]23:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0xE1015968[0x18]23:55:47:453 0632 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk23:55:47:453 0632 DetectCureTDL3: IrpHandler (0) addr: F765DBB023:55:47:453 0632 DetectCureTDL3: IrpHandler (1) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (2) addr: F765DBB023:55:47:453 0632 DetectCureTDL3: IrpHandler (3) addr: F7657D1F23:55:47:453 0632 DetectCureTDL3: IrpHandler (4) addr: F7657D1F23:55:47:453 0632 DetectCureTDL3: IrpHandler (5) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (6) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (7) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (8) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (9) addr: F76582E223:55:47:453 0632 DetectCureTDL3: IrpHandler (10) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (11) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (12) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (13) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (14) addr: F76583BB23:55:47:453 0632 DetectCureTDL3: IrpHandler (15) addr: F765BF2823:55:47:453 0632 DetectCureTDL3: IrpHandler (16) addr: F76582E223:55:47:453 0632 DetectCureTDL3: IrpHandler (17) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (18) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (19) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (20) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (21) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (22) addr: F7659C8223:55:47:453 0632 DetectCureTDL3: IrpHandler (23) addr: F765E99E23:55:47:453 0632 DetectCureTDL3: IrpHandler (24) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (25) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (26) addr: 804FA88E23:55:47:453 0632 TDL3_FileDetect: Processing driver: Disk23:55:47:453 0632 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys23:55:47:453 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys23:55:47:453 0632 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean23:55:47:453 0632 23:55:47:453 0632 DetectCureTDL3: DEVICE_OBJECT: 89A809F023:55:47:453 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89A809F023:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0x89A809F0[0x38]23:55:47:453 0632 DetectCureTDL3: DRIVER_OBJECT: 89B7894023:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0x89B78940[0xA8]23:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0xE1015968[0x18]23:55:47:453 0632 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk23:55:47:453 0632 DetectCureTDL3: IrpHandler (0) addr: F765DBB023:55:47:453 0632 DetectCureTDL3: IrpHandler (1) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (2) addr: F765DBB023:55:47:453 0632 DetectCureTDL3: IrpHandler (3) addr: F7657D1F23:55:47:453 0632 DetectCureTDL3: IrpHandler (4) addr: F7657D1F23:55:47:453 0632 DetectCureTDL3: IrpHandler (5) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (6) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (7) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (8) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (9) addr: F76582E223:55:47:453 0632 DetectCureTDL3: IrpHandler (10) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (11) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (12) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (13) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (14) addr: F76583BB23:55:47:453 0632 DetectCureTDL3: IrpHandler (15) addr: F765BF2823:55:47:453 0632 DetectCureTDL3: IrpHandler (16) addr: F76582E223:55:47:453 0632 DetectCureTDL3: IrpHandler (17) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (18) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (19) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (20) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (21) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (22) addr: F7659C8223:55:47:453 0632 DetectCureTDL3: IrpHandler (23) addr: F765E99E23:55:47:453 0632 DetectCureTDL3: IrpHandler (24) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (25) addr: 804FA88E23:55:47:453 0632 DetectCureTDL3: IrpHandler (26) addr: 804FA88E23:55:47:453 0632 TDL3_FileDetect: Processing driver: Disk23:55:47:453 0632 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys23:55:47:453 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys23:55:47:453 0632 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean23:55:47:453 0632 23:55:47:453 0632 DetectCureTDL3: DEVICE_OBJECT: 89B77AB823:55:47:453 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89B77AB823:55:47:453 0632 DetectCureTDL3: DEVICE_OBJECT: 89B78A3823:55:47:453 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89B78A3823:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0x89B78A38[0x38]23:55:47:453 0632 DetectCureTDL3: DRIVER_OBJECT: 89B08A0823:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0x89B08A08[0xA8]23:55:47:453 0632 KLMD_ReadMem: Trying to ReadMemory 0xE1019D90[0x20]23:55:47:453 0632 DetectCureTDL3: DRIVER_OBJECT name: \Driver\viamraid, Driver Name: viamraid23:55:47:468 0632 DetectCureTDL3: IrpHandler (0) addr: 89C121F823:55:47:468 0632 DetectCureTDL3: IrpHandler (1) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (2) addr: 89C121F823:55:47:468 0632 DetectCureTDL3: IrpHandler (3) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (4) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (5) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (6) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (7) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (8) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (9) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (10) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (11) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (12) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (13) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (14) addr: 89C121F823:55:47:468 0632 DetectCureTDL3: IrpHandler (15) addr: 89C121F823:55:47:468 0632 DetectCureTDL3: IrpHandler (16) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (17) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (18) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (19) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (20) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (21) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (22) addr: 89C121F823:55:47:468 0632 DetectCureTDL3: IrpHandler (23) addr: 89C121F823:55:47:468 0632 DetectCureTDL3: IrpHandler (24) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (25) addr: 804FA88E23:55:47:468 0632 DetectCureTDL3: IrpHandler (26) addr: 804FA88E23:55:47:468 0632 KLMD_ReadMem: Trying to ReadMemory 0xF74C040E[0x400]23:55:47:468 0632 TDL3_StartIoHookDetect: CheckParameters: 1, F74C417C, 023:55:47:468 0632 TDL3_FileDetect: Processing driver: viamraid23:55:47:468 0632 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\viamraid.sys23:55:47:468 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\viamraid.sys23:55:47:484 0632 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\viamraid.sys - Verdict: Clean23:55:47:484 0632 23:55:47:484 0632 DetectCureTDL3: DEVICE_OBJECT: 89B7703023:55:47:484 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89B7703023:55:47:484 0632 DetectCureTDL3: DEVICE_OBJECT: 89B79A3823:55:47:484 0632 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89B79A3823:55:47:484 0632 KLMD_ReadMem: Trying to ReadMemory 0x89B79A38[0x38]23:55:47:484 0632 DetectCureTDL3: DRIVER_OBJECT: 89B08A0823:55:47:484 0632 KLMD_ReadMem: Trying to ReadMemory 0x89B08A08[0xA8]23:55:47:484 0632 KLMD_ReadMem: Trying to ReadMemory 0xE1019D90[0x20]23:55:47:484 0632 DetectCureTDL3: DRIVER_OBJECT name: \Driver\viamraid, Driver Name: viamraid23:55:47:484 0632 DetectCureTDL3: IrpHandler (0) addr: 89C121F823:55:47:484 0632 DetectCureTDL3: IrpHandler (1) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (2) addr: 89C121F823:55:47:484 0632 DetectCureTDL3: IrpHandler (3) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (4) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (5) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (6) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (7) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (8) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (9) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (10) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (11) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (12) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (13) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (14) addr: 89C121F823:55:47:484 0632 DetectCureTDL3: IrpHandler (15) addr: 89C121F823:55:47:484 0632 DetectCureTDL3: IrpHandler (16) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (17) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (18) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (19) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (20) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (21) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (22) addr: 89C121F823:55:47:484 0632 DetectCureTDL3: IrpHandler (23) addr: 89C121F823:55:47:484 0632 DetectCureTDL3: IrpHandler (24) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (25) addr: 804FA88E23:55:47:484 0632 DetectCureTDL3: IrpHandler (26) addr: 804FA88E23:55:47:484 0632 KLMD_ReadMem: Trying to ReadMemory 0xF74C040E[0x400]23:55:47:484 0632 TDL3_StartIoHookDetect: CheckParameters: 1, F74C417C, 023:55:47:484 0632 TDL3_FileDetect: Processing driver: viamraid23:55:47:484 0632 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\viamraid.sys23:55:47:484 0632 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\viamraid.sys23:55:47:500 0632 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\viamraid.sys - Verdict: Clean23:55:47:500 0632 23:55:47:500 0632 Completed23:55:47:500 0632 23:55:47:500 0632 Results:23:55:47:500 0632 Memory objects infected / cured / cured on reboot: 0 / 0 / 023:55:47:500 0632 Registry objects infected / cured / cured on reboot: 0 / 0 / 023:55:47:500 0632 File objects infected / cured / cured on reboot: 0 / 0 / 023:55:47:500 0632 23:55:47:500 0632 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.s
ys) returned status 0000000023:55:47:500 0632 UtilityDeinit: KLMD(ARK) unloaded successfully

2010-02-12 kl 07:59

har du installerat nåt prgram som heter prio?
kolla egenskaper på prio.dll om du kan få fram vilket företag den tillhör
stäng firefox och kör den här filen, posta logg
http://jpshortstuff.247fixes.com/GooredFix.exe
hur länge sedan startade detta problem?

2010-02-12 kl 08:21

jag installerade prio efter problemet uppstod. http://www.prnwatch.com/
så jag kan se vart processerna ligger. jag har haft problemet i 2veckor
ungefär.
GooredFix by jpshortstuff (08.01.10.1)Log created at 08:24 on 12/02/2010 (Niklas)Firefox version 3.5.7 (sv-SE)========== GooredScan ==================== GooredLog ==========C:\Program\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-32081
98ce6fd} [13:07 03/09/2009]C:\Documents and Settings\Niklas\Application Data\Mozilla\Firefox\Profiles\58r3wf7s.default\ex
tensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [19:38 03/02/2010][HKEY_LOCAL_MACHINE\Software\Mozilla\F
irefox\Extensions]"{20a82645-c095-46ed-80e3-088257
60534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Win
dows Presentation Foundation\DotNetAssistantExtension\" [01:52 15/08/2009]-=E.O.F=-

2010-02-12 kl 16:56

hittills så ser allt bra ut, kör combofix så får vi se vad som dyker upp
http://www.bleepingcomputer.com/combofix/se/hur-c
ombofix-ska-anvandas

2010-02-12 kl 18:01

ComboFix 10-02-11.04 - Niklas 2010-02-12 17:42:44.1.1 - x86Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.2047.1575 [GMT 1:00]Körs från: d:\documents and settings\Niklas\Mina dokument\Hämtade filer\ComboFix.exeAV: F-Secure Client Security 8.00 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}FW: F-Secure Client Security 8.00 *disabled* {D4747503-0346-49EB-9262-997542F79BF4} * Resident AV is activeVARNINIG -ÅTERSTÄLLNINGSKONSOLEN (THE RECOVERY CONSOLE) ÄR INTE INSTALLERAD PÅ DEN HÄR DATORN !!.(((((((((((((((((((((((( Filer Skapade från 2010-01-12 till 2010-02-12 )))))))))))))))))))))))))))))).2010-02-11 16:14 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2010-0
2-11 16:14 . 2010-02-11 16:14 -------- d-----w- c:\program\Malwarebytes' Anti-Malware2010-02-11 16:14 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys2010-02-11 02:03 . 2010-02-11 02:03 -------- d-sh--w- c:\documents and settings\Default User\IETldCache2010-02-08 21:22 . 2010-02-08 21:32 -------- d-----w- c:\program\Spybot - Search & Destroy2010-02-05 15:11 . 2010-02-05 15:12 -------- d-----w- c:\program\CCleaner2010-02-05 13:55 . 2010-02-05 13:55 -------- d-----w- c:\program\Prio2010-02-03 15:53 . 2010-02-11 02:22 -------- d-----w- c:\documents and settings\Niklas\Application Data\uTorrent2010-01-31 16:10 . 2010-01-31 16:10 52224 ----a-w- c:\documents and settings\Niklas\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS
\SD10005.dll2010-01-31 16:10 . 2010-02-06 09:30 117760 ----a-w- c:\documents and settings\Niklas\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS
\UIREPAIR.DLL2010-01-31 16:07 . 2010-01-31 16:07 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com2010-01-31 16:07 . 2010-01-31 16:07 -------- d-----w- c:\program\SUPERAntiSpyware2010-01-31 16:07 . 2010-01-31 16:07 -------- d-----w- c:\documents and settings\Niklas\Application Data\SUPERAntiSpyware.com2010-01-31 16:06 . 2010-01-31 16:06 -------- d-----w- c:\program\Delade filer\Wise Installation Wizard2010-01-31 10:49 . 2010-01-31 10:49 -------- d-----w- c:\documents and settings\Niklas\Application Data\Malwarebytes2010-01-31 10:49 . 2010-01-31 10:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes2010-01-30 12:52 . 2010-02-09 05:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy2010-01-29 20:25 . 2010-01-29 20:25 102400 --sha-r- c:\windows\system32\dmremote4.dll2010-01-24 10:11 . 2010-01-24 10:11 -------- d-----w- c:\documents and settings\LocalService\Skrivbord2010-01-24 09:48 . 2010-02-01 18:41 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}2010-0
1-24 09:48 . 2009-12-07 14:10 2953352 -c--a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-Aw
areInstallation.exe2010-01-24 09:46 . 2010-02-01 18:40 -------- d-----w- c:\program\Lavasoft2010-01-24 09:46 . 2010-02-01 18:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft.(((((((((((((((((((((((((((((((((((
((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))
)).2010-02-12 16:39 . 2009-09-23 09:05 -------- d-----w- c:\documents and settings\Niklas\Application Data\WTablet2010-02-12 16:37 . 2009-09-10 11:07 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet2010-02-12 16:36 . 2009-08-14 10:04 -------- d-----w- c:\documents and settings\Niklas\Application Data\vlc2010-02-12 07:51 . 2009-08-11 22:42 -------- d-----w- c:\documents and settings\Niklas\Application Data\U32010-02-12 05:50 . 2009-08-11 23:09 -------- d-----w- c:\program\F-Secure2010-02-11 02:22 . 2009-08-14 10:22 -------- d-----w- c:\documents and settings\Niklas\Application Data\BitTorrent2010-02-11 02:05 . 2009-09-30 16:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help2010-02-10 22:43 . 2009-08-17 18:51 -------- d-----w- c:\documents and settings\Niklas\Application Data\dvdcss2010-02-05 15:07 . 2009-12-29 13:05 -------- d-----w- c:\program\Delade filer\Apple2010-01-24 14:20 . 2009-10-08 10:46 -------- d-----w- c:\program\RegCure2010-01-21 11:33 . 2009-08-12 15:32 -------- d-----w- c:\program\Microsoft Silverlight2010-01-16 13:33 . 2009-12-29 13:12 -------- d-----w- c:\documents and settings\Niklas\Application Data\Apple Computer2009-12-31 16:50 . 2004-08-04 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys2009-12-29 14:33 . 2009-09-30 17:05 -------- d-----w- c:\program\Microsoft Works2009-12-29 13:15 . 2009-08-15 15:41 -------- d-----w- c:\documents and settings\Niklas\Application Data\Spotify2009-12-29 13:11 . 2009-12-29 13:09 -------- d-----w- c:\program\iTunes2009-12-29 13:11 . 2009-12-29 13:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}2009-1
2-29 13:10 . 2009-12-29 13:10 -------- d-----w- c:\program\iPod2009-12-29 13:09 . 2009-12-29 13:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer2009-12-29 13:09 . 2009-12-29 13:09 -------- d-----w- c:\program\Bonjour2009-12-29 13:09 . 2009-12-29 13:07 -------- d-----w- c:\program\QuickTime2009-12-29 13:07 . 2009-12-29 13:06 -------- d-----w- c:\program\Apple Software Update2009-12-29 13:05 . 2009-12-29 13:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple2009-12-21 19:09 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll2009-12-21 09:36 . 2009-09-01 19:06 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet2009-12-20 22:02 . 2009-12-20 22:02 -------- d-----w- c:\program\Delade filer\en-US2009-12-20 22:01 . 2009-12-20 22:01 -------- d-----w- c:\program\Delade filer\ja-JP2009-12-20 22:00 . 2009-08-18 16:14 -------- d-----w- c:\program\Delade filer\Autodesk Shared2009-12-20 22:00 . 2009-08-18 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk2009-12-20 21:54 . 2009-08-18 16:05 -------- d-----w- c:\program\Autodesk2009-12-18 15:54 . 2009-11-27 19:14 -------- d-----w- c:\program\hl2009-12-17 07:42 . 2009-08-11 21:37 343552 ----a-w- c:\windows\system32\mspaint.exe2009-12-14 07:10 . 2004-08-04 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll2009-12-12 06:36 . 2004-08-04 12:00 94678 ----a-w- c:\windows\system32\perfc01D.dat2009-12-12 06:36 . 2004-08-04 12:00 474574 ----a-w- c:\windows\system32\perfh01D.dat2009-12-09 10:11 . 2004-08-04 01:24 2066816 ----a-w- c:\windows\system32
tkrnlpa.exe2009-12-09 10:11 . 2004-08-04 12:00 2189952 ----a-w- c:\windows\system32
toskrnl.exe2009-12-04 18:22 . 2004-08-04 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys2009-11-27 17:14 . 2004-08-04 12:00 1293824 ----a-w- c:\windows\system32\quartz.dll2009-11-27 17:14 . 2004-08-04 01:33 17920 ----a-w- c:\windows\system32\msyuv.dll2009-11-27 16:10 . 2004-08-04 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll2009-11-27 16:10 . 2004-08-04 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll2009-11-27 16:10 . 2004-08-04 12:00 11264 ----a-w- c:\windows\system32\msrle32.dll2009-11-27 16:10 . 2004-08-04 01:33 48128 ----a-w- c:\windows\system32\iyuv_32.dll2009-11-27 16:10 . 2001-09-06 20:33 8704 ----a-w- c:\windows\system32\tsbyuv.dll2009-11-21 16:03 . 2004-08-04 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll2009-05-14 20:02 . 2009-05-14 20:02 3392872 ----a-w- c:\program\Delade filer\adlmint_libFNP.dll2009-05-14 20:02 . 2009-05-14 20:02 3298152 ----a-w- c:\program\Delade filer\adlmint.dll.(((((((((((((((((((((((((((((((
((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))..
*Not* Tomma poster & legitima standardposter visas inte. REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Run]"msnmsgr"="c:\program\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]"MSMSGS"="c:\program\Messenger\msmsgs.exe" [2008-04-14 1695232]"SUPERAntiSpyware"="c:\program\SUPERAntiSpywar
e\SUPERAntiSpyware.exe" [2010-01-05 2002160]"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Run]"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]"SunJavaUpdateSched"="c:\program\Java\jre1.5.0\b
in\jusched.exe" [2009-08-11 36972]"SynTPLpr"="c:\program\Synaptics\SynTP\SynTPLpr.
exe" [2005-03-18 98393]"SynTPEnh"="c:\program\Synaptics\SynTP\SynTPEnh.
exe" [2005-03-18 688217]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-01 7118848]"nwiz"="nwiz.exe" [2005-07-01 1519616]"F-Secure Manager"="c:\program\F-Secure\Common\FSM32.EXE" [2008-10-09 182936]"F-Secure TNB"="c:\program\F-Secure\FSGUI\TNBUtil.exe" [2008-10-09 1182304]"InstantOn"="c:\program\CyberLink\PowerCinema Linux\ion_install.exe" [2005-05-11 93640]"SoundMan"="SOUNDMAN.EXE" [2009-08-11 90112]"AlcWzrd"="ALCWZRD.EXE" [2009-08-11 2803712]"DAEMON Tools"="c:\program\DAEMON Tools\daemon.exe" [2005-11-08 128920]"Adobe Reader Speed Launcher"="c:\program\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]"AdobeCS4ServiceManager"="c:\program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.e
xe" [2008-08-14 611712]"GrooveMonitor"="c:\program\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]"QuickTime Task"="c:\program\QuickTime\QTTask.exe" [2009-11-10 417792]"iTunesHelper"="c:\program\iTunes\iTunesHelper.
exe" [2009-11-12 141600]c:\documents and settings\Niklas\Start-meny\Program\Autostart\Telia Mobilt bredband.lnk - c:\program\Telia\Telia_Mobilt_bredband\Telia_Mobilt
_bredband.exe [2009-5-14 2050048]c:\documents and settings\All Users\Start-meny\Program\Autostart\Windows Desktop Search.lnk - c:\program\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784][hkey_local_machine\software\microsoft\win
dows\currentversion\explorer\ShellExecuteHooks]"{5
6F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400][HKEY_LOCAL_MACHINE\software\microsoft\win
dows nt\currentversion\winlogon otify\!SASWinLogon]2009-09-03 13:21 548352 ----a-w- c:\program\SUPERAntiSpyware\SASWINLO.dll[HKLM\~\ser
vices\sharedaccess\parameters\firewallpolicy\stan
dardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\fir
ewallpolicy\standardprofile\AuthorizedApplication
s\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\
Network Diagnostic\\xpnetdiag.exe"="c:\\Program\\BitTorrent\\
bittorrent.exe"="c:\\Program\\Spotify\\spotify.exe"="c:\\
Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManage
r.exe"="c:\\Program\\Microsoft Office\\Office12\\OUTLOOK.EXE"="c:\\Program\\Microsoft Office\\Office12\\GROOVE.EXE"="c:\\Program\\Microsoft Office\\Office12\\ONENOTE.EXE"="c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program\\Messenger
\\msmsgs.exe"="c:\\Program\\Bonjour\\mDNSResponder.exe"
;="c:\\Program\\iTunes\\iTunes.exe"=[HKLM\~\services\
sharedaccess\parameters\firewallpolicy\standardpr
ofile\GloballyOpenPorts\List]"5353:TCP"= 5353:TCP:Adobe CSI CS4R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-08-12 33920]R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2009-08-12 79872]R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program\F-Secure\HIPS\drivers\fshs.sys [2009-08-12 66720]R1 prio;Prio;c:\windows\system32\drivers\prio.sys [2009-09-12 51448]R1 SASDIFSV;SASDIFSV;c:\program\SUPERAntiSpyware\sasdi
fsv.sys [2010-01-05 9968]R1 SASKUTIL;SASKUTIL;c:\program\SUPERAntiSpyware\SASKU
TIL.SYS [2010-01-05 74480]R2 TabletServicePen;TabletServicePen;c:\windows\system
32\Pen_Tablet.exe [2009-09-07 2749736]R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program\F-Secure\Anti-Virus\minifilte
r\fsgk.sys [2009-08-12 107104]R3 FSORSPClient;F-Secure ORSP Client;c:\program\F-Secure\ORSP Client\fsorsp.exe [2009-08-12 55904]R3 GTUHSBUS;GT UHS BUS;c:\windows\system32\drivers\gtuhsbus.sys [2009-02-04 63360]R3 GTUHSNDISIPXP;GT UHS IP NDIS;c:\windows\system32\drivers\gtuhs51.sys [2009-02-04 105856]R3 GTUHSSER;GT UHS SER;c:\windows\system32\drivers\gtuhsser.sys [2009-02-04 8064]S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-08-15 722416]S3 SASENUM;SASENUM;c:\program\SUPERAntiSpyware\SASENUM
.SYS [2010-01-05 7408]S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-09-07 15656]S4 F-Secure Filter;F-Secure File System Filter;c:\program\F-Secure\Anti-Virus\win2k\fsfilte
r.sys [2009-08-12 39776]S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program\F-Secure\Anti-Virus\win2k\fsr
ec.sys [2009-08-12 25184].Innehållet i mappen 'Schemalagda aktiviteter':2010-02-12 c:\windows\Tasks\RegCure Program Check.job- c:\program\RegCure\RegCure.exe [2007-08-02 10:47]2010-02-11 c:\windows\Tasks\RegCure.job- c:\program\RegCure\RegCure.exe [2007-08-02 10:47]2010-02-12 c:\windows\Tasks\User_Feed_Synchronization-{60A1D85
5-5A76-43B9-BC63-90C246284B64}.job- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]..------- Extra genomsökning -------.uInternet Settings,ProxyOverride = *.localIE: E&xportera till Microsoft Excel - c:\program\MI1933~1\Office12\EXCEL.EXE/3000LSP: c:\program\F-Secure\FSPS\program\FSLSP.DLLFF - ProfilePath - c:\documents and settings\Niklas\Application Data\Mozilla\Firefox\Profiles\58r3wf7s.default\FF - plugin: c:\program\Java\jre1.5.0\bin\NPJava11.dllFF - plugin: c:\program\Java\jre1.5.0\bin\NPJava12.dllFF - plugin: c:\program\Java\jre1.5.0\bin\NPJava13.dllFF - plugin: c:\program\Java\jre1.5.0\bin\NPJava14.dllFF - plugin: c:\program\Java\jre1.5.0\bin\NPJava32.dllFF - plugin: c:\program\Java\jre1.5.0\bin\NPJPI150.dllFF - plugin: c:\program\Java\jre1.5.0\bin\NPOJI610.dllFF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\---- FIREFOX POLICY ----c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");.- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-E
BB7F4A000DA} - (no file)AddRemove-uTorrent - j:\utorrent\uTorrent.exe***************************
***********************************************ca
tchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2010-02-12 17:50Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0************************************************
**************************.--------------------- LÅSTA REGISTERNYCKLAR ---------------------[HKEY_USERS\S-1-5-21-5159678
99-57989841-725345543-1005\Software\SecuROM\Licen
se information*]"datasecu"=hex:7d,46,98,21,d2,9b,cf,67
,ea,a2,25,8f,d0,5d,81,78,8a,3a,1d,65,5e, 18,8a,44,84,78,b4,3a,a1,dd,21,dd,37,9a,b5,58,ee,d
9,fb,3c,c4,42,81,e5,60,6c,\"rkeysecu"=hex:0f,fd,de,
2d,9d,a4,40,47,ce,d7,91,d6,db,c1,e1,f9.----------
----------- DLLer som "laddats" under processer som körs ---------------------- - - - - - - > 'winlogon.exe'(808)c:\program\SUPERAntiSpyware\SA
SWINLO.dllc:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll- - - - - - - > 'lsass.exe'(864)c:\program\F-Secure\FSPS\progra
m\FSLSP.DLL.Sluttid: 2010-02-12 17:54:58ComboFix-quarantined-files.txt 2010-02-12 16:54Före genomsökningen: 6 555 267 072 byte ledigtEfter genomsökningen: 6 580 432 896 byte ledigt- - End Of File - - F3B0241290D57A6218408A57DE6FAE94här är den loggen:

2010-02-12 kl 18:35

det man kan se av loggarna är att combofix hitta inget och att inga filer har tillkommit mellan 24 och 29:e förutom den här dll filen. efter 29:e har du installera spybot och sen malwarebytes så skicka upp den här filen till fuskbugg så ska jag försöka se vad det är för fil
c:\windows\system32\dmremote4.dll
sker ditt problem på legitma sidor, typ swedbank, telia, ginza osv?

2010-02-12 kl 21:39

den filen finns inte någonstans dessvärre :S problemet uppstår endast via goggle. Tack så mycket att du lägger ner tid att hjälpa mig btw. :D

2010-02-13 kl 00:04

den finns men du måste ha visning på dolda filer för att se den

2010-02-13 kl 12:03

ah vad dum jag va...

http://data.fuskbugg.se/skalman01/dmremote4.dll

2010-02-13 kl 12:26

kolla hur stor den är i din dator, den du skicka var 0 bytes så testa skicka upp filen igen.

2010-02-13 kl 13:10

provar ladda upp igen den ska vara 100kb http://data.fuskbugg.se/skalman01/-dmremote4.dll
den verkar bli 0byte varje gång har prövat 5 gånger

2010-02-13 kl 19:24

testa högerklicka och packa filen och se hur stor den blev då. då kan du ju skicka upp zip/rar filen

  • 19 svar
Avatar

Inte inloggad

Logga in Bli medlem

Läs mer

  • Senaste
  • Mest läst
  • Mest kommenterat

Kom in i diskussionen

Detta innehåll är skapat av PC Hemmas besökare

Test: HP Officejet 4500

1 kommentar

andy1n2: 695 kr är priset denna vecka i vår butik i lilla Köping

Forum

Detta innehåll är skapat av PC Hemmas medlemmar.

Tester

  • Senaste
  • Mest läst
  • Mest kommenterat

Artikelkommentarer


Egmont logo
© Egmont Tidskrifter