2008-11-26, 22:37
#1
Jaa vad underbart.
Suttit flera j*vla timmar idag och rensat bort skit, och fick det att fungera fram tills nu.
Nu dyker dom dr helvetes jvla popupsidorna upp igen som fr tankarna till Smitfraud.
Har krt senaste uppdatering utav adaware, superantispyware, Malwarebytes' Anti-malware och gud vet vad.
Postar en log frn Smitfraudfix, det kanske r till ngon hjlp. Tillggas br att jag INTE r en nolla med datorer men det hr r fan fr mycket!
Suttit flera j*vla timmar idag och rensat bort skit, och fick det att fungera fram tills nu.
Nu dyker dom dr helvetes jvla popupsidorna upp igen som fr tankarna till Smitfraud.
Har krt senaste uppdatering utav adaware, superantispyware, Malwarebytes' Anti-malware och gud vet vad.
Postar en log frn Smitfraudfix, det kanske r till ngon hjlp. Tillggas br att jag INTE r en nolla med datorer men det hr r fan fr mycket!
Citat:
SmitFraudFix v2.378
Scan done at 22:31:53,82, 2008-11-26
Run from C:\Documents and Settings\Jani\Skrivbord\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\Program\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\DNA\btdna.exe
C:\Program\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\MSN Messenger\msnmsgr.exe
C:\Program\mIRC\mirc.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Winamp\winampa.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Jani\Skrivbord\SmitfraudFix\Policies.exe
C:\WINDOWS\System32\cmd.exe
hosts
C:\
C:\WINDOWS
C:\WINDOWS\system
C:\WINDOWS\Web
C:\WINDOWS\system32
C:\Documents and Settings\Jani
C:\DOCUME~1\Jani\LOKALA~1\Temp
C:\Documents and Settings\Jani\Application Data
Start Menu
C:\DOCUME~1\Jani\FAVORI~1
Desktop
C:\Program
Corrupted keys
Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="about:Home"
"SubscribedURL"="about:Home"
"FriendlyName"="Min aktuella startsida"
o4Patch
!!!Attention, following keys are not inevitably infected!!!
o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri
IEDFix
!!!Attention, following keys are not inevitably infected!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
404Fix
!!!Attention, following keys are not inevitably infected!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"
[HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\fudarepe.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3F D-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\fudarepe.dll"
AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="dvwlpt.dll C:\\WINDOWS\\System32\\kefuguhi.dll c:\\windows\\system32\\besenije.dll c:\\windows\\system32\\kazarige.dll c:\\windows\\system32\\fudarepe.dll"
"LoadAppInit_DLLs"=dword:00000001
Winlogon
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.ex e,"
"System"=""
RK
DNS
Description: Realtek RTL8139 Family PCI Fast Ethernet NIC - Miniport fr paketschemalggning
DNS Server Search Order: 78.108.48.35
DNS Server Search Order: 212.112.166.18
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9528A886-DD03-44DC-BC46-7C287EF1EE1F}: DhcpNameServer=78.108.48.35 212.112.166.18
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9528A886-DD03-44DC-BC46-7C287EF1EE1F}: DhcpNameServer=78.108.48.35 212.112.166.18
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=78.108.48.35 212.112.166.18
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=78.108.48.35 212.112.166.18
Scanning for wininet.dll infection
End
Scan done at 22:31:53,82, 2008-11-26
Run from C:\Documents and Settings\Jani\Skrivbord\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\Program\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\DNA\btdna.exe
C:\Program\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\MSN Messenger\msnmsgr.exe
C:\Program\mIRC\mirc.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Winamp\winampa.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Jani\Skrivbord\SmitfraudFix\Policies.exe
C:\WINDOWS\System32\cmd.exe
hosts
C:\
C:\WINDOWS
C:\WINDOWS\system
C:\WINDOWS\Web
C:\WINDOWS\system32
C:\Documents and Settings\Jani
C:\DOCUME~1\Jani\LOKALA~1\Temp
C:\Documents and Settings\Jani\Application Data
Start Menu
C:\DOCUME~1\Jani\FAVORI~1
Desktop
C:\Program
Corrupted keys
Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="about:Home"
"SubscribedURL"="about:Home"
"FriendlyName"="Min aktuella startsida"
o4Patch
!!!Attention, following keys are not inevitably infected!!!
o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri
IEDFix
!!!Attention, following keys are not inevitably infected!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
404Fix
!!!Attention, following keys are not inevitably infected!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"
[HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\fudarepe.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3F D-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\fudarepe.dll"
AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="dvwlpt.dll C:\\WINDOWS\\System32\\kefuguhi.dll c:\\windows\\system32\\besenije.dll c:\\windows\\system32\\kazarige.dll c:\\windows\\system32\\fudarepe.dll"
"LoadAppInit_DLLs"=dword:00000001
Winlogon
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.ex e,"
"System"=""
RK
DNS
Description: Realtek RTL8139 Family PCI Fast Ethernet NIC - Miniport fr paketschemalggning
DNS Server Search Order: 78.108.48.35
DNS Server Search Order: 212.112.166.18
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9528A886-DD03-44DC-BC46-7C287EF1EE1F}: DhcpNameServer=78.108.48.35 212.112.166.18
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9528A886-DD03-44DC-BC46-7C287EF1EE1F}: DhcpNameServer=78.108.48.35 212.112.166.18
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=78.108.48.35 212.112.166.18
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=78.108.48.35 212.112.166.18
Scanning for wininet.dll infection
End