Spyware filer ødelægger min computer
Jeg har et stort stort problem med spyware.Jeg har før fået hjælp til at få fjernet spyware herinde, men det er desværre kommet igen.
Det er så slemt at jeg lige pt ikke er istand til at komme på nettet på min computer (derfor skriver jeg fra mit arbejde). Processeren kører hele tiden på 100%, der kommer irriterende links i foretrukne, startsiden til internetet ændres og i det hele taget tror jeg min computer er virkelig inficeret!
Sidste gang jeg fik hjælp kan jeg huske at jeg skulle lave en log fil i et program der hedder hijak. Så jeg har lavet et logfil her. Jeg ved dog ikke om jeg skulle have lavet den i fejlfri tilstand eller noget?
men her er den ihvertfald. ¨
Håber der er nogen der kan hjælpe mig med hvad jeg skal gøre. Der er ihvertfald 200 point til den der kan hjælpe da det er et kæmpe problem for mig.
Logfile of HijackThis v1.98.2
Scan saved at 07:32:03, on 07-02-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\windows\system\hpsysdrv.exe
C:\Programmer\VERITAS Software\Update Manager\sgtray.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programmer\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe
C:\WINDOWS\system32\xpsp2fw.exe
C:\WINDOWS\System32\tibs3.exe
C:\WINDOWS\system32\dptinfm.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\stisvsq.exe
C:\WINDOWS\svshost.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\msqdevl.exe
C:\WINDOWS\lssas.exe
C:\WINDOWS\mservice.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\DOCUME~1\Ejer\LOKALE~1\Temp\tmp4F.tmp
C:\DOCUME~1\Ejer\LOKALE~1\Temp\tmp59.tmp
C:\Documents and Settings\Ejer\Skrivebord\hijak\hijackthis.exe
C:\WINDOWS\System32\tmpf00.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\dload.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://realsearch.cc/?a=2&b=xyz
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://realsearch.cc/?a=2&b=xyz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://realsearch.cc/?a=2&b=xyz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://realsearch.cc/?a=2&b=xyz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://realsearch.cc/?b=xyz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://realsearch.cc/?a=2&b=xyz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://realsearch.cc/?a=2&b=xyz
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://realsearch.cc/?a=2&b=xyz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://realsearch.cc/?a=2&b=xyz
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://realsearch.cc/?a=2&b=xyz
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://realsearch.cc/?a=2&b=xyz
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = https://
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Programmer\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [WCOLOREAL] C:\Programmer\COMPAQ\Coloreal\coloreal.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Ulead Memory Card Detector] C:\Programmer\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe
O4 - HKLM\..\Run: [XPSP2 Firewall] C:\WINDOWS\system32\xpsp2fw.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKLM\..\Run: [16E557DE] C:\WINDOWS\system32\dptinfm.exe
O4 - HKLM\..\Run: [E2EDF90E] C:\WINDOWS\system32\ledatli.exe
O4 - HKLM\..\Run: [D162F8D3] C:\WINDOWS\system32\cledc42gnt.exe
O4 - HKLM\..\Run: [5AC90ACE] C:\WINDOWS\system32\iltpvc.exe
O4 - HKLM\..\Run: [C0AA0256] C:\WINDOWS\system32\sferew.exe
O4 - HKLM\..\Run: [EB40C86B] C:\WINDOWS\system32\rxyaptmp.exe
O4 - HKLM\..\Run: [DCADAE6E] C:\WINDOWS\system32\pacgnsr.exe
O4 - HKLM\..\Run: [DCADC876] C:\WINDOWS\system32\dsattiod.exe
O4 - HKLM\..\Run: [B6E51DF3] C:\WINDOWS\system32\dsllndm.exe
O4 - HKLM\..\Run: [8B6C58F6] C:\WINDOWS\system32\cimseadvp.exe
O4 - HKLM\..\Run: [8068FB73] C:\WINDOWS\system32\acsfrows.exe
O4 - HKLM\..\Run: [DF3A94D6] C:\WINDOWS\system32\cdertuid.exe
O4 - HKLM\..\Run: [FA28907E] C:\WINDOWS\system32\sncbmmres.exe
O4 - HKLM\..\Run: [E87250CE] C:\WINDOWS\system32\apisipcace.exe
O4 - HKLM\..\Run: [D9CCE74E] C:\WINDOWS\system32\edsesarevm.exe
O4 - HKLM\..\Run: [E3A286E3] C:\WINDOWS\system32\tmlc42.exe
O4 - HKLM\..\Run: [C5CDCA06] C:\WINDOWS\system32\apgntewm.exe
O4 - HKLM\..\Run: [A0D8CE4E] C:\WINDOWS\system32\ctiewm.exe
O4 - HKLM\..\Run: [8521DA4B] C:\WINDOWS\system32\diteamac.exe
O4 - HKLM\..\Run: [AD2CD1DE] C:\WINDOWS\system32\i32bdsld.exe
O4 - HKLM\..\Run: [AB4EA0CE] C:\WINDOWS\system32\trvicdfv.exe
O4 - HKLM\..\Run: [D9835D43] C:\WINDOWS\system32\cluitml.exe
O4 - HKLM\..\Run: [8B9CFCCE] C:\WINDOWS\system32\extdlfrgr.exe
O4 - HKLM\..\Run: [D3C93F6E] C:\WINDOWS\system32\o4ctxp.exe
O4 - HKLM\..\Run: [A82D99D3] C:\WINDOWS\system32\svidtmg.exe
O4 - HKLM\..\Run: [8CFBCA56] C:\WINDOWS\system32\acmime.exe
O4 - HKLM\..\Run: [DEB73886] C:\WINDOWS\system32\fatdi.exe
O4 - HKLM\..\Run: [D1F52083] C:\WINDOWS\system32\aaabo.exe
O4 - HKLM\..\Run: [8846BB4E] C:\WINDOWS\system32\ldpackvifi.exe
O4 - HKLM\..\Run: [CC02DF4B] C:\WINDOWS\system32\cmcpnmo.exe
O4 - HKLM\..\Run: [F0A80E4B] C:\WINDOWS\system32\sfervi.exe
O4 - HKLM\..\Run: [E6D90253] C:\WINDOWS\system32\cluitr.exe
O4 - HKLM\..\Run: [D0EECBCB] C:\WINDOWS\system32\metepst.exe
O4 - HKLM\..\Run: [A418DCF6] C:\WINDOWS\system32\luimse.exe
O4 - HKLM\..\Run: [40AA9A76] C:\WINDOWS\system32\dbmpbk.exe
O4 - HKLM\..\Run: [BE99E186] C:\WINDOWS\system32\amouthp32.exe
O4 - HKLM\..\Run: [FA2C94DB] C:\WINDOWS\system32\cluwsew.exe
O4 - HKLM\..\Run: [50BBDA8E] C:\WINDOWS\system32\licopromm.exe
O4 - HKLM\..\Run: [1EE8A5DE] C:\WINDOWS\system32\bfeuidlcscu.exe
O4 - HKLM\..\Run: [BEBA41F6] C:\WINDOWS\system32\if3dlepv.exe
O4 - HKLM\..\Run: [AFDA005E] C:\WINDOWS\system32\p32oma.exe
O4 - HKLM\..\Run: [ABA2E68E] C:\WINDOWS\system32\bvcfsys.exe
O4 - HKLM\..\Run: [F0470B06] C:\WINDOWS\system32\ootXc32.exe
O4 - HKLM\..\Run: [8F28D206] C:\WINDOWS\system32\ipinpt.exe
O4 - HKLM\..\Run: [CC799A06] C:\WINDOWS\system32\cfgCPAco.exe
O4 - HKLM\..\Run: [57D96F7E] C:\WINDOWS\system32\dsnacefil.exe
O4 - HKLM\..\Run: [B4AE925E] C:\WINDOWS\system32\erroutod.exe
O4 - HKLM\..\Run: [CE6A5EE6] C:\WINDOWS\system32\svcsnesf.exe
O4 - HKLM\..\Run: [F6898666] C:\WINDOWS\system32\etresctl.exe
O4 - HKLM\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
O4 - HKLM\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKLM\..\Run: [Games Acceleration] svshost.exe
O4 - HKLM\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKLM\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKLM\..\Run: [Multimedia extensions] mservice.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows Update Client ] C:\WINDOWS\system32\wuclient.exe
O4 - HKCU\..\Run: [16E557DE] C:\WINDOWS\system32\dptinfm.exe
O4 - HKCU\..\Run: [E2EDF90E] C:\WINDOWS\system32\ledatli.exe
O4 - HKCU\..\Run: [D162F8D3] C:\WINDOWS\system32\cledc42gnt.exe
O4 - HKCU\..\Run: [5AC90ACE] C:\WINDOWS\system32\iltpvc.exe
O4 - HKCU\..\Run: [C0AA0256] C:\WINDOWS\system32\sferew.exe
O4 - HKCU\..\Run: [EB40C86B] C:\WINDOWS\system32\rxyaptmp.exe
O4 - HKCU\..\Run: [DCADAE6E] C:\WINDOWS\system32\pacgnsr.exe
O4 - HKCU\..\Run: [DCADC876] C:\WINDOWS\system32\dsattiod.exe
O4 - HKCU\..\Run: [B6E51DF3] C:\WINDOWS\system32\dsllndm.exe
O4 - HKCU\..\Run: [8B6C58F6] C:\WINDOWS\system32\cimseadvp.exe
O4 - HKCU\..\Run: [8068FB73] C:\WINDOWS\system32\acsfrows.exe
O4 - HKCU\..\Run: [DF3A94D6] C:\WINDOWS\system32\cdertuid.exe
O4 - HKCU\..\Run: [FA28907E] C:\WINDOWS\system32\sncbmmres.exe
O4 - HKCU\..\Run: [E87250CE] C:\WINDOWS\system32\apisipcace.exe
O4 - HKCU\..\Run: [D9CCE74E] C:\WINDOWS\system32\edsesarevm.exe
O4 - HKCU\..\Run: [E3A286E3] C:\WINDOWS\system32\tmlc42.exe
O4 - HKCU\..\Run: [C5CDCA06] C:\WINDOWS\system32\apgntewm.exe
O4 - HKCU\..\Run: [A0D8CE4E] C:\WINDOWS\system32\ctiewm.exe
O4 - HKCU\..\Run: [8521DA4B] C:\WINDOWS\system32\diteamac.exe
O4 - HKCU\..\Run: [AD2CD1DE] C:\WINDOWS\system32\i32bdsld.exe
O4 - HKCU\..\Run: [AB4EA0CE] C:\WINDOWS\system32\trvicdfv.exe
O4 - HKCU\..\Run: [D9835D43] C:\WINDOWS\system32\cluitml.exe
O4 - HKCU\..\Run: [8B9CFCCE] C:\WINDOWS\system32\extdlfrgr.exe
O4 - HKCU\..\Run: [D3C93F6E] C:\WINDOWS\system32\o4ctxp.exe
O4 - HKCU\..\Run: [A82D99D3] C:\WINDOWS\system32\svidtmg.exe
O4 - HKCU\..\Run: [8CFBCA56] C:\WINDOWS\system32\acmime.exe
O4 - HKCU\..\Run: [DEB73886] C:\WINDOWS\system32\fatdi.exe
O4 - HKCU\..\Run: [D1F52083] C:\WINDOWS\system32\aaabo.exe
O4 - HKCU\..\Run: [8846BB4E] C:\WINDOWS\system32\ldpackvifi.exe
O4 - HKCU\..\Run: [CC02DF4B] C:\WINDOWS\system32\cmcpnmo.exe
O4 - HKCU\..\Run: [F0A80E4B] C:\WINDOWS\system32\sfervi.exe
O4 - HKCU\..\Run: [E6D90253] C:\WINDOWS\system32\cluitr.exe
O4 - HKCU\..\Run: [D0EECBCB] C:\WINDOWS\system32\metepst.exe
O4 - HKCU\..\Run: [A418DCF6] C:\WINDOWS\system32\luimse.exe
O4 - HKCU\..\Run: [40AA9A76] C:\WINDOWS\system32\dbmpbk.exe
O4 - HKCU\..\Run: [BE99E186] C:\WINDOWS\system32\amouthp32.exe
O4 - HKCU\..\Run: [FA2C94DB] C:\WINDOWS\system32\cluwsew.exe
O4 - HKCU\..\Run: [50BBDA8E] C:\WINDOWS\system32\licopromm.exe
O4 - HKCU\..\Run: [1EE8A5DE] C:\WINDOWS\system32\bfeuidlcscu.exe
O4 - HKCU\..\Run: [BEBA41F6] C:\WINDOWS\system32\if3dlepv.exe
O4 - HKCU\..\Run: [AFDA005E] C:\WINDOWS\system32\p32oma.exe
O4 - HKCU\..\Run: [ABA2E68E] C:\WINDOWS\system32\bvcfsys.exe
O4 - HKCU\..\Run: [F0470B06] C:\WINDOWS\system32\ootXc32.exe
O4 - HKCU\..\Run: [8F28D206] C:\WINDOWS\system32\ipinpt.exe
O4 - HKCU\..\Run: [CC799A06] C:\WINDOWS\system32\cfgCPAco.exe
O4 - HKCU\..\Run: [57D96F7E] C:\WINDOWS\system32\dsnacefil.exe
O4 - HKCU\..\Run: [B4AE925E] C:\WINDOWS\system32\erroutod.exe
O4 - HKCU\..\Run: [CE6A5EE6] C:\WINDOWS\system32\svcsnesf.exe
O4 - HKCU\..\Run: [F6898666] C:\WINDOWS\system32\etresctl.exe
O4 - HKCU\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
O4 - HKCU\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKCU\..\Run: [Games Acceleration] svshost.exe
O4 - HKCU\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKCU\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKCU\..\Run: [Multimedia extensions] mservice.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O4 - Startup: winupdate30501296[1].exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmer\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmer\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {D799B0E4-BEDE-41d2-AEE0-1E3A1C4EF918} - C:\Programmer\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe (HKCU)
O9 - Extra 'Tools' menuitem: IE Privacy Keeper - {D799B0E4-BEDE-41d2-AEE0-1E3A1C4EF918} - C:\Programmer\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe (HKCU)
O15 - Trusted Zone: http://*.69sexsearch.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - https://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O21 - SSODL: MSMserv - {FDE60093-ABF2-4DEB-9633-4C7040D06D86} - C:\WINDOWS\System32\wshetils.dll