Avatar billede monyt Nybegynder
13. december 2005 - 21:33 Der er 18 kommentarer og
1 løsning

WININET.DLL crash

har fået en trojansk hest ind der cracher min Wininet.dll fil hele tiden og der gør at jeg ikke kan åbne nogle programmer men hvordan fjærner jeg den uden at geninstalere
Avatar billede monyt Nybegynder
13. december 2005 - 21:37 #1
jeg kan ikke bruge nogle .exe filer
Avatar billede halvamatoer Nybegynder
13. december 2005 - 21:38 #2
Kan du kører Hijackthis i fejlsikker.
www.exp.dk/artikler/755 - hvis ja som kom med en log
Avatar billede monyt Nybegynder
13. december 2005 - 21:41 #3
Logfile of HijackThis v1.99.1
Scan saved at 21:41:45, on 13-12-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\wlmsn.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\monty\Desktop\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ati.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Updaterd] SVCHOSTE.EXE
O4 - HKLM\..\Run: [RAMBooster.Net] D:\Program Files\RAMBooster.Net\RAMBooster.exe -m
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [norten Software Intrenet ] norten.pif
O4 - HKLM\..\Run: [Sygate Personal Firewall] t1ktik.exe
O4 - HKLM\..\Run: [REGEDIT] C:\DOCUME~1\monty\LOCALS~1\Temp\IXP000.TMP\zlip3.exe
O4 - HKLM\..\Run: [SECRETSERVICE] C:\Program Files\MSN Messenger\1033\test\c4nn0t.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AdobeReaderPro] googlex.exe
O4 - HKLM\..\Run: [VoiceMaskPro] "C:\Program Files\VoiceMaskPro\Voicemaskpro.exe"
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O4 - HKLM\..\Run: [Windows live Support] wlmsn.exe
O4 - HKLM\..\RunServices: [ivr] winupdate.exe
O4 - HKLM\..\RunServices: [Updaterd] SVCHOSTE.EXE
O4 - HKLM\..\RunServices: [AdobeReaderPro] googlex.exe
O4 - HKLM\..\RunServices: [Windows live Support] wlmsn.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add to &Teleport - C:\Program Files\Teleport Pro\teleport.htm
O23 - Service: ivr (a3x) - Unknown owner - C:\WINDOWS\System32\winupdate.exe" -service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Avatar billede halvamatoer Nybegynder
13. december 2005 - 22:11 #4
Vi prøver lige med et triks:
fix følgende:
O4 - HKLM\..\Run: [Updaterd] SVCHOSTE.EXE

O4 - HKLM\..\Run: [REGEDIT] C:\DOCUME~1\monty\LOCALS~1\Temp\IXP000.TMP\zlip3.exe
O4 - HKLM\..\Run: [SECRETSERVICE] C:\Program Files\MSN Messenger\1033\test\c4nn0t.exe
O4 - HKLM\..\Run: [AdobeReaderPro] googlex.exe

O4 - HKLM\..\RunServices: [ivr] winupdate.exe
O4 - HKLM\..\RunServices: [Updaterd] SVCHOSTE.EXE
O4 - HKLM\..\RunServices: [AdobeReaderPro] googlex.exe

Genstart i normal og lad os se om du ikke kan starte den op og give en ny HTJ-log
Avatar billede monyt Nybegynder
13. december 2005 - 22:36 #5
Logfile of HijackThis v1.99.1
Scan saved at 22:35:19, on 13-12-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\intell32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\LVComsX.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Documents and Settings\monty\Desktop\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ati.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [norten Software Intrenet ] norten.pif
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O4 - HKLM\..\RunServices: [Windows live Support] wlmsn.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add to &Teleport - C:\Program Files\Teleport Pro\teleport.htm
O23 - Service: ivr (a3x) - Unknown owner - C:\WINDOWS\System32\winupdate.exe" -service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe



det virker stadig ikke...  :(
Avatar billede halvamatoer Nybegynder
13. december 2005 - 23:38 #6
finder lige en ven
Avatar billede fromsej Praktikant
14. december 2005 - 16:18 #7
1. Hent og dobbeltklik på smitRem.exe

http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

Programmet pakker sig ud til mappen smitRem.

2. Hent Ad-aware

http://spywarefri.dk/vaerktoj.htm#ad-aware

Installer programmet, start det og opdater online, du skal IKKE scanne endnu.
Indstil Ad-Aware efter denne vejledning:
http://www.spywarefri.dk/manualer/adaware-manual.htm
Luk Ad-Aware igen.

3. Hent Ewido:

http://www.spywarefri.dk/downloads1/ewido-setup.exe

Installer og kør Ewido - Opdater straks efter installationen programmet (men lad være med at scanne endnu).

4. Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:

http://fromsej.dk/html/xpfejl.html

5. Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på "Fix checked":

O4 - HKLM\..\Run: [norten Software Intrenet ] norten.pif
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O4 - HKLM\..\RunServices: [Windows live Support] wlmsn.exe


6. Åbn mappen smitRem,  og dobbeltklik på RunThis.bat (Følg vejledningen i vinduet.)

7. Kør en fuld scanning med Ad-Aware, fjern alt det finder.

8. Kør en fuld scanning med Ewido. Programmet laver en lille log, som du skal kopiere herind.

9. Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".
Brug af Start->Søg.
Klik på "Skift søgefunktioner for filer og mapper"
Sæt prik i "Avanceret" og klik OK.
Klik på "Alle filer og mapper"
Klik på "Flere avancerede indstillinger"
Sæt flueben i de tre øverste.
C:\WINDOWS\System32\intell32.exe
C:\WINDOWS\System32\wlmsn.exe
norten.pif

10. Genstart almindeligt, kør denne onlinescanner:

http://www.pandasoftware.com/activescan/activescan.asp?Language=2&Country=63&Partner=1&Ref=EN-PR-AS-107 , (sæt den til Automatic removal).

11. Genstart og kom med en frisk Hijackthislog, samt loggen fra Ewido. Find smitfiles.txt via Start/Søg. Kopier også denne log ind.
Avatar billede monyt Nybegynder
14. december 2005 - 17:04 #8
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            16:55:17, 14-12-2005
+ Report-Checksum:        F5730338

+ Scan result:

    HKLM\SOFTWARE\Classes\WUSN.1 -> Spyware.SaveNow : Cleaned with backup
    :mozilla.6:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.9:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.10:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.24:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.30:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.31:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.32:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.33:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.34:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.44:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.53:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.54:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.55:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.56:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.57:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.58:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.59:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.62:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.63:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.64:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.79:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    :mozilla.81:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.82:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.83:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.84:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.85:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.86:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.87:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.88:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.89:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.90:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.91:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.92:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.93:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.96:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.97:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.98:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.100:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.101:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.102:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.103:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.105:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.106:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.107:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.122:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Itrack : Cleaned with backup
    :mozilla.162:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.163:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.164:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.165:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.166:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.174:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
    :mozilla.175:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
    :mozilla.191:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
    :mozilla.216:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.232:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.233:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.234:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.235:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.257:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    :mozilla.258:C:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\5hkv8m1n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@dbbsrv[1].txt -> Spyware.Cookie.Dbbsrv : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@spylog[1].txt -> Spyware.Cookie.Spylog : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@weborama[1].txt -> Spyware.Cookie.Weborama : Cleaned with backup
    C:\Documents and Settings\monty\Cookies\monty@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
    C:\Program Files\MSN Messenger\1033\test\v1r3 -> Backdoor.IRC.Mox.a : Cleaned with backup
    C:\Program Files\MSN Messenger\1033\test\x -> Worm.Randon.aa : Cleaned with backup
    C:\Program Files\Save -> Spyware.SaveNow : Cleaned with backup
    C:\Program Files\Save\SaveUninst.exe -> Spyware.SaveNow : Cleaned with backup
    C:\WINDOWS\loadclean.exe -> Dropper.Paradrop.a : Cleaned with backup
    C:\WINDOWS\system32\c.bat -> Backdoor.BotGet.FtpA : Cleaned with backup
    C:\WINDOWS\system32\cmd32.exe -> Dropper.Paradrop.a : Cleaned with backup
    C:\WINDOWS\system32\dial32.exe -> Trojan.Dialer.ay : Cleaned with backup
    C:\WINDOWS\system32\sh.EXE/zlip1.cpl -> Backdoor.Flood.ay : Cleaned with backup
    C:\WINDOWS\system32\sh.EXE/zlip1.cpl -> Backdoor.Flood.ay : Cleaned with backup
    C:\WINDOWS\system32\wlmsn.exe -> Heuristic.Win32.Backdoor.IrcBot : Cleaned with backup
    D:\WINDOWS\system32\exdl.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\exdl0.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\exul.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\javexulm.vxd -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\msbe.dll -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\exdl1.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\exul1.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\WINDOWS\system32\mqexdlm.srg -> Spyware.BargainBuddy : Cleaned with backup
    D:\Documents and Settings\monty\Local Settings\Temp\uninstall.exe -> Spyware.SurfAccuracy : Cleaned with backup
    D:\Documents and Settings\monty\My Documents\Modtagne filer\BuzZ_Hook_v1.7.rar/BuzZ_Hook_v1.7\Buzz.exe -> Trojan.Agent.JZ : Cleaned with backup
    D:\Documents and Settings\monty\Desktop\ns hax\Buzz.exe -> Trojan.Agent.JZ : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@xxxcounter[1].txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@counter4.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@counter3.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@cz8.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@www.sidefind[2].txt -> Spyware.Cookie.Sidefind : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@ehg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@adtech[1].txt -> Spyware.Cookie.Adtech : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@adopt.euroclick[2].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@microsofteup.112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@trafic[1].txt -> Spyware.Cookie.Trafic : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    D:\Documents and Settings\monty\Cookies\monty@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
    :mozilla.30:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
    :mozilla.32:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.33:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.34:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.35:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.36:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.37:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.38:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.44:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.45:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.46:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.47:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.48:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.49:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.50:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.51:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.52:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
    :mozilla.54:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
    :mozilla.55:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
    :mozilla.56:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.57:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.68:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup
    :mozilla.74:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    :mozilla.79:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.102:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
    :mozilla.104:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.105:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.106:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.107:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.124:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
    :mozilla.125:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
    :mozilla.130:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    :mozilla.131:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.138:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.139:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.140:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.141:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.142:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.143:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.144:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.145:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
    :mozilla.146:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
    :mozilla.150:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.153:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
    :mozilla.176:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
    :mozilla.177:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
    :mozilla.196:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.197:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.202:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    :mozilla.206:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    :mozilla.207:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    :mozilla.217:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.218:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    :mozilla.219:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    :mozilla.220:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.223:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.224:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.225:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.226:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.227:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.229:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.230:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.231:D:\Documents and Settings\monty\Application Data\Mozilla\Firefox\Profiles\twi7qhmv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    D:\Program Files\BullsEye Network\bin\bargains.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\Program Files\BullsEye Network\bin\adv.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\Program Files\BullsEye Network\bin\adx.exe -> Spyware.BargainBuddy : Cleaned with backup
    D:\Program Files\SideFind\sfbho.dll -> Spyware.SideFind : Cleaned with backup
    D:\Program Files\SideFind\sidefind.dll -> Spyware.SideFind : Cleaned with backup


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 17:04:27, on 14-12-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\LVComsX.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Winamp\Winamp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\monty\Desktop\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ati.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Add to &Teleport - C:\Program Files\Teleport Pro\teleport.htm
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
Avatar billede halvamatoer Nybegynder
14. december 2005 - 17:12 #9
øh! hvordan kom I uden om kan ikke køre .exe filer?
Avatar billede monyt Nybegynder
14. december 2005 - 17:51 #10
kan køre nogle enklte .. men ikke særlig mange ... så det er lidt fucked ved ikke hvorfor... tror jeg er oppe på 3 filer... Ewido og HJT og firefox
Avatar billede fromsej Praktikant
14. december 2005 - 18:51 #11
Download denne fil:
http://www.kellys-korner-xp.com/regs_edits/exefix.reg
Dobbeltklik på filen og svar ja til at "merge" filen i registreringsdatabasen.
Genstart og se om der er nogle ændringer i dit problem.
Avatar billede monyt Nybegynder
14. december 2005 - 18:58 #12
linket virker ikke... det er bare en siden med en masse data i.. men ikke nogen fil
Avatar billede monyt Nybegynder
14. december 2005 - 19:13 #13
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[HKEY_CLASSES_ROOT\.exe\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"

[HKEY_CLASSES_ROOT\exefile]
@="Application"
"EditFlags"=hex:38,07,00,00
"TileInfo"="prop:FileDescription;Company;FileVersion"
"InfoTip"="prop:FileDescription;Company;FileVersion;Create;Size"

[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@="%1"

[HKEY_CLASSES_ROOT\exefile\shell]

[HKEY_CLASSES_ROOT\exefile\shell\open]
"EditFlags"=hex:00,00,00,00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\runas]

[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shellex]

[HKEY_CLASSES_ROOT\exefile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers]

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PEAnalyser]
@="{09A63660-16F9-11d0-B1DF-004F56001CA7}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PifProps]
@="{86F19A00-42A0-1069-A2E9-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page]
@="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"

[HKEY_CLASSES_ROOT\regfile]
@="Registration Entries"
"EditFlags"=dword:00100000
"BrowserFlags"=dword:00000008

[HKEY_CLASSES_ROOT\regfile\DefaultIcon]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
  00,5c,00,72,00,65,00,67,00,65,00,64,00,69,00,74,00,2e,00,65,00,78,00,65,00,\
  2c,00,31,00,00,00

[HKEY_CLASSES_ROOT\regfile\shell]
@="open"

[HKEY_CLASSES_ROOT\regfile\shell\edit]

[HKEY_CLASSES_ROOT\regfile\shell\edit\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
  00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4e,00,4f,00,\
  54,00,45,00,50,00,41,00,44,00,2e,00,45,00,58,00,45,00,20,00,25,00,31,00,00,\
  00

[HKEY_CLASSES_ROOT\regfile\shell\open]
@="Mer&ge"

[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\""

[HKEY_CLASSES_ROOT\regfile\shell\print]

[HKEY_CLASSES_ROOT\regfile\shell\print\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
  00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4e,00,4f,00,\
  54,00,45,00,50,00,41,00,44,00,2e,00,45,00,58,00,45,00,20,00,2f,00,70,00,20,\
  00,25,00,31,00,00,00

[HKEY_CLASSES_ROOT\.lnk]
@="lnkfile"

[HKEY_CLASSES_ROOT\.lnk\ShellEx]

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{000214EE-0000-0000-C000-000000000046}]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{000214F9-0000-0000-C000-000000000046}]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{00021500-0000-0000-C000-000000000046}]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellNew]
"Command"="rundll32.exe appwiz.cpl,NewLinkHere %1"

[HKEY_CLASSES_ROOT\lnkfile]
@="Shortcut"
"EditFlags"=dword:00000001
"IsShortcut"=""
"NeverShowExt"=""

[HKEY_CLASSES_ROOT\lnkfile\CLSID]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\lnkfile\shellex]

[HKEY_CLASSES_ROOT\lnkfile\shellex\ContextMenuHandlers]

[HKEY_CLASSES_ROOT\lnkfile\shellex\ContextMenuHandlers\Offline Files]
@="{750fdf0e-2a26-11d1-a3ea-080036587f03}"

[HKEY_CLASSES_ROOT\lnkfile\shellex\ContextMenuHandlers\{00021401-0000-0000-C000-000000000046}]

[HKEY_CLASSES_ROOT\lnkfile\shellex\DropHandler]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\lnkfile\shellex\IconHandler]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\lnkfile\shellex\PropertySheetHandlers]

[HKEY_CLASSES_ROOT\lnkfile\shellex\PropertySheetHandlers\ShimLayer Property Page]
@="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}]
@="Shortcut"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32]
@="shell32.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\PersistentAddinsRegistered]

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\PersistentAddinsRegistered\{89BCB740-6119-101A-BCB7-00DD010655AF}]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\PersistentHandler]
@="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID]
@="lnkfile"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\shellex]

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\shellex\MayChangeDefaultMenu]



hvad skal jeg gøre med den
Avatar billede fromsej Praktikant
14. december 2005 - 19:30 #14
Prøv at højreklikke på linket i stedet for og vælg at gemme filen.
Jeg overså at du ikke bruger IE.
Avatar billede monyt Nybegynder
14. december 2005 - 19:50 #15
okay... har genstartet efter den blev registretet men det hjalp ikke den siger statig at :  ...
  This application has failed to start because Wininet.dll was not found. re-installing the application  max fix this problem
Avatar billede fromsej Praktikant
14. december 2005 - 20:09 #16
Så er der nok kun Repair tilbage.
http://hcma.dk/tips1to10.htm#no4
Avatar billede monyt Nybegynder
14. december 2005 - 20:10 #17
tror jeg bliver nød til at formatere... desværre :( ... men tak for hjælpen... smid et svar... så du kan få dine velfortjænte points
Avatar billede fromsej Praktikant
14. december 2005 - 21:01 #18
Sådan går det desværre en gang imellem.

For undgå noget lignende kan du kigge på vores pakke til formålet.
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm
Som minimum anbefaler jeg Spywareguard, Spywareblaster, IE-Spyad og IE Privacy Keeper.
Samt selvfølgelig et godt Antivirus og en Firewall.
Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
http://fromsej.dk/html/avoid.html
Mvh:
Fromsej/Team Spywarefri.
Avatar billede fromsej Praktikant
14. december 2005 - 23:38 #19
Tak for point.*S*
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester