Avatar billede tizian Nybegynder
25. december 2005 - 17:42 Der er 8 kommentarer og
2 løsninger

Virus (timessquare.exe?)

Hej!

Forleden dag var jeg så uheldig at downloade noget software der indeholdt virus. (Tro dog ikke at jeg kørte den uden at scanne for virus, det gjorde jeg nemlig, men Avast AntiVirus fik ikke bid...)
Avast begyndte med det samme jeg havde åbnet filen at rapportere virusaktivitet og jeg prøvede desperat at stoppe processen osv.
Det hjalp ikke, og selv efter gentagne boot-scans osv troede jeg den var væk, men ak, et par gange om dagen kommer antivirussen op med meddelelse om virusforekomster.

Jeg installerede Spybot - Search and Destroy, som da også fjernede en masse adware osv, men intet hjalp det.

Nu har jeg så installeret en trial af ZoneLabs store sikkerhedspakke med firewall, antivirus, anti-spyware og jeg-skal-gi'-dig-ska'-jeg. Selvom jeg scanner både i fejlsikret tilstand og i boot (og finder virus) bliver den ved med at være der.

Jeg er gentagne gange stødt på processen timessquare.exe, både i Windows Jobliste, hijackthis osv., så jeg har en mistanke om at det kan have noget med virussen at gøre.

Min computer er en Windows XP SP2, nu både med Zonelabs Security Suite, Avast Antivirus og Spybot - Search and Destroy.

Hvordan får jeg fjernet virussen?

På forhånd tusind tak!
Philip

P.S. Er der noget med at i skal bruge en hijackthis rapport? Så sig endelig til.
Avatar billede arlet Juniormester
25. december 2005 - 18:09 #1
Hent nyeste version af hijackthis(1.99.1) herfra : http://www.arlet.dk/hjt.htm
Avatar billede tizian Nybegynder
25. december 2005 - 20:23 #2
Logfile of HijackThis v1.99.1
Scan saved at 20:23:17, on 25-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\spil\Steam\Steam.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\DOCUMENTS AND SETTINGS\PHILIP\SKRIVEBORD\hjt.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] C:\spil\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sysvcs.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131478698090
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37490.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\system32\msctl32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede tizian Nybegynder
25. december 2005 - 20:56 #4
Jo, men det hjælper mig ikke med at fjerne den...
25. december 2005 - 21:03 #5
<arlet> kommer tilbage og siger/skriver de bevingede ord...
Avatar billede arlet Juniormester
25. december 2005 - 21:53 #6
Download og gem disse scanner på skrivebordet:

Mwav: http://www.spywareinfo.dk/download/mwav.exe
(men lad være med at scanne endnu).

-----

Ewido: http://www.ewido.net/en/download/
Klik på Download now. Installer og kør Ewido. Opdater straks efter installationen programmet, (men lad være med at scanne endnu).

Du skal nu til at i gang med at fixe:

Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.
Dobbelttjek, så alt kommer med.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sysvcs.exe

O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\system32\msctl32.dll (file missing)

--------------------------------------------------------------------

Åbn en tilfældig mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

------------------------------

Hent denne bats fil og kør den :
http://www.spywareinfo.dk/download/cleantempxp2k.bat
den sletter alt i din temp mappe.

------------------------------

Genstart computeren i fejlsikret tilstand(Du skal klikke på f8 tasten under genstarten (ca. lige når der er talt ram), og så vælge fejlsikret tilstand. Er du i tvivl, så klik bare på f8 flere gange.)
Find og slet disse manuelt :

C:\WINDOWS\system32\sysvcs.exe

------

Kør nu en fuld scanning med Ewido. Når den er færdig trykker du save report og gemmer rapporten.

-----

Klik på mwav.exe som du hentede, programmet pakker sig selv ud og starter.
Sæt flueben i følgende:
Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende:
All local drives og Scan all files. Klik på scan clean. Når scanneren er færdig med at scanne, så kopier indholdet af vinduet "Virus Log Information" herind (marker det, og tast ctrl-c)

-----

Begge rapporter kopier du herind sammen med en ny hijackthis taget efter du har kørt de 2 scannere
Avatar billede tizian Nybegynder
26. december 2005 - 10:43 #7
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            23:53:25, 25-12-2005
+ Rapport-Checksum:        720EBC69

+ Scanningsresultat:
    HKLM\SOFTWARE\Classes\.s3d -> Spyware.BrilliantDigital : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Renset med backup
    HKLM\SOFTWARE\PSGuard.com -> Spyware.PSGuard : Fejl under renselse
    HKLM\SOFTWARE\PSGuard.com\PSGuard -> Spyware.PSGuard : Fejl under renselse
    HKLM\SOFTWARE\PSGuard.com\PSGuard\P.S.Guard -> Spyware.PSGuard : Fejl under renselse
    HKLM\SOFTWARE\PSGuard.com\PSGuard\P.S.Guard\License -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Far & Hanne\Cookies\far & hanne@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\Far & Hanne\Cookies\far & hanne@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\Far & Hanne\Cookies\far & hanne@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.9:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.11:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Doubleclick : Renset med backup
    :mozilla.12:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.22:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Com : Renset med backup
    :mozilla.24:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Com : Renset med backup
    :mozilla.27:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Atdmt : Renset med backup
    :mozilla.31:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Fastclick : Renset med backup
    :mozilla.32:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Fastclick : Renset med backup
    :mozilla.33:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Fastclick : Renset med backup
    :mozilla.51:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.57:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Mediaplex : Renset med backup
    :mozilla.80:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Onestat : Renset med backup
    :mozilla.81:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Onestat : Renset med backup
    :mozilla.82:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Onestat : Renset med backup
    :mozilla.83:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Onestat : Renset med backup
    :mozilla.84:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Onestat : Renset med backup
    :mozilla.106:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Renset med backup
    :mozilla.109:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.110:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.111:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.112:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.114:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.115:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Questionmarket : Renset med backup
    :mozilla.116:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Questionmarket : Renset med backup
    :mozilla.124:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.125:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.126:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.154:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.155:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.156:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.166:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.167:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.168:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.169:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.170:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.171:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.172:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.173:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.174:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.175:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.176:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.177:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.184:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Valueclick : Renset med backup
    :mozilla.185:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Valueclick : Renset med backup
    :mozilla.187:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.188:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.189:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.190:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.191:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.192:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.193:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.194:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.195:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.215:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Ru4 : Renset med backup
    :mozilla.217:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Ru4 : Renset med backup
    :mozilla.227:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Euroclick : Renset med backup
    :mozilla.228:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Euroclick : Renset med backup
    :mozilla.229:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Euroclick : Renset med backup
    :mozilla.242:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Spylog : Renset med backup
    :mozilla.243:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Renset med backup
    :mozilla.244:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Overture : Renset med backup
    :mozilla.245:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Overture : Renset med backup
    :mozilla.257:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.258:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.259:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.260:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.279:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Burstnet : Renset med backup
    :mozilla.281:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Burstnet : Renset med backup
    :mozilla.283:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Adserver : Renset med backup
    :mozilla.284:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Adserver : Renset med backup
    :mozilla.285:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Adserver : Renset med backup
    :mozilla.287:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.288:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.289:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.290:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.291:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.298:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.304:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Renset med backup
    :mozilla.325:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.326:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.327:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.328:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.329:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.330:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.331:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.332:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.344:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Revenue : Renset med backup
    :mozilla.387:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Pointroll : Renset med backup
    :mozilla.388:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Pointroll : Renset med backup
    :mozilla.389:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Pointroll : Renset med backup
    :mozilla.390:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Pointroll : Renset med backup
    :mozilla.398:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.415:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Bfast : Renset med backup
    :mozilla.419:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.420:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.421:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.422:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.435:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Targetnet : Renset med backup
    :mozilla.436:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.437:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.438:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.439:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.440:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.515:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.516:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.540:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Liveperson : Renset med backup
    :mozilla.541:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Liveperson : Renset med backup
    :mozilla.552:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.553:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.608:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Trafic : Renset med backup
    :mozilla.625:C:\Documents and Settings\Philip\Application Data\Mozilla\Firefox\Profiles\t0377nv7.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\HKCURun -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\HKCURun\RunOnce -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\HKCURun\RunOnceEx -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\HKLMRun -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\HKLMRun\RunOnce -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\HKLMRun\RunOnceEx -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\StartMenuAllUsers -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\Autorun\StartMenuCurrentUser -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Application Data\PSGuard.com\P.S.Guard\BrowserObjects -> Spyware.PSGuard : Renset med backup
    C:\Documents and Settings\Philip\Cookies\philip@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Philip\Cookies\philip@as-eu.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\Philip\Cookies\philip@microsoftwga.112.2o7[1].txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\Philip\Cookies\philip@sel.as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\Philip\Cookies\philip@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\Philip\Cookies\philip@web2.realtracker[2].txt -> Spyware.Cookie.Realtracker : Renset med backup
    :mozilla.23:C:\Documents and Settings\Sophine\Application Data\Mozilla\Firefox\Profiles\rcpkr7a0.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@2o7[2].txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@advertising[2].txt -> Spyware.Cookie.Advertising : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@atdmt[2].txt -> Spyware.Cookie.Atdmt : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@fastclick[2].txt -> Spyware.Cookie.Fastclick : Renset med backup
    C:\Documents and Settings\Sophine\Cookies\sophine@web2.realtracker[2].txt -> Spyware.Cookie.Realtracker : Renset med backup
    C:\WINDOWS\country.exe.tcf -> Trojan.Small : Renset med backup
    C:\WINDOWS\kl.exe -> Logger.Small.eg : Renset med backup


::Rapport slut


-------------------------------------


File C:\WINDOWS\system32\oleext.dll infected by "Trojan.Win32.Small.ev" Virus. Action Taken: File Deleted.
File C:\RECYCLER\S-1-5-21-220523388-1682526488-682003330-1004\Dc178.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
File C:\System Volume Information\_restore{726EBF34-74AE-478A-BE01-8F60209C288D}\RP89\A0010652.exe infected by "Trojan.Win32.Small.ev" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{726EBF34-74AE-478A-BE01-8F60209C288D}\RP89\A0010654.exe infected by "Trojan-Downloader.Win32.Small.vu" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{726EBF34-74AE-478A-BE01-8F60209C288D}\RP90\A0013687.exe infected by "Trojan-Proxy.Win32.Small.di" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{726EBF34-74AE-478A-BE01-8F60209C288D}\RP96\A0014157.dll infected by "Trojan.Win32.Small.ev" Virus. Action Taken: File Deleted.


-----------------------------


Logfile of HijackThis v1.99.1
Scan saved at 10:40:50, on 26-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\Programmer\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\spil\Steam\Steam.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
c:\Programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\Philip\Skrivebord\hjt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Programmer\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] C:\spil\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131478698090
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37490.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



Ser det godt ud? :D
Avatar billede arlet Juniormester
26. december 2005 - 11:09 #8
Ja, det ser godt ud.

Så er din log ren.

Efter sådan en tur er det altid en god ide og rydde op i dine systemgendannelses filerne.
Deaktiver systemgendannelse ( http://www.arlet.dk/systemgendannelsen.htm ) - genstart din computer - aktiver systemgendannelse.

Generel oprydning: http://www.arlet.dk/oprydning.htm

For at beskytte dig mod snavs har jeg lavet en sikkerhedspakke,
som du kan se her : www.arlet.dk/pakke.htm
Avatar billede tizian Nybegynder
26. december 2005 - 13:03 #9
Det har du styr på kan jeg godt fornemme :)
Avatar billede arlet Juniormester
26. december 2005 - 13:05 #10
Jeg har prøvet det en gang eller 2 før*S*
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester