Hej igen eksperter. Jeg takker for den hurtige respons på mit spørgsmål som det vist også gik lidt for hurtigt med at få oprettet. Jeg glemte at smide logfilerne med. Her kommer de så inclusive en hijackthis.
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 355760
Infected objects found: 2
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 34
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 4
Objects cured: 0
Objects deleted: 2
Objects renamed: 38
Objects moved: 0
Objects ignored: 0
Scan speed: 138 Kb/s
Scan time: 03:46:04
ewido anti-malware - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 06:42:35, 07-03-2006
+ Rapport-Checksum: 247E2335
+ Scanningsresultat:
[768] C:\WINDOWS\system32\cqmpstui.dll -> Adware.Look2Me : Fejl under renselse
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Dokumenter\eDonkey2000 Downloads\Nero 7.0 Premium with keygen.rar/Nero 7.0 Premium\setup.exe -> Trojan.KillAV.ft : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temp\install\Setup.exe -> Worm.VB.dw : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temp\temp.fr1EF7\zangohoo0.#ll -> Adware.180Solutions : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temp\temp.fr1EF7\zango__0.#xe -> Adware.180Solutions : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\69XUVI5O\gimmygames9[1].exe -> Downloader.VB.ww : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\7AC3JXOH\winsysupd9[1].exe -> Downloader.VB.wy : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\ED0JEHUX\AppWrap[1].#xe -> Adware.Zestyfind : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\ED0JEHUX\AppWrap[2].#xe -> Adware.AdURL : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\ED0JEHUX\ucmoreiex[1].#xe/UCMTSAIE.DLL -> Adware.Ucmore : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\ED0JEHUX\ucmoreiex[1].#xe/IUCMORE.DLL -> Adware.Ucmore : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\K1QB0DU7\drsmartload[1].exe -> Downloader.VB.wr : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\KD2B8DI3\winsysban9[1].exe -> Hijacker.VB.ld : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\SLAR096Z\AppWrap[1].#xe -> Adware.AdURL : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\SLAR096Z\stub_113_4_0_4_0[1].#xe -> Downloader.TSUpdate.o : Renset med backup
C:\Documents and Settings\Bjarne Schack.BJARNE-KONTORET\Lokale indstillinger\Temporary Internet Files\Content.IE5\Y3URY1UJ\Installer[1].#xe -> Adware.Look2Me : Renset med backup
C:\drsmartload1.exe -> Downloader.VB.wr : Renset med backup
C:\gimmygames9.exe -> Downloader.VB.ww : Renset med backup
C:\Programmer\outlook\outlook.exe -> Worm.VB.dw : Renset med backup
C:\Programmer\outlook\p.zip/Setup.exe -> Worm.VB.dw : Renset med backup
C:\Programmer\outlook\v.tmp -> Worm.VB.dw : Renset med backup
C:\WINDOWS\Downloaded Program Files\cssweb.#ll -> Adware.CSSWeb : Renset med backup
C:\WINDOWS\gimmygames9.exe -> Downloader.VB.ww : Renset med backup
C:\WINDOWS\pgtun__0.#xe -> Adware.180Solutions : Renset med backup
C:\WINDOWS\system32\astr.exe -> Downloader.VB.na : Renset med backup
C:\WINDOWS\system32\cqmpstui.#ll -> Adware.Look2Me : Renset med backup
C:\WINDOWS\system32\cshbe.exe -> Downloader.Agent.uj : Renset med backup
C:\WINDOWS\system32\favset.exe -> Trojan.Favadd.an : Renset med backup
C:\WINDOWS\system32\im.#xe -> Not-A-Virus.PSWTool.Win32.Messen.103 : Renset med backup
C:\WINDOWS\system32\ir80l5lm1.#ll -> Adware.Look2Me : Renset med backup
C:\WINDOWS\system32\k4nole531h.#ll -> Adware.Look2Me : Renset med backup
C:\WINDOWS\system32\mowsock.#ll -> Adware.Look2Me : Renset med backup
C:\WINDOWS\system32\n8r2li9o18.#ll -> Adware.Look2Me : Renset med backup
C:\WINDOWS\system32\ps.exe -> Dropper.Agent.mf : Renset med backup
C:\WINDOWS\system32\pwha.#xe -> Not-A-Virus.PSWTool.Win32.PassView.162 : Renset med backup
C:\WINDOWS\system32\winlog.exe -> Backdoor.Rbot : Renset med backup
C:\WINDOWS\Temp\bw2.#om -> Adware.AdURL : Fejl under renselse
C:\WINDOWS\Temp\Cookies\bjarne schack@2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
C:\WINDOWS\Temp\Cookies\bjarne schack@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset med backup
C:\WINDOWS\Temp\Cookies\bjarne schack@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Renset med backup
C:\WINDOWS\Temp\Cookies\bjarne schack@h.starware[2].txt -> TrackingCookie.Starware : Renset med backup
C:\WINDOWS\Temp\Cookies\bjarne schack@overture[1].txt -> TrackingCookie.Overture : Renset med backup
C:\WINDOWS\Temp\Cookies\bjarne schack@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Renset med backup
C:\WINDOWS\Temp\Cookies\bjarne schack@www.starware[1].txt -> TrackingCookie.Starware : Renset med backup
C:\WINDOWS\Temp\Cookies\bjarne schack@zedo[1].txt -> TrackingCookie.Zedo : Renset med backup
C:\WINDOWS\winsysban9.exe -> Hijacker.VB.ld : Renset med backup
C:\WINDOWS\winsysupd9.exe -> Downloader.VB.wy : Renset med backup
D:\Programmer\Fælles filer\GMT\EGIEProces0.#ll -> Adware.Gator : Renset med backup
E:\Bjarne Schack\Winrar.3.30.Final.DK.Dansk.Danish.incl.Keygen.crack.vejledning.rar/WinRAR_v3.30_KeyGen.exe -> Hijacker.StartPage.sv : Renset med backup
::Rapport slut
Logfile of HijackThis v1.99.1
Scan saved at 18:23:00, on 07-03-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Antivirusprogrammer\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmer\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programmer\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Programmer\Brother\Brmfl03a\BrStDvPt.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\system32\idemlog.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SmartUI.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone:
http://*.billingnow.comO15 - Trusted Zone: *.danskebank.dk
O15 - Trusted Zone:
http://*.reliablestats.comO15 - Trusted Zone:
http://*.winantispyware.comO15 - Trusted Zone:
http://*.winantivirus.comO15 - Trusted Zone:
http://*.winantiviruspro.comO15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone:
http://*.winfixer.comO15 - Trusted Zone:
http://*.winnanny.comO15 - Trusted Zone:
http://*.winsoftware.comO16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.games.yahoo.com/games/web_games/popcap/chuzzle/popcaploader_v6.cabO18 - Protocol: pcl - {182D0C85-206F-4103-B4FA-DCC1FB0A0A44} - C:\Programmer\Autodesk\Inventor Professional 8\bin\HSPCLPRO10.dll
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\k2800clmefqa0.dll
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PavPrSrv - Unknown owner - (no file)
O23 - Service: PAVSRV - Unknown owner - (no file)
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe