Avatar billede alex_h_jensen Nybegynder
06. april 2006 - 19:51 Der er 7 kommentarer og
2 løsninger

Check af logfiler

Hej, (igen) så er den gal igen. Er der en der vil checke denne  logfil?


På forhånd tak.
Alex H. Jensen
Avatar billede alex_h_jensen Nybegynder
06. april 2006 - 19:52 #1
Logfile of HijackThis v1.99.1
Scan saved at 19:48:47, on 06-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Billionton\Bluetooth Software\bin\btwdins.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\VM_STI.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\MuchTV\tvrmvcr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10MT2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10RN2.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\SAGENT4.EXE
C:\Programmer\Fælles filer\EPSON\eEBAPI\eEBSVC.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {F210FD83-EBFB-FC54-A31C-9B8D35F1C351} - WinInitDll.dll (file missing)
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\rzuse.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\rzuse.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [exe.dtxmd] C:\WINDOWS\system32\dmxtd.exe
O4 - HKLM\..\Run: [NopeZ] barint.exe
O4 - HKLM\..\Run: [control64] Testimonials.exe
O4 - HKLM\..\Run: [exe.gbhmd] C:\WINDOWS\system32\dmhbg.exe
O4 - HKLM\..\Run: [ccApp] C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P23 "EPSON Stylus C86 Series" /M "Stylus C86" /EF "HKCU"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [sound64] media64.exe
O4 - HKCU\..\Run: [uio] typeconf.exe
O4 - HKCU\..\Run: [NukeSpan] prgsys0984.exe
O4 - Global Startup: MuchTV Remote.lnk = ?
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Programmer\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Programmer\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Programmer\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Programmer\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A63B9D5-9313-453E-9028-5607348B5468}: NameServer = 85.255.114.108,85.255.112.143
O17 - HKLM\System\CCS\Services\Tcpip\..\{86C894F6-A92D-476A-932D-C7900BEA9A9F}: NameServer = 85.255.114.108,85.255.112.143
O17 - HKLM\System\CCS\Services\Tcpip\..\{B381D39C-17E5-4343-8979-43C6A0E33F79}: NameServer = 85.255.114.108,85.255.112.143
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A63B9D5-9313-453E-9028-5607348B5468}: NameServer = 85.255.114.108,85.255.112.143
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Programmer\Billionton\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - Unknown owner - C:\Programmer\Fælles filer\EPSON\eEBAPI\SAgent2.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
Avatar billede ejvindh Ekspert
06. april 2006 - 19:57 #2
Jeg kigger på det :-)
Avatar billede ejvindh Ekspert
06. april 2006 - 20:03 #3
Under dette fix vil computeren blive genstartet, og du bør derfor printe vejledningen ud, for at have den ved din side under hele fixet. Fixet skal bruge adgang til internettet, så det skal du sikre dig, at der er.

-- Hent Ewido herfra (14 dages version af plus-versionen)
http://www.spywarefri.dk/downloads1/ewido-setup.exe
Installer og kør Ewido - opdater programmet.

-- Hent FixWareout fra et af disse links:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

-- Gem filen på dit Skrivebord og dobbeltklik på den. Klik Next -> Install og check, at der er et flueben i "Run fixit" - klik herefter på Finish. Fixet vil nu starte, og du skal blot følge instruktionerne. Du vil blive bedt om at genstarte din computer - gør venligst det. Genstarten vil tage lidt længere tid end normalt...

-- Når dit system genstarter skal du fortsat følge den vejledning, der gives på skærmen. Når fixet er færdigt vil der åbnes en log (report.txt), som du skal gemme og lægge herind i næste post.

-- Kør herefter HijackThis - klik på "Do a systemscan only", og sæt et flueben ud for følgende linier - luk øvrige programvinduer - klik "Fix checked":

R3 - URLSearchHook: (no name) - {F210FD83-EBFB-FC54-A31C-9B8D35F1C351} - WinInitDll.dll (file missing)
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\rzuse.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\rzuse.dll
O4 - HKLM\..\Run: [exe.dtxmd] C:\WINDOWS\system32\dmxtd.exe
O4 - HKLM\..\Run: [NopeZ] barint.exe
O4 - HKLM\..\Run: [control64] Testimonials.exe
O4 - HKLM\..\Run: [exe.gbhmd] C:\WINDOWS\system32\dmhbg.exe
O4 - HKCU\..\Run: [sound64] media64.exe
O4 - HKCU\..\Run: [uio] typeconf.exe
O4 - HKCU\..\Run: [NukeSpan] prgsys0984.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A63B9D5-9313-453E-9028-5607348B5468}: NameServer = 85.255.114.108,85.255.112.143
O17 - HKLM\System\CCS\Services\Tcpip\..\{86C894F6-A92D-476A-932D-C7900BEA9A9F}: NameServer = 85.255.114.108,85.255.112.143
O17 - HKLM\System\CCS\Services\Tcpip\..\{B381D39C-17E5-4343-8979-43C6A0E33F79}: NameServer = 85.255.114.108,85.255.112.143
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A63B9D5-9313-453E-9028-5607348B5468}: NameServer = 85.255.114.108,85.255.112.143

-- Genstart til fejlsikret (tryk på <F8> under opstarten).

-- Kør en fuld scanning med Ewido, og lad den slette det, den finder. Programmet laver en lille log, som du skal kopiere herind i dit næste svar.

-- Luk HJT. Genstart din computer, og kopier indholdet af C:\fixwareout\report.txt herind sammen med en frisk HijackThis log.
Avatar billede alex_h_jensen Nybegynder
06. april 2006 - 22:47 #4
Så er det klaret. Jeg kom lige i tanke om hvorfor det tog et par dage sidst. *S* Her er logfilen og filen fra ewido:

Logfile of HijackThis v1.99.1
Scan saved at 22:46:28, on 06-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\VM_STI.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Billionton\Bluetooth Software\bin\btwdins.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\MuchTV\tvrmvcr.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [exe.lxsmd] C:\WINDOWS\system32\dmsxl.exe
O4 - HKLM\..\Run: [ccApp] C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P23 "EPSON Stylus C86 Series" /M "Stylus C86" /EF "HKCU"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: MuchTV Remote.lnk = ?
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Programmer\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Programmer\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Programmer\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Programmer\AutoCAD 2002\AcPreview.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Programmer\Billionton\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - Unknown owner - C:\Programmer\Fælles filer\EPSON\eEBAPI\SAgent2.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

og
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            22:39:04, 06-04-2006
+ Rapport-Checksum:        F1FB3783

+ Scanningsresultat:
    HKLM\SOFTWARE\Classes\CLSID\{04FC5C29-73C6-99FE-9568-2D6316E0DB4F} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{065A3DF4-4253-B880-16A3-75DA427DD453} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{085D8F6F-6EF0-7151-03BD-8923F318C4F4} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2CCE5B81-6D28-8A8F-02CA-6ED9C85DE395} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2DAD5652-3FF5-FF26-8446-2EE69A7D486A} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{367621ED-3460-6D3E-460F-EF17F9AEAF1C} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{38676255-FF52-44C8-27F2-446E092C177F} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{3F196571-8AE3-1455-9565-1D33F6C41C58} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{46F83DE2-4037-83D3-C38B-C0E3BBEF1FAA} -> Adware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{49D9C3D0-94CC-611C-83AF-233BCD1C07C4} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{4B5BB1BE-21E9-F573-F231-873433F3AC38} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{5C0B625D-8487-3C7F-C960-F3F287636C8B} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{67C3D253-86E0-3455-99E5-3DD535E435E7} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{6A69821F-18F4-B763-5240-1F762A039561} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{6BA13B87-DA76-DCBF-8B9F-C13DA50A9571} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{6F2EB59A-6F50-8B14-0D7D-BCC43DC7177A} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{6F61BA9A-5EA1-7903-5454-DCA081431490} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{7336446D-6302-31A5-850C-92DCAEABD49C} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{7B4A1389-49FB-707C-A673-D7AF81767AD4} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{7E72EF25-4095-D844-4224-B322BFBF6B06} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{7FDF9C3E-86C5-8A37-1FB0-CAF34B57433C} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{819572E4-6450-CDDE-7A95-4EE8A0DE2F1B} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{833C2A45-D78C-FBD9-4797-2BF8F49B3F3F} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{8516B14C-A215-9B6D-EB6E-7283E8A2619A} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{983D1105-2366-D1D5-E5DA-05F4CC5CDA8E} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{9D99EF1B-BA68-5875-41C6-4CA3C3742635} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{AC9850C2-11A3-C5E4-FF97-6BE07B32010F} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{CD982133-C8CB-ADFC-ECDA-3AFE92ABDA8E} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{D4BBFCAF-3F30-7E69-4762-58A3BA736796} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{DB29A986-131A-F212-4C89-18F9E42C205A} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{E0563D13-F3FE-E98C-6537-41C8EEC36A67} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{E6226C29-4068-EB26-B869-9B4C7E50B3E9} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{EA0DFCB9-7E1F-F294-C21E-B815C236819B} -> Adware.CoolWebSearch : Renset uden backup
    HKLM\SOFTWARE\Classes\CLSID\{EDCEAC15-AF3E-C5F1-8804-D0FCA512F9C1} -> Adware.CoolWebSearch : Renset uden backup
    C:\WINDOWS\SYSTEM32\dfrgsrv.exe -> Trojan.Small : Renset uden backup
    C:\WINDOWS\SYSTEM32\rzuse.dll -> Adware.SBSoft : Renset uden backup
    C:\WINDOWS\SYSTEM32\howiper.exe -> Trojan.Small.gq : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@valueclick[1].txt -> TrackingCookie.Valueclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@c.enhance[1].txt -> TrackingCookie.Enhance : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@doubleclick[1].txt -> TrackingCookie.Doubleclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@c.goclick[2].txt -> TrackingCookie.Goclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cs.sexcounter[1].txt -> TrackingCookie.Sexcounter : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@image.masterstats[1].txt -> TrackingCookie.Masterstats : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter5.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter8.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@hotlog[1].txt -> TrackingCookie.Hotlog : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@adtech[2].txt -> TrackingCookie.Adtech : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@com[2].txt -> TrackingCookie.Com : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@servedby.advertising[1].txt -> TrackingCookie.Advertising : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@spylog[1].txt -> TrackingCookie.Spylog : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@atdmt[2].txt -> TrackingCookie.Atdmt : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sexlist[2].txt -> TrackingCookie.Sexlist : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@2o7[1].txt -> TrackingCookie.2o7 : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@statcounter[1].txt -> TrackingCookie.Statcounter : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter15.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter14.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@hitbox[2].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@tacoda[1].txt -> TrackingCookie.Tacoda : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@vip2.clickzs[2].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter16.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@yadro[2].txt -> TrackingCookie.Yadro : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@hitbox[1].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@advertising[1].txt -> TrackingCookie.Advertising : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ehg-console.hitbox[1].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@zedo[2].txt -> TrackingCookie.Zedo : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@targetnet[2].txt -> TrackingCookie.Targetnet : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter2.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@trafficmp[1].txt -> TrackingCookie.Trafficmp : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter12.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ilead.itrack[2].txt -> TrackingCookie.Itrack : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@perf.overture[1].txt -> TrackingCookie.Overture : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter6.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ehg-hitent.hitbox[1].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@questionmarket[1].txt -> TrackingCookie.Questionmarket : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@overture[2].txt -> TrackingCookie.Overture : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@linksynergy[1].txt -> TrackingCookie.Linksynergy : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@fastclick[1].txt -> TrackingCookie.Fastclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sel.as-eu.falkag[2].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz5.clickzs[2].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@estat[1].txt -> TrackingCookie.Estat : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sextracker[3].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@vip.clickzs[2].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz8.clickzs[2].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter3.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@paycounter[2].txt -> TrackingCookie.Paycounter : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter11.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz7.clickzs[1].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@c.goclick[3].txt -> TrackingCookie.Goclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@c.enhance[3].txt -> TrackingCookie.Enhance : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@z1.adserver[1].txt -> TrackingCookie.Adserver : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@serving-sys[1].txt -> TrackingCookie.Serving-sys : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz11.clickzs[2].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sel.as-eu.falkag[1].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz9.clickzs[2].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@www.belstat[2].txt -> TrackingCookie.Belstat : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@as1.falkag[2].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter7.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter4.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz4.clickzs[1].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter10.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter13.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter1.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ehg-hitent.hitbox[3].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@banner.clubdicecasino[1].txt -> TrackingCookie.Clubdicecasino : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz7.clickzs[3].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@targetnet[1].txt -> TrackingCookie.Targetnet : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@count.xhit[1].txt -> TrackingCookie.Xhit : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@hg1.hitbox[2].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@statcounter[3].txt -> TrackingCookie.Statcounter : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ecnext.122.2o7[1].txt -> TrackingCookie.2o7 : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter13.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ilead.itrack[1].txt -> TrackingCookie.Itrack : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@as-eu.falkag[3].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sel.as-eu.falkag[3].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter2.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@questionmarket[2].txt -> TrackingCookie.Questionmarket : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@vip2.clickzs[1].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cs.sexcounter[3].txt -> TrackingCookie.Sexcounter : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter7.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter9.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter14.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@xxxcounter[2].txt -> TrackingCookie.Xxxcounter : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@hitbox[4].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@fastclick[3].txt -> TrackingCookie.Fastclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter4.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter.hitslink[3].txt -> TrackingCookie.Hitslink : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter9.sextracker[4].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter16.sextracker[3].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter12.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter3.sextracker[3].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@stats1.reliablestats[3].txt -> TrackingCookie.Reliablestats : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@fastclick[4].txt -> TrackingCookie.Fastclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@yieldmanager[4].txt -> TrackingCookie.Yieldmanager : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@as-eu.falkag[4].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@casalemedia[2].txt -> TrackingCookie.Casalemedia : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter9.sextracker[3].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@media.fastclick[2].txt -> TrackingCookie.Fastclick : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@casalemedia[3].txt -> TrackingCookie.Casalemedia : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@as-us.falkag[2].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sel.as-eu.falkag[4].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ad.yieldmanager[4].txt -> TrackingCookie.Yieldmanager : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@as1.falkag[1].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter5.sextracker[3].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter8.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sextracker[5].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@sexlist[3].txt -> TrackingCookie.Sexlist : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter11.sextracker[1].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter1.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@cz11.clickzs[1].txt -> TrackingCookie.Clickzs : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@counter10.sextracker[2].txt -> TrackingCookie.Sextracker : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@hitbox[5].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\standard\Cookies\standard@ehg-newarkinone.hitbox[2].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Lokale indstillinger\Temporary Internet Files\Content.IE5\UTELU5WJ\script-34[1].htm -> Not-A-Virus.Exploit.HTML.CodeBaseExec : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@doubleclick[1].txt -> TrackingCookie.Doubleclick : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@advertising[2].txt -> TrackingCookie.Advertising : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@ilead.itrack[1].txt -> TrackingCookie.Itrack : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@hitbox[2].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@ehg-hitent.hitbox[1].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@questionmarket[1].txt -> TrackingCookie.Questionmarket : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@advertising[3].txt -> TrackingCookie.Advertising : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@ecnext.122.2o7[1].txt -> TrackingCookie.2o7 : Renset uden backup
    C:\Documents and Settings\Kristina M. Jensen\Cookies\kristina m. jensen@statse.webtrendslive[3].txt -> TrackingCookie.Webtrendslive : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@hitbox[1].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@adtech[2].txt -> TrackingCookie.Adtech : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@doubleclick[1].txt -> TrackingCookie.Doubleclick : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@sel.as-eu.falkag[1].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@ilead.itrack[2].txt -> TrackingCookie.Itrack : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@as1.falkag[2].txt -> TrackingCookie.Falkag : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@ehg-hitent.hitbox[1].txt -> TrackingCookie.Hitbox : Renset uden backup
    C:\Documents and Settings\Kristina\Cookies\kristina@2o7[2].txt -> TrackingCookie.2o7 : Renset uden backup
    C:\System Volume Information\_restore{28384791-0234-4FBD-845B-24BD2CB0E71B}\RP340\A0065168.exe -> Hijacker.Small.kg : Renset uden backup
    C:\System Volume Information\_restore{28384791-0234-4FBD-845B-24BD2CB0E71B}\RP340\A0065169.exe -> Trojan.Small.gq : Renset uden backup
    C:\Recycled\NPROTECT\00001143.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001144.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001145.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001146.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001148.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001149.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001150.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001151.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001152.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001153.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001154.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001155.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001156.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001157.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001158.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001159.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\NPROTECT\00001160.TXT -> TrackingCookie.2o7 : Renset uden backup
    C:\Recycled\Dc5.exe -> Hijacker.Small : Renset uden backup
    C:\Recycled\Dc12.exe -> Adware.Msnagent : Renset uden backup
    C:\Recycled\Dc13.exe -> Adware.FindSpy : Renset uden backup


::Rapport slut
Avatar billede ejvindh Ekspert
07. april 2006 - 12:30 #5
De logs du har lagt ser bedre ud. Fik du ikke en logfil fra Fixwareout? Jeg vil meget gerne se denne log, da du tilsyneladende har en ny version af en kendt infektion. Den skulle ligge her:
C:\fixwareout\report.txt

Der mangler en enkelt i Hijackthis-loggen. Kør derfor Hijackthis igen, og fix denne linie:
O4 - HKLM\..\Run: [exe.lxsmd] C:\WINDOWS\system32\dmsxl.exe
Bemærk at navn filen godt kan have skiftet navn. Du skal lede efter en fil på 5 bogstaver, der følger dette mønster (*** er tilfældige tegn):
dm***.exe
...og "navnet" på entryen staver filnavnet baglæns:
[exe.***md]

Genstart til fejlsikret tilstand, og slet den tilhørende fil:
C:\WINDOWS\system32\dm***.exe

Muligvis vil du være nødt til først at slå udvidet fil-visning til. Det gøres sådan her:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

Genstart herefter til normal tilstand, og lav en ny log med Hijackthis, som du lægger herind til check.
Avatar billede alex_h_jensen Nybegynder
07. april 2006 - 21:43 #6
Hej her er fixin report:


Fixwareout ver 1.003
Last edited march/15/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\32refaselif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\lxsmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\32refaselif
...

Random Runs removed from HKLM
...

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Search by size and names...

»»»»» Misc files
* thequicklink  C:\WINDOWS\System32\RZUSE.DLL

»»»»» Checking for older varients covered by the Rem3 tool

Skal jeg køre ewido i fejl sikret igen?

jeg kan kun finde C:\WINDOWS\system32\dmvsh.exe men ingen entry..
Avatar billede ejvindh Ekspert
07. april 2006 - 22:01 #7
Slet den fil, som du finder, og lav en ny log med Hijackthis. Vent lidt med at køre Ewido igen.
Avatar billede alex_h_jensen Nybegynder
07. april 2006 - 22:17 #8
sådan :Logfile of HijackThis v1.99.1
Scan saved at 22:15:11, on 07-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Billionton\Bluetooth Software\bin\btwdins.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\VM_STI.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\HijackThis.exe
C:\Programmer\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [ccApp] C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P23 "EPSON Stylus C86 Series" /M "Stylus C86" /EF "HKCU"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: MuchTV Remote.lnk = ?
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Programmer\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Programmer\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Programmer\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Programmer\AutoCAD 2002\AcPreview.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Programmer\Billionton\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - Unknown owner - C:\Programmer\Fælles filer\EPSON\eEBAPI\SAgent2.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
Avatar billede ejvindh Ekspert
08. april 2006 - 11:27 #9
Så blev loggen helt ren. Du kan nu køre en sidste scanning med Ewido, for at få slettet eventuelle passive rester. Alternativt kunne det måske være en ide at køre en scanning med en anden scanner:

Hent Dr. Web, og gem det på skrivebordet:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Genstart til fejlsikret tilstand (tryk F8 under opstarten)

Dobbeltklik på drweb-cureit.exe, den vil køre en expressscan, det siger du ja til.
Når den skriver Done nederst til venstre, skal du klikke på Options->Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Rename.
Klik så på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de er valgt.

Klik så på den grønne pil ovre til højre på siden, så starter scanningen.
Første gang Dr.Web finder noget, klik "Yes to All", så fjerner den hvad den finder.
Klik så på Start->Søg, find filen drweb32w.log kopier det nederste af teksten herind, startende med:
Scan statistics.

Vejledning i billeder findes her:
http://fromsej.dk/Vejledninger/html/drweb.html

Men det er ren oprydning. Efter alle kendetegn at dømme, er infektionen slået ned. Når du er færdig med dette kan du fortsætte oprydningen:

Det kan være en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse (http://www.spywarefri.dk/virusscannere.htm#alle) - genstart din computer - aktiver systemgendannelse.
Og så kan det også være en god ide at skjule dine systemfiler og -mapper igen, så du ikke ved en fejl kommer til at slette en vigtig fil. Det gør du samme sted, hvor du satte det til at vise alle filer, denne gang vælger du bare: Vis ikke skjulte filer og mapper.

Det kan også være en god ide at få renset ud i dine midlertidige filer. Det kan gøres på en hurtig og nem måde med denne fil
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------

For at forhindre gentagelser, vil jeg anbefale dig at lægge nogle små programmer ind, som forhindrer spyware i at komme ind i første omgang. Du finder links og gode råd her:
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at du læser denne artikel om hvordan du kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester