Avatar billede sezam Nybegynder
10. juni 2006 - 21:12 Der er 11 kommentarer og
1 løsning

Jeg bombaderes af Pop-up bokse - virus?

Jeg har lavet en hijackthis-scanning - måske den kan fortælle nogen noget?

Logfile of HijackThis v1.99.1
Scan saved at 21:11:13, on 10-06-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\crypserv.exe
F:\SYMANT~1\NORTON~4\GHOSTS~2.EXE
F:\Symantec 2004\Norton Antivirus\navapsvc.exe
F:\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Philips ToUcam Camera\VProperty.exe
F:\SYMANT~1\NORTON~2\NPROTECT.EXE
F:\zonealarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MediaGateway\MediaGateway.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
F:\SYMANT~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Messenger\msmsgs.exe
F:\Symantec 2004\Norton Antivirus\SAVScan.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\John\Desktop\hjt.exe

O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Zango Toolbar - {EA0D26BD-9029-431A-86E0-83152D67828A} - C:\Program Files\Zango Programs\Zango Toolbar\ZangoTB.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] F:\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program Files\Philips ToUcam Camera\VProperty.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Zone Labs Client] F:\zonealarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "F:\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - F:\ICQ\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - F:\ICQ\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {8D82B1AB-F4C5-42BB-9A79-27A7B687D74F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8D82B1AB-F4C5-42BB-9A79-27A7B687D74F} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe
O16 - DPF: {8B3512EF-4FF5-4AA4-9CDE-56BB03E04B9F} (SAXFileEE ActiveX Control) - http://www.billedbutikken.dk/upload/SAXFileEE.cab
O16 - DPF: {CA79DF4A-E7DD-4175-A88A-7B72533A4130} (Sky Software FolderView ActiveX Control 6.0) - http://www.billedbutikken.dk/upload/digiupload.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IP-Uploader Control) - http://asp01.photoprintit.de/microsite/16/defaults/activex/ImageUploader3.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: GhostStartService - Symantec Corporation - F:\SYMANT~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - F:\Symantec 2004\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\SYMANT~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Symantec 2004\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - F:\SYMANT~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede ejvindh Ekspert
10. juni 2006 - 21:23 #1
Jeg kigger på den :-)
Avatar billede ejvindh Ekspert
10. juni 2006 - 21:28 #2
Jo, der var lidt i den :-)

-- Hent "SuperAntiSpyware free" herfra:
http://www.spywarefri.dk/downloads1.htm
Installer, og opdater scannereren. Men vent med at scanne.

Fuld vejledning til superantispyware finder du her:
http://www.spywarefri.dk/manualer/superantispyware-manual.htm

-- Gå ind i kontrolpanel-tilføj/fjern programmer, og se om du kan få lov til at afinstallere følgende programmer:
180solutions
Zango Toolbar
MediaGateway

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: Zango Toolbar - {EA0D26BD-9029-431A-86E0-83152D67828A} - C:\Program Files\Zango Programs\Zango Toolbar\ZangoTB.dll
O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
O9 - Extra button: Microsoft AntiSpyware helper - {8D82B1AB-F4C5-42BB-9A79-27A7B687D74F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8D82B1AB-F4C5-42BB-9A79-27A7B687D74F} - (no file) (HKCU)

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Du skal nu til at slette. Som indledning hertil skal du have slået "Udvidet filvisning" til:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

-- Slet herefter følgende (hvis du kan finde dem):
Mapper:
C:\Program Files\Zango Programs\
C:\Program Files\MediaGateway\

-- Start SuperAntispyware, klik "Scan your computer", sæt flueben i dine drev, ovre til venstre i vinduet. Ovre til højre i vinduet, sætter du prik i "Perform Complete Scan". Klik "næste", nu scanner den. Når den er færdig, så markerer du det den finder, og lader scannereren fjerne det.

-- Genstart til normal tilstand. Åbn SuperAntispyware-scannereren igen, og klik "preferences"-> "stastics/logs". Marker loggen, og klik "View log". Kopier loggen her ind i tråden, sammen med en ny HijackThis log.
Avatar billede sezam Nybegynder
10. juni 2006 - 21:57 #3
Jeg startede op i fejlsikret tilstand men havde ikke held med at finde:
C:\Program Files\Zango Programs\
C:\Program Files\MediaGateway\

- næste step gik heller ikke; SuperAntispyware kan ikke starte i fejlsikret tilstand ?
Avatar billede ejvindh Ekspert
10. juni 2006 - 21:59 #4
At du ikke kan finde mapperne kan skyldes at de er blevet succesfuldt afinstalleret -- så det er jo bare dejligt.

Angående SAS så lyder det for mig som om, du ikke har fået installeret (og opdateret) programmet, inden du gik i fejlsikret. Kan det passe?
Avatar billede ejvindh Ekspert
10. juni 2006 - 22:00 #5
Hvis ja, så genstart til normal tilstand, installer og opdater SAS, genstart herefter til fejlsikret tilstand, og fortsæt proceduren der hvor du var kommet til.
Avatar billede sezam Nybegynder
10. juni 2006 - 23:31 #6
SUPERAntiSpyware Scan Log
Generated 06/10/2006 at 10:57 PM

Core Rules Database Version : 2974
Trace Rules Database Version: 1071

Memory threats detected  : 0
Registry threats detected : 15
File threats detected    : 109

Adware.Tracking Cookie
    C:\Documents and Settings\John\Cookies\john@globalstat[1].txt
    C:\Documents and Settings\John\Cookies\john@click-fr[1].txt
    C:\Documents and Settings\John\Cookies\john@adserver.o2[1].txt
    C:\Documents and Settings\John\Cookies\john@xiti[1].txt
    C:\Documents and Settings\John\Cookies\john@spylog[2].txt
    C:\Documents and Settings\John\Cookies\john@tripod.lycos[1].txt
    C:\Documents and Settings\John\Cookies\john@cgi-bin[2].txt
    C:\Documents and Settings\John\Cookies\john@e-2dj6wfloupczkdo.stats.esomniture[2].txt
    C:\Documents and Settings\John\Cookies\john@iqtv.122.2o7[2].txt
    C:\Documents and Settings\John\Cookies\john@server.iad.liveperson[2].txt
    C:\Documents and Settings\John\Cookies\john@countus.get.kadserver[1].txt
    C:\Documents and Settings\John\Cookies\john@hurricanedigitalmedia[1].txt
    C:\Documents and Settings\John\Cookies\john@vhost.oddcast[2].txt
    C:\Documents and Settings\John\Cookies\john@revenue[2].txt
    C:\Documents and Settings\John\Cookies\john@tacoda[1].txt
    C:\Documents and Settings\John\Cookies\john@www.belstat[2].txt
    C:\Documents and Settings\John\Cookies\john@tribalfusion[1].txt
    C:\Documents and Settings\John\Cookies\john@2o7[1].txt
    C:\Documents and Settings\John\Cookies\john@zedo[1].txt
    C:\Documents and Settings\John\Cookies\john@oddcast[1].txt
    C:\Documents and Settings\John\Cookies\john@www.livewebstats[1].txt
    C:\Documents and Settings\John\Cookies\john@adserver.etrafik[1].txt
    C:\Documents and Settings\John\Cookies\john@e2.emediate[1].txt
    C:\Documents and Settings\John\Cookies\john@fastclick[1].txt
    C:\Documents and Settings\John\Cookies\john@indextools[1].txt
    C:\Documents and Settings\John\Cookies\john@sel.as-eu.falkag[1].txt
    C:\Documents and Settings\John\Cookies\john@banner.cdpoker[1].txt
    C:\Documents and Settings\John\Cookies\john@ads.arto[1].txt
    C:\Documents and Settings\John\Cookies\john@data3.perf.overture[1].txt
    C:\Documents and Settings\John\Cookies\john@stats1.reliablestats[2].txt
    C:\Documents and Settings\John\Cookies\john@cgi-bin[3].txt
    C:\Documents and Settings\John\Cookies\john@www.admedian[1].txt
    C:\Documents and Settings\John\Cookies\john@adtech[2].txt
    C:\Documents and Settings\John\Cookies\john@rotator.adjuggler[2].txt
    C:\Documents and Settings\John\Cookies\john@cz4.clickzs[2].txt
    C:\Documents and Settings\John\Cookies\john@estat[1].txt
    C:\Documents and Settings\John\Cookies\john@ad.adtoma[2].txt
    C:\Documents and Settings\John\Cookies\john@stat.onestat[2].txt
    C:\Documents and Settings\John\Cookies\john@free.wegcash[2].txt
    C:\Documents and Settings\John\Cookies\john@tradedoubler[1].txt
    C:\Documents and Settings\John\Cookies\john@showit[1].txt
    C:\Documents and Settings\John\Cookies\john@statcounter[2].txt
    C:\Documents and Settings\John\Cookies\john@ads2.jubii[2].txt
    C:\Documents and Settings\John\Cookies\john@e-2dj6wjmyekajmdo.stats.esomniture[2].txt
    C:\Documents and Settings\John\Cookies\john@clicks.hmcampaign[1].txt
    C:\Documents and Settings\John\Cookies\john@www.cibleclick[1].txt
    C:\Documents and Settings\John\Cookies\john@hit.stat[1].txt
    C:\Documents and Settings\John\Cookies\john@adopt.euroclick[1].txt
    C:\Documents and Settings\John\Cookies\john@questionmarket[1].txt
    C:\Documents and Settings\John\Cookies\john@fortunecity[1].txt
    C:\Documents and Settings\John\Cookies\john@m1.webstats4u[1].txt
    C:\Documents and Settings\John\Cookies\john@weborama[1].txt
    C:\Documents and Settings\John\Cookies\john@82763522[2].txt
    C:\Documents and Settings\John\Cookies\john@please[1].txt
    C:\Documents and Settings\John\Cookies\john@as-eu.falkag[1].txt
    C:\Documents and Settings\John\Cookies\john@banner.prestigecasino[1].txt
    C:\Documents and Settings\John\Cookies\john@e-2dj6wjl4omdpsko.stats.esomniture[1].txt
    C:\Documents and Settings\John\Cookies\john@sdc.rbistats[1].txt
    C:\Documents and Settings\John\Cookies\john@http.edge.vru4[2].txt
    C:\Documents and Settings\John\Cookies\john@perf.overture[1].txt
    C:\Documents and Settings\John\Cookies\john@bluestreak[1].txt
    C:\Documents and Settings\John\Cookies\john@tripod[1].txt
    C:\Documents and Settings\John\Cookies\john@roiservice[1].txt
    C:\Documents and Settings\John\Cookies\john@track.adform[2].txt
    C:\Documents and Settings\John\Cookies\john@realmedia[1].txt
    C:\Documents and Settings\John\Cookies\john@ad1.emediate[2].txt
    C:\Documents and Settings\John\Cookies\john@ad.yieldmanager[1].txt
    C:\Documents and Settings\John\Cookies\john@ads.monster[1].txt
    C:\Documents and Settings\John\Cookies\john@91338698[1].txt
    C:\Documents and Settings\John\Cookies\john@admarketplace[2].txt
    C:\Documents and Settings\John\Cookies\john@hotlog[1].txt
    C:\Documents and Settings\John\Cookies\john@xml.bravenetmedianetwork[2].txt
    C:\Documents and Settings\John\Cookies\john@ad.adocean[2].txt
    C:\Documents and Settings\John\Cookies\john@cgi-bin[5].txt
    C:\Documents and Settings\John\Cookies\john@as-us.falkag[2].txt
    C:\Documents and Settings\John\Cookies\john@burstnet[1].txt
    C:\Documents and Settings\John\Cookies\john@adknowledge[2].txt
    C:\Documents and Settings\John\Cookies\john@1072387179[1].txt
    C:\Documents and Settings\John\Cookies\john@maxserving[1].txt
    C:\Documents and Settings\John\Cookies\john@adfarm1.adition[2].txt
    C:\Documents and Settings\John\Cookies\john@cgi-bin[4].txt
    C:\Documents and Settings\John\Cookies\john@1070430424[1].txt
    C:\Documents and Settings\John\Cookies\john@clicktorrent[2].txt
    C:\Documents and Settings\John\Cookies\john@1067631990[1].txt
    C:\Documents and Settings\John\Cookies\john@adserver.banneradministration[2].txt
    C:\Documents and Settings\John\Cookies\john@ads.realtechnetwork[1].txt
    C:\Documents and Settings\John\Cookies\john@filmloop.adbureau[1].txt
    C:\Documents and Settings\John\Cookies\john@18766632[1].txt
    C:\Documents and Settings\John\Cookies\john@astats[1].txt
    C:\Documents and Settings\John\Local Settings\Temp\Cookies\john@ads.guardian.co[1].txt
    C:\Documents and Settings\John\Local Settings\Temp\Cookies\john@adtech[2].txt
    C:\Documents and Settings\John\Local Settings\Temp\Cookies\john@c2.gostats[2].txt
    C:\Documents and Settings\John\Local Settings\Temp\Cookies\john@stat.inleadmedia[1].txt
    C:\Documents and Settings\John\Local Settings\Temp\Cookies\john@track.adform[2].txt
    C:\Documents and Settings\John\Local Settings\Temp\Cookies\john@www.countercentral[2].txt

Adware.IST/ISTBar (Slotch Bar)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ISTactivex.dll
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ISTactivex.dll#.Owner
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ISTactivex.dll#{386A771C-E96A-421F-8BA7-32F1B706892F}
    HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}
    HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1
    HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\0
    HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\0\win32
    HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\FLAGS
    HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\HELPDIR

Adware.MyWay
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWaySearchAssistant
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWaySearchAssistant#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWaySearchAssistant#HelpLink
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWaySearchAssistant#Publisher
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWaySearchAssistant#UninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWaySearchAssistant#UrlInfoAbout

Adware.WhenU
    C:\Program Files\VVSN\VVSN.exe.mwt.mwt

Adware.180solutions/Search Assistant
    C:\RECYCLER\NPROTECT\00006775.EXE
    C:\RECYCLER\NPROTECT\00006776.exe

Adware.Zango Toolbar
    C:\RECYCLER\NPROTECT\00006781.dll

Trojan.NewDotNet
    C:\WINDOWS\NDNuninstall6_30.exe

Adware.Media Gateway
    E:\norton system works 2006 (updated)\norton system works 2006\keygen.exe


FRA HIJACKTHIS:
Logfile of HijackThis v1.99.1
Scan saved at 23:31:04, on 10-06-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\crypserv.exe
F:\SYMANT~1\NORTON~4\GHOSTS~2.EXE
F:\Symantec 2004\Norton Antivirus\navapsvc.exe
F:\SYMANT~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
F:\SYMANT~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Philips ToUcam Camera\VProperty.exe
F:\zonealarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Messenger\msmsgs.exe
F:\Symantec 2004\Norton Antivirus\SAVScan.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\John\Desktop\hjt.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] F:\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program Files\Philips ToUcam Camera\VProperty.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Zone Labs Client] F:\zonealarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "F:\Quicktime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - F:\ICQ\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - F:\ICQ\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe
O16 - DPF: {8B3512EF-4FF5-4AA4-9CDE-56BB03E04B9F} (SAXFileEE ActiveX Control) - http://www.billedbutikken.dk/upload/SAXFileEE.cab
O16 - DPF: {CA79DF4A-E7DD-4175-A88A-7B72533A4130} (Sky Software FolderView ActiveX Control 6.0) - http://www.billedbutikken.dk/upload/digiupload.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IP-Uploader Control) - http://asp01.photoprintit.de/microsite/16/defaults/activex/ImageUploader3.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: GhostStartService - Symantec Corporation - F:\SYMANT~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - F:\Symantec 2004\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\SYMANT~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Symantec 2004\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - F:\SYMANT~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede ejvindh Ekspert
10. juni 2006 - 23:41 #7
Så er loggen ren. Har du også fået løst dit problem?

For at gøre arbejdet helt færdig:
Det kan være en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse (http://www.spywarefri.dk/virusscannere.htm#alle) - genstart din computer - aktiver systemgendannelse.
Og så kan det også være en god ide at skjule dine systemfiler og -mapper igen, så du ikke ved en fejl kommer til at slette en vigtig fil. Det gør du samme sted, hvor du satte det til at vise alle filer, denne gang vælger du bare: Vis ikke skjulte filer og mapper.

Det kan også være en god ide at få renset ud i dine midlertidige filer. Det kan gøres på en hurtig og nem måde med denne fil
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------

For at forhindre gentagelser, vil jeg anbefale dig at lægge nogle små programmer ind, som forhindrer spyware i at komme ind i første omgang. Du finder links og gode råd her:
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at du læser denne artikel om hvordan du kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Brug af crackede programmer kan nogle gange også være en årsag til infektioner. Den ene af de infektioner du havde på computeren stammede sandsynligvis fra et crack til Norton.
Avatar billede sezam Nybegynder
10. juni 2006 - 23:43 #8
Alletiders - tak for hjælpen :-)
Avatar billede ejvindh Ekspert
13. juni 2006 - 11:57 #9
Det var så lidt. Husk at lukke spørgsmålet igen, ved at markere mit navn, og klikke på Acceptér

:-)
Avatar billede ejvindh Ekspert
26. juni 2006 - 15:00 #10
Husk at lukke spørgsmålet :-)
Avatar billede sezam Nybegynder
26. juni 2006 - 16:36 #11
Ups...beklager! :-)
Avatar billede ejvindh Ekspert
26. juni 2006 - 19:26 #12
Alt i orden :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester