Avatar billede paolomalaco Nybegynder
13. juni 2006 - 15:59 Der er 8 kommentarer og
1 løsning

Project1 Virus

Hej jeg har lige faaet en mega dejlig virus over messenger jeg tror den hedder Project1!!! Jeg har lige downloaded hijackthis saa jeg kan poste en log men har ikke nogen erfaring med at fjerne virus saa haaber at nogen kan hjaelpe?
Avatar billede paolomalaco Nybegynder
13. juni 2006 - 16:01 #1
her er min log file. Jeg har endnu ikke restartet min computer siden jeg fik virusen ved ikke om det hjaelper noget?

Logfile of HijackThis v1.99.1
Scan saved at 15:00:32, on 13/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Apoint2K\EzCapt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\drivers\helpsys\msnexplorer.exe
c:\myspaces.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
C:\Program Files\hijackthis\HijackThis.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe
c:\drsmartload422a.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MSN Explorer] c:\windows\system32\drivers\helpsys\msnexplorer.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [MSN Explorer] c:\windows\system32\drivers\helpsys\msnexplorer.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {53B3ABEA-4445-44D9-A01E-088144CAABD9} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/da/filesharingctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095070389683
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138810667588
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede ejvindh Ekspert
13. juni 2006 - 16:08 #2
Jeg ser på den :-)
Avatar billede paolomalaco Nybegynder
13. juni 2006 - 16:10 #3
mange tak. Kan du hjaelpe mig lidt med hvad jeg skal kigge efter jeg ville jo gerne laere lidt om hvad du kigger efter?
Avatar billede ejvindh Ekspert
13. juni 2006 - 16:14 #4
Hent Ewido herfra (14 dages version af plus-versionen)
http://www.spywarefri.dk/downloads1/ewido-setup.exe
Installer og kør Ewido - opdater programmet.

Hent Dr. Web, og gem det på skrivebordet:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Genstart til fejlsikret tilstand (tryk F8 under opstarten)

Kør en fuld scanning med Ewido. Programmet laver en lille log, som du skal kopiere herind i dit næste svar.

Dobbeltklik på drweb-cureit.exe, den vil køre en expressscan, det siger du ja til.
Når den skriver "Select object for Scanning" nederst til venstre, skal du klikke på Options->Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Rename.
Klik så på OK, for at komme ud til hovedmenuen igen.
Klik så på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de er valgt.

Klik så på den grønne pil ovre til højre på siden, så starter scanningen.
Første gang Dr.Web finder noget, klik "Yes to All", så fjerner den hvad den finder.
Klik så på Start->Søg, find filen CureIt.log kopier det nederste af teksten herind, startende med:
Scan statistics.

Genstart herefter computeren til normal tilstand, og lav en ny log med Hijackthis, som du lægger herind. Så kan jeg se, hvor langt du er kommet :-)
Avatar billede ejvindh Ekspert
13. juni 2006 - 16:15 #5
Angående selv at lære at læse logs, så vil jeg anbefale dig at læse denne artikel. Her har jeg skrevet noget om, hvordan jeg arbejder med logsene:

http://www.eksperten.dk/artikler/642
Avatar billede paolomalaco Nybegynder
13. juni 2006 - 18:27 #6
her er min log fra Ewido:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            16:27:46, 13/06/2006
+ Report-Checksum:        D0639A84

+ Scan result:

    HKU\S-1-5-21-1645522239-2111687655-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
    HKU\S-1-5-21-1645522239-2111687655-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
    HKU\S-1-5-21-1645522239-2111687655-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -> Spyware.WinFavorites : Cleaned with backup
    HKU\S-1-5-21-1645522239-2111687655-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{197AB1D7-A7DD-4C86-A938-1FCC0DB21B85} -> Spyware.OrbitExplorer : Cleaned with backup
    HKU\S-1-5-21-1645522239-2111687655-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -> Spyware.ComLoad : Cleaned with backup
    :mozilla.32:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.33:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.34:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.35:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.36:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.37:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.39:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.40:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.41:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.42:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.43:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.44:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.45:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.46:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.47:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.48:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.49:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.50:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.51:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.52:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.53:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.54:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.55:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.56:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.57:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.58:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.59:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.60:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.61:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.62:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.63:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.64:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.65:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.66:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.67:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.68:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.69:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.70:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.71:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.89:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.90:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.91:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.92:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.93:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.137:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.142:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.143:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.149:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.150:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.151:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.155:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
    :mozilla.227:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.228:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.283:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.284:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.285:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.290:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.291:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.333:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.335:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.336:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.337:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.338:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.339:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.340:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.341:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.342:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.343:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.344:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.345:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.503:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    :mozilla.629:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    :mozilla.707:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
    :mozilla.708:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
    :mozilla.763:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    :mozilla.764:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    :mozilla.817:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    :mozilla.870:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    :mozilla.893:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
    :mozilla.894:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
    :mozilla.895:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
    :mozilla.898:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
    :mozilla.899:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    :mozilla.929:C:\Documents and Settings\Dennis Holmer\Application Data\Mozilla\Firefox\Profiles\s5mdh9ej.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@a-1shz2prbmdj6wvny-1sez2pra2dj6wjlyuiczeapw-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmycld5wcog-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@banner.commissionpartner[2].txt -> Spyware.Cookie.Commissionpartner : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@e-2dj6wflouicjodp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@ilead.itrack[1].txt -> Spyware.Cookie.Itrack : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkogmcpmcowidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@y-1shz2prbmdj6wvny-1sez2pra2dj6wfliajdjaeqqsdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@y-1shz2prbmdj6wvny-1sez2pra2dj6wflokncpologudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4ancjedogidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Dennis Holmer\Cookies\dennis holmer@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmyskcjccoaydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\WINDOWS\system32\MRT.exe -> Heuristic.Win32.AVKiller : Cleaned with backup


::Report End
Avatar billede paolomalaco Nybegynder
13. juni 2006 - 18:28 #7
og her er fra Dr Web:

Scan statistics

Objects scanned: 103911
Infected objects found: 4
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 2
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 4
Objects renamed: 2
Objects moved: 0
Objects ignored: 0
Scan speed: 1411 Kb/s
Scan time: 00:43:39
Avatar billede paolomalaco Nybegynder
13. juni 2006 - 18:29 #8
her er saa min nyeste hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 17:29:28, on 13/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {53B3ABEA-4445-44D9-A01E-088144CAABD9} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/da/filesharingctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095070389683
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138810667588
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede ejvindh Ekspert
13. juni 2006 - 19:29 #9
Det hjalp på den. Du mangler bare at fixe en enkelt linie med Hijackthis:

Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS

Så er loggen ren. Kan du mærke en forbedring på computeren?

For at gøre arbejdet helt færdig:
Det kan være en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse (http://www.spywarefri.dk/virusscannere.htm#alle) - genstart din computer - aktiver systemgendannelse.
Og så kan det også være en god ide at skjule dine systemfiler og -mapper igen, så du ikke ved en fejl kommer til at slette en vigtig fil. Det gør du samme sted, hvor du satte det til at vise alle filer, denne gang vælger du bare: Vis ikke skjulte filer og mapper.

Det kan også være en god ide at få renset ud i dine midlertidige filer. Det kan gøres på en hurtig og nem måde med denne fil
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------

For at forhindre gentagelser, vil jeg anbefale dig at lægge nogle små programmer ind, som forhindrer spyware i at komme ind i første omgang. Du finder links og gode råd her:
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at du læser denne artikel om hvordan du kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester