Avatar billede exert Nybegynder
25. juli 2006 - 01:17 Der er 3 kommentarer

OHPE ver 4.12_23

Jeg får en alert med nogenlunde den her tekst:
Your system is infected with spyware pop-ups advertisements (OHPE ver 4.12_23)
click the icon to learn more on what you can do about pop-up windows and other unwanted software.

Derudover får jeg naturligvis nogle popup-reklamer.

Efter en søgning på nettet har jeg fuldt svar nummer to i dette forum:
http://www.computing.net/security/wwwboard/forum/17277.html

Det har dog ikke hjulpet endnu.
Nedenfor er de tre logger adskildt af
************************************************************




************************************************************


SmitRem-loggen ser således ud:

  smitRem © log file
    version 3.1

    by noahdfear


Microsoft Windows XP [Version 5.1.2600]
"IE"="6.0000"
The current date is: 24/07/2006
The current time is: 21:41:15.21

Running from
C:\Documents and Settings\Frank\Desktop\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!


checking for drsmartload2 key


drsmartload2 key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
AlfaCleaner uninstaller NOT present
SpyFalcon uninstaller NOT present
SpywareQuake uninstaller NOT present
SpywareSheriff uninstaller NOT present


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Trust Cleaner Fix © by noahdfear



Starting Trust Cleaner uninstaller

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


SpyHeal uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url
Online Security Guide.url
Security Troubleshooting.url
Security Troubleshooting.url


~~~ Favorites ~~~



~~~ system32 folder ~~~

amcompat.tlb
nscompat.tlb


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 780 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :)



************************************************************




Ewido-rapporten ser således ud:

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at:    00:20:33 25/07/2006

+ Scan result:   



HKLM\SOFTWARE\Classes\CLSID\{5753791b-f607-48ca-814e-91c14d081f9e} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5753791b-f607-48ca-814e-91c14d081f9e} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-851695425-3864511265-3079715437-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5753791B-F607-48CA-814E-91C14D081F9E} -> Adware.Generic : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.125:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.244:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.263:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.268:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.269:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.350:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.50:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.57:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.58:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.59:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.60:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Frank\Cookies\frank@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Frank\Cookies\frank@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.537:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.538:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
C:\Documents and Settings\Frank\Cookies\frank@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.518:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.636:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Etracker : Cleaned with backup (quarantined).
:mozilla.470:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.471:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.472:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.473:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.94:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.95:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.641:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.547:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.548:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.549:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.550:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.551:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.552:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.553:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
C:\Documents and Settings\Frank\Cookies\frank@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.417:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.559:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.560:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.561:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.562:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.563:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.338:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.339:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.340:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.341:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.342:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.343:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.344:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.345:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.354:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.355:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.356:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.357:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.362:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.363:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.364:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.365:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.366:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.367:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.368:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.369:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.370:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.371:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.372:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.373:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.374:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.379:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.380:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.390:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.391:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.392:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.393:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
C:\Documents and Settings\Frank\Cookies\frank@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Frank\Cookies\frank@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.402:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.412:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.425:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.426:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.427:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.439:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.440:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.441:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.432:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.433:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.434:C:\Documents and Settings\Frank\Application Data\Mozilla\Firefox\Profiles\noxhluv8.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end




************************************************************



Hijackthis-loggen ser således ud:
Logfile of HijackThis v1.99.1
Scan saved at 00:38:10, on 25/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\IntCodec\isamonitor.exe
C:\Program Files\IntCodec\pmsngr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\IntCodec\isamini.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\IntCodec\pmmon.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5753791b-f607-48ca-814e-91c14d081f9e} - C:\Program Files\IntCodec\isaddon.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Protection Bar - {d1ac752e-883f-4ed8-8828-b618c3a72152} - C:\Program Files\IntCodec\iesplugin.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {F073BDC9-0D67-4ff0-879E-27241C843828} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SSC_UserPrompt] "c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37840.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede exert Nybegynder
25. juli 2006 - 16:07 #1
Det ser ikke ud til at der er nogen der vil give sig i kast med mit problem.
Er det muligt at forhøje til 200 point nogen steder?
Avatar billede exert Nybegynder
25. juli 2006 - 18:08 #2
Jeg kan nu tilføje en ny Alert der lyder på iworm_attck_v122.02a
Avatar billede exert Nybegynder
25. juli 2006 - 22:47 #3
Alle eksperterne er åbenbart på sommerferie, så jeg har selv prøvet så godt jeg nu kan. Det ser ind til videre ud til at lykkedes, men venter lige og ser om det nu også kan passe. Jeg brugte Prevx1 http://www.prevx.com/ hvilket var meget let og virked effektivt.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester