Avatar billede dhpii Nybegynder
23. september 2006 - 14:01 Der er 14 kommentarer og
1 løsning

Hjælp til fjernelse af 'WinFixer'.

Hej eksperter.

Jeg mangler hjælp til fjernelse af virussen 'WinFixer'. Jeg kører nortonantivirus, som konstant kommer med et advarlsesvindue omkring den omtalte virus.

Nu er det tid til at få et par ekspertøjne på. :)
Avatar billede nva Praktikant
23. september 2006 - 14:05 #1
Har du prøvet denne vejledning http://www.eksperten.dk/artikler/954 ? Ellers prøv det, men det bliver nok ikke mig der følger op.
Avatar billede dhpii Nybegynder
23. september 2006 - 14:30 #2
Tak ^^

Jeg vil følge vejl., og poste resultater herind. Mon ikke arlet, fromsej ell. lign. slår et sving forbi :)
Avatar billede dhpii Nybegynder
23. september 2006 - 18:51 #3
SUPERAntiSpyware Scan Log
Generated 09/23/2006 at 06:39 PM

Core Rules Database Version : 3090
Trace Rules Database Version: 1119

Memory threats detected  : 0
Registry threats detected : 105
File threats detected    : 193

Adware.Tracking Cookie
    C:\Documents and Settings\David Pii\Cookies\david pii@www.asianparadisexxx[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@www.burstbeacon[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@cassava[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@revenue[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@4[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@413[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@atwola[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@ilead.itrack[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@623[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@ad1.emediate[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@statse.webtrendslive[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@fastclick[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@www.dgm2[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@adtech[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@realmedia[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@1071241502[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@statcounter[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@adfair[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@c3.gostats[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@as-us.falkag[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@mediaplex[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@S130376[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@1[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@casalemedia[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@ads.realcastmedia[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@tradedoubler[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@link.vericlick[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@0[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@307[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@S005-01-5-11-246249-74419[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@563[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@stats1.reliablestats[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@toplist[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@3[3].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@S148884[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@dcsc4zjzre9xjy8po3jq8687n_4q8l[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@doubleclick[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@www.click-now[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@as1.falkag[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@targetnet[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@3[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@advertising[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@image.masterstats[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@serving-sys[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@burstnet[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@click-now[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@cgi-bin[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@ads.realtechnetwork[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@S151261[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@S149247[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@hitbox[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@dcs2omr9fpifwznrgv67zf9ub_7p8i[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@2[4].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@cgi-bin[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@2[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@z1.adserver[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@ads2.jubii[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@track.adform[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@atdmt[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@888[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@ads.beamfile[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@rightmedia[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@spylog[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@media.fastclick[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@hotlog[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@belnk[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@valueclick[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@dist.belnk[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@ehg-bskyb.hitbox[1].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@bs.serving-sys[2].txt
    C:\Documents and Settings\David Pii\Cookies\david pii@cracks[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@a.websponsors[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ad.adnet[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ad.letssingit[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ad.mp-gamer[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ad.pro-advertising[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ad.zanox[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ad1.emediate[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@adecn[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@adopt.hbmediapro[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ads.beamfile[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ads.digitalpoint[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ads.iq-studio[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ads.monster[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ads2.gamereactor[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ads2.jubii[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@adserver.banneradministration[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@adv.juventus[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@apmebf[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@atdmt[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@ath.belnk[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@atwola[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@banner.monacogoldcasino[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@belnk[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@bizrate[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@cassava[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@clicksor[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@counter[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@cracks[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@dist.belnk[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@exitexchange[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@focalex[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@fortunecity[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@free-banners[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@http.edge.vru4[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@interclick[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@kanoodle[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@maxserving[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@oddcast[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@offeroptimizer[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@pacificpoker[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@partypoker[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@realmedia[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@rightmedia[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@stats[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@toplist[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@track.adform[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@tripod.lycos[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@tripod[1].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@vhost.oddcast[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@winfixer[2].txt
    C:\Documents and Settings\Jakob Pii\Cookies\jakob pii@xiti[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ad1.emediate[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@adlegend[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ads.beamfile[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ads.gambling[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ads.monster[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ads.ussearch[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ads2.jubii[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@adserver.banneradministration[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@adv.webmd[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@advertising[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@atdmt[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@banner.fastwincasino[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@bs.serving-sys[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@click.tuinordiccampaign.buyingexperience[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@counter[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@dk.winantivirus[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@doubleclick[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@ehg-foxmovies.hitbox[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@go.winantivirus[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@hitbox[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@indextools[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@kmed52.adx[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@msnportal.112.2o7[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@nextag[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@secure.winantivirus[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@serving-sys[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@stat.katalysatormedia[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@stats.manticoretechnology[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@stats24[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@track.adform[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@tradedoubler[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@winantivirus[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@winfixer[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@winfixer[3].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@www.countercentral[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@www.dgm2[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@www.winantivirus[2].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@www.winfixer[1].txt
    C:\Documents and Settings\Kurt Pii\Cookies\kurt pii@xiti[1].txt
    C:\found.000\dir0000.chk\Cookies\pia pii@ad1.emediate[1].txt
    C:\found.000\dir0000.chk\Cookies\pia pii@belnk[1].txt
    C:\found.000\dir0000.chk\Cookies\pia pii@cassava[1].txt
    C:\found.000\dir0000.chk\Cookies\pia pii@dist.belnk[2].txt
    C:\found.000\dir0000.chk\Cookies\pia pii@maxserving[1].txt
    C:\found.000\dir0000.chk\Cookies\pia pii@track.adform[2].txt
    C:\found.000\dir0000.chk\Cookies\pia pii@wvw.silkroadtech[2].txt

Adware.180solutions/ZangoSearch
    C:\Programmer\Zango

Trojan.Error Safe Free
    C:\Programmer\Error Safe Free

Trojan.WinAntiSpyware/WinAntiVirus 2006
    HKCR\WAP6.PCheck
    HKCR\WAP6.PCheck\CLSID
    HKCR\WAP6.PCheck\CurVer
    HKCR\WAP6.PCheck.1
    HKCR\WAP6.PCheck.1\CLSID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#DeviceDesc
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Capabilities
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Driver
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000\LogConf
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000\Control
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#DeviceDesc
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Capabilities
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Driver
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000\LogConf
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000\Control
    HKLM\SYSTEM\CurrentControlSet\Services\vspf
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Type
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Start
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Tag
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Group
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#DependOnService
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#DependOnGroup
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Security#Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#0
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#Count
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Type
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Start
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Tag
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Group
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Security#Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#0
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#Count
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#DeviceDesc
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#Type
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#Start
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#ObjectName
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#Description
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Security
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Security#Security
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum#0
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum#Count
    HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum#NextInstance
    C:\Documents and Settings\David Pii\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
    C:\Documents and Settings\David Pii\Application Data\WinAntiVirus Pro 2006\Logs
    C:\Documents and Settings\David Pii\Application Data\WinAntiVirus Pro 2006
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\Afinstallér WinAntiVirus Pro 2006.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\Feedback on Support Quality.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\Henvend til kundehjælpeafdeling.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\Report Software Defect.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\Request for Instructions.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\Share Your Suggestions.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\Uninstall WinAntiVirus Pro 2006.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Brugeranvisning.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Knowledge base.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Manual.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\WinAntiVirus Pro 2006

Trojan.ErrorSafe
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Error Safe Unregistered Version\Deinstaller ErrorSafe.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Error Safe Unregistered Version\Error Safe på nettet.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Error Safe Unregistered Version\Error Safe.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Error Safe Unregistered Version\Feedback om hjælpekvalitet.lnk
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Error Safe Unregistered Version
    C:\WINDOWS\system32\ErrorSafeSetup.exe

----------------------------------------------------

Dr. Web-resultater;

A0000131.exe;C:\System Volume Information\_restore{649DFC26-95BF-4F69-84DC-0D63E8B71836}\RP5;Adware.Zango;Renamed.;

A0000147.dll;C:\System Volume Information\_restore{649DFC26-95BF-4F69-84DC-0D63E8B71836}\RP5;Adware.Zango;Renamed.;

A0000176.exe;C:\System Volume Information\_restore{649DFC26-95BF-4F69-84DC-0D63E8B71836}\RP5;Adware.Zango;Renamed.;

----------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 18:49:57, on 23-09-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Programmer\ewido anti-spyware 4.0\guard.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\PMJ151LA.BIN
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Creative\Shared Files\CamTray.exe
C:\Programmer\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Common Files\Companion Wizard\compwiz.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Microsoft Office\Office\EXCEL.EXE
C:\Documents and Settings\David Pii\Skrivebord\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.dk/0SEDADK/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lectio.dk/lectio/37/default.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmer\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NAV_Update] C:\NAV_Update.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programmer\Creative\Shared Files\CamTray.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Programmer\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CompanionWizard] "C:\Programmer\Common Files\Companion Wizard\compwiz.exe" /silent
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [BearShare] "C:\Programmer\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .mp3: C:\Programmer\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tiff: C:\Programmer\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: Nordea Online investering 7 - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103306680171
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://dakocytomation.webex.com/client/v_mywebex/webex/ieatgpc.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmer\ewido anti-spyware 4.0\guard.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PMJ151 AutoLaunch Service (PMJ151LA) - Matsushita Electric Industrial Co. ,Ltd, - C:\WINDOWS\PMJ151LA.BIN
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe


...Håber på hurtig respons :)
Avatar billede nva Praktikant
23. september 2006 - 19:21 #4
Upload denne fil Programmer\Common Files\Companion Wizard\compwiz.exe til online virus-scan http://virusscan.jotti.org/ og slet den hvis det er virus.
Avatar billede dhpii Nybegynder
24. september 2006 - 14:36 #5
Resultat af jotti's virusscan;

File:  compwiz.exe 
Status:  INFECTED/MALWARE 
MD5  9a312293003848198aa9004a94d6dd35 
Packers detected:  -
Scanner results 
AntiVir  Found Adware-Spyware/Companion.A.2 adware 
ArcaVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found nothing
BitDefender  Found nothing
ClamAV  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
UNA  Found nothing
VirusBuster  Found nothing
VBA32  Found Embedded.Application.Win32.Adware.WinAntiVirus (probable variant) 


Hvorledes skal jeg slette den?
Avatar billede nva Praktikant
24. september 2006 - 16:13 #6
De fleste antivirus programmer mener åbenbart ikke at det er malware. Så jeg vil foreslå at du i første omgang bare omdøber den til fx. compwiz.old og så ser hvordan din maskine opfører sig. Hvis den kører fint i et par dage, så sletter du den bare helt.
Avatar billede dhpii Nybegynder
24. september 2006 - 17:38 #7
Når jeg går ind i dens mappe, reagerer mit norton helt vildt, og "blokerer" nykomne .dll filer som mappen er fyldt med.

WapCHK{7CF2E07F-214C-45BE-BF10-C348DDDE37EC}.dll

for bare at nævne en af dem. Er det stadig nok med omdøbing, som hermed er gjort?
Avatar billede nva Praktikant
24. september 2006 - 21:22 #8
Det lyder godt nok som om den mappe er fyldt med skidt - hmmm. Så smid hele mappen i papirkurven, hvis du kan. Bare underligt at du ikke finder de virus med SuperAntiSpyware - har du fulgt denne http://www.eksperten.dk/artikler/954 - ellers tag de scannere derfra som du ikke har kørt endnu.
Avatar billede nva Praktikant
24. september 2006 - 21:23 #9
Du har vist kørt de fleste ser det ud til. Hvad hedder folderen?
Avatar billede nva Praktikant
24. september 2006 - 21:28 #10
Har du set om den er under tilføj/fjern programmer?
Avatar billede nva Praktikant
24. september 2006 - 21:29 #11
Du kan også starte op i fejlsikker tilstand og prøve en scan med McAfee igen.
Avatar billede nva Praktikant
24. september 2006 - 21:31 #12
Prøv denne http://fileinfo.prevx.com/QQe2f618725282-WAPC4679406/WAPCHK.DLL.html - hvis intet af det jeg foreslår virker så kan jeg kun sige HJÆLP.
Avatar billede dhpii Nybegynder
28. september 2006 - 21:29 #13
Det sidste link du postede, fjerne optimalt! Skriv et "svar", så får du dine credits :)
Avatar billede dhpii Nybegynder
28. september 2006 - 21:29 #14
fjernede*
Avatar billede nva Praktikant
29. september 2006 - 08:21 #15
Det var en hård nød - nok 'out of my league' hehe, men godt det lykkedes :D
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester