Avatar billede dk_musa Nybegynder
04. oktober 2006 - 21:49 Der er 20 kommentarer og
1 løsning

Trojan Horse

Jeg har for nogle dage siden fået den frygteligste virus. Det er en af typen trojan horse, men det irriterende ved det er, at der hele tiden dukker noget op, der hedder dev.exe og mit virusprogram bliver ved med at melde den samme virus, og uanset hvor mange gange jeg sletter den, kommer den igen og igen. Jeg kan næsten ikke logge på msn længere, da den automatisk sender en adresse til mine kontaktpersoner. Det er adresse med sam22 et eller andet, hvor den spørger, om det er vedkommende der er på billedet. Og den får min computer fuldstændig til at fryse fast. Jeg har prøvet at anvende AVG, men det har ikke givet noget resultat. Heller ikke Hijackthis har givet et resultat. Jeg tror virusen hlnger sammen med noget der hedder Toolbar888, som jeg heller ikke kan fjerne på nogen som helst måder. Håber nogle kan hjælpe mig
Avatar billede levich Nybegynder
04. oktober 2006 - 21:53 #1
Scan med hijackthis og kopier teksten fra loggen herind, så ser jeg på det.
Avatar billede dk_musa Nybegynder
04. oktober 2006 - 21:56 #2
Logfile of HijackThis v1.98.2
Scan saved at 21:56:38, on 04-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe
C:\Documents and Settings\FARUK\Skrivebord\Yinstall.exe
C:\PROGRA~2\PRINTV~1\pvmodule.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\WEATHE~1\Weather.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Programmer\TEXTware\QUICKfind\QFServer.exe
C:\WINDOWS\System32\logon.scr
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Spyware Doctor\swdoctor.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Fælles filer\{2C6C1616-0572-1030-1007-02080101002d}\Update.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\MUSA\Skrivebord\hijackthis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Programmer\Fælles filer\{3C6C1616-0572-1030-1007-02080101002d}\MyToolBar.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programmer\TEXTware\QUICKfind\PlugIns\IEHelp.dll
O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Programmer\Fælles filer\{3C6C1616-0572-1030-1007-02080101002d}\MyToolBar.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Realtime Audio Engine] mmrtkrnl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmer\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\FARUK\Skrivebord\Yinstall.exe
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~2\PRINTV~1\pvmodule.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WeatherCast] C:\PROGRA~1\WEATHE~1\Weather.exe /q
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmer\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msgr.exe" /background
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmer\Fælles filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\programmer\google\google desktop search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: c:\programmer\google\google desktop search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: c:\programmer\google\google desktop search\googledesktopnetwork1.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {53B3ABEA-4445-44D9-A01E-088144CAABD9} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/da/filesharingctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} (Installer Class) - http://activex.matcash.com/speedtest2.dll
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
Avatar billede levich Nybegynder
04. oktober 2006 - 22:00 #3
Du kan hente den nyeste version af hijackthis her: Hent http://www.spychecker.com/program/hijackthis.html.
Installer den og lav en ny log.
Avatar billede dk_musa Nybegynder
04. oktober 2006 - 22:10 #4
Logfile of HijackThis v1.99.1
Scan saved at 22:06:50, on 04-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe
C:\Documents and Settings\FARUK\Skrivebord\Yinstall.exe
C:\PROGRA~2\PRINTV~1\pvmodule.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\WEATHE~1\Weather.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Programmer\TEXTware\QUICKfind\QFServer.exe
C:\WINDOWS\System32\logon.scr
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Spyware Doctor\swdoctor.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Fælles filer\{2C6C1616-0572-1030-1007-02080101002d}\Update.exe
C:\Programmer\WinRAR\WinRAR.exe
C:\DOCUME~1\MUSA\LOKALE~1\Temp\Rar$EX00.213\HijackThis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Programmer\Fælles filer\{3C6C1616-0572-1030-1007-02080101002d}\MyToolBar.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programmer\TEXTware\QUICKfind\PlugIns\IEHelp.dll
O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Programmer\Fælles filer\{3C6C1616-0572-1030-1007-02080101002d}\MyToolBar.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Realtime Audio Engine] mmrtkrnl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmer\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\FARUK\Skrivebord\Yinstall.exe
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~2\PRINTV~1\pvmodule.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WeatherCast] C:\PROGRA~1\WEATHE~1\Weather.exe /q
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmer\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msgr.exe" /background
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmer\Fælles filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {53B3ABEA-4445-44D9-A01E-088144CAABD9} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/da/filesharingctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} (Installer Class) - http://activex.matcash.com/speedtest2.dll
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Programmer\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Programmer\Spyware Doctor\sdhelp.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Programmer\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
Avatar billede dk_musa Nybegynder
04. oktober 2006 - 22:20 #5
er du der ?
Avatar billede levich Nybegynder
04. oktober 2006 - 22:21 #6
Læs alle punkterne inden du gør noget.

(1)
Hent http://www.spywarefri.dk/downloads1/ewido-setup.exe (Ewido).
Installer programmer og opdater det, men vent med at scanne.

(2)
Scan med Ewido, fix de ting som den finder og gem loggen, f.eks. på skrivebordet.

(3)
Genstart computeren i fejlsikret tilstand (tryk F8 når Windows starter op), og fix følgende linjer med HijackThis:
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Programmer\Fælles filer\{3C6C1616-0572-1030-1007-02080101002d}\MyToolBar.dll
O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Programmer\Fælles filer\{3C6C1616-0572-1030-1007-02080101002d}\MyToolBar.dll
O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\FARUK\Skrivebord\Yinstall.exe
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~2\PRINTV~1\pvmodule.exe

(4)
Åbn "denne computer", i menuen skal du klikke på Funktioner -> Mappeindstillinger -> Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler" og ved "Skjul filtypenavne for kendte filtyper", sæt prik i "Vis skjulte filer og mapper". Husk at trykke på knappen "Anvend på alle mapper" i stedet for "ok".

søg efter og slet følgende fil(er):
C:\Programmer\Fælles filer\{3C6C1616-0572-1030-1007-02080101002d}\MyToolBar.dll
C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL
C:\Documents and Settings\FARUK\Skrivebord\Yinstall.exe
C:\PROGRA~2\PRINTV~1\pvmodule.exe

(5)
Start -> kør -> skriv "cleanmgr" -> Slet Temporary internet files, papirkurv og midlertidige filer. Gentag for alle dine drev.

(6)
Genstart computeren normalt. Lav en ny log med HijackThis, og send den herind sammen med loggen fra Ewido.



*****Dette er en note til mig selv, du skal ikke gøre noget ***********
O4 - HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1
Avatar billede levich Nybegynder
04. oktober 2006 - 22:22 #7
I punkt (4) skal denne fil også slettes:
C:\Programmer\Fælles filer\{2C6C1616-0572-1030-1007-02080101002d}\Update.exe
Avatar billede dk_musa Nybegynder
04. oktober 2006 - 22:35 #8
fra trin 3 skal det hele klares i fejlsikret tilstand , ikk ?
Avatar billede levich Nybegynder
04. oktober 2006 - 23:03 #9
jo, alt i fejlsikret tilstand.
Avatar billede levich Nybegynder
04. oktober 2006 - 23:04 #10
Ja, du må undskylde - jeg sidder ikke ved computeren hele tiden.
Avatar billede dk_musa Nybegynder
04. oktober 2006 - 23:58 #11
Mester, jeg bliver nødt til at smutte nu .. Nåede ikke lige helt at blive fæørdig med ewido-scanningen, men annullerede den ved 25% . Den har rettet ca. 170 filer, men laver scanningen og de andre punkter i morgen, hvis det er i orden ? :)
Avatar billede dk_musa Nybegynder
05. oktober 2006 - 18:08 #12
Nu har jeg lavet det hele, og her er logfilen fra hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 18:07:33, on 05-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Spyware Doctor\sdhelp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\HijackThis\HijackThis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programmer\TEXTware\QUICKfind\PlugIns\IEHelp.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Realtime Audio Engine] mmrtkrnl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmer\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmer\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmer\Fælles filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {53B3ABEA-4445-44D9-A01E-088144CAABD9} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/da/filesharingctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} (Installer Class) - http://activex.matcash.com/speedtest2.dll
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Programmer\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Programmer\Spyware Doctor\sdhelp.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Programmer\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)


Hvis du også vil have scanningsrapporten fra Ewido, kan jeg også sende den..

Men jeg har lige et spørgsmål , for jeg har stadigvæk 2 ting på mit skrivebord.. Noget der hedder "b" og noget der hedder "mny". Skal jeg bare slette dem direkte fra skrivebordet, eller hvordan skal jeg komme af med dem ?
Avatar billede levich Nybegynder
05. oktober 2006 - 22:10 #13
Kom lige med Ewido-loggen.
Avatar billede dk_musa Nybegynder
06. oktober 2006 - 17:07 #14
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            17:23:32, 05-10-2006
+ Rapport-Checksum:        59F5EC1F

+ Scanningsresultat:
    C:\Documents and Settings\FARUK\Lokale indstillinger\Temporary Internet Files\Content.IE5\TNF31DGE\drsmartload_js[1].htm -> Downloader.IstBar.j : Renset med backup
    C:\Documents and Settings\FARUK\Lokale indstillinger\Temporary Internet Files\Content.IE5\TNF31DGE\speedtest2[1].dll -> Not-A-Virus.Downloader.Win32.InsTool.a : Renset med backup
    C:\Documents and Settings\FARUK\Lokale indstillinger\Temporary Internet Files\Content.IE5\TNF31DGE\Yinstall[1].mp3 -> Adware.PurityScan : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\Config.xml -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\db -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\db\Aliases.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\db\Sites.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\dwld -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\dwld\WhiteList.xip -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\persist.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\report -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\report\ag.xml -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\report\ag.xml.db -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\report\send.xml -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\report\send.xml.db -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\res2 -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\cs\res2\WhiteList.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1123962355.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124021964.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124028513.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124034926.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124039917.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124043633.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124047233.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124113207.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124124598.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124130694.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124133492.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124196052.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124297196.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124391495.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124631216.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124637680.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124723009.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124740987.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124907489.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124995471.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124996671.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1124999429.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125063793.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125069216.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125165467.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125167537.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125169668.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125237549.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125322435.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125341510.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125414442.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125423400.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125573173.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125588290.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125596048.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125679835.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1125835858.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126007134.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126032922.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126287173.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126360980.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126362339.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126365034.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126546139.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126638569.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126870448.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1126876298.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127044675.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127239929.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127313801.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127380760.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127388243.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127820314.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127827893.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127917645.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1127935421.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128018326.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128082995.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128085666.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128170947.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128179145.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128200522.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128361905.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Application Data\ShopperReports\shprrprt_1128363108.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ad-logics[1].txt -> TrackingCookie.Ad-logics : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ad.adnet[2].txt -> TrackingCookie.Adnet : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@adbrite[2].txt -> TrackingCookie.Adbrite : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@addcontrol[2].txt -> TrackingCookie.Addcontrol : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ads03.bpath[1].txt -> TrackingCookie.Bpath : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@adtech[2].txt -> TrackingCookie.Adtech : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@advertising[1].txt -> TrackingCookie.Advertising : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@as1.falkag[1].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@atdmt[2].txt -> TrackingCookie.Atdmt : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@bfast[2].txt -> TrackingCookie.Bfast : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@bilbo.counted[1].txt -> TrackingCookie.Counted : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@burstnet[1].txt -> TrackingCookie.Burstnet : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@c.enhance[1].txt -> TrackingCookie.Enhance : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@cartoonnetwork.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@casalemedia[2].txt -> TrackingCookie.Casalemedia : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@centrport[1].txt -> TrackingCookie.Centrport : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@com[2].txt -> TrackingCookie.Com : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@doubleclick[1].txt -> TrackingCookie.Doubleclick : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ehg-ladbrokes.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ehg-thebrainyard.hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@euniverseads[1].txt -> TrackingCookie.Euniverseads : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@fastclick[2].txt -> TrackingCookie.Fastclick : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@hg1.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@ilead.itrack[1].txt -> TrackingCookie.Itrack : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@media.fastclick[1].txt -> TrackingCookie.Fastclick : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@overture[2].txt -> TrackingCookie.Overture : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@perf.overture[1].txt -> TrackingCookie.Overture : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@questionmarket[2].txt -> TrackingCookie.Questionmarket : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@revenue[1].txt -> TrackingCookie.Revenue : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@serving-sys[2].txt -> TrackingCookie.Serving-sys : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@spinbox[2].txt -> TrackingCookie.Spinbox : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@stat.onestat[1].txt -> TrackingCookie.Onestat : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@statcounter[1].txt -> TrackingCookie.Statcounter : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@trafficmp[2].txt -> TrackingCookie.Trafficmp : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@valueclick[1].txt -> TrackingCookie.Valueclick : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@webpdp.gator[1].txt -> TrackingCookie.Gator : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@wrigley.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@www.etracker[1].txt -> TrackingCookie.Etracker : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@www7.paypopup[1].txt -> TrackingCookie.Paypopup : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@z1.adserver[1].txt -> TrackingCookie.Adserver : Renset med backup
    C:\Documents and Settings\FATOS\Cookies\fatos@zedo[2].txt -> TrackingCookie.Zedo : Renset med backup
    C:\Documents and Settings\FATOS\drsmartload1135a.exe -> Downloader.Adload.fu : Renset med backup
    C:\Documents and Settings\FATOS\Lokale indstillinger\Temporary Internet Files\Content.IE5\09C70JSZ\popup[1].htm -> Hijacker.Agent.a : Renset med backup
    C:\Documents and Settings\FATOS\Lokale indstillinger\Temporary Internet Files\Content.IE5\ETVWHW7E\drsmartload_js[1].htm -> Downloader.IstBar.j : Renset med backup
    C:\Documents and Settings\FATOS\Lokale indstillinger\Temporary Internet Files\Content.IE5\ETVWHW7E\speedtest2[1].dll -> Not-A-Virus.Downloader.Win32.InsTool.a : Renset med backup
    C:\Documents and Settings\FATOS\Lokale indstillinger\Temporary Internet Files\Content.IE5\GNRZQO95\VVSNI_LOFS120501Inst[1].exe -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\FATOS\Lokale indstillinger\Temporary Internet Files\Content.IE5\RU54T7BB\Yinstall[1].mp3 -> Adware.PurityScan : Renset med backup
    C:\Documents and Settings\FATOS\Lokale indstillinger\Temporary Internet Files\Content.IE5\UG5HN7ZZ\drsmartload1135a[1].exe -> Downloader.Adload.fu : Renset med backup
    C:\Documents and Settings\FATOS\Yinstall.exe -> Adware.PurityScan : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@112.2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ad.adocean[2].txt -> TrackingCookie.Adocean : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@adbrite[2].txt -> TrackingCookie.Adbrite : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ads1.revenue[1].txt -> TrackingCookie.Revenue : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@adtech[1].txt -> TrackingCookie.Adtech : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@advertising[1].txt -> TrackingCookie.Advertising : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@as-us.falkag[1].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@as1.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@atdmt[2].txt -> TrackingCookie.Atdmt : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@b.casalemedia[2].txt -> TrackingCookie.Casalemedia : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@banner.commissionpartner[1].txt -> TrackingCookie.Commissionpartner : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@bfast[2].txt -> TrackingCookie.Bfast : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@bilbo.counted[2].txt -> TrackingCookie.Counted : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@bluestreak[1].txt -> TrackingCookie.Bluestreak : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@burstnet[1].txt -> TrackingCookie.Burstnet : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@c.enhance[1].txt -> TrackingCookie.Enhance : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@casalemedia[1].txt -> TrackingCookie.Casalemedia : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@centrport[2].txt -> TrackingCookie.Centrport : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@com[2].txt -> TrackingCookie.Com : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@counter13.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@counter15.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@counter7.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@doubleclick[2].txt -> TrackingCookie.Doubleclick : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@e-2dj6wjkosld5wgp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@edge.ru4[1].txt -> TrackingCookie.Ru4 : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ehg-edgebe.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ehg-mtv.hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ehg-nokiafin.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ehg-sonycomputer.hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ehg-thebrainyard.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@euniverseads[1].txt -> TrackingCookie.Euniverseads : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@fastclick[1].txt -> TrackingCookie.Fastclick : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@findwhat[1].txt -> TrackingCookie.Findwhat : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@free.wegcash[2].txt -> TrackingCookie.Wegcash : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@gde.adocean[2].txt -> TrackingCookie.Adocean : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@image.masterstats[1].txt -> TrackingCookie.Masterstats : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ivwbox[2].txt -> TrackingCookie.Ivwbox : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@komtrack[2].txt -> TrackingCookie.Komtrack : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@media.fastclick[1].txt -> TrackingCookie.Fastclick : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@overture[1].txt -> TrackingCookie.Overture : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@paycounter[1].txt -> TrackingCookie.Paycounter : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@perf.overture[1].txt -> TrackingCookie.Overture : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@ppms.popularix[2].txt -> TrackingCookie.Popularix : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@pro-market[2].txt -> TrackingCookie.Pro-market : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@qksrv[2].txt -> TrackingCookie.Qksrv : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@questionmarket[2].txt -> TrackingCookie.Questionmarket : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@revenue[2].txt -> TrackingCookie.Revenue : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@server3.web-stat[2].txt -> TrackingCookie.Web-stat : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@serving-sys[2].txt -> TrackingCookie.Serving-sys : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@sexlist[2].txt -> TrackingCookie.Sexlist : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@sonymediasoftware.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@spylog[2].txt -> TrackingCookie.Spylog : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@stat.onestat[2].txt -> TrackingCookie.Onestat : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@statcounter[2].txt -> TrackingCookie.Statcounter : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@targetnet[2].txt -> TrackingCookie.Targetnet : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@trafic[1].txt -> TrackingCookie.Trafic : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@valueclick[1].txt -> TrackingCookie.Valueclick : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@valueclick[2].txt -> TrackingCookie.Valueclick : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@web-stat[1].txt -> TrackingCookie.Web-stat : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@webpdp.gator[1].txt -> TrackingCookie.Gator : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@webstat[2].txt -> TrackingCookie.Web-stat : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@www.burstnet[1].txt -> TrackingCookie.Burstnet : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@www.etracker[2].txt -> TrackingCookie.Etracker : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@www.holdem.com.18345.fb.dbbsrv[1].txt -> TrackingCookie.Dbbsrv : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@z1.adserver[2].txt -> TrackingCookie.Adserver : Renset med backup
    C:\Documents and Settings\MUSA\Cookies\musa@zedo[2].txt -> TrackingCookie.Zedo : Renset med backup
    C:\Documents and Settings\MUSA\Lokale indstillinger\Temp\saveinstwm.exe/VVSN.exe -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\Lokale indstillinger\Temp\saveinstwm.exe/VVSN.exe -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\Lokale indstillinger\Temporary Internet Files\Content.IE5\CRDZE6F5\passchk[1].exe/dev.exe -> Backdoor.VanBot.s : Renset med backup
    C:\Documents and Settings\MUSA\Lokale indstillinger\Temporary Internet Files\Content.IE5\D7RJHHGE\Yinstall[1].mp3 -> Adware.PurityScan : Renset med backup
    C:\Documents and Settings\MUSA\Lokale indstillinger\Temporary Internet Files\Content.IE5\D7RJHHGE\Yinstall[2].mp3 -> Adware.PurityScan : Renset med backup
    C:\Documents and Settings\MUSA\Lokale indstillinger\Temporary Internet Files\Content.IE5\QTN4LCRM\drsmartload1135a[1].exe -> Downloader.Adload.fu : Renset med backup
    C:\Documents and Settings\MUSA\Lokale indstillinger\Temporary Internet Files\Content.IE5\QTN4LCRM\drsmartload_js[2].htm -> Downloader.IstBar.j : Renset med backup
    C:\Documents and Settings\MUSA\Menuen Start\Programmer\WeatherCast -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\Menuen Start\Programmer\WeatherCast\WeatherCast.lnk -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\Menuen Start\Programmer\WhenU -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\Menuen Start\Programmer\WhenU\Learn More About Save!.url -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\Menuen Start\Programmer\WhenU\Learn More About SaveNow.url -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\Menuen Start\Programmer\WhenU\WhenU.com Website.url -> Adware.SaveNow : Renset med backup
    C:\Documents and Settings\MUSA\passchk.exe/dev.exe -> Backdoor.VanBot.s : Renset med backup
    C:\Documents and Settings\MUSA\Skrivebord\passchk.exe/dev.exe -> Backdoor.VanBot.s : Renset med backup
    C:\Documents and Settings\MUSA\Skrivebord\Yinstall.exe -> Adware.PurityScan : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\Config.xml -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\db -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\db\Aliases.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\db\Sites.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\dwld -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\dwld\WhiteList.xip -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\persist.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\report -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\report\ag.xml -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\report\ag.xml.db -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\report\send.xml -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\report\send.xml.db -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\res2 -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\cs\res2\WhiteList.dbs -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1124216990.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1124453835.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1125171150.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1125173454.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1125251113.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1125336590.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1125409650.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1125583092.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1125743360.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1126026683.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1126275940.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1126433434.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1126940848.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1127309981.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1127410323.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1127595531.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1127599693.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1128000777.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1128091562.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1128098837.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1128260140.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Application Data\ShopperReports\shprrprt_1128348337.log -> Adware.HotBar : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@247realmedia[1].txt -> TrackingCookie.247realmedia : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@a.as-us.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@ad-logics[1].txt -> TrackingCookie.Ad-logics : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@adtech[1].txt -> TrackingCookie.Adtech : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@advertising[2].txt -> TrackingCookie.Advertising : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@as-us.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@as1.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@atdmt[2].txt -> TrackingCookie.Atdmt : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@bilbo.counted[2].txt -> TrackingCookie.Counted : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@bluestreak[1].txt -> TrackingCookie.Bluestreak : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@burstnet[1].txt -> TrackingCookie.Burstnet : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@casalemedia[1].txt -> TrackingCookie.Casalemedia : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@centrport[1].txt -> TrackingCookie.Centrport : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@commissionpartner[2].txt -> TrackingCookie.Commissionpartner : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@com[1].txt -> TrackingCookie.Com : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter10.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter11.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter12.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter13.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter14.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter15.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter2.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter3.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter4.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter5.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter6.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter7.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter8.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@counter9.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@doubleclick[1].txt -> TrackingCookie.Doubleclick : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@ehg-interlifeform.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@ehg-newsinternational.hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@ehg-playboy.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@euniverseads[1].txt -> TrackingCookie.Euniverseads : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@fastclick[1].txt -> TrackingCookie.Fastclick : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@hg1.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@ilead.itrack[1].txt -> TrackingCookie.Itrack : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@image.masterstats[1].txt -> TrackingCookie.Masterstats : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@kmpads[1].txt -> TrackingCookie.Kmpads : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@media.fastclick[1].txt -> TrackingCookie.Fastclick : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@paycounter[1].txt -> TrackingCookie.Paycounter : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@perf.overture[1].txt -> TrackingCookie.Overture : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@pro-market[2].txt -> TrackingCookie.Pro-market : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@questionmarket[1].txt -> TrackingCookie.Questionmarket : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@revenue[2].txt -> TrackingCookie.Revenue : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@server3.web-stat[2].txt -> TrackingCookie.Web-stat : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@serving-sys[1].txt -> TrackingCookie.Serving-sys : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@sexlist[1].txt -> TrackingCookie.Sexlist : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@statcounter[2].txt -> TrackingCookie.Statcounter : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@trafficmp[2].txt -> TrackingCookie.Trafficmp : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@valueclick[2].txt -> TrackingCookie.Valueclick : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@valueclick[3].txt -> TrackingCookie.Valueclick : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@vip.clickzs[2].txt -> TrackingCookie.Clickzs : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@webpdp.gator[2].txt -> TrackingCookie.Gator : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@xxxcounter[2].txt -> TrackingCookie.Xxxcounter : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Cookies\süleyman@z1.adserver[2].txt -> TrackingCookie.Adserver : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\drsmartload1135a.exe -> Downloader.Adload.fu : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Lokale indstillinger\Temporary Internet Files\Content.IE5\EQY9P942\speedtest2[1].dll -> Not-A-Virus.Downloader.Win32.InsTool.a : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Lokale indstillinger\Temporary Internet Files\Content.IE5\F71PPD9I\drsmartload1135a[1].exe -> Downloader.Adload.fu : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Lokale indstillinger\Temporary Internet Files\Content.IE5\TKP575LF\drsmartload_js[1].htm -> Downloader.IstBar.j : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Lokale indstillinger\Temporary Internet Files\Content.IE5\Y7CZ52B6\Yinstall[1].mp3 -> Adware.PurityScan : Renset med backup
    C:\Documents and Settings\SÜLEYMAN\Yinstall.exe -> Adware.PurityScan : Renset med backup
    C:\Programmer\Adverts\uninst.exe -> Adware.Lop : Renset med backup
    C:\Programmer\BearShare\Installer\saveinstwm.exe/VVSN.exe -> Adware.SaveNow : Renset med backup
    C:\Programmer\BearShare\Installer\saveinstwm.exe/VVSN.exe -> Adware.SaveNow : Renset med backup
    C:\Programmer\Save -> Adware.SaveNow : Renset med backup
    C:\Programmer\Save\save.db -> Adware.SaveNow : Renset med backup
    C:\Programmer\Save\Save.exe -> Adware.SaveNow : Renset med backup
    C:\Programmer\Save\save.htm -> Adware.SaveNow : Renset med backup
    C:\Programmer\Save\SaveUninst.exe -> Adware.SaveNow : Renset med backup
    C:\Programmer\Save\store.db -> Adware.SaveNow : Renset med backup
    C:\Programmer\WeatherCast -> Adware.SaveNow : Renset med backup
    C:\Programmer\WeatherCast\Uninst.exe -> Adware.SaveNow : Renset med backup
    C:\Programmer\WeatherCast\Weather.exe -> Adware.SaveNow : Renset med backup
    C:\Programmer\WeatherCast\weatherupdate.exe -> Adware.SaveNow : Renset med backup
    C:\RECYCLER\S-1-5-21-1409082233-113007714-1060284298-1004\Dc155.exe -> Adware.Trymedia : Renset med backup
    C:\RECYCLER\S-1-5-21-1409082233-113007714-1060284298-1004\Dc157.exe -> Adware.Trymedia : Renset med backup
    C:\RECYCLER\S-1-5-21-1409082233-113007714-1060284298-1004\Dc159.exe -> Adware.Trymedia : Renset med backup
    C:\RECYCLER\S-1-5-21-1409082233-113007714-1060284298-1004\Dc161.exe -> Adware.Trymedia : Renset med backup
    C:\RECYCLER\S-1-5-21-1409082233-113007714-1060284298-1004\Dc162.exe -> Adware.Trymedia : Renset med backup
    C:\RECYCLER\S-1-5-21-1409082233-113007714-1060284298-1005\Dc15.exe -> Adware.Trymedia : Renset med backup
    C:\WINDOWS\system32\bpk.exe -> Not-A-Virus.Monitor.Win32.Perflogger.ad : Renset med backup
    C:\WINDOWS\system32\bpkwb.dll -> Logger.Perfloger.i : Renset med backup


::Rapport slut
Avatar billede levich Nybegynder
07. oktober 2006 - 21:53 #15
Jeg har fundet et værktøj, som kan fjerne det der "mny":
http://fileinfo.prevx.com/fileinfo.asp?PXC=9fad42944537
Tryk på download for at hente programmet. Installer det og kør programmet.

Bagefter opdater dit antivirusprogram (avg), og lav en fuld scanning af alle dine harddiske.
Avatar billede dk_musa Nybegynder
11. oktober 2006 - 15:33 #16
Levich , du må undskylde at jeg er lidt langsom , men har her i de sidste dage overhoved ikke haft tid til noget som helst .. Jeg har downloaded det der PrevX og har også fået fjernet mny , så jeg mangler bare lige at opdatere og scanne med AVG, som jeg får ordnet i morgen
Avatar billede levich Nybegynder
11. oktober 2006 - 17:42 #17
Der var både "mny" og "b" på dig skrivebord. Er de begge væk?

Desuden, er de andre problemer som du havde væk?
Avatar billede dk_musa Nybegynder
12. oktober 2006 - 19:15 #18
Altså det der b fik jeg væk med ewido .. Og det der mny fik jeg væk med det program du sendte.. Og virusen er også stoppet med at dukke op og blive sendt automatisk til mine kontaktpersoner på msn..
Jeg har også lige lavet scanningen med AVG, og den fandt ingen virus.. Så jeg håber det er overstået nu .. Men indimellem dukker der et pop-up fra AVG eller PrevX, hvor der står, at den har fundet en virus, som jeg får slettet.. Men det overrasker mig bare, at testen siger 0 virus, når der kommer de der pop-ups..
Og har også lige et andet spørgsmål. Var lige inde og tjekke programlisten under kontrolpanel, og i listen stod der stadigvæk ToolBar888 , skal jeg bare slette den fra listen ?
Avatar billede levich Nybegynder
12. oktober 2006 - 21:04 #19
Ja, slet endelig Toolbar888 fra listen. Den er sikker slettet fra harddisken, selv om de står på listen under tilføj/fjern programmer.
Avatar billede dk_musa Nybegynder
15. oktober 2006 - 00:13 #20
Okay , tak for hjælpen
Avatar billede dk_musa Nybegynder
15. oktober 2006 - 00:13 #21
Hvo
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester