Avatar billede sbpweb.dk Nybegynder
02. januar 2007 - 18:40 Der er 16 kommentarer og
1 løsning

HiJackThis log

Vil nogen tjekke denne log igennem?

----
Logfile of HijackThis v1.99.1
Scan saved at 18:38:23, on 02-01-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmer\fælles filer\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Windows Media Player\WMPNSCFG.exe
C:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
C:\Programmer\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\Documents and Settings\Administrator\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.unoeuro.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programmer\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programmer\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmer\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Send til &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O15 - Trusted Zone: http://www.sf-anytime.com
O15 - Trusted Zone: http://www.trendsales.dk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Programmer\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Insight Web Agent (cpqWebDmi) - Hewlett-Packard Company - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Remote Diagnostics Enabling Agent (DfwWebAgent) - Hewlett-Packard - C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\SHARED\HPQWMI.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmer\fælles filer\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Programmer\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
02. januar 2007 - 20:42 #1
... oplever du nogle problemer ?
Avatar billede sbpweb.dk Nybegynder
02. januar 2007 - 21:28 #2
Ja, uønskede popups i Internet Explorer, selvom popup-blokeringen er slået til. For at afhjælpe problemet installerede jeg Ad-Aware og Spybot, skannede systemet med begge, og slettede de ting de fandt. Jeg tror det har hjulpet meget, men der kommer stadig popups.
02. januar 2007 - 21:37 #3
Følg guiden herfra ->
http://www.eksperten.dk/artikler/1021
Avatar billede sbpweb.dk Nybegynder
02. januar 2007 - 21:46 #4
Computeren har ikke MSN Messenger installeret, men Windows Messenger. Kan det alligevel have nogen effekt at følge guiden?
02. januar 2007 - 22:06 #5
Ja ...
(Der kan godt skjule sig elementer som ikke umiddelbart fremgår af en HiJackThis Log...)
02. januar 2007 - 22:07 #6
... hvilke former for uønskede popups ?
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 17:31 #8
Jeg har fulgt guiden fra http://www.eksperten.dk/artikler/1021 og herefter følger mine logfiler.
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 17:32 #9
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            17:07:24, 23-02-2007
+ Report-Checksum:        DF64D8F1

+ Scan result:

    HKLM\SOFTWARE\Classes\CLSID\{1DC1FA5E-773D-11D3-9F9F-006097A7311B} -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{1DC1FA5E-773D-11D3-9F9F-006097A7311B}\TypeLib\\ -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\FlexActive.FlexActive -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\FlexActive.FlexActive\CurVer -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\FlexActive.FlexActive.1 -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\FlexActive.FlexActive.1\CLSID\\ -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{1DC1FA5D-773D-11D3-9F9F-006097A7311B} -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{1DC1FA5D-773D-11D3-9F9F-006097A7311B}\TypeLib\\ -> Spyware.TimeSink : Cleaned with backup
    HKLM\SOFTWARE\Classes\TypeLib\{1DC1FA50-773D-11D3-9F9F-006097A7311B} -> Spyware.TimeSink : Cleaned with backup
    C:\Documents and Settings\Administrator\Cookies\administrator@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Marie backup\Administrator\Cookies\administrator@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP100\A0009253.exe -> Heuristic.Win32.AVKiller : Cleaned with backup
    C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP107\A0012635.exe -> Heuristic.Win32.AVKiller : Cleaned with backup
    C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP109\A0013002.dll -> Spyware.TimeSink : Cleaned with backup
    C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP83\A0007062.exe -> Heuristic.Win32.AVKiller : Cleaned with backup
    C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP91\A0007454.exe -> Heuristic.Win32.AVKiller : Cleaned with backup
    C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP95\A0009002.#xe -> Spyware.TimeSink : Cleaned with backup
    C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP95\A0009003.#ll -> Spyware.TimeSink : Cleaned with backup
    C:\WINDOWS\system32\MRT.exe -> Heuristic.Win32.AVKiller : Cleaned with backup
    C:\WINDOWS\TSAd.#ll -> Spyware.TimeSink : Cleaned with backup


::Report End
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 17:34 #10
SUPERAntiSpyware Scan Log
Generated 02/23/2007 at 03:05 PM

Application Version : 3.5.1016

Core Rules Database Version : 3188
Trace Rules Database Version: 1198

Scan type      : Complete Scan
Total Scan Time : 00:32:46

Memory items scanned      : 182
Memory threats detected  : 0
Registry items scanned    : 4428
Registry threats detected : 0
File items scanned        : 22720
File threats detected    : 75

Adware.Tracking Cookie
    C:\Documents and Settings\Administrator\Cookies\administrator@stat.postdanmark[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@www.webstat[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@www.searchenginetracking[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@adtech[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@ads.realtechnetwork[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@www.statssheet[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@partypoker[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@52412438[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@1071427968[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@1064398213[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@1072704879[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@bannere.fyens[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@kanoodle[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@48709310[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@komtrack[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@7372395[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@e2.emediate[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@cassava[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@cgi-bin[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@1071596268[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@18766632[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@cpvfeed[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@indextools[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@stats.drivecleaner[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@text.burstnet[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@server.iad.liveperson[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@dk.drivecleaner[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@76711721[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@ad1.emediate[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@www.burstnet[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@ads2.jubii[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@publishers.clickbooth[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@track.adform[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@www.sexlinien[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@tracking.notabenestats[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@ilead.itrack[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@drivecleaner[2].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@m1.webstats4u[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@888[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@xtendmedia[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@cgi-bin[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@stats[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@tradersclub_click_2006_03[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@ad1.emediate[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@ads.as4x.tmcs[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@ads.realtechnetwork[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@ads2.jubii[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@adtech[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@bannere.fyens[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@cassava[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@cpvfeed[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@e2.emediate[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@ilead.itrack[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@indextools[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@kanoodle[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@komtrack[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@m1.webstats4u[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@partypoker[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@publishers.clickbooth[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@server.iad.liveperson[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@stat.postdanmark[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@stats.drivecleaner[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@stats[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@tacoda[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@text.burstnet[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@track.adform[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@tracking.notabenestats[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@tradersclub_click_2006_03[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@www.burstnet[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@www.searchenginetracking[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@www.sexlinien[2].txt
    C:\Marie backup\Administrator\Cookies\administrator@www.statssheet[1].txt
    C:\Marie backup\Administrator\Cookies\administrator@xtendmedia[1].txt
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 17:37 #11
SUPERAntiSpyware bad mig om at genstarte da den viste mig opsummeringen. Efter genstarten i fejlsikret tilstand åbnede jeg igen SUPERAntiSpyware og slettede alle de fundne infektioner.
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 17:37 #12
DrWeb log:

dsaoms.dll;c:\windows\system32;Adware.Cydoor;;
Ace Animated Cartoon Email 2.09.exe;C:\Documents and Settings\Administrator\Skrivebord;Adware.TimeSink;Renamed.;
Ace Animated Cartoon Email 2.09.exe;C:\Marie backup\Administrator\Skrivebord;Adware.TimeSink;Renamed.;
A0012999.exe;C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP109;Adware.TimeSink;Renamed.;
A0013000.exe;C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP109;Adware.TimeSink;Renamed.;
A0009002.exe;C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP95;Adware.TimeSink;Renamed.;
A0009003.dll;C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP95;Adware.TimeSink;Renamed.;
A0009006.exe;C:\System Volume Information\_restore{20DF02B9-73FA-413E-8F6A-D10BB86465FF}\RP95;Adware.TimeSink;Renamed.;
flexactv.dll;C:\WINDOWS;Adware.TimeSink;Renamed.;
TSAd.dll;C:\WINDOWS;Adware.TimeSink;Renamed.;
dsaoms.dll;C:\WINDOWS\system32;Adware.Cydoor;Renamed.;
wkcajax.dll;C:\WINDOWS\system32;Adware.Cserz;Renamed.;
~isdrt.tmp;C:\WINDOWS\system32;Adware.Bho;Renamed.;
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 17:39 #13
Logfile of HijackThis v1.99.1
Scan saved at 17:39:07, on 23-02-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmer\fælles filer\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
C:\Programmer\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Windows Media Player\WMPNSCFG.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe
C:\Programmer\Skype\Plugin Manager\SkypePM.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Skrivebord\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.unoeuro.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Programmer\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Programmer\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmer\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: BTTray.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Programmer\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Insight Web Agent (cpqWebDmi) - Hewlett-Packard Company - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Remote Diagnostics Enabling Agent (DfwWebAgent) - Hewlett-Packard - C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\SHARED\HPQWMI.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmer\fælles filer\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Programmer\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
23. februar 2007 - 18:09 #14
... og hvordan kører putter så nu ?
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 20:12 #15
Den kører fint. Så hvis der ikke er noget i HiJackthis loggen, så er det vel fint?
Som sagt, så bad SuperAntiSpyware om genstart efter scanningen, hvilket jeg gjorde. Det betyder at jeg ikke helt kunne følge guiden trin omkring SuperAntiSpyware. Gør det noget? Som også nævnt, så slettede jeg efter genstarten alle de ting SuperAntiSpyware havde fundet.
23. februar 2007 - 20:37 #16
Du er velkommen en anden gang...

Åbn en mappe, klik på Funktioner >Mappeindstillinger >Vis.
Sæt flueben ved "Skjul beskyttede operativsystemfiler".
Sæt prik i "Vis ikke skjulte filer og mapper".

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...
Avatar billede sbpweb.dk Nybegynder
23. februar 2007 - 21:04 #17
Tusind tak for hjælpen!
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester