Ewido har fundet 4 som den har sat i karantæne.
Der står: spyware.cookie.adtich
spyware.cookie.adv...
spyware.cookie.medi...
spyware.cookie.medi...
Jeg har forsøgt at fjerne dem, men når jeg starter pcén på ny så er de der igen.
Jeg har lige lagt en frisk hijack.
Logfile of HijackThis v1.99.1
Scan saved at 10:21:19, on 28-02-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\SYSTEM32\DWRCS.EXE
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmer\oracle\ora92\bin\omtsreco.exe
C:\Programmer\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Programmer\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Programmer\Sophos\AutoUpdate\ALsvc.exe
C:\Programmer\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\DWRCST.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Sophos\AutoUpdate\ALMon.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\ewido anti-malware\SecuritySuite.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\TEMP\sophos_autoupdate1.dir\alupdate.exe
C:\Documents and Settings\mom\Skrivebord\Ole´s\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.dk/ieR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.sdu.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.sdu.dk/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by IT-service
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [lycosInside] C:\Programmer\lycos\Lyc_SysTray.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Programmer\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Programmer\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Programmer\PTPNDFLS\PTPNDFLS.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sdu.dk/
O15 - Trusted Zone: *.csc.dk
O15 - Trusted Zone:
http://*.csc.dkO15 - Trusted Zone: *.e-boks.dk
O15 - Trusted Zone:
http://*.e-boks.dkO15 - Trusted Zone:
http://guard.group4login.comO15 - Trusted Zone: *.group4login.com
O15 - Trusted Zone: *.group5login.com
O15 - Trusted Zone: *.oes.dk
O15 - Trusted Zone:
http://*.oes.dkO15 - Trusted Zone: *.regionsyddanmark.dk
O15 - Trusted Zone:
http://info.adm.sdu.dkO15 - Trusted Zone:
http://intern.sdu.dkO15 - Trusted Zone:
http://nova.adm.sdu.dkO15 - Trusted Zone: *.sdu.dk
O15 - Trusted Zone:
http://*.sdu.dkO15 - Trusted Zone: *.sdu.tradebuilder.dk
O15 - Trusted Zone: *.csc.dk (HKLM)
O15 - Trusted Zone: *.e-boks.dk (HKLM)
O15 - Trusted Zone: *.group4login.com (HKLM)
O15 - Trusted Zone: *.group5login.com (HKLM)
O15 - Trusted Zone: *.oes.dk (HKLM)
O15 - Trusted Zone: *.regionsyddanmark.dk (HKLM)
O15 - Trusted Zone: *.sdu.dk (HKLM)
O15 - Trusted Zone: *.sdu.tradebuilder.dk (HKLM)
O15 - Trusted IP range: 212.180.59.8
O15 - Trusted IP range: 212.180.59.8 (HKLM)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138529092078O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
http://www.kortal.dk/ecwplugins/ncs.cabO16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) -
http://scanner.virus112.com/cabs/cssweb.cabO16 - DPF: {CAFECAFE-0013-0001-0024-ABCDEFABCDEF} (JInitiator 1.3.1.24) -
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adm.c.sdu.dk
O17 - HKLM\Software\..\Telephony: DomainName = adm.c.sdu.dk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = adm.c.sdu.dk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = adm.c.sdu.dk
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\Programmer\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\Programmer\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Programmer\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Programmer\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos Agent - Unknown owner - C:\Programmer\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Programmer\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Unknown owner - C:\Programmer\Sophos\Remote Management System\RouterNT.exe" -service -name Router -ORBListenEndpoints
iiop://:8193/ssl_port=8194 (file missing)