Fjernelse af Spylocked på Windows 98
Hej, min første gang som bruger, så håber virkelig at i kan være til hjælp.Har kigget lidt på artiklerne omkring hvordan man fjerner Spylocked. Har kommet til at få det ind på min fars lettere ældre Pc og der er en verden til forskel på de log's jeg ser i de andre artikler her på siden, og så til mine.
Men her kommer de:
SUPERAntiSpyware Scan Log
Generated 05/18/2007 at 02:57 PM
Application Version : 3.5.1016
Core Rules Database Version : 3240
Trace Rules Database Version: 1251
Scan type : Complete Scan
Total Scan Time : 00:22:31
Memory items scanned : 60
Memory threats detected : 0
Registry items scanned : 1756
Registry threats detected : 12
File items scanned : 6282
File threats detected : 4
Adware.Tracking Cookie
C:\WINDOWS\Cookies\verner og co.@track.adform[2].txt
C:\WINDOWS\Cookies\verner og co.@adtech[2].txt
C:\WINDOWS\Cookies\verner og co.@www.spylocked[2].txt
Malware.SpyLocked
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\CLSID
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\InprocServer32
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\InprocServer32#ThreadingModel
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\ProgID
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\Thjp
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\flEyb
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\gtyimtnK
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\jkEeamlti
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\gkeW
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\efaA
HKCR\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}\UxdvrXbzXek
Trojan.Smitfraud Variant
C:\WINDOWS\SYSTEM\KGKDBSK.DLL
Og
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:22:47, on 19-05-07
Platform: Windows 98 SE (Win9x 4.10.2222A)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\HPZTSB04.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.02.0002.1001\DA\MSNAPPAU.EXE
C:\THORKIL\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMER\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\DRWATSON.EXE
C:\PROGRAMMER\INTERNET EXPLORER\IEXPLORE.EXE
C:\THORKIL\HIJACKTHIS_V2.EXE
R1 - HKLM\Software\Microsoft\Internet explorer\Main,Default_Page_URL = http://tdconline.dk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer leveret af TDC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\DA\MSNTB.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\DA\MSNTB.DLL
O4 - HKLM\..\Run: [Skan registreringsdatabase] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [Job-oversigt] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb04.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [msnappau] "c:\program files\MSN Apps\Updater\01.02.0002.1001\da\msnappau.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Planlægningsagent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\THORKIL\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O4 - HKUS\.DEFAULT\..\Run: [SUPERAntiSpyware] C:\THORKIL\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE (User 'Default user')
O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE (User 'Default user')
O4 - .DEFAULT Startup: PowerReg Scheduler.exe (User 'Default user')
O4 - Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Startup: PowerReg Scheduler.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://tdconline.dk
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5032/mcfscan.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\SYSTEM\BROWSEUI.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\SYSTEM\BROWSEUI.DLL
--
End of file - 3613 bytes