Avatar billede natman Nybegynder
10. juli 2007 - 21:37 Der er 3 kommentarer og
1 løsning

HiJackthis logfil og andet.

Efter mange timers forsøg på at rense min lillesøsters PC beder jeg Jer om at kigge på om jeg nu også har renset den ordenligt.
Her er logfiler fra hhv. drweb, superantispyware og hijackthis:

DRWEB:

ipv6mons.dll;f:\windows\system32;Trojan.PWS.Tanspy;Will be cured after reboot.;
i19C.#mp;C:\Documents and Settings\Mor.3200MHZ\Lokale indstillinger\Temp;Adware.Surfside;Deleted.;
un35E.#mp;C:\Documents and Settings\Mor.3200MHZ\Lokale indstillinger\Temp;Adware.Surfside;Deleted.;
A0279202.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP61;Adware.Cdn;Deleted.;
A0279203.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP61;Adware.Cdn;Deleted.;
A0285345.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP62;Adware.Cnshel;Deleted.;
A0300402.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP64;Adware.Cdn;Deleted.;
A0311485.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP65;Adware.Cdn;Deleted.;
A0329501.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP65;Adware.Cdn;Deleted.;
A0329513.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP65;Adware.Cdn;Deleted.;
A0329514.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP65;Adware.Cdn;Deleted.;
A0329515.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP65;Adware.Cnshel;Deleted.;
A0343685.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP70;Adware.Cdn;Deleted.;
A0343686.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP70;Adware.Cdn;Deleted.;
A0343687.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP70;Adware.Cdn;Deleted.;
A0344947.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP70;Adware.Cdn;Deleted.;
A0357027.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74;Adware.Surfside;Deleted.;
A0357028.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74;Adware.Surfside;Deleted.;
A0357029.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74;Adware.Surfside;Deleted.;
A0359034.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74;Adware.FastSearch;Deleted.;
A0359037.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74;Adware.DollarRevenue;Deleted.;
A0365060.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP76;Adware.FastSearch;Deleted.;
A0365063.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP76;Adware.DollarRevenue;Deleted.;
A0365073.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP76;Adware.Softomate;Deleted.;
A0366107.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP77;Adware.Cdn;Deleted.;
A0366111.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP77;Adware.Cdn;Deleted.;
A0366116.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP77;Adware.Cdn;Deleted.;
A0367081.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP78;Adware.Cdn;Deleted.;
A0376118.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP80;Adware.Cdn;Deleted.;
A0376119.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP80;Adware.Cdn;Deleted.;
A0386217.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81;Adware.Zango;Deleted.;
A0386218.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81;Adware.Zango;Deleted.;
A0386219.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81;Adware.Zango;Deleted.;
A0387150.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81;Adware.Hotbar;Deleted.;
A0388227.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP83;Adware.Zango;Deleted.;
A0391265.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP84;Adware.Softomate;Deleted.;
A0402366.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP84;Adware.Cdn;Deleted.;
A0404370.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP84;Adware.Cdn;Deleted.;
A0413367.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.Cdn;Deleted.;
A0415364.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.Cdn;Deleted.;
A0423367.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.PrintView;Deleted.;
A0423368.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.PrintView;Deleted.;
A0425362.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.Cdn;Deleted.;
A0432365.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.Cdn;Deleted.;
A0434369.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.Runk;Deleted.;
A0440350.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.Cdn;Deleted.;
A0445315.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86;Adware.Cnshel;Deleted.;
A0462396.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP87;Adware.Comet;Deleted.;
A0462852.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP87;Tool.ProcessKill;Renamed.;
A0462853.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP87;Tool.ProcessKill;Renamed.;
A0462854.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP87;Tool.ProcessKill;Renamed.;
A0462950.#ys;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.Cdn;Deleted.;
A0463103.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.TryMedia;Deleted.;
A0463110.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.DollarRevenue;Deleted.;
A0463111.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.DollarRevenue;Deleted.;
A0463113.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.Ucmore;Deleted.;
A0463114.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.Look2me;Deleted.;
A0463368.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.Comet;Deleted.;
A0463377.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.Surfside;Deleted.;
A0463378.#ll;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.Surfside;Deleted.;
A0463379.#xe;C:\System Volume Information\_restore{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88;Adware.Surfside;Deleted.;
A0124811.dll;C:\System Volume Information\_restore{5F10E55D-D3EE-45C7-8633-8E568E426AD6}\RP51;Trojan.Proxy.493;Deleted.;
A0124812.exe;C:\System Volume Information\_restore{5F10E55D-D3EE-45C7-8633-8E568E426AD6}\RP51;Trojan.Proxy.493;Deleted.;
A0124816.exe;C:\System Volume Information\_restore{5F10E55D-D3EE-45C7-8633-8E568E426AD6}\RP51;Adware.Zango;Deleted.;
mhyp.#xe;C:\WINDOWS;Adware.Zango;Deleted.;
A0124741.#ll;F:\System Volume Information\_restore{5F10E55D-D3EE-45C7-8633-8E568E426AD6}\RP51;Adware.Softomate;Deleted.;
A0124813.exe;F:\System Volume Information\_restore{5F10E55D-D3EE-45C7-8633-8E568E426AD6}\RP51;BackDoor.IRC.Sdbot.901;Deleted.;
A0124814.exe;F:\System Volume Information\_restore{5F10E55D-D3EE-45C7-8633-8E568E426AD6}\RP51;BackDoor.IRC.Sdbot.901;Deleted.;
A0124815.exe;F:\System Volume Information\_restore{5F10E55D-D3EE-45C7-8633-8E568E426AD6}\RP51;Win32.HLLW.MyBot.based;Deleted.;
ipv6mons.dll;F:\WINDOWS\system32;Trojan.PWS.Tanspy;Will be cured after reboot.;


SUPERANTISPYWARE:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/10/2007 at 09:19 PM

Application Version : 3.9.1008

Core Rules Database Version : 3267
Trace Rules Database Version: 1278

Scan type      : Quick Scan
Total Scan Time : 00:28:09

Memory items scanned      : 284
Memory threats detected  : 0
Registry items scanned    : 519
Registry threats detected : 7
File items scanned        : 40904
File threats detected    : 233

Unclassified.Unknown Origin
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73364D99-1240-4dff-B12A-67E448373148}
    HKCR\CLSID\{73364D99-1240-4DFF-B12A-67E448373148}
    HKCR\CLSID\{73364D99-1240-4DFF-B12A-67E448373148}\InprocServer32
    HKCR\CLSID\{73364D99-1240-4DFF-B12A-67E448373148}\InprocServer32#ThreadingModel
    HKCR\CLSID\{73364D99-1240-4DFF-B12A-67E448373148}\InprocServer32#Enable Browser Extensions
    F:\WINDOWS\SYSTEM32\IPV6MONS.DLL
    HKCR\CLSID\{73364D99-1240-4DFF-B12A-67E448373148}

Adware.Tracking Cookie
    F:\Documents and Settings\Mirella\Cookies\mirella@2o7[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@spylog[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@kanoodle[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adrevolver[3].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@mdlfr[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@fastclick[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@realmedia[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@image.masterstats[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@16847762[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adbrite[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@hitbox[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@msnaccountservices.112.2o7[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@doubleclick[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@1070148968[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.cartoonnetwork[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@estat[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ehg-groupernetworks.hitbox[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@zedo[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@as1.falkag[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adopt.specificclick[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@toplist[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adultfriendfinder[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@teentrendsgirls.everythinggirl[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ad.ofir[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@3.adbrite[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@hc2.humanclick[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@jobzonen.112.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@cgi-bin[4].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@sixapart.112.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ad1.emediate[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@tradedoubler[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@6736109[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@goclick[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@sextracker[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.bostonwebproperties[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@tribalfusion[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adfair[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@www.smartadserver[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@4.adbrite[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@questionmarket[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@bs.serving-sys[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adserver.adreactor[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@tripod[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@efashionsolutions.122.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@statcounter[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@nextag[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.pointroll[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@mb[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@microsoftwga.112.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@franceguide[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@valueclick[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@serving-sys[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@server.cpmstar[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@server.iad.liveperson[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@sexlist[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@indexstats[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@mediaplex[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@as-eu.falkag[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@atdmt[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@weborama[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adopt.euroclick[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ehg-tfl.hitbox[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adv.surinter[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.hi5[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@drivecleaner[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@www.burstnet[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.freeway[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@msnportal.112.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@track.adform[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adrevolver[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@tacoda[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@advertising[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@indextools[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@data2.perf.overture[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ehg-youtube.hitbox[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@hotbar[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@atwola[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@911190555233333[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@bluestreak[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ad.yieldmanager[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@www.windowsmedia[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@metacafe.122.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@tracking.publicidees[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@e2.emediate[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@xiti[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@revenue[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.planetactive[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.toonamijetstream[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.freeonlinegames[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@overture[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@centrebet.advertserve[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adserver.banneradministration[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@statse.webtrendslive[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ehg-dig.hitbox[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.arto[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@www.0stats[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@m1.webstats4u[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@premiumtv.122.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@casalemedia[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@cgi-bin[3].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@clicktorrent[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@partygaming.122.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@qnsr[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@maxserving[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@perf.overture[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adtech[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@cgi-bin[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@73403369[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ad.e-kolay[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@cassava[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads2.jubii[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ehg-segaofamerica.hitbox[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@123stat[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adfarm1.adition[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@edsa.122.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@dk.drivecleaner[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@revsci[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@stats1.reliablestats[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@1070618373[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ehg-lionsgate.hitbox[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ad[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@zbox.zanox[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@888[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@partypoker[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.adbrite[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@data4.perf.overture[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ad.zanox[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@ads.addynamix[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@counter11.sextracker[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@enhance[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adinterax[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@keywordmax[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@a[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@cgi-bin[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@1072534390[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@www.drivecleaner[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@new-pcp[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@adserver.easyad[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@eas.apm.emediate[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@microsoftwlmessengermkt.112.2o7[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@1071357141[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@azjmp[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@1070361695[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@1070527576[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@specificclick[2].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@pacificpoker[1].txt
    F:\Documents and Settings\Mirella\Cookies\mirella@stats.drivecleaner[2].txt
    C:\Documents and Settings\LocalService\Cookies\mirella@ehg-nvidia.hitbox[2].txt
    C:\Documents and Settings\LocalService\Cookies\mirella@hitbox[2].txt
    C:\Documents and Settings\LocalService\Cookies\mirella@windowsmedia[1].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@ad.yieldmanager[1].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@adopt.hotbar[1].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@dk.drivecleaner[1].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@drivecleaner[1].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@media.licenseacquisition[1].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@tradedoubler[2].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@www.drivecleaner[2].txt
    C:\Documents and Settings\Mor.3200MHZ\Cookies\mor@www.globaladvertisingservices[1].txt

Adware.AdSponsor
    HKCR\AppId\{73364D99-1240-4dff-B12A-67E448373148}

Trojan.Freeprod
    C:\DOCUMENTS AND SETTINGS\MOR\ALFA.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74\A0359042.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74\A0359057.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP75\A0359068.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP75\A0361041.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP75\A0363039.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP76\A0365066.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP76\A0366074.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP87\A0462738.EXE

Adware.SurfSideKick
    C:\DOCUMENTS AND SETTINGS\MOR\APPLICATION DATA\SSKKNWRD.DLL
    C:\DOCUMENTS AND SETTINGS\MOR.3200MHZ\APPLICATION DATA\SSKKNWRD.DLL
    C:\DOCUMENTS AND SETTINGS\MOR.3200MHZ\LOKALE INDSTILLINGER\TEMP\U19D.BAT

Trojan.Rootkit-Gen
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP62\A0281246.SYS

Adware.Director
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP74\A0359035.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP75\A0360046.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP75\A0361044.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP76\A0365061.EXE

Browser Hijacker.Deskbar
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP76\A0366062.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP84\A0391264.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88\A0463104.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88\A0463105.EXE

Trojan.ErrorSafe
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP77\A0366129.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP77\A0366130.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP77\A0366131.EXE

Trojan.Unknown Origin
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP78\A0370082.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP78\A0371080.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP79\A0372083.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP79\A0373080.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP80\A0374086.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP80\A0374117.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP80\A0375114.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP80\A0376114.SYS
    C:\WINDOWS\TWLYZWXSYSBKZW5ZZW4\NQ5VTQUPSM14TQCWTQB.VBS
    C:\WINDOWS\UNINSTALL_NMON.VBS
    F:\DOCUMENTS AND SETTINGS\MIRELLA\DOCTORWEB\QUARANTINE\A0124807.EXE
    F:\DOCUMENTS AND SETTINGS\MIRELLA\DOCTORWEB\QUARANTINE\A0124809.EXE
    F:\DOCUMENTS AND SETTINGS\MIRELLA\DOCTORWEB\QUARANTINE\INSTALLER[1].EXE

Unclassified.Unknown Origin/System
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81\A0384200.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81\A0385211.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81\A0386206.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP81\A0387227.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP82\A0387241.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP83\A0388204.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP85\A0405362.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP85\A0406365.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP85\A0407375.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0408367.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0409359.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0410361.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0411361.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0412369.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0413362.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0414361.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0415367.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0416364.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0417358.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0418368.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0419365.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0420361.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0421360.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0422362.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0423366.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0424361.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0425360.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0426363.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0427362.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0435356.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0437359.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0438362.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP86\A0440348.SYS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{451E7937-EB30-48C2-98A3-03A2FE984F3C}\RP88\A0463076.EXE

Trojan.SmartLoad
    C:\WINDOWS\DRSMARTLOAD2.DAT

Adware.ClickSpring/MediaTickets
    F:\DOCUMENTS AND SETTINGS\MIRELLA\DOCTORWEB\QUARANTINE\A0462741.EXE

Trojan.Downloader-CommandDesktop
    F:\DOCUMENTS AND SETTINGS\MIRELLA\DOCTORWEB\QUARANTINE\CMDINST.EXE




HIJACKTHIS:

Logfile of HijackThis v1.99.1
Scan saved at 21:29:03, on 10-07-2007
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\SOUNDMAN.EXE
F:\Programmer\Creative\Video Blaster WebCam Control\CAMTRAY.EXE
F:\WINDOWS\System32\ctfmon.exe
F:\Programmer\MSN Messenger\MsnMsgr.Exe
F:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
F:\WINDOWS\System32\notepad.exe
F:\WINDOWS\system32\NOTEPAD.EXE
F:\Programmer\Internet Explorer\iexplore.exe
F:\Documents and Settings\Mirella\Dokumenter\alternativ.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.creaf.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Programmer\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Programmer\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Creative WebCam Tray] F:\Programmer\Creative\Video Blaster WebCam Control\CAMTRAY.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "F:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Windows Live Search - res://F:\Programmer\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://F:\Programmer\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6054246bb83540539733b8bf19551129
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://F:\Programmer\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6054246bb83540539733b8bf19551129
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - F:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - F:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.creaf.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - F:\Programmer\SUPERAntiSpyware\SASWINLO.DLL

På forhånd tak!
Avatar billede johnstigers Seniormester
11. juli 2007 - 00:23 #1
Ingen opdateringer installeret?
Avatar billede natman Nybegynder
11. juli 2007 - 12:12 #2
Nej. Det tænkt jeg sgu ikke over. Anyways, jeg prøvede at hente updates hos microsoft men fik besked på at XP'en er ulovligt hvilket i hvert fald ikke er sandt. Min tumpe af en lillesøster kunne dog ikke finde hendes reboot cd til xp så nu står jeg i et dillemma. Kunne det tænkes at udefra kommende kræfter har nappet pc'ens licensnummer så den nu står som ugyldigt hos microsoft?
Avatar billede natman Nybegynder
11. juli 2007 - 18:41 #3
Jeg har lige installeret XP'en igen og opdateret til SP2. Det ser ud som om det kører nogenlunde nu. Jeg lukker denne tråd og prøver at se hvordan det går de næste par dage. Jeg vender tilbage hvis jeg støder ind i problemer.
14. juli 2007 - 18:09 #4
Sådan går det når man leger med BEARSHARE !!!

(Husk de >80 opdateringer fra M$ EFTER SP2 !!! )

Samt http://www.spywarefri.dk/manualer/sikkerhedspakke.htm
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester