Avatar billede euka-menthol Nybegynder
22. juli 2007 - 15:43 Der er 15 kommentarer og
1 løsning

Irriterende popup

Jeg har fået fat i en meget træls adware/spyware. Når jeg søger rundt på nettet, kommer der en pop up, med reklamer der er målrettet mod mig. Ganske smart marketing, men pisse irriterende. Jeg har nu brugt "Ad-Aware SE Personal", spybot, SpywareBlaster, SUPERAntiSpyware Free Edition, og panda anivirus, og ingen af dem har fjernet den.

Nogen der har et forslag til hvordan jeg får det fjernet?

Jeg kan huske, at jeg engang lavede en log, hvor I så kunne fortælle mig, hvilke ting jeg skulle slette, nogen der kan huske hvad programmet hed, og nogen der er klar på at se på min log?

(ps det er self IKKE bare de alm pou ups der kommer når man besøger en side)
Avatar billede levich Nybegynder
22. juli 2007 - 15:51 #1
Hent http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php.
Kør HijackThis, klik på scan, kopier loggens tekst og smidt den herind.
Avatar billede euka-menthol Nybegynder
22. juli 2007 - 15:56 #2
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:55:43, on 22-07-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\Programmer\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Anti-Blaxx\Anti-Blaxx.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE
C:\Programmer\Winamp\winampa.exe
C:\Programmer\SiteAdvisor\6066\SiteAdv.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Programmer\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Programmer\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programmer\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Programmer\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programmer\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Programmer\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Programmer\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [The locks settings ante] C:\Documents and Settings\All Users\Application Data\Cool Eggs The Locks\Seek Hole.exe
O4 - HKLM\..\Run: [Browse Bleh Drive Ante] C:\Documents and Settings\All Users\Application Data\rule soft ante cool\spam owns glue.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Pulse] C:\Programmer\Pulse\Pulse.exe -splash
O4 - HKCU\..\Run: [Steam] C:\Programmer\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Poker Messenger] "C:\Programmer\Poker Messenger\Poker Messenger.exe" -r
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Programmer\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [tunebite.exe] C:\Programmer\Tunebite\tunebite.exe -tray
O4 - HKCU\..\Run: [bone blue] C:\DOCUME~1\Munk\APPLIC~1\AMEN64~1\glueadmin.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [NAVAutoStart] navapsvc.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [NAVAutoStart] navapsvc.exe (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Gem formularer - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: RF værktøjslinie - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Tilpas RF menu - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Udfyld formularer - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Dream Poker - {2841F778-7EAA-4e5a-BE73-E93F9420390E} - C:\Programmer\dreampokerMPP\MPPoker.exe
O9 - Extra button: BetOnBet Poker - {2B936D2B-EDD7-405f-9057-3685BE897E62} - C:\Programmer\betonbetMPP\MPPoker.exe
O9 - Extra button: Udfyld - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Udfyld formularer - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Gem - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Gem formularer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: VC Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\VCPOKE~1\client.exe
O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Programmer\32RedMPP\MPPoker.exe
O9 - Extra button: betEDpoker.com Poker - {45ACB1C6-77F9-43d1-B13A-DB1152DFA51E} - C:\Programmer\betedpokerMPP\MPPoker.exe (file missing)
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Programmer\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Programmer\Titan Poker\casino.exe (file missing)
O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Programmer\BetwayMPP\MPPoker.exe
O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Programmer\PartyGaming\PartyGammon\RunBackGammon.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Programmer\PartyGaming\PartyGammon\RunBackGammon.exe (file missing)
O9 - Extra button: Betdirect Poker - {6709727A-27C0-4822-ACF7-C572E1899CD6} - C:\Programmer\betdirectMPP\MPPoker.exe (file missing)
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Programmer\Poker.com\poker.exe (file missing)
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Programmer\PokerTimeMPP\MPPoker.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF værktøjslinie - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra button: All In Poker - {7FD14A80-30CB-434e-90A3-DEC1B1EA2014} - C:\Programmer\allinpokerMPP\MPPoker.exe (file missing)
O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programmer\crazyvegasMPP\MPPoker.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Programmer\CDPoker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Programmer\CDPoker\casino.exe (file missing)
O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Programmer\bet365MPP\MPPoker.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programmer\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programmer\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Programmer\Noble Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Programmer\Noble Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Programmer\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Programmer\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Programmer\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Programmer\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - C:\Programmer\MANSION\Villa\MANSION.exe
O9 - Extra 'Tools' menuitem: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - C:\Programmer\MANSION\Villa\MANSION.exe
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programmer\nordicbetMPP\MPPoker.exe
O9 - Extra button: Poker Share Poker - {F2522E05-5A47-44d9-8634-B12B3B818971} - C:\Programmer\PokerShareMPP\MPPoker.exe
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Programmer\royalvegasMPP\MPPoker.exe
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Programmer\PokermMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra button: PokerNordica - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Programmer\PokerNordica\Poker.exe (HKCU)
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108129558514
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.ladbrokes.com/instant-play-en/FlashAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA11BE55-F7F5-4D60-AE66-02156A75A0D2}: NameServer = 85.255.113.92,85.255.112.13
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Programmer\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Programmer\SiteAdvisor\6066\SAService.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe

--
End of file - 16246 bytes
Avatar billede levich Nybegynder
22. juli 2007 - 16:11 #3
Jeg ser på det, øjeblik.
Avatar billede fromsej Praktikant
22. juli 2007 - 16:14 #4
Levich >> Der er Lop og ikke mindst Wareout på maskinen, kunne jeg narre jer til at prøve vores nyeste "sampak"?
http://www.eksperten.dk/artikler/1123
Selvom jeg tvivler på at den tager Wareout.
Avatar billede levich Nybegynder
22. juli 2007 - 16:23 #5
Jeg har nu set loggen igennem, og lavet en vejledning til dig.
Hvis det skulle vise sig, at det ikke klarer problemet, så ser jeg på fromsej's link og henter inspiration derfra.

Læs alle punkterne inden du gør noget.

(1)
Hent AVG Anti-Spyware her: http://www.grisoft.com/doc/downloads-products/us/crp/0?prd=triasw.
Installer programmer og opdater det, men vent med at scanne.

Hent http://www.stevengould.org/downloads/cleanup/CleanUp452.exe og installer det.

(2)
Genstart computeren i fejlsikret tilstand (tryk F8 når Windows starter op), og fix følgende linjer med HijackThis:
O4 - HKLM\..\Run: [The locks settings ante] C:\Documents and Settings\All Users\Application Data\Cool Eggs The Locks\Seek Hole.exe
O4 - HKLM\..\Run: [Browse Bleh Drive Ante] C:\Documents and Settings\All Users\Application Data\rule soft ante cool\spam owns glue.exe
O4 - HKCU\..\Run: [bone blue] C:\DOCUME~1\Munk\APPLIC~1\AMEN64~1\glueadmin.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA11BE55-F7F5-4D60-AE66-02156A75A0D2}: NameServer = 85.255.113.92,85.255.112.13

(3)
Start AVG Anti-Spyware, vælg fanebladet "scanner" og klik på "complete system scan".
Bagefter klik "apply all actions", "save report", "save report as" og gem logfil, f.eks. på skrivebordet.

(4)
Åbn "denne computer", i menuen skal du klikke på Funktioner -> Mappeindstillinger -> Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler" og ved "Skjul filtypenavne for kendte filtyper", sæt prik i "Vis skjulte filer og mapper". Husk at trykke på knappen "Anvend på alle mapper" i stedet for "ok".

søg efter og slet følgende fil(er):
C:\Documents and Settings\All Users\Application Data\Cool Eggs The Locks\Seek Hole.exe
C:\Documents and Settings\All Users\Application Data\rule soft ante cool\spam owns glue.exe
C:\DOCUME~1\Munk\APPLIC~1\AMEN64~1\glueadmin.exe

(5)
Start -> kør -> skriv "cleanmgr" -> Slet Temporary internet files, papirkurv og midlertidige filer. Gentag for alle dine drev.

(6)
Genstart computeren normalt. Lav en ny log med HijackThis, og send den herind sammen med loggen fra AVG Anti-Spyware.
Avatar billede euka-menthol Nybegynder
22. juli 2007 - 17:26 #6
Ok, jeg går igang med det nu!
Avatar billede euka-menthol Nybegynder
22. juli 2007 - 19:00 #7
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:59:17, on 22-07-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
C:\Programmer\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Anti-Blaxx\Anti-Blaxx.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE
C:\Programmer\Winamp\winampa.exe
C:\Programmer\SiteAdvisor\6066\SiteAdv.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Programmer\Windows Defender\MSASCui.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Programmer\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programmer\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Programmer\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programmer\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Programmer\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Programmer\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Pulse] C:\Programmer\Pulse\Pulse.exe -splash
O4 - HKCU\..\Run: [Steam] C:\Programmer\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Poker Messenger] "C:\Programmer\Poker Messenger\Poker Messenger.exe" -r
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Programmer\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [NAVAutoStart] navapsvc.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [NAVAutoStart] navapsvc.exe (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Gem formularer - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: RF værktøjslinie - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Tilpas RF menu - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Udfyld formularer - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Dream Poker - {2841F778-7EAA-4e5a-BE73-E93F9420390E} - C:\Programmer\dreampokerMPP\MPPoker.exe
O9 - Extra button: BetOnBet Poker - {2B936D2B-EDD7-405f-9057-3685BE897E62} - C:\Programmer\betonbetMPP\MPPoker.exe
O9 - Extra button: Udfyld - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Udfyld formularer - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Gem - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Gem formularer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: VC Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\VCPOKE~1\client.exe
O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Programmer\32RedMPP\MPPoker.exe
O9 - Extra button: betEDpoker.com Poker - {45ACB1C6-77F9-43d1-B13A-DB1152DFA51E} - C:\Programmer\betedpokerMPP\MPPoker.exe (file missing)
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Programmer\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Programmer\Titan Poker\casino.exe (file missing)
O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Programmer\BetwayMPP\MPPoker.exe
O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Programmer\PartyGaming\PartyGammon\RunBackGammon.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Programmer\PartyGaming\PartyGammon\RunBackGammon.exe (file missing)
O9 - Extra button: Betdirect Poker - {6709727A-27C0-4822-ACF7-C572E1899CD6} - C:\Programmer\betdirectMPP\MPPoker.exe (file missing)
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Programmer\Poker.com\poker.exe (file missing)
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Programmer\PokerTimeMPP\MPPoker.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF værktøjslinie - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programmer\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra button: All In Poker - {7FD14A80-30CB-434e-90A3-DEC1B1EA2014} - C:\Programmer\allinpokerMPP\MPPoker.exe (file missing)
O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programmer\crazyvegasMPP\MPPoker.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Programmer\CDPoker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Programmer\CDPoker\casino.exe (file missing)
O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Programmer\bet365MPP\MPPoker.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programmer\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programmer\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Programmer\Noble Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Programmer\Noble Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Programmer\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Programmer\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Programmer\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Programmer\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - C:\Programmer\MANSION\Villa\MANSION.exe
O9 - Extra 'Tools' menuitem: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - C:\Programmer\MANSION\Villa\MANSION.exe
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programmer\nordicbetMPP\MPPoker.exe
O9 - Extra button: Poker Share Poker - {F2522E05-5A47-44d9-8634-B12B3B818971} - C:\Programmer\PokerShareMPP\MPPoker.exe
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Programmer\royalvegasMPP\MPPoker.exe
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Programmer\PokermMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra button: PokerNordica - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Programmer\PokerNordica\Poker.exe (HKCU)
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108129558514
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.ladbrokes.com/instant-play-en/FlashAX.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Programmer\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Programmer\SiteAdvisor\6066\SAService.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe

--
End of file - 15781 bytes


-----------------------------

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:    18:45:53 22-07-2007

+ Scan result:   



C:\WINDOWS\Club Dice Poker setup.exe -> Adware.Casino : Ignored.
C:\WINDOWS\Prestige Poker setup.exe -> Adware.Casino : Ignored.
C:\WINDOWS\system32\SetupCarnival.exe -> Adware.Casino : Ignored.
C:\System Volume Information\_restore{08BA7746-8987-41EA-B404-DFD2D1A0BC60}\RP587\A0238561.EXE -> Backdoor.Hupigon.kg : Ignored.
C:\Programmer\Free KGB Key Logger\winlogon.dll -> Not-A-Virus.Monitor.Win32.KGBSpy.34 : Ignored.
:mozilla.6:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.247realmedia : Ignored.
:mozilla.62:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.76:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.7:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.85:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.8:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.98:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.2o7 : Ignored.
:mozilla.9:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.14:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.15:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Adbrite : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@addcontrol[1].txt -> TrackingCookie.Addcontrol : Ignored.
:mozilla.165:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Adobe : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@www.adobe[1].txt -> TrackingCookie.Adobe : Ignored.
:mozilla.16:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.17:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.77:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Adtech : Ignored.
:mozilla.78:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Adtech : Ignored.
:mozilla.23:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Advertising : Ignored.
:mozilla.24:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Advertising : Ignored.
:mozilla.25:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Advertising : Ignored.
:mozilla.26:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Advertising : Ignored.
:mozilla.53:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@www.belstat[1].txt -> TrackingCookie.Belstat : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@www.belstat[2].txt -> TrackingCookie.Belstat : Ignored.
:mozilla.170:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.6:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Casalemedia : Ignored.
:mozilla.7:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Casalemedia : Ignored.
:mozilla.8:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Casalemedia : Ignored.
:mozilla.32:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Connextra : Ignored.
:mozilla.33:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Connextra : Ignored.
:mozilla.89:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Connextra : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@connextra[1].txt -> TrackingCookie.Connextra : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@connextra[2].txt -> TrackingCookie.Connextra : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@connextra[3].txt -> TrackingCookie.Connextra : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@connextra[4].txt -> TrackingCookie.Connextra : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@connextra[6].txt -> TrackingCookie.Connextra : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@connextra[7].txt -> TrackingCookie.Connextra : Ignored.
:mozilla.34:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Doubleclick : Ignored.
:mozilla.94:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Falkag : Ignored.
:mozilla.95:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Falkag : Ignored.
:mozilla.96:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Falkag : Ignored.
:mozilla.10:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Fastclick : Ignored.
:mozilla.11:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Fastclick : Ignored.
:mozilla.12:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Fastclick : Ignored.
:mozilla.13:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Fastclick : Ignored.
:mozilla.9:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Fastclick : Ignored.
:mozilla.53:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Imrworldwide : Ignored.
:mozilla.54:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Imrworldwide : Ignored.
:mozilla.73:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Imrworldwide : Ignored.
:mozilla.74:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Imrworldwide : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@ilead.itrack[2].txt -> TrackingCookie.Itrack : Ignored.
:mozilla.150:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Live : Ignored.
:mozilla.151:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Live : Ignored.
:mozilla.152:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Live : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@search.live[2].txt -> TrackingCookie.Live : Ignored.
:mozilla.54:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@auto.search.msn[1].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@search.msn[3].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@search.msn[4].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@search.msn[6].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@search.msn[9].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@www.myaffiliateprogram[4].txt -> TrackingCookie.Myaffiliateprogram : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@navrcholu[2].txt -> TrackingCookie.Navrcholu : Ignored.
:mozilla.112:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Netflame : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@ssl-hints.netflame[3].txt -> TrackingCookie.Netflame : Ignored.
:mozilla.182:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Paypal : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@www.paypal[1].txt -> TrackingCookie.Paypal : Ignored.
:mozilla.107:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.108:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.110:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Revenue : Ignored.
:mozilla.34:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Sexcounter : Ignored.
:mozilla.35:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Sexcounter : Ignored.
:mozilla.84:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Sexcounter : Ignored.
:mozilla.85:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Sexcounter : Ignored.
:mozilla.161:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Statistik-gallup : Ignored.
:mozilla.76:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Statistik-gallup : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Ignored.
:mozilla.18:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Trafficmp : Ignored.
:mozilla.19:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Trafficmp : Ignored.
:mozilla.20:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Trafficmp : Ignored.
:mozilla.21:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Trafficmp : Ignored.
:mozilla.22:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Trafficmp : Ignored.
:mozilla.117:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.14:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.146:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Webtrends : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@m.webtrends[2].txt -> TrackingCookie.Webtrends : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@m.webtrends[3].txt -> TrackingCookie.Webtrends : Ignored.
C:\Documents and Settings\Munk\Cookies\munk@m.webtrends[4].txt -> TrackingCookie.Webtrends : Ignored.
:mozilla.134:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.135:C:\Documents and Settings\Munk\Application Data\Mozilla\Profiles\default\vjb7ix9c.slt\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.102:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Zedo : Ignored.
:mozilla.103:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Zedo : Ignored.
:mozilla.104:C:\FOUND.008\FILE0009.CHK -> TrackingCookie.Zedo : Ignored.


::Report end

Tror ikke rigtig jeg fik slettet nogen filer i avg. Men testen tog over 1 time...
Avatar billede levich Nybegynder
22. juli 2007 - 19:17 #8
De problematiske filer, som jeg kunne se i din første hijackthis-log er ikke til stede i den nyeste log, hvilket tegner godt. Hvordan med popups nu?

Disse første linjer fra AVG-loggen:
C:\WINDOWS\Club Dice Poker setup.exe -> Adware.Casino : Ignored.
C:\WINDOWS\Prestige Poker setup.exe -> Adware.Casino : Ignored.
C:\WINDOWS\system32\SetupCarnival.exe -> Adware.Casino : Ignored.
C:\Programmer\Free KGB Key Logger\winlogon.dll -> Not-A-Virus.Monitor.Win32.KGBSpy.34 : Ignored.

... ser lidt problematiske ud, dog har AVG valg ikke at gøre noget ved dem. Det er muligt at tyde program-navnene ud fra linjerne - kender du til programmerne? Jeg tænker især på "Free KGB Key Logger".

Endelig har du en masser pokerprogrammer installeret, eller har haft. Er det noget, som du skal have ryddet op i?
Avatar billede euka-menthol Nybegynder
22. juli 2007 - 19:31 #9
Ja, de to første er pokersider, den 3 kender jeg ikke, og kgb var noget jeg selv dl for lang tid siden. Troede egentlig jeg havde slettet det igen, men det må jeg så lige tag og få gjort. Jeg har vel en 50-60 pokersider installeret, og efter som jeg kun bruger 10, burde jeg vel få ryddet dem af vejen, nogen smart metode til det?

Og så ser det ikke ud til at den (pop uppen) kommer mere, hvilket er super godt!
Avatar billede levich Nybegynder
22. juli 2007 - 19:52 #10
Jeg tror ikke at disse programmer gør noget skal. Tag og afinstaller de pokerprogrammer, som du ikke bruger, under kontrolpanel -> tilføj/fjern programmer.

Ellers er vi vel færdige?
Avatar billede euka-menthol Nybegynder
22. juli 2007 - 19:58 #11
Jep, 1000 tak for hjælpen!
Avatar billede fromsej Praktikant
22. juli 2007 - 20:12 #12
Jeg kunne godt tænke mig at se loggen fra Fixwareout.

Under dette fix vil computeren blive genstartet, og du bør derfor printe vejledningen ud, for at have den ved din side under hele fixet. Fixet skal bruge adgang til internettet, så det skal du sikre dig, at der er.

1. Hent FixWareout fra et af disse links:

http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

2. Gem filen på dit Skrivebord og dobbeltklik på den. Klik Next -> Install og check, at der er et flueben i "Run fixit" - klik herefter på Finish. Fixet vil nu starte, og du skal blot følge instruktionerne. Du vil blive bedt om at genstarte din computer - gør venligst det. Genstarten vil tage lidt længere tid end normalt...

3. Når dit system genstarter skal du fortsat følge den vejledning, der gives på skærmen. Når fixet er færdigt vil der åbnes en log (report.txt), som du skal gemme og lægge herind i næste post.
Avatar billede euka-menthol Nybegynder
22. juli 2007 - 20:37 #13
Username "Munk" - 2007-07-22 20:32:55 [Fixwareout edited 2007/07/05]

»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="csjhu.exe"

DNS Resolver Cache blev tømt.


System was rebooted successfully.

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1dedoc"  Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "llams_ogol"  Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "repiwh"  Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "ytpme"  Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "domdnb"  Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "orcimlh"  Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "putesprpgd"  Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "lavinraCputeS"  Deleted
....
»»»»» Misc files.
C:\WINDOWS\Help\SPAlert.chm Deleted
C:\WINDOWS\RDT.INI Deleted
C:\WINDOWS\System32\setupcarnival.exe Deleted
C:\Casino  Deleted
....
»»»»» Checking for older varients.
....

»»»»» Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"SunJavaUpdateSched"="\"C:\\Programmer\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"DAEMON Tools-1033"="\"C:\\Programmer\\D-Tools\\daemon.exe\"  -lang 1033"
"Anti-Blaxx Manager"="C:\\Programmer\\Anti-Blaxx\\Anti-Blaxx.exe"
"Google Desktop Search"="\"C:\\Programmer\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"QuickTime Task"="\"C:\\Programmer\\QuickTime\\qttask.exe\" -atboottime"
"APVXDWIN"="\"C:\\Programmer\\Panda Software\\Panda Antivirus Titanium\\APVXDWIN.EXE\" /s"
"WinampAgent"="C:\\Programmer\\Winamp\\winampa.exe"
"SiteAdvisor"="C:\\Programmer\\SiteAdvisor\\6066\\SiteAdv.exe"
"SnoopFreeUI"="SnoopFreeUI.exe"
"Windows Defender"="\"C:\\Programmer\\Windows Defender\\MSASCui.exe\" -hide"
"!AVG Anti-Spyware"="\"C:\\Programmer\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Programmer\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Skype"="\"C:\\Programmer\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"Pulse"="C:\\Programmer\\Pulse\\Pulse.exe -splash"
"Steam"="C:\\Programmer\\Steam\\Steam.exe -silent"
"Poker Messenger"="\"C:\\Programmer\\Poker Messenger\\Poker Messenger.exe\" -r"
"swg"="C:\\Programmer\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"RoboForm"="\"C:\\Programmer\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
Avatar billede fromsej Praktikant
22. juli 2007 - 20:47 #14
Bingo. *S*
Så fik vi også svaret på Setupcarnival, det var en del af Wareout.

Hvis i nogensinde lægger vejen forbi Kiev, så find lige ham her og knald ham en med en skovl fra mig:
Andrei Kislizin

ul.Antonova 5, Kiev,
03186, Ukraine
+38 044 2404332
Avatar billede euka-menthol Nybegynder
22. juli 2007 - 20:55 #15
Hehe, hvad er Wareout, og hvor har jeg fået det fra?
Avatar billede fromsej Praktikant
22. juli 2007 - 21:20 #16
Wareout er en hel familie af falske scannere, de vil have dig til at købe deres skrammel, og narrer dig med at "finde" en masse, hvis du hopper på limpinden og prøver deres scannere.
Nogle gange følges infektionen med Virtumundo, der opfører sig på næsten samme måde, med popups osv.
Det er ekstremt svært at fjerne igen, men LonnyRjones´ program gør heldigvis tricket.
Jeg tror at jeg havde kunne se det i en Combofix log også, men er ikke sikker.
Virtuomundo skal der så andre værktøjer til, helst combofix.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester