Avatar billede mokof Novice
15. november 2007 - 18:13 Der er 14 kommentarer og
3 løsninger

Evt. virus

Er der en der vil kigge på min (sønnens)log.PC'en er mega langsom
Avatar billede arlet Juniormester
15. november 2007 - 18:14 #1
Ja..

Den ser fin ud...
Avatar billede mokof Novice
15. november 2007 - 18:15 #2
Glemte lige loggen :-)  Logfile of HijackThis v1.99.1
Scan saved at 18:14:27, on 15-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programmer\CASIO\Photo Loader\Plauto.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\CASIO\Photo Loader\Plauto.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmer\Java\jre1.5.0_10\bin\jucheck.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\hijackthis\HijackThis.exe
C:\WINDOWS\system32\service.exe
C:\WINDOWS\system32\service.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Programmer\ContextTool\ContextTool-2.dll
O2 - BHO: TBSB06180 - {4A2E1038-0885-4C92-8E28-A04CF8B94911} - C:\PROGRA~1\WINSTR~1\WIN_ST~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Win Stream plugin - {BFB5F154-9212-46F3-B547-AC6106030A54} - C:\Programmer\Win Stream plugin\win_stream_plugin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Programmer\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [X-Cleaner Deluxe] "C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Programmer\CASIO\Photo Loader\Plauto.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparlolland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0D1E3B8-A2E3-41F4-AE29-BB9E0DAC99CD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
15. november 2007 - 18:18 #3
<arlet>: Du må gerne køre videre her *S*
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe ???
Avatar billede arlet Juniormester
15. november 2007 - 18:27 #4
Kør trin 1 og 2 her http://www.malwarecheck.dk/forum/viewtopic.php?t=11
Genstart og ny hijackthis log(med nyeste version, som du finder her: www.arlet.dk/hijackthis.htm) samt log´ne fra SuperAntiSpyware scanneren og Avg/Ewido
Avatar billede mokof Novice
19. november 2007 - 20:04 #5
Hej igen og undskyld ventetiden men jeg har haft en del at se til.
her er de 3 log's du bad om, håber det er gjort
rigtigt :-/
__________________________________________________
ewido anti-spyware online scanner
    http://www.ewido.net
__________________________________________________


Name: TrackingCookie.Adbrite
Path: C:\Documents and Settings\Mogens\Cookies\mogens@4.adbrite[1].txt
Risk: Medium

Name: TrackingCookie.Yieldmanager
Path: C:\Documents and Settings\Mogens\Cookies\mogens@ad.yieldmanager[1].txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: C:\Documents and Settings\Mogens\Cookies\mogens@adbrite[1].txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: C:\Documents and Settings\Mogens\Cookies\mogens@ads.adbrite[1].txt
Risk: Medium

Name: TrackingCookie.Adtech
Path: C:\Documents and Settings\Mogens\Cookies\mogens@adtech[1].txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: C:\Documents and Settings\Mogens\Cookies\mogens@advertising[1].txt
Risk: Medium

Name: TrackingCookie.Serving-sys
Path: C:\Documents and Settings\Mogens\Cookies\mogens@bs.serving-sys[1].txt
Risk: Medium

Name: TrackingCookie.Connextra
Path: C:\Documents and Settings\Mogens\Cookies\mogens@connextra[1].txt
Risk: Medium

Name: TrackingCookie.Cpvfeed
Path: C:\Documents and Settings\Mogens\Cookies\mogens@cpvfeed[1].txt
Risk: Medium

Name: TrackingCookie.Masterstats
Path: C:\Documents and Settings\Mogens\Cookies\mogens@image.masterstats[1].txt
Risk: Medium

Name: TrackingCookie.Webtrends
Path: C:\Documents and Settings\Mogens\Cookies\mogens@m.webtrends[2].txt
Risk: Medium

Name: TrackingCookie.Questionmarket
Path: C:\Documents and Settings\Mogens\Cookies\mogens@questionmarket[2].txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: C:\Documents and Settings\Mogens\Cookies\mogens@revsci[2].txt
Risk: Medium

Name: TrackingCookie.Serving-sys
Path: C:\Documents and Settings\Mogens\Cookies\mogens@serving-sys[1].txt
Risk: Medium

Name: TrackingCookie.Statistik-gallup
Path: C:\Documents and Settings\Mogens\Cookies\mogens@statistik-gallup[1].txt
Risk: Medium

Name: TrackingCookie.Tribalfusion
Path: C:\Documents and Settings\Mogens\Cookies\mogens@tribalfusion[2].txt
Risk: Medium

Name: TrackingCookie.Xxxcounter
Path: C:\Documents and Settings\Mogens\Cookies\mogens@xxxcounter[1].txt
Risk: Medium

Name: TrackingCookie.Doubleclick
Path: C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@doubleclick[1].txt
Risk: Medium

Name: TrackingCookie.2o7
Path: C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@sonofon.112.2o7[1].txt
Risk: Medium

Name: TrackingCookie.Statistik-gallup
Path: C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@statistik-gallup[1].txt
Risk: Medium


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/19/2007 at 07:06 PM

Application Version : 3.9.1008

Core Rules Database Version : 3346
Trace Rules Database Version: 1347

Scan type      : Complete Scan
Total Scan Time : 01:21:44

Memory items scanned      : 442
Memory threats detected  : 1
Registry items scanned    : 4849
Registry threats detected : 14
File items scanned        : 37620
File threats detected    : 124

Trojan.Service
    C:\WINDOWS\SYSTEM32\SERVICE.EXE
    C:\WINDOWS\SYSTEM32\SERVICE.EXE
    [MDNS] C:\WINDOWS\SYSTEM32\SERVICE.EXE
    C:\WINDOWS\Prefetch\SERVICE.EXE-396E850B.pf

Unclassified.Unknown Origin
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{af3fd9a8-1287-4159-9212-9a5b4494af70}

Adware.Tracking Cookie
    C:\Documents and Settings\Mogens\Cookies\mogens@www.sexymomstown[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@indextools[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@tribalfusion[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@df[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@sexulus[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@sexymaturechicks[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@pacificpoker[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@counter5.sextracker[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@eas.apm.emediate[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.xxx-69-xxx[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@image.masterstats[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@partypoker[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.pornoverview[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@wivesinporn[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@angleinteractive.directtrack[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@bs.serving-sys[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@adultadworld[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@qxl.banneradministration[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@zedo[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@directtrack[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@sexlist[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@adtech[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@serving-sys[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@xxxcounter[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@momsteachingteens[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@cassava[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@fuckthislady[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@amour-xxx-angels[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.grannypornmovs[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@qxl.adservinginternational[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@join.momsteachingteens[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@teenempires[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@1071793501[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@counter7.sextracker[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@sextracker[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@teensmoreteens[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@sexadditions[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@tradedoubler[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@revsci[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@specificclick[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.topwebteens[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@4.adbrite[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@atdmt[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@counter4.sextracker[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.matureporno[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@doubleclick[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.olderwomansexvideos[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@counter12.sextracker[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.trafficadept[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@adserver.banneradministration[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.momspornvideo[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@cgi-bin[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@moms4fuck[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@thefuckdolls[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.extra-teens[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@adbrite[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@hentaicounter[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@momspornvideo[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@matureadultmoviematrix[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@lesssex[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@chokertraffic[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@dtr[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@ad.yieldmanager[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@mediatraffic[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@xren_cj[3].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@adfair[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@mediaplex[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@track.adform[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@nichetrafficticket[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.sexhungrymoms[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@clickbank[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@ads2.jubii[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@porntower[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.clubteenpix[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@questionmarket[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@mymomsfuckingblackzilla[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@teensart[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@casalemedia[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@1062884206[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@ads.dk-kogebogen[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@new-pcp[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@888[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@advertising[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@fastclick[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@ads.adbrite[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@ad[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@cgi-bin[3].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@www.2superteens[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@smileycentral[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@blackfuckwhite[2].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@teens-girls[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@statcounter[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@fresh-sex-girls[1].txt
    C:\Documents and Settings\Mogens\Cookies\mogens@top[1].txt
    C:\Documents and Settings\Anette\Cookies\anette@ad1.emediate[2].txt
    C:\Documents and Settings\Anette\Cookies\anette@e2.emediate[1].txt
    C:\Documents and Settings\Anette\Cookies\anette@track.adform[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@adfair[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@ads.dk-kogebogen[2].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@ads2.jubii[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@adserver.banneradministration[2].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@adtech[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@advertising[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@atdmt[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@bs.serving-sys[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@doubleclick[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@e2.emediate[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@eas.apm.emediate[2].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@fastclick[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@indextools[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@qxl.banneradministration[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@serving-sys[2].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@stat.postdanmark[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@track.adform[1].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@tradedoubler[2].txt
    C:\Documents and Settings\Anette.ANETTE-0SDU9P5A\Cookies\anette@tribalfusion[1].txt
    C:\Documents and Settings\Jac\Cookies\jac@track.adform[1].txt

Trojan.Security Toolbar
    C:\Documents and Settings\All Users\Menuen Start\Online Security Guide.url
    C:\Documents and Settings\All Users\Menuen Start\Security Troubleshooting.url

Trojan.Homepage/Puper
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#wininet.dll

Browser Hijacker.Deskbar
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\Implemented Categories
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\InprocServer32
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\InprocServer32#ThreadingModel
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\ProgID
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\Programmable
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\TypeLib
    HKCR\CLSID\{BFB5F154-9212-46F3-B547-AC6106030A54}\VersionIndependentProgID
    HKLM\Software\Microsoft\Internet Explorer\Toolbar#{BFB5F154-9212-46F3-B547-AC6106030A54}

Adware.HBHelper
    C:\PROGRAMMER\WIN STREAM PLUGIN\TBHELPER.DLL

Trojan.Unknown Origin
    C:\WINDOWS\SYSTEM32\OT.ICO

Adware.Mirar/NetNucleus
    C:\WINDOWS\SYSTEM32\WINNB58.DLL


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:55:21, on 19-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programmer\CASIO\Photo Loader\Plauto.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\SUPERAntiSpyware.exe
C:\Programmer\CASIO\Photo Loader\Plauto.exe
C:\Programmer\Java\jre1.5.0_10\bin\jucheck.exe
C:\Programmer\HJTrenamed.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Programmer\ContextTool\ContextTool-2.dll
O2 - BHO: TBSB06180 - {4A2E1038-0885-4C92-8E28-A04CF8B94911} - C:\PROGRA~1\WINSTR~1\WIN_ST~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Programmer\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Programmer\CASIO\Photo Loader\Plauto.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparlolland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0D1E3B8-A2E3-41F4-AE29-BB9E0DAC99CD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 6883 bytes
Avatar billede arlet Juniormester
19. november 2007 - 20:54 #6
Kører du med noget openDns??
Avatar billede mokof Novice
19. november 2007 - 22:01 #7
Hvad er "openDns"
Avatar billede arlet Juniormester
19. november 2007 - 22:12 #8
Avatar billede arlet Juniormester
19. november 2007 - 22:18 #9
Kør Hijackthis, scan, sæt flueben ved linien/linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.

R3 - Default URLSearchHook is missing
O2 - BHO: TBSB06180 - {4A2E1038-0885-4C92-8E28-A04CF8B94911} - C:\PROGRA~1\WINSTR~1\WIN_ST~1.DLL

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0D1E3B8-A2E3-41F4-AE29-BB9E0DAC99CD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

Genstart og ny hijackthis log
Avatar billede mokof Novice
20. november 2007 - 13:36 #10
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:35:29, on 20-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programmer\CASIO\Photo Loader\Plauto.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\SUPERAntiSpyware.exe
C:\Programmer\CASIO\Photo Loader\Plauto.exe
C:\Programmer\Java\jre1.5.0_10\bin\jucheck.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\HJTrenamed.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Programmer\ContextTool\ContextTool-2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Programmer\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Programmer\CASIO\Photo Loader\Plauto.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparlolland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 6479 bytes
Avatar billede arlet Juniormester
20. november 2007 - 16:48 #11
Dit Java er forældet, derfor skal du afinstaller dit Java via Kontrolpanel => Tilføj/Fjern Programmer. Af sikkerhedsmæssige årsager, skal den gamle version af programmet slettes, inden man henter nyeste version.

Hent derefter den nye version Java her:
http://www.java.com/en/

-----

Så ser det bedre ud..

Hjalp kuren??

Kør lige trin 5 og 6 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11
Avatar billede mokof Novice
21. november 2007 - 10:04 #12
Helt fint. Tak for hjælpen.
P.S. Jeg har nogle tomme programmer, jeg ikke kan fjerne, på tilføj/fjern programmer. Er der noget at gøre ved det ?
Avatar billede arlet Juniormester
21. november 2007 - 10:57 #13
Prøv først ccleaner www.arlet.dk/ccleaner.htm

----------

Hvis det ikke virker, så gør dette her:

Gå i start - kør og skriv regedit

Gå ned til:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

Tryk på "+" ud for Uninstall mappen og find mapperne og slet dem.
Avatar billede mokof Novice
22. november 2007 - 18:48 #14
Jeg kan stadig ikke fjerne dem, for de er ikke nævnt i regedit.
Men tak for hjælpen med det andet.
Avatar billede arlet Juniormester
22. november 2007 - 18:56 #15
Okay, så har jeg ikke nogen løsning..
Avatar billede mokof Novice
23. november 2007 - 19:35 #16
Har du fået pointne for jeg har stadig gult flag, selvom jeg har accepteret svar ..
Avatar billede arlet Juniormester
23. november 2007 - 20:35 #17
Ja, det skulle være i orden-..
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester