ok Jeg har løst problemet ved at følge disse instrukser fra
www.antivirus.comMANUAL REMOVAL INSTRUCTIONS
Removing Malware Entries from the Registry
Removing entries from the registry prevents the malware from performing its DNS redirection.
Open Registry Editor. To do this, click Start>Run, type REGEDIT, then press Enter.
In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>Internet Explorer>Main
Use Search Asst="no"
Select and delete the above registry entry.
Repeat the same deletion process for the following registry entries:
HKEY_CURRENT_USER>Software>Microsoft>Internet Explorer>Main
Search Bar="
http://www.google.com/ie" HKEY_CURRENT_USER>Software>Microsoft>Internet Explorer>SearchUrl
@=http://www.google.com/keyword/%s
HKEY_CURRENT_USER>Software>Microsoft>Windows
CurrentVersion>Internet Settings
MigrateProxy=0
HKEY_CURRENT_USER>Software>Microsoft>Internet Explorer>Main
Search Page=http://www.google.com
HKEY_CURRENT_USER>Software>Microsoft>Internet Explorer>SearchUrl
Provider=”gogl"
HKEY_LOCAL_MACHINE>Software>Microsoft>Internet Explorer
Search = SearchAssistant=http://www.google.com/ie
HKEY_LOCAL_MACHINE>System>CurrentControlSet
Services\VxD\MSTCP
HostName="host"
HKEY_LOCAL_MACHINE>System>CurrentControlSet
Services>VxD>MSTCP
Domain="mydomain.com"
HKEY_LOCAL_MACHINE>System>CurrentControlSet
Services>VxD>MSTCP
NameServer="69.57.146.14,69.57.147.175"
HKEY_LOCAL_MACHINE>System>ControlSet001>Services
Tcpip>Parameters
DataBasePath=25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,
6f,00,6f,00,74,00,25,00,5c,00,68,00,65,00,6c,00,70,00,00,00 (HEX)
HKEY_LOCAL_MACHINE>System>ControlSet002>Services
Tcpip>Parameters
DataBasePath=25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,
6f,00,6f,00,74,00,25,00,5c,00,68,00,65,00,6c,00,70,00,00,00 (HEX)
HKEY_LOCAL_MACHINE>System>ControlSet001>
Services>Tcpip>Parameters>interfaces>windows
r0x="your s0x"
HKEY_LOCAL_MACHINE>System>ControlSet002
Services>Tcpip>Parameters>interfaces>windows
r0x="your s0x"
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters
DataBasePath=25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,
00,6f,00,74,00,25,00,5c,00,68,00,65,00,6c,00,70,00,00,00
(equivalent to %SystemRoot%\Help)
Modify the DataBasePath to the following value
equivalent to %SystemRoot%\System32\drivers\etc):
DataBasePath=25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,
00,6f,00,6f,00,74,00,25,00,5c,00,64,00,72,00,69,00,76,00,65,
00,72,00,73,00,5c,00,65,00,74,00,63,00,00,00,00
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters
DataBasePath=25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,
00,6f,00,74,00,25,00,5c,00,68,00,65,00,6c,00,70,00,00,00
(equivalent to %SystemRoot%\Help)
Modify the DataBasePath to the following value
(equivalent to %SystemRoot%\System32\drivers\etc):
DataBasePath=25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,
00,6f,00,6f,00,74,00,25,00,5c,00,64,00,72,00,69,00,76,00,65,
00,72,00,73,00,5c,00,65,00,74,00,63,00,00,00,00
Close Registry Editor
Det tog sin tid men nu virker alle sider. se alle instrukser her:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_QHOSTS.A