Avatar billede picasso Nybegynder
15. juli 2004 - 12:44 Der er 12 kommentarer

virus fil: W32.Netsky.P@mm!enc

Jeg har lige fået en besked fra mit Norton antivirus program, at jeg har en fil med virus. Hvad betyder følgende besked (skal jeg forsøge at fjerne den; i givet fald hvordan). Beskeden var følgende:
Objektnavn: DOCUME~1\LARSJR~1\Lokale~1\TempNAV7A.tmp
Virus navn: W32.Netsky.P@mm!enc
Valgte handling: kan ikke reperare denne fil
Adgang til filen nægtet

mvh.
Avatar billede resist Nybegynder
15. juli 2004 - 12:58 #1
Hvis du har Windows XP eller ME så slå systemgendannelse fra: http://www.spywarefri.dk/virusscannere.htm#alle

Prøv derefter at tage en scanning med en eller flere af disse onlinescannere:

Housecall: http://housecall.trendmicro.com/
Panda: http://www.pandasoftware.com/activescan/com/activescan_principal.htm
BitDefender: http://www.bitdefender.com/scan/license.php
Avatar billede picasso Nybegynder
15. juli 2004 - 14:46 #2
Tak for svaret. Jeg slået systemgendannelse fra og scannet med panda. Beskeden var følgende: 
  Your Opinion  FAQs  Help

Scan finishedScan report 
   
 
  System  Files  Messages 

  Scanned Yes  112947  45 
  Infected -  1  0 
  Suspicious -  0  0 
  Disinfected -  0  0 
 
Your PC is infected with a virus that ActiveScan has not been able to remove, for more information about viruses, click on the following link: encyclopedia 


Så hvad skal jeg gøre nu? Prøve de andre to scannere?
Avatar billede resist Nybegynder
15. juli 2004 - 15:09 #3
Prøv også de andre scannere!

Gerne fra fejlsikret tilstand (F8 i opstart med netadgang).

Alternativt kan du selv prøve at slette filen manuelt fra fejlsikret tilstand.

Du skal også være velkommen til at kopiere en HijackThis-log herind – måske viser den noget: http://www.spywarefri.dk/vaerktoj.htm#hijackthis (lad være med selv at fixe/slette noget med HijackThis!).
Avatar billede picasso Nybegynder
15. juli 2004 - 18:06 #4
Jeg er en 'stor' amatør. For blot at tage ét eksempel aner jeg ikke hvordan det er muligt at bevare netadgang og arbejde i fejlsikret tilstand.
Jf. tidligere kommentar fandt panda en inficeret fil. Housecall fandt ingenting. Mens BitDefender fandt følgende, (indeholder det nogen interessant information?):

Memory ok
Master Boot Record 80 ok (Windows 95 B20 - Windows 98)
Partition Boot 1 (primary) (active) ok (Windows NT 2000 NTFS)
Master Boot Record 81 ok (Windows 95 B20 - Windows 98)
Partition Boot 1 (primary) (active) ok (Win95 OSR2, Win98 FAT32)
Boot Sector of Drive A: ok (DOS 3.3)
C:\Programmer\Norton AntiVirus\Quarantine\02441DED.tmp=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Thu, 8 Jul 2004 07:05:29 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
C:\Programmer\Norton AntiVirus\Quarantine\0840085E.tmp=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Sat, 3 Jul 2004 15:41:16 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
C:\Programmer\Norton AntiVirus\Quarantine\1D03256D.tmp=>(Quarantine)=>[Subject: Re: screensaver][Date: Wed, 14 Jul 2004 05:50:49 -0400]=>(MIME part)=>screensaver.pif infected: Win32.Netsky.P@mm
C:\Programmer\Norton AntiVirus\Quarantine\1D4B411E.tmp=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Wed, 14 Jul 2004 06:31:37 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
C:\Programmer\Norton AntiVirus\Quarantine\1D4B411E.tmp=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Wed, 14 Jul 2004 06:31:37 -0400]=>(MIME part)=>message.scr infected: Win32.Netsky.P@mm
C:\Programmer\Norton AntiVirus\Quarantine\2C891479.tmp=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Sat, 3 Jul 2004 04:57:01 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
C:\Programmer\Norton AntiVirus\Quarantine\6422172A.tmp=>(Quarantine) infected: Win32.Netsky.P@mm
C:\Programmer\Norton AntiVirus\Quarantine\6422172A.tmp=>(Quarantine) unable to disinfect
C:\Programmer\Norton AntiVirus\Quarantine\644D38FB.tmp=>(Quarantine) infected: Win32.Netsky.P@mm
C:\Programmer\Norton AntiVirus\Quarantine\644D38FB.tmp=>(Quarantine) unable to disinfect
C:\Programmer\Norton AntiVirus\Quarantine\649E52A1.tmp=>(Quarantine) infected: Win32.Netsky.P@mm
C:\Programmer\Norton AntiVirus\Quarantine\649E52A1.tmp=>(Quarantine) unable to disinfect
C:\Programmer\Norton AntiVirus\Quarantine\66090712.tmp=>(Quarantine) infected: Win32.Netsky.P@mm
C:\Programmer\Norton AntiVirus\Quarantine\66090712.tmp=>(Quarantine) unable to disinfect
C:\Programmer\Norton AntiVirus\Quarantine\66B96250.tmp=>(Quarantine) infected: Win32.Netsky.P@mm
C:\Programmer\Norton AntiVirus\Quarantine\66B96250.tmp=>(Quarantine) unable to disinfect
D:\WINDOWS\Temporary Internet Files\Content.IE5\WLAZ01Q3\casino[2].exe infected: Trojan.Swizzor.B
D:\WINDOWS\Temporary Internet Files\Content.IE5\WLAZ01Q3\casino[2].exe unable to disinfect
D:\WINDOWS\Temporary Internet Files\Content.IE5\WLAZ01Q3\casino[3].exe infected: Trojan.Swizzor.B
D:\WINDOWS\Temporary Internet Files\Content.IE5\WLAZ01Q3\casino[3].exe unable to disinfect
D:\WINDOWS\Temporary Internet Files\Content.IE5\AVMFUFUL\casino[2].exe infected: Trojan.Swizzor.B
D:\WINDOWS\Temporary Internet Files\Content.IE5\AVMFUFUL\casino[2].exe unable to disinfect
D:\WINDOWS\Temporary Internet Files\Content.IE5\AVMFUFUL\casino[1].exe infected: Trojan.Swizzor.B
D:\WINDOWS\Temporary Internet Files\Content.IE5\AVMFUFUL\casino[1].exe unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\3B4B49AF.bat=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\3B4B49AF.bat=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\4DDE153E.exe=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\4DDE153E.exe=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\659D17EF.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\659D17EF.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\69263D2E.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\69263D2E.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\69D36E70.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\69D36E70.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\61253757.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\61253757.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\35993824.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\35993824.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\60C119E5.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\60C119E5.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\21FA57DA.TMP=>(Quarantine) infected: Win32.BugBear.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\21FA57DA.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\32A157D0.TMP=>(Quarantine) infected: Win32.BugBear.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\32A157D0.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\761E325C.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\761E325C.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\4C461EAF.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\4C461EAF.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\3C03393B.TMP=>(Quarantine)=>(Upx) infected: Win32.Lirva.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\3C03393B.TMP=>(Quarantine)=>(Upx) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\79250AF3.TMP=>(Quarantine) infected: Win32.BugBear.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\79250AF3.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\2DE33FDD.TMP=>(Quarantine) infected: Win32.Dumaru.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\2DE33FDD.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\2E240795.TMP=>(Quarantine) infected: Win32.Dumaru.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\2E240795.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\4FAE4C63.TMP=>(Quarantine) infected: Win32.Dumaru.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\4FAE4C63.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\091D2178.TMP=>(Quarantine) infected: Win32.Dumaru.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\091D2178.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\093D4555.TMP=>(Quarantine) infected: Win32.Dumaru.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\093D4555.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\09571538.TMP=>(Quarantine) infected: Win32.Dumaru.A@mm
D:\Programmer\Norton AntiVirus\Quarantine\09571538.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\254F19CC.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\254F19CC.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\06541E28.TMP=>(Quarantine) infected: Win32.Klez.H@mm
D:\Programmer\Norton AntiVirus\Quarantine\06541E28.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\0ADA0BB3.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\0ADA0BB3.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\0B125576.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\0B125576.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\601A1BE3.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\601A1BE3.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\344C0785.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\344C0785.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\741A04BB.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\741A04BB.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\3F4A45B3.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\3F4A45B3.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\3F6E138C.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\3F6E138C.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\3F950B61.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\3F950B61.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\3FD97D15.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\3FD97D15.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\402542C3.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\402542C3.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\58127584.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\58127584.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\7C3B12DE.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\7C3B12DE.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\57746075.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\57746075.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\1D7F1886.TMP=>(Quarantine)=>bwwpv.exe infected: Win32.Bagle.J@mm
D:\Programmer\Norton AntiVirus\Quarantine\1D7F1886.TMP=>(Quarantine)=>bwwpv.exe unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\49852DC9.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\49852DC9.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\609260FC.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\609260FC.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\0EF5690D.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\0EF5690D.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\18375924.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\18375924.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\27025F6F.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\27025F6F.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\50842576.TMP=>(Quarantine) infected: Win32.Netsky.B@mm
D:\Programmer\Norton AntiVirus\Quarantine\50842576.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\173106D3.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\173106D3.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\04D06BE1.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\04D06BE1.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\055C7946.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\055C7946.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\52002F31.zip=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\52002F31.zip=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\3CE56710.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\3CE56710.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\6942523E.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\6942523E.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\69467C3A.TMP=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Tue, 22 Jun 2004 04:06:53 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
D:\Programmer\Norton AntiVirus\Quarantine\01483D84.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\01483D84.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\43B42566.TMP=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Tue, 22 Jun 2004 18:35:50 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
D:\Programmer\Norton AntiVirus\Quarantine\0C1B422C.scr=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\0C1B422C.scr=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\36231FE9.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\36231FE9.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\37E641F9.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\37E641F9.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\37E96BF6.TMP=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Sun, 27 Jun 2004 12:14:41 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
D:\Programmer\Norton AntiVirus\Quarantine\51DC7BB0.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\51DC7BB0.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\143A427B.TMP=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Sun, 27 Jun 2004 16:07:37 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
D:\Programmer\Norton AntiVirus\Quarantine\520A477E.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\520A477E.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\523E6744.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\523E6744.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\41AF4666.TMP=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Mon, 28 Jun 2004 02:26:24 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
D:\Programmer\Norton AntiVirus\Quarantine\18586741.TMP=>(Quarantine) infected: Win32.Netsky.P@mm
D:\Programmer\Norton AntiVirus\Quarantine\18586741.TMP=>(Quarantine) unable to disinfect
D:\Programmer\Norton AntiVirus\Quarantine\185C113E.TMP=>(Quarantine)=>[Subject: Mail Delivery (failure hansen-jorgense][Date: Wed, 30 Jun 2004 22:04:41 -0400]=>(MIME part)=>(MIME part)=>(message body) suspect: Exploit.Iframe.Vulnerability
Avatar billede resist Nybegynder
15. juli 2004 - 18:19 #5
Nu kender jeg ikke meget til Norton, men som jeg læser det, har Norton lagt filer i Quarantine. Der må i Norton være en mulighed for at slette filer i Quarantine?

Jeg vil godt se en HijackThis-log. Følg denne vejledning: http://www.eksperten.dk/artikler/127 (punkt 1-4). Altså kopier en log fra HijackThis herind i tråden.
Avatar billede picasso Nybegynder
15. juli 2004 - 20:55 #6
Efter lidt øvelse! Kommer her (forhåbentlig) den log, som du ønskede:

Logfile of HijackThis v1.98.0
Scan saved at 20:58:02, on 15-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Messenger\MSMSGS.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programmer\Outlook Express\msimn.exe
C:\Documents and Settings\HijackThis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O9 - Extra button: TREND MICRO HouseCall - {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} - http://uk.trendmicro-europe.com/enterprise/products/housecall_pre.php (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8044F153-FD71-442C-B53F-7E31D32C05E1}: NameServer = 212.242.40.3 212.242.40.51
Avatar billede resist Nybegynder
15. juli 2004 - 21:36 #7
Der er ikke rigtig noget at komme efter i loggen fra HijackThis.

Prøv at slette alle temp filer og derefter at tømme papirkurven.

Tag også en scanning med denne engangsscanner: http://www.mwti.net/download/tools/mwav.exe

Har du problemer med computeren?
Avatar billede picasso Nybegynder
15. juli 2004 - 21:49 #8
Jeg har flere spørgsmål - og jeg skal nok give flere point til resist, hvis du ovenikøbet følger op med svar på disse (hvis man kan det).

Nej, jeg har ikke problemer med computeren. Men jeg fik den igår - med nyinstalleret xp og den 'gamle' harddisk tilsluttet. Samtidig skulle sælger installere mit norton anti-virus program. Det er fra 2002, men det havde jo været løbende opdateret. Med mit ringe kendskab til pc'ere frygtede jeg netop, at der kunne gå virus ind i den mellemtid, der var mellem at det gamle norton-program var installeret og jeg åbnede for mails. Men sælger lovede at det var opdateret - så jeg tog ingen forholdsregler. Mem modtog blot post - da det endelig var lykkedes mig at koble mig på nettet. Kort efter bad jeg norton om at lede efter opdateringer - og den fandt 5 opdateringer! Så meget for sælgers lovning om at norton var opdateret. Jeg kan ikke lade være med at tro, at det er forklaringen på, at jeg få timer efter får besked om, at der er virus på computeren. Lyder det ikke sandsynligt? Vil det være smart at bede om at få xp geninstalleret?
Jeg skal nok prøve at tage også denne scanning og slette temp. filer mv.
Avatar billede picasso Nybegynder
15. juli 2004 - 22:15 #9
nu har jeg slettet temp filer og papirkurv. og taget den nævnte scanning. Her er resultatet:

Thu Jul 15 12:23:42 2004 => **********************************************************
Thu Jul 15 12:23:42 2004 => eScan AntiVirus Toolkit Utility.
Thu Jul 15 12:23:42 2004 => Copyright © 2003-2004,  MicroWorld Technologies Inc.
Thu Jul 15 12:23:42 2004 => **********************************************************
Thu Jul 15 12:23:42 2004 => Version 4.2.6
Thu Jul 15 12:23:42 2004 => Log File: C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\mwav.log
Thu Jul 15 12:23:42 2004 => Latest Date of files inside MWAV: 09 Jul 2004  12:06:55.
Thu Jul 15 12:23:44 2004 => AV Library Loaded...
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavss.exe
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\Getvlist.exe
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavss.dll
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavssdi.dll
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavssi.dll
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavvlg.dll
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\msvlclnt.dll
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\ipc.dll
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\main.avi
Thu Jul 15 12:23:44 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\virus.avi
Thu Jul 15 12:23:44 2004 => Virus Database Date: 2004/07/09
Thu Jul 15 12:23:44 2004 => Virus Database Count: 96426
Thu Jul 15 12:25:01 2004 => Generating Virus List... getvlist.exe C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\vlist.txt

Thu Jul 15 12:25:24 2004 => **********************************************************
Thu Jul 15 12:25:24 2004 => eScan AntiVirus Toolkit Utility.
Thu Jul 15 12:25:24 2004 => Copyright © 2003-2004,  MicroWorld Technologies Inc.
Thu Jul 15 12:25:24 2004 =>
Thu Jul 15 12:25:24 2004 => Support: support@mwti.net
Thu Jul 15 12:25:24 2004 => Web: http://www.mwti.net
Thu Jul 15 12:25:24 2004 => **********************************************************
Thu Jul 15 12:25:24 2004 => Version 4.2.6
Thu Jul 15 12:25:24 2004 => Log File: C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\mwav.log
Thu Jul 15 12:25:24 2004 => Latest Date of files inside MWAV: 09 Jul 2004  12:06:55.

Thu Jul 15 12:25:24 2004 => Options Selected by User:
Thu Jul 15 12:25:24 2004 => Memory Check: Enabled
Thu Jul 15 12:25:24 2004 => Registry Check: Enabled
Thu Jul 15 12:25:24 2004 => StartUp Folder Check: Enabled
Thu Jul 15 12:25:24 2004 => System Folder Check: Disabled
Thu Jul 15 12:25:24 2004 => System Area Check: Disabled
Thu Jul 15 12:25:24 2004 => Services Check: Enabled
Thu Jul 15 12:25:24 2004 => Drive Check Option Disabled
Thu Jul 15 12:25:24 2004 => Scanning Type: Scan And Clean
Thu Jul 15 12:25:24 2004 => Folder Check: Disabled

Thu Jul 15 12:25:24 2004 => ***** Scanning Memory Files *****
Thu Jul 15 12:25:24 2004 => Scanning File C:\WINDOWS\system32\services.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\WINDOWS\system32\lsass.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\WINDOWS\system32\spoolsv.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapsvc.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\WINDOWS\Explorer.EXE
Thu Jul 15 12:25:25 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapw32.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\WINDOWS\System32\ctfmon.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\Programmer\Messenger\MSMSGS.EXE
Thu Jul 15 12:25:25 2004 => Scanning File C:\WINDOWS\System32\wuauclt.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\PROGRA~1\OUTLOO~1\msimn.exe
Thu Jul 15 12:25:25 2004 => Scanning File C:\PROGRA~1\INTERN~1\iexplore.exe
Thu Jul 15 12:25:26 2004 => Scanning File C:\PROGRA~1\INTERN~1\iexplore.exe
Thu Jul 15 12:25:26 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\mwavscan.com
Thu Jul 15 12:25:26 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavss.exe

Thu Jul 15 12:25:26 2004 => ***** Scanning Registry Files *****
Thu Jul 15 12:25:26 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Thu Jul 15 12:25:26 2004 => Scanning File C:\WINDOWS\Explorer.exe
Thu Jul 15 12:25:26 2004 => Scanning File C:\WINDOWS\system32\userinit.exe
Thu Jul 15 12:25:26 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Thu Jul 15 12:25:26 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapw32.exe
Thu Jul 15 12:25:26 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Thu Jul 15 12:25:26 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Thu Jul 15 12:25:26 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Thu Jul 15 12:25:26 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Thu Jul 15 12:25:26 2004 => Scanning File C:\WINDOWS\System32\ctfmon.exe
Thu Jul 15 12:25:26 2004 => Scanning File C:\Programmer\Messenger\MSMSGS.EXE
Thu Jul 15 12:25:26 2004 => Scanning File C:\PROGRA~1\SYMNET~1\SNDMon.exe
Thu Jul 15 12:25:26 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Thu Jul 15 12:25:26 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Thu Jul 15 12:25:26 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Thu Jul 15 12:25:26 2004 => Scanning HKCR\txtfile\shell\open\command
Thu Jul 15 12:25:26 2004 => Scanning HKCR\comfile\shell\open\command
Thu Jul 15 12:25:26 2004 => Scanning HKCR\exefile\shell\open\command
Thu Jul 15 12:25:26 2004 => Scanning HKCR\dllfile\shell\open\command
Thu Jul 15 12:25:26 2004 => Scanning HKCR\batfile\shell\open\command
Thu Jul 15 12:25:26 2004 => Scanning HKCR\piffile\shell\open\command
Thu Jul 15 12:25:26 2004 => Scanning HKCR\scrfile\shell\open\command
Thu Jul 15 12:25:26 2004 => Scanning HKCR\scrfile\shell\config\command
Thu Jul 15 12:25:27 2004 => Scanning HKCR\regfile\shell\open\command

Thu Jul 15 12:25:27 2004 => ***** Scanning StartUp Folders *****

Thu Jul 15 12:25:27 2004 => ***** Scanning C:\Documents and Settings\Lars Jørgensen\Menuen Start\Programmer\Start Folder *****
Thu Jul 15 12:25:27 2004 => Scanning Folder: C:\Documents and Settings\Lars Jørgensen\Menuen Start\Programmer\Start\*.*
Thu Jul 15 12:25:27 2004 => Scanning File C:\Documents and Settings\Lars Jørgensen\Menuen Start\Programmer\Start\desktop.ini

Thu Jul 15 12:25:27 2004 => ***** Scanning C:\Documents and Settings\All Users\Menuen Start\Programmer\Start Folder *****
Thu Jul 15 12:25:27 2004 => Scanning Folder: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\*.*
Thu Jul 15 12:25:27 2004 => Scanning File C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\desktop.ini

Thu Jul 15 12:25:27 2004 => ***** Scanning Service Files *****
Thu Jul 15 12:25:27 2004 => Scanning HKLM\SYSTEM\CurrentControlSet\Services
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ACPI.sys
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\drivers\aec.sys
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\drivers\afd.sys
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\alg.exe
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\asyncmac.sys
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\atapi.sys
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\atmarpc.sys
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:27 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\audstub.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\cdrom.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\system32\cisvc.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\system32\clipsrv.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\dllhost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\disk.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\dmadmin.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\drivers\dmboot.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\drivers\dmio.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\drivers\dmload.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\drivers\DMusic.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\drivers\drmkaud.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\system32\services.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\fdc.sys
Thu Jul 15 12:25:28 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\fetnd5.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ftdisk.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\gameenum.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\msgpc.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\i8042prt.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\imapi.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\imapi.exe
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipinip.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipnat.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipsec.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\irenum.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\isapnp.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\drivers\kmixer.sys
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:29 2004 => Scanning File C:\WINDOWS\System32\mnmsrvc.exe
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\mouclass.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\mrxdav.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\msdtc.exe
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\msiexec.exe
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\drivers\MSKSSRV.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\drivers\MSPCLOCK.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\drivers\MSPQM.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\drivers\msmpu401.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\SYSTEM32\DRIVERS\NAVAP.SYS
Thu Jul 15 12:25:30 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapsvc.exe
Thu Jul 15 12:25:30 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\VIRUSD~1\20040714.020\NAVENG.SYS
Thu Jul 15 12:25:30 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\VIRUSD~1\20040714.020\NAVEX15.SYS
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Thu Jul 15 12:25:30 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\netbios.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\netbt.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\system32\netdde.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\system32\netdde.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\lsass.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\lsass.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\parport.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\pci.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\drivers\pfc.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\system32\services.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\lsass.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\raspptp.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\processr.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\system32\lsass.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\psched.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ptilink.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\rasacd.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Thu Jul 15 12:25:31 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\raspti.sys
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\rdbss.sys
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\system32\sessmgr.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\redbook.sys
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\locator.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\rsvp.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\s3gnbm.sys
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\system32\lsass.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\SCardSvr.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\SCardSvr.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\secdrv.sys
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\serenum.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\serial.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\SNDSrvc.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\drivers\splitter.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\system32\spoolsv.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\sr.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\srv.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\swenum.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\drivers\swmidi.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\dllhost.exe
Thu Jul 15 12:25:33 2004 => Scanning File C:\PROGRAMMER\SYMANTEC\SYMEVENT.SYS
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\SYSTEM32\DRIVERS\SYMREDRV.SYS
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\SYSTEM32\DRIVERS\SYMTDI.SYS
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\System32\drivers\sysaudio.sys
Thu Jul 15 12:25:33 2004 => Scanning File C:\WINDOWS\system32\smlogsvc.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\tcpip.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\termdd.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\update.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\ups.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\usbehci.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\usbhub.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\drivers\vga.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\viaagp.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\viaagp1.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\viaidexp.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\drivers\viaudios.sys
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\vssvc.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\wanarp.sys
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\drivers\wdmaud.sys
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wbem\wmiapsrv.exe
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\svchost.exe

Thu Jul 15 12:25:35 2004 => ***** Scanning Important System Files *****
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\winsock.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\ws2help.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\ws2_32.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wscript.exe
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshatm.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshcon.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshda.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshext.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wship6.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshisn.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshnetbs.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshom.ocx
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\WshRm.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wshtcpip.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wsnmp32.dll
Thu Jul 15 12:25:35 2004 => Scanning File C:\WINDOWS\System32\wsock32.dll
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\wstdecod.dll
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\explorer.exe
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\explorer.scf
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\NOTEPAD.EXE
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\notepad.exe
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\cmd.exe
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\kernel32.dll
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\ntoskrnl.exe
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\ntkrnlpa.exe
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\hal.dll
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\win32k.sys
Thu Jul 15 12:25:36 2004 => Scanning File C:\WINDOWS\System32\ntdll.dll
Thu Jul 15 12:25:37 2004 => Scanning File C:\WINDOWS\System32\advapi32.dll
Thu Jul 15 12:25:37 2004 => Scanning File C:\WINDOWS\System32\user32.dll
Thu Jul 15 12:25:37 2004 => Scanning File C:\WINDOWS\System32\gdi32.dll
Thu Jul 15 12:25:37 2004 => Scanning File C:\WINDOWS\System32\bootvid.dll
Thu Jul 15 12:25:37 2004 => Scanning File C:\WINDOWS\System32\command.com

Thu Jul 15 12:25:37 2004 => ***** Checking for specific ITW Viruses *****
Thu Jul 15 12:25:37 2004 => Checking for Welchia Virus...
Thu Jul 15 12:25:37 2004 => Checking for LovGate Virus...
Thu Jul 15 12:25:37 2004 => Checking for CodeRed Virus...
Thu Jul 15 12:25:37 2004 => Checking for OpaServ Virus...
Thu Jul 15 12:25:37 2004 => Checking for Sobig.e Virus...
Thu Jul 15 12:25:37 2004 => Checking for Winupie Virus...
Thu Jul 15 12:25:37 2004 => Checking for Swen Virus...
Thu Jul 15 12:25:37 2004 => Checking for JS.Fortnight Virus...
Thu Jul 15 12:25:37 2004 => Checking for Novarg Virus...
Thu Jul 15 12:25:37 2004 => Checking for Pagabot Virus...

Thu Jul 15 12:25:37 2004 => ***** Scanning complete. *****

Thu Jul 15 12:25:37 2004 => Total Number of Files Scanned: 222
Thu Jul 15 12:25:37 2004 => Total Number of Virus(es) Found: 0
Thu Jul 15 12:25:37 2004 => Total Number of Disinfected Files: 0
Thu Jul 15 12:25:37 2004 => Total Number of Files Renamed: 0
Thu Jul 15 12:25:37 2004 => Total Number of Deleted Files: 0
Thu Jul 15 12:25:37 2004 => Total Number of Errors: 0
Thu Jul 15 12:25:37 2004 => Time Elapsed: 00:00:13
Thu Jul 15 12:25:37 2004 => Virus Database Date: 2004/07/09
Thu Jul 15 12:25:37 2004 => Virus Database Count: 96426

Thu Jul 15 12:25:37 2004 => Scan Completed.

Thu Jul 15 12:26:21 2004 => Virus Database Date: 2004/07/09
Thu Jul 15 12:26:21 2004 => Virus Database Count: 96426
Thu Jul 15 12:26:59 2004 => AV Library Unloaded (3)...
Thu Jul 15 22:14:59 2004 => **********************************************************
Thu Jul 15 22:14:59 2004 => eScan AntiVirus Toolkit Utility.
Thu Jul 15 22:14:59 2004 => Copyright © 2003-2004,  MicroWorld Technologies Inc.
Thu Jul 15 22:14:59 2004 => **********************************************************
Thu Jul 15 22:14:59 2004 => Version 4.2.6
Thu Jul 15 22:14:59 2004 => Log File: C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\mwav.log
Thu Jul 15 22:14:59 2004 => Latest Date of files inside MWAV: 09 Jul 2004  12:06:55.
Thu Jul 15 22:15:00 2004 => AV Library Loaded...
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavss.exe
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\Getvlist.exe
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavss.dll
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavssdi.dll
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavssi.dll
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavvlg.dll
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\msvlclnt.dll
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\ipc.dll
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\main.avi
Thu Jul 15 22:15:00 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\virus.avi
Thu Jul 15 22:15:00 2004 => Virus Database Date: 2004/07/09
Thu Jul 15 22:15:00 2004 => Virus Database Count: 96426

Thu Jul 15 22:16:24 2004 => **********************************************************
Thu Jul 15 22:16:24 2004 => eScan AntiVirus Toolkit Utility.
Thu Jul 15 22:16:24 2004 => Copyright © 2003-2004,  MicroWorld Technologies Inc.
Thu Jul 15 22:16:24 2004 =>
Thu Jul 15 22:16:24 2004 => Support: support@mwti.net
Thu Jul 15 22:16:24 2004 => Web: http://www.mwti.net
Thu Jul 15 22:16:24 2004 => **********************************************************
Thu Jul 15 22:16:24 2004 => Version 4.2.6
Thu Jul 15 22:16:24 2004 => Log File: C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\mwav.log
Thu Jul 15 22:16:24 2004 => Latest Date of files inside MWAV: 09 Jul 2004  12:06:55.

Thu Jul 15 22:16:24 2004 => Options Selected by User:
Thu Jul 15 22:16:24 2004 => Memory Check: Enabled
Thu Jul 15 22:16:25 2004 => Registry Check: Enabled
Thu Jul 15 22:16:25 2004 => StartUp Folder Check: Enabled
Thu Jul 15 22:16:25 2004 => System Folder Check: Disabled
Thu Jul 15 22:16:25 2004 => System Area Check: Disabled
Thu Jul 15 22:16:25 2004 => Services Check: Enabled
Thu Jul 15 22:16:25 2004 => Drive Check Option Disabled
Thu Jul 15 22:16:25 2004 => Scanning Type: Scan And Clean
Thu Jul 15 22:16:25 2004 => Folder Check: Disabled

Thu Jul 15 22:16:25 2004 => ***** Scanning Memory Files *****
Thu Jul 15 22:16:25 2004 => Scanning File C:\WINDOWS\system32\services.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\WINDOWS\system32\lsass.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\WINDOWS\system32\spoolsv.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapsvc.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\WINDOWS\Explorer.EXE
Thu Jul 15 22:16:25 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapw32.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\WINDOWS\System32\ctfmon.exe
Thu Jul 15 22:16:25 2004 => Scanning File C:\Programmer\Messenger\MSMSGS.EXE
Thu Jul 15 22:16:26 2004 => Scanning File C:\PROGRA~1\INTERN~1\iexplore.exe
Thu Jul 15 22:16:26 2004 => Scanning File C:\WINDOWS\System32\wuauclt.exe
Thu Jul 15 22:16:26 2004 => Scanning File C:\PROGRA~1\OUTLOO~1\msimn.exe
Thu Jul 15 22:16:26 2004 => Scanning File E:\setup.exe
Thu Jul 15 22:16:31 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\mwavscan.com
Thu Jul 15 22:16:31 2004 => Scanning File C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\kavss.exe

Thu Jul 15 22:16:31 2004 => ***** Scanning Registry Files *****
Thu Jul 15 22:16:31 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Thu Jul 15 22:16:31 2004 => Scanning File C:\WINDOWS\Explorer.exe
Thu Jul 15 22:16:31 2004 => Scanning File C:\WINDOWS\system32\userinit.exe
Thu Jul 15 22:16:31 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Thu Jul 15 22:16:31 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapw32.exe
Thu Jul 15 22:16:32 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Thu Jul 15 22:16:32 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Thu Jul 15 22:16:32 2004 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Thu Jul 15 22:16:32 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Thu Jul 15 22:16:32 2004 => Scanning File C:\WINDOWS\System32\ctfmon.exe
Thu Jul 15 22:16:32 2004 => Scanning File C:\Programmer\Messenger\MSMSGS.EXE
Thu Jul 15 22:16:32 2004 => Scanning File C:\PROGRA~1\SYMNET~1\SNDMon.exe
Thu Jul 15 22:16:32 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Thu Jul 15 22:16:32 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Thu Jul 15 22:16:32 2004 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Thu Jul 15 22:16:32 2004 => Scanning HKCR\txtfile\shell\open\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\comfile\shell\open\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\exefile\shell\open\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\dllfile\shell\open\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\batfile\shell\open\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\piffile\shell\open\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\scrfile\shell\open\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\scrfile\shell\config\command
Thu Jul 15 22:16:32 2004 => Scanning HKCR\regfile\shell\open\command

Thu Jul 15 22:16:32 2004 => ***** Scanning StartUp Folders *****

Thu Jul 15 22:16:32 2004 => ***** Scanning C:\Documents and Settings\Lars Jørgensen\Menuen Start\Programmer\Start Folder *****
Thu Jul 15 22:16:32 2004 => Scanning Folder: C:\Documents and Settings\Lars Jørgensen\Menuen Start\Programmer\Start\*.*
Thu Jul 15 22:16:32 2004 => Scanning File C:\Documents and Settings\Lars Jørgensen\Menuen Start\Programmer\Start\desktop.ini

Thu Jul 15 22:16:32 2004 => ***** Scanning C:\Documents and Settings\All Users\Menuen Start\Programmer\Start Folder *****
Thu Jul 15 22:16:32 2004 => Scanning Folder: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\*.*
Thu Jul 15 22:16:32 2004 => Scanning File C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\desktop.ini

Thu Jul 15 22:16:32 2004 => ***** Scanning Service Files *****
Thu Jul 15 22:16:32 2004 => Scanning HKLM\SYSTEM\CurrentControlSet\Services
Thu Jul 15 22:16:32 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ACPI.sys
Thu Jul 15 22:16:32 2004 => Scanning File C:\WINDOWS\System32\drivers\aec.sys
Thu Jul 15 22:16:32 2004 => Scanning File C:\WINDOWS\System32\drivers\afd.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\alg.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\asyncmac.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\atapi.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\atmarpc.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\audstub.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\cdrom.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\system32\cisvc.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\system32\clipsrv.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\dllhost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\disk.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\dmadmin.exe
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\drivers\dmboot.sys
Thu Jul 15 22:16:33 2004 => Scanning File C:\WINDOWS\System32\drivers\dmio.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\drivers\dmload.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\drivers\DMusic.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\drivers\drmkaud.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\system32\services.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\fdc.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\fetnd5.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ftdisk.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\gameenum.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\msgpc.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\i8042prt.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\imapi.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\imapi.exe
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
Thu Jul 15 22:16:34 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipinip.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipnat.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ipsec.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\irenum.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\isapnp.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\drivers\kmixer.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\mnmsrvc.exe
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\mouclass.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\mrxdav.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\msdtc.exe
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\msiexec.exe
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\drivers\MSKSSRV.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\drivers\MSPCLOCK.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\drivers\MSPQM.sys
Thu Jul 15 22:16:35 2004 => Scanning File C:\WINDOWS\System32\drivers\msmpu401.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\SYSTEM32\DRIVERS\NAVAP.SYS
Thu Jul 15 22:16:36 2004 => Scanning File C:\PROGRA~1\NORTON~1\navapsvc.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\VIRUSD~1\20040714.020\NAVENG.SYS
Thu Jul 15 22:16:36 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\VIRUSD~1\20040714.020\NAVEX15.SYS
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\netbios.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\netbt.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\system32\netdde.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\system32\netdde.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\lsass.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\lsass.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\parport.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\pci.sys
Thu Jul 15 22:16:36 2004 => Scanning File C:\WINDOWS\System32\drivers\pfc.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\system32\services.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\lsass.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\raspptp.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\processr.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\system32\lsass.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\psched.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\ptilink.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\rasacd.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\raspti.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\rdbss.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\system32\sessmgr.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\redbook.sys
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\locator.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\rsvp.exe
Thu Jul 15 22:16:37 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\s3gnbm.sys
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\system32\lsass.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\SCardSvr.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\SCardSvr.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\secdrv.sys
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\serenum.sys
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\serial.sys
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\PROGRA~1\FLLESF~1\SYMANT~1\SNDSrvc.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\drivers\splitter.sys
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\system32\spoolsv.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\sr.sys
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\srv.sys
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:38 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\swenum.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\drivers\swmidi.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\dllhost.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\PROGRAMMER\SYMANTEC\SYMEVENT.SYS
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\SYSTEM32\DRIVERS\SYMREDRV.SYS
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\SYSTEM32\DRIVERS\SYMTDI.SYS
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\drivers\sysaudio.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\system32\smlogsvc.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\tcpip.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\termdd.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\update.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\ups.exe
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\usbehci.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\usbhub.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\drivers\vga.sys
Thu Jul 15 22:16:39 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\viaagp.sys
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\viaagp1.sys
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\viaidexp.sys
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\drivers\viaudios.sys
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\vssvc.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\DRIVERS\wanarp.sys
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\drivers\wdmaud.sys
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\wbem\wmiapsrv.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\svchost.exe

Thu Jul 15 22:16:40 2004 => ***** Scanning Important System Files *****
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\winsock.dll
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\ws2help.dll
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\ws2_32.dll
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\wscript.exe
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\wshatm.dll
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\wshcon.dll
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\wshda.dll
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\wshext.dll
Thu Jul 15 22:16:40 2004 => Scanning File C:\WINDOWS\System32\wship6.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\wshisn.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\wshnetbs.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\wshom.ocx
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\WshRm.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\wshtcpip.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\wsnmp32.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\wsock32.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\wstdecod.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\explorer.exe
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\explorer.scf
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\NOTEPAD.EXE
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\notepad.exe
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\cmd.exe
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\kernel32.dll
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\ntoskrnl.exe
Thu Jul 15 22:16:41 2004 => Scanning File C:\WINDOWS\System32\ntkrnlpa.exe
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\hal.dll
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\win32k.sys
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\ntdll.dll
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\advapi32.dll
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\user32.dll
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\gdi32.dll
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\bootvid.dll
Thu Jul 15 22:16:42 2004 => Scanning File C:\WINDOWS\System32\command.com

Thu Jul 15 22:16:42 2004 => ***** Checking for specific ITW Viruses *****
Thu Jul 15 22:16:42 2004 => Checking for Welchia Virus...
Thu Jul 15 22:16:42 2004 => Checking for LovGate Virus...
Thu Jul 15 22:16:42 2004 => Checking for CodeRed Virus...
Thu Jul 15 22:16:42 2004 => Checking for OpaServ Virus...
Thu Jul 15 22:16:42 2004 => Checking for Sobig.e Virus...
Thu Jul 15 22:16:42 2004 => Checking for Winupie Virus...
Thu Jul 15 22:16:42 2004 => Checking for Swen Virus...
Thu Jul 15 22:16:42 2004 => Checking for JS.Fortnight Virus...
Thu Jul 15 22:16:42 2004 => Checking for Novarg Virus...
Thu Jul 15 22:16:42 2004 => Checking for Pagabot Virus...

Thu Jul 15 22:16:42 2004 => ***** Scanning complete. *****

Thu Jul 15 22:16:42 2004 => Total Number of Files Scanned: 222
Thu Jul 15 22:16:43 2004 => Total Number of Virus(es) Found: 0
Thu Jul 15 22:16:43 2004 => Total Number of Disinfected Files: 0
Thu Jul 15 22:16:43 2004 => Total Number of Files Renamed: 0
Thu Jul 15 22:16:43 2004 => Total Number of Deleted Files: 0
Thu Jul 15 22:16:43 2004 => Total Number of Errors: 0
Thu Jul 15 22:16:43 2004 => Time Elapsed: 00:00:19
Thu Jul 15 22:16:43 2004 => Virus Database Date: 2004/07/09
Thu Jul 15 22:16:43 2004 => Virus Database Count: 96426

Thu Jul 15 22:16:43 2004 => Scan Completed.
Avatar billede resist Nybegynder
15. juli 2004 - 22:35 #10
Tøm denne mappe for indhold:

C:\DOCUME~1\LARSJR~1\LOKALE~1\Temp\ >>>> mappen temp

Derudover ser scanningen med http://www.mwti.net fin ud.

Angående de filer som Norton har i karantæne så prøv:

Højreklik i tray (i hjørnet ved siden af uret), åbn Quarantine og slet filerne
Avatar billede picasso Nybegynder
15. juli 2004 - 22:49 #11
Jeg kan ikke finde den mappe. Jeg har prøvet at søge på stifinder. Med flueben til skjulte filer mv. i mappeinstillinger. Jeg kan ikke finde tray hverken til højre eller venstre for uret (nederst til højre).
Jeg går fra nu. Håber på et svar til imorgen.
Tak for hjælpen idag.

Lars
Avatar billede resist Nybegynder
16. juli 2004 - 00:05 #12
Du kan prøve at få Empty Temp Folders til at slette for dig:

http://www.spywarefri.dk/vaerktoj.htm#emptytemp

Manual: http://www.spywarefri.dk/emptytempfolders.manual.htm
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester