Avatar billede hwks Nybegynder
26. august 2005 - 14:28 Der er 9 kommentarer og
1 løsning

Hijackthis-logfil - PC lukker ned

Hej Eksperter

Min PC (Windows 2000) lukker ned efter denne fejl "Systemet er ved at lukke. Gem alt igangværende arbejde og log af. Ændringer, som ikke er gemt, vil gå tabt. Lukningen er iværksat af NT AUTHORITY SYSTEM.... Tid tilbage før der lukkes.....

'Systemprocessen C:\WINNT\system32\services.exe' afsluttede uventet med statuskode 128.

Jeg har kørt FxSasser og FixBlast i fejlsikret tilstand og i normal tilstand. Jeg har virusscannet med Pandas Onlinescanner. Jeg har downloadet og installeret Windows Patch KB835732-x86-DAN. Jeg har kørt Nukers onlinescanner.

Intet har hjulpet - og det ser ud som om, at der ikke er virus.

Nu har jeg kørt Hijackthis - og poster her en logfil. Jeg håber, at en ekspert kan se hvor svinet gemmer sig.

Her er logfilen:

Logfile of HijackThis v1.99.1
Scan saved at 14:15:59, on 26-08-2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Programmer\ahead\InCD\InCD.exe
C:\Programmer\Fælles filer\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Programmer\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\FSI\F-Prot\F-StopW.EXE
C:\Programmer\FSI\F-Prot\F-Sched.exe
C:\WINNT\system32\internat.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Programmer\SmartDisk\FlashPath\sdstat.exe
C:\Programmer\TEXTware\HotKey\Twalink.exe
C:\Programmer\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Programmer\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\HWS\LOKALE~1\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\WINNT\Downloaded Program Files\googlenav.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [InCD] C:\Programmer\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Programmer\Fælles filer\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmer\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [F-StopW] C:\Programmer\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [FRISK FP-Scheduler] C:\Programmer\FSI\F-Prot\F-Sched.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [RO2001] C:\Programmer\RO2001\RO2001starter.exe -compact
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmer\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: FlashPath Monitor.lnk = C:\Programmer\SmartDisk\FlashPath\sdstat.exe
O4 - Global Startup: HotKey.lnk = C:\Programmer\TEXTware\HotKey\Twalink.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 1.lnk = C:\Programmer\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O15 - Trusted Zone: *.e-cbs.dk
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://erfyaalsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (WebProgramManager Class) - http://instantsupport.europe.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124744107997
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A590956F-AE99-4419-BB39-3C721276C625} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-0504.exe
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://scanner.virus112.com/cabs/cssweb.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.danskebank.dk/html/activex/danskesikker/DB/DanskeSikker.cab
O16 - DPF: {F9408298-9658-482C-8B02-93F09A80225F} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-0104.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
Avatar billede fromsej Praktikant
26. august 2005 - 14:34 #1
Der er ikke noget at se i loggen, prøv de to scannere fra denne artikel:
http://www.eksperten.dk/artikler/755
Avatar billede hwks Nybegynder
26. august 2005 - 14:36 #2
OK - jeg prøver også dem og vender tilbage... tak :)
Avatar billede hwks Nybegynder
26. august 2005 - 16:40 #3
Hej igen

Her er logfilsudsnit fra Drweb:

Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 48778
Infected objects found: 1
Objects with modifications found: 0
Suspicious objects found: 0
Objects cured: 0
Objects deleted: 1
Objects renamed: 0
Objects moved: 0
Scan speed: 321 Kb/s
Scan time: 01:39:00

Jeg fortsætter med Ewido...
Avatar billede hwks Nybegynder
27. august 2005 - 09:18 #4
Hej igen

Jeg troede ellers lige, at den var der - PC'en var i live i et par timer - men gik ned igen.....

Her er logfil fra Ewido... jeg har slettet de filer, som den kom op og sagde var inficeret - i alt 134 filer....

Spybot fandt yderligere 4 filer og dem slettede den også.

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            21:33:30, 26-08-2005
+ Report-Checksum:        E990B0AC

+ Scan result:

    HKLM\SOFTWARE\Classes\CLSID\{21FFB6C0-0DA1-11D5-A9D5-00500413153C} -> Spyware.Gator : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ad-logics[2].txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ads.specificpop[2].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ads.x10[1].txt -> Spyware.Cookie.X10 : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@adserv3.ads360[1].txt -> Spyware.Cookie.Ads360 : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@adserver.ads360[1].txt -> Spyware.Cookie.Ads360 : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@bs.serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@clickagents[1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@commissionpartner[1].txt -> Spyware.Cookie.Commissionpartner : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@counter.hitslink[2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@counter2.hitslink[2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@doubleclick[3].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@edge.ru4[2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ehg-dig.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ehg-isoinc.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ehg-nokiafin.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ehg-ti.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ehg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@excite[2].txt -> Spyware.Cookie.Excite : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@fastclick[3].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@fl01.ct2.comclick[1].txt -> Spyware.Cookie.Comclick : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@gator[2].txt -> Spyware.Cookie.Gator : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@hg1.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@hotlog[2].txt -> Spyware.Cookie.Hotlog : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@ilead.itrack[2].txt -> Spyware.Cookie.Itrack : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@phg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@pro-market[2].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@qksrv[1].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@servedfor.valuead[1].txt -> Spyware.Cookie.Valuead : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@spylog[1].txt -> Spyware.Cookie.Spylog : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@statse.webtrendslive[1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@t1.adserver[2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@w131.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@weborama[2].txt -> Spyware.Cookie.Weborama : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@webpdp.gator[2].txt -> Spyware.Cookie.Gator : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@www.commission-junction[2].txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@www.qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Cookies\henrik & charlotte@z1.adserver[2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
    C:\Documents and Settings\Henrik & Charlotte.HENRIK-V1YYWM5O\Dokumenter\HENRIK\S-DREV\Dokumenter\Funnies\Viagra3 -> Not-A-Virus.Joke.Viagra : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ad-logics[2].txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ads.specificpop[2].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ads.x10[1].txt -> Spyware.Cookie.X10 : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@adserv3.ads360[1].txt -> Spyware.Cookie.Ads360 : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@adserver.ads360[1].txt -> Spyware.Cookie.Ads360 : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@bs.serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@clickagents[1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@commissionpartner[1].txt -> Spyware.Cookie.Commissionpartner : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@counter.hitslink[2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@counter2.hitslink[2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@doubleclick[3].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@edge.ru4[2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ehg-dig.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ehg-isoinc.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ehg-nokiafin.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ehg-ti.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ehg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@excite[2].txt -> Spyware.Cookie.Excite : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@fastclick[3].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@fl01.ct2.comclick[1].txt -> Spyware.Cookie.Comclick : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@gator[2].txt -> Spyware.Cookie.Gator : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@hg1.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@hotlog[2].txt -> Spyware.Cookie.Hotlog : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@ilead.itrack[2].txt -> Spyware.Cookie.Itrack : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@phg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@pro-market[2].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@qksrv[1].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@servedfor.valuead[1].txt -> Spyware.Cookie.Valuead : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@spylog[1].txt -> Spyware.Cookie.Spylog : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@statse.webtrendslive[1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@t1.adserver[2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@w131.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@weborama[2].txt -> Spyware.Cookie.Weborama : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@webpdp.gator[2].txt -> Spyware.Cookie.Gator : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@www.commission-junction[2].txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@www.qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\henrik & charlotte@z1.adserver[2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@statse.webtrendslive[1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    C:\Documents and Settings\HWS\Cookies\hws@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\HWS\Dokumenter\HENRIK\Funnies\Viagra3 -> Not-A-Virus.Joke.Viagra : Cleaned with backup


::Report End


Her er logfilsudsnit fra Hijackthis....

Logfile of HijackThis v1.99.1
Scan saved at 09:22:10, on 27-08-2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Programmer\ahead\InCD\InCD.exe
C:\Programmer\Fælles filer\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Programmer\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\FSI\F-Prot\F-StopW.EXE
C:\Programmer\FSI\F-Prot\F-Sched.exe
C:\WINNT\system32\internat.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Programmer\SmartDisk\FlashPath\sdstat.exe
C:\Programmer\TEXTware\HotKey\Twalink.exe
C:\Programmer\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Programmer\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Spybot - Search & Destroy\SpybotSD.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\HWS\LOKALE~1\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\WINNT\Downloaded Program Files\googlenav.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [InCD] C:\Programmer\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Programmer\Fælles filer\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmer\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [F-StopW] C:\Programmer\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [FRISK FP-Scheduler] C:\Programmer\FSI\F-Prot\F-Sched.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [RO2001] C:\Programmer\RO2001\RO2001starter.exe -compact
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmer\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: FlashPath Monitor.lnk = C:\Programmer\SmartDisk\FlashPath\sdstat.exe
O4 - Global Startup: HotKey.lnk = C:\Programmer\TEXTware\HotKey\Twalink.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 1.lnk = C:\Programmer\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O15 - Trusted Zone: *.e-cbs.dk
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://erfyaalsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (WebProgramManager Class) - http://instantsupport.europe.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124744107997
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A590956F-AE99-4419-BB39-3C721276C625} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-0504.exe
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://scanner.virus112.com/cabs/cssweb.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.danskebank.dk/html/activex/danskesikker/DB/DanskeSikker.cab
O16 - DPF: {F9408298-9658-482C-8B02-93F09A80225F} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-0104.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
Avatar billede fromsej Praktikant
27. august 2005 - 09:57 #5
Hmm, der er ikke noget at se.
Prøv at uploade denne hos Jotti: http://virusscan.jotti.org/
C:\WINNT\system32\services.exe

Nu kan jeg ikke huske om Dcombobulator virker i Win 2000, men det var oplagt at prøve:
http://grc.com/dcom/
Du skal disable Dcom.
Avatar billede hwks Nybegynder
27. august 2005 - 20:28 #6
Hej fromsej

Har uploadet services.exe til jotti.org - alt fik OK. Har disablet Dcom i Dcombolator.

Nu lader jeg den lige køre et par timer .... måske er den død.... jeg kommer retur og beder dig kaste et svar :))
Avatar billede hwks Nybegynder
28. august 2005 - 17:25 #7
Nu har den stået tændt x-antal timer og det ser ud som om, at alt er i den skønneste orden.

Tak for din tid og din ekspertise  - og jeg vil gerne give dig point - så svar lige...

Kh

Henrik
Avatar billede fromsej Praktikant
28. august 2005 - 21:06 #8
Velbekomme, det lyder godt at det kører. :o)
Avatar billede hwks Nybegynder
28. august 2005 - 21:55 #9
Den er fin - 150 point til dig :))
Avatar billede fromsej Praktikant
28. august 2005 - 22:59 #10
Tak for point.*S*
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester