så kom der lidt nyt.. tog sgu sin tid og gøre de ting, det sidste program kørte 2 ½ time ..gab ,men det fandt pokkers mange ting...
Her er logfil fra Ewido:
+ Scanningsresultat:
HKLM\SOFTWARE\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{014DA6CB-189F-421a-88CD-07CFE51CFF10} -> Spyware.BargainBuddy : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} -> Spyware.SideFind : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} -> Spyware.MoneyTree : Renset med backup
HKLM\SOFTWARE\Need2Find -> Spyware.Need2Find : Renset med backup
HKLM\SOFTWARE\Need2Find\bar -> Spyware.Need2Find : Renset med backup
HKLM\SOFTWARE\Need2Find\bar\Partner -> Spyware.Need2Find : Renset med backup
HKLM\SOFTWARE\Policies\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKU\S-1-5-21-839522115-1060284298-1343024091-1003\Software\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKU\S-1-5-21-839522115-1060284298-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Renset med backup
HKU\S-1-5-21-839522115-1060284298-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04079851-5845-4DEA-848C-3ECD647AA554} -> Spyware.MySearchBar : Renset med backup
HKU\S-1-5-21-839522115-1060284298-1343024091-1003\Software\NavExcel Ltd -> Spyware.NavExcel : Renset med backup
HKU\S-1-5-21-839522115-1060284298-1343024091-1003\Software\Need2Find -> Spyware.Need2Find : Renset med backup
HKU\S-1-5-21-839522115-1060284298-1343024091-1003\Software\Need2Find\bar -> Spyware.Need2Find : Renset med backup
HKU\S-1-5-21-839522115-1060284298-1343024091-1003\Software\Policies\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
:mozilla.23:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.24:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.25:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.26:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.27:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.28:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.29:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.30:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.31:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.32:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.33:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.34:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.35:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
:mozilla.40:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Doubleclick : Renset med backup
:mozilla.42:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
:mozilla.43:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
:mozilla.59:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Mediaplex : Renset med backup
:mozilla.62:C:\Documents and Settings\Carste\Application Data\Mozilla\Firefox\Profiles\j6oeni8y.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Renset med backup
C:\Documents and Settings\Carste\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\BlackBox.class-2cbedef0-781e49dd.class -> Not-A-Virus.Exploit.Java.ByteVerify : Renset med backup
C:\Documents and Settings\Carste\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\BlackBox.class-4861ae92-3e699a05.class -> Not-A-Virus.Exploit.Java.ByteVerify : Renset med backup
C:\Documents and Settings\Carste\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\VerifierBug.class-17f8ddf4-6dad33bf.class -> Not-A-Virus.Exploit.Java.ByteVerify : Renset med backup
C:\Documents and Settings\Carste\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\VerifierBug.class-2671f658-4f28272a.class -> Not-A-Virus.Exploit.Java.ByteVerify : Renset med backup
C:\Documents and Settings\Carste\Lokale indstillinger\Temp\6.tmp -> Trojan.Small : Renset med backup
C:\Documents and Settings\Carste\Lokale indstillinger\Temp\A.tmp -> Trojan.Small.ga : Renset med backup
C:\ms32.tmp -> Downloader.Small.azk : Renset med backup
C:\Program Files\SpySheriff\Uninstall.exe -> Adware.SpySheriff : Renset med backup
C:\Programmer\Fælles filer\CMEII\CMEIIAPI.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\CMESys.exe -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GAppMgr.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GController.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GDwldEng.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GIocl.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GIoclClient.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GMTProxy.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GObjs.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GStore.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\GStoreServer.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\CMEII\Gtools.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\GMT\EGGCEngine.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\GMT\egIEEngine.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\GMT\EGIEProcess.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\GMT\EGNSEngine.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\GMT\GatorRes.dll -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\rpdtlrlh\renpttcnap\fntnbpjll.exe -> Adware.Gator : Renset med backup
C:\Programmer\Fælles filer\rpdtlrlh\tfrprlhj\nttlbllp.exe -> Adware.Gator : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/10.scl -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/11.scl -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/12.scl -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/14.scl -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/15.scl -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/16.scl -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/18.scl/AltnetUninstall.exe -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/18.scl/asmend.exe -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/22.scl/mySetp.exe -> Spyware.MyWebSearch : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/23.scl/Points Manager.exe -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/24.scl/setup.cab/PMuninstall.bde -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/24.scl/sysdetect.dll -> Adware.BrilliantDigital : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/27.scl -> Spyware.Altnet : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/46.scl -> Adware.Gator : Renset med backup
C:\Programmer\Spy Cleaner Free Version\Backup\11_03_200513_30_42.zip/53.scl -> Spyware.NewDotNet : Renset med backup
C:\RECYCLER\S-1-5-21-839522115-1060284298-1343024091-500\Dc2.dll -> Adware.SearchPage : Renset med backup
C:\RECYCLER\S-1-5-21-839522115-1060284298-1343024091-500\Dc7.exe -> Trojan.Small : Renset med backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Renset med backup
D:\Program Files\Altnet\Download Manager\asm.exe -> Spyware.Altnet : Renset med backup
D:\Program Files\Altnet\Download Manager\asmps.dll -> Spyware.Altnet : Renset med backup
::Rapport slut
og en log fra HJT:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\CleanMyPC\Registry Cleaner\RCScheduler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
C:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Carste\Dokumenter\Modtagne filer\Ny mappe\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.dk/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://pc-cillin9.antivirus.com/en/90/pccreg/wcoRegister.asp?SN=PCEB%2D9995%2D7410%2D2629%2D5085&GUID=454747424746464F46404645474177&VID=TWP9002002R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Programmer\Burn4Free Toolbar\v2.0.0.2\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Programmer\Burn4Free Toolbar\v2.0.0.2\Burn4Free_Toolbar.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Programmer\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) -
http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37390.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.com/games/popcaploader_v6.cabO23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Kan dog ik lige forstå jeg skal slette C:\Programmer\SuperCleaner da det er et program som renser pc for cookies og sider der er besøgt osv.??