Avatar billede jdamgaard Nybegynder
15. december 2005 - 20:31 Der er 12 kommentarer og
2 løsninger

Hjælp jeg har spy og virus tror jeg

Her en logfil og desuden er alle ikoner på skrivebordet væk,der kan ikke oprettes nye 



Logfile of HijackThis v1.99.1
Scan saved at 20:36:59, on 15-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Norman\Bin\Zanda.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Norman\Nvc\bin\nvcoas.exe
C:\Norman\bin\NJEEVES.EXE
C:\WINDOWS\System32\alg.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\Norman\bin\ZLH.EXE
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\system32\atlam32.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\DitExp.exe
C:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\sdkvg.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Nvc\bin\cclaw.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Anette Damgaard\Skrivebord\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Class - {8D169E2E-8319-8F6C-013A-36574F8EC46F} - C:\WINDOWS\appmv32.dll
O2 - BHO: Class - {A5B70C48-44FC-EE21-10FB-6B345BD9B634} - C:\WINDOWS\system32\mskh.dll
O2 - BHO: Class - {A81A1A73-0ABD-D6BC-44CD-1C5B54E9058A} - C:\WINDOWS\apixm32.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ipcs.exe] C:\WINDOWS\system32\ipcs.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [addpc32.exe] C:\WINDOWS\system32\addpc32.exe
O4 - HKLM\..\Run: [atlam32.exe] C:\WINDOWS\system32\atlam32.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Programmer\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup:  Labtec Mouse Software 2.0.lnk = C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Erotik - {95347D30-555E-4534-A05F-2229074E0A88} - http://www.porno.dk (file missing)
O9 - Extra 'Tools' menuitem: Erotik... - {95347D30-555E-4534-A05F-2229074E0A88} - http://www.porno.dk (file missing)
O9 - Extra button: Sol Dating - {D5721FC7-8FBE-4d71-9C65-9718CFA078A8} - http://www.soldating.dk (file missing)
O9 - Extra 'Tools' menuitem: Sol Dating... - {D5721FC7-8FBE-4d71-9C65-9718CFA078A8} - http://www.soldating.dk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/15a2f7d5f76aa55c1005/netzip/RdxIE601.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sdkvg.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Avatar billede halvamatoer Nybegynder
15. december 2005 - 20:42 #1
start med at følge nedenstående link
www.exp.dk/artikler/755 og kom med nye logs efter det
Avatar billede jdamgaard Nybegynder
15. december 2005 - 21:54 #2
Såskulle de gerne være der alle 3



---------------------------------------------------------
ewido security suite - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            21:41:09, 15-12-2005
+ Rapport-Checksum:        C0757A6C

+ Scanningsresultat:
    HKLM\SOFTWARE\Classes\CLSID\{3E8AEA49-2882-96D1-D4B0-D1EA3E4EEFD2} -> Spyware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{4FCD2C21-6232-FD0F-36AA-4EFFC9284B2A} -> Spyware.CoolWebSearch : Renset med backup
    C:\Documents and Settings\All Users\Application Data\SecTaskMan\2D9.tmp.exe.q_4E402E77_q -> Trojan.Small.ga : Renset med backup
    :mozilla.6:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.7:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Doubleclick : Renset med backup
    :mozilla.9:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.15:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.16:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Atdmt : Renset med backup
    :mozilla.17:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.18:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.19:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.20:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.21:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.29:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Com : Renset med backup
    :mozilla.30:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Com : Renset med backup
    :mozilla.59:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.61:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.108:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.114:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Mediaplex : Renset med backup
    :mozilla.119:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Fastclick : Renset med backup
    :mozilla.122:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.123:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.124:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.125:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.126:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    :mozilla.127:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.132:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Bfast : Renset med backup
    :mozilla.142:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.143:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.144:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.145:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.146:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.147:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.148:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.149:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.150:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.151:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.152:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.153:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.154:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.155:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.156:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.157:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.158:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.159:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.160:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.161:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.162:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.257:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.258:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.270:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Spylog : Renset med backup
    :mozilla.275:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.276:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.277:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.278:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.279:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.280:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Valueclick : Renset med backup
    :mozilla.292:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Paycounter : Renset med backup
    :mozilla.312:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.313:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.314:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.315:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.319:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Overture : Renset med backup
    :mozilla.320:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Overture : Renset med backup
    :mozilla.321:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Overture : Renset med backup
    :mozilla.330:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Masterstats : Renset med backup
    :mozilla.343:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.349:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.359:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.360:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.362:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.363:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.365:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.366:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.369:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.370:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.371:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Findwhat : Renset med backup
    :mozilla.373:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.374:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.376:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.377:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.379:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.380:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.381:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.383:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Renset med backup
    :mozilla.386:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.389:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.390:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.391:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.392:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.395:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.396:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Hitbox : Renset med backup
    :mozilla.398:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.400:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.403:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.418:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.Clickzs : Renset med backup
    :mozilla.426:C:\Documents and Settings\Anette Damgaard\Application Data\Mozilla\Firefox\Profiles\487evwhj.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\1.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\10.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\11.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\12.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\13.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\14.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\16.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\2.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\2D9.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\3.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\4.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\5.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\6.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\7.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\8.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\9.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\A.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\B.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\C.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\Cookies\anette damgaard@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\D.tmp -> Trojan.Small.ga : Renset med backup
    C:\Documents and Settings\Anette Damgaard\Lokale indstillinger\Temp\E.tmp -> Trojan.Small.ga : Renset med backup
    C:\WINDOWS\002434_.tmp:roqwj -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\addgt.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\addhq.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\addkv32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\addrj32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\apida32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\apiry32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\apiti32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\apity.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\apiww32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\apphb.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\appxb32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\atlbi32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\atldc.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\atlel.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\atlgh32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\atlib.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\atlyv.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\creb.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\crof.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\d3nf.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\d3si.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\d3tg32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\d3xl.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\iedw.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\iedx32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\iefk32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\ipgn.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\ipwc32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\javaad.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\javaak.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\javabm32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\javacd32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\javasc32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\javawr32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\KB817778Uninst.log:qepcl -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\mfcey32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\mfcsp.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\mfcsz.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\mfcvn.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\msbq32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\msni32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\mspf.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\netbj32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\netca32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\netgz32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\netif32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\netni32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\netpr32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\netus.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\netvb32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\ntdb.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\ntmb32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\ntot.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\ntra.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\nttk32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\ntwj.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\ntzn.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\orun32(2).ini:fvyko -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\orun32(3).ini:fvyko -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\orun32(4).ini:fvyko -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\orun32.ini:fvyko -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\sdklo32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\sysci32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\sysrx.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\addhz32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\addnf32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\apigg.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\apigo.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\apiiy.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\apipp32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\appat32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\appsv.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\appvr.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\atlts.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\crcp.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\crde32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\croa.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\cryy.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\d3br.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\d3et32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\d3mx.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\d3tv.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\iegs32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\iemk.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\iepd.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\iero32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\iewt32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\ipch32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\iplg32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\iprs32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\javany32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\javaov.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\mfcbo32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\mfccq.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\mfctl.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\msoh.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\mspf32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\msqr.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\msws32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\mszt32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\netcf32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\netjc32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\ntbx.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\ntdo32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\ntuq.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\ntwj32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sdkfi.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sdkgn.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sdkng.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sdkno32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\sdkuf.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sdkwi.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\sdkxu.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\sdkya32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sysay.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\syshd.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sysie.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sysiu.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sysjc32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\sysne.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\syspo.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\winmj32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\system32\winuv.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\system32\winxz32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\sysyj.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\sysyv32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\syszi32.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\winfg32.exe -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\winky.exe -> Trojan.Agent.bi : Renset med backup
    C:\WINDOWS\_default(2).pif:lnhus -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\_default(3).pif:lnhus -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\_default(4).pif:lnhus -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\_default(5).pif:argda -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\_default(5).pif:lnhus -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\_default(6).pif:argda -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\_default(6).pif:lnhus -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\_default(7).pif:argda -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\_default(7).pif:lnhus -> Downloader.Agent.td : Renset med backup
    C:\WINDOWS\_default.pif:argda -> Downloader.WinShow.bg : Renset med backup
    C:\WINDOWS\_default.pif:lnhus -> Downloader.Agent.td : Renset med backup


::Rapport slut



Logfile of HijackThis v1.99.1
Scan saved at 21:54:12, on 15-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Norman\Bin\Zanda.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\Norman\bin\NJEEVES.EXE
C:\WINDOWS\System32\alg.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\Norman\bin\ZLH.EXE
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\Dit.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Nvc\bin\cclaw.exe
C:\WINDOWS\DitExp.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\addfq.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\javaaf.exe
C:\Documents and Settings\Anette Damgaard\Skrivebord\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Class - {8D169E2E-8319-8F6C-013A-36574F8EC46F} - C:\WINDOWS\appmv32.dll (file missing)
O2 - BHO: Class - {A5B70C48-44FC-EE21-10FB-6B345BD9B634} - C:\WINDOWS\system32\mskh.dll (file missing)
O2 - BHO: Class - {A81A1A73-0ABD-D6BC-44CD-1C5B54E9058A} - C:\WINDOWS\apixm32.dll
O2 - BHO: Class - {D849A7FC-710D-53C7-D561-509D49D3C396} - C:\WINDOWS\system32\atlit.dll (file missing)
O2 - BHO: Class - {F736EFCA-786C-7C51-6EE0-0CFF9B1F763E} - C:\WINDOWS\atlri.dll (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [javaaf.exe] C:\WINDOWS\system32\javaaf.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Programmer\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup:  Labtec Mouse Software 2.0.lnk = C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Erotik - {95347D30-555E-4534-A05F-2229074E0A88} - http://www.porno.dk (file missing)
O9 - Extra 'Tools' menuitem: Erotik... - {95347D30-555E-4534-A05F-2229074E0A88} - http://www.porno.dk (file missing)
O9 - Extra button: Sol Dating - {D5721FC7-8FBE-4d71-9C65-9718CFA078A8} - http://www.soldating.dk (file missing)
O9 - Extra 'Tools' menuitem: Sol Dating... - {D5721FC7-8FBE-4d71-9C65-9718CFA078A8} - http://www.soldating.dk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/15a2f7d5f76aa55c1005/netzip/RdxIE601.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\addfq.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


[Scan path] C:\
Master Boot Record HDD1 - Ok
Active OS/2 or WinNT Boot Sector HDD1 - Ok

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 2
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 0 Kb/s
Scan time: 00:00:09
-----------------------------------------------------------------------------

Scanning interrupted by user!
[Scan path] C:\
Master Boot Record HDD1 - Ok
Active OS/2 or WinNT Boot Sector HDD1 - Ok

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 2
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 0 Kb/s
Scan time: 00:00:02
-----------------------------------------------------------------------------

Scanning interrupted by user!
[Scan path] C:\
Master Boot Record HDD1 - Ok
Active OS/2 or WinNT Boot Sector HDD1 - Ok

[Scan path] D:\
>D:\Driver\CardReader\Firmware\IIUSBISP.dll - Ok
D:\Driver\CardReader\Firmware\IIUSBISP.ini - Ok
D:\Driver\CardReader\Firmware\Index.txt - Ok
D:\Driver\CardReader\Firmware\Medion_30A_1.HEX - archive MAIL
D:\Driver\CardReader\Firmware\USB ISP Type1 V0.96.0730.exe - Ok
D:\Driver\CardReader\Firmware\USBISP.ini - Ok
D:\Driver\CardReader\Make bootable flashcards\AUTOEXEC.BAT - Ok
D:\Driver\CardReader\Make bootable flashcards\autoexec.default - Ok
D:\Driver\CardReader\Make bootable flashcards\COMMAND.COM - Ok
D:\Driver\CardReader\Make bootable flashcards\CONFIG.Default - Ok
D:\Driver\CardReader\Make bootable flashcards\CONFIG.SYS - Ok
D:\Driver\CardReader\Make bootable flashcards\country.sys - Ok
D:\Driver\CardReader\Make bootable flashcards\DISPLAY.SYS - Ok
D:\Driver\CardReader\Make bootable flashcards\EGA.CPI - Ok
D:\Driver\CardReader\Make bootable flashcards\Gate.dll - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-e.htm - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-g.htm - Ok
D:\Driver\CardReader\Make bootable flashcards\History.txt - Ok
D:\Driver\CardReader\Make bootable flashcards\Image1.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\Image2.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\Image3.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\Image4.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\Image5.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\Image6.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\IO.SYS - Ok
D:\Driver\CardReader\Make bootable flashcards\KEYB.COM - Ok
D:\Driver\CardReader\Make bootable flashcards\KEYBOARD.SYS - Ok
D:\Driver\CardReader\Make bootable flashcards\Language.ini - Ok
D:\Driver\CardReader\Make bootable flashcards\MasStor.dll - Ok
D:\Driver\CardReader\Make bootable flashcards\medion.ico - Ok
D:\Driver\CardReader\Make bootable flashcards\MkBootW.exe - Ok
D:\Driver\CardReader\Make bootable flashcards\MODE.COM - Ok
>D:\Driver\CardReader\Make bootable flashcards\MSCDEX.EXE - Ok
D:\Driver\CardReader\Make bootable flashcards\MSDOS.SYS - Ok
D:\Driver\CardReader\Make bootable flashcards\OAKCDROM.SYS - Ok
D:\Driver\CardReader\Make bootable flashcards\Thumbs.db - Ok
D:\Driver\CardReader\Make bootable flashcards\Thumbs.db:encryptable - Ok
D:\Driver\CardReader\Make bootable flashcards\zip100_2KXP.img - Ok
>D:\Driver\CardReader\Make bootable flashcards\zip100_98ME.img - Ok
D:\Driver\CardReader\Make bootable flashcards\zip250_2KXP.img - Ok
D:\Driver\CardReader\Make bootable flashcards\zip250_98ME.img - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-e-Dateien\filelist.xml - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-e-Dateien\image001.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-e-Dateien\image002.jpg - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-e-Dateien\image003.jpg - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-e-Dateien\image004.jpg - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-g-Dateien\filelist.xml - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-g-Dateien\image001.gif - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-g-Dateien\image002.jpg - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-g-Dateien\image003.jpg - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-g-Dateien\image004.jpg - Ok
D:\Driver\CardReader\Make bootable flashcards\Help-g-Dateien\image005.jpg - Ok
D:\Driver\CardReader\Setup\DATA1.CAB - Ok
D:\Driver\CardReader\Setup\DATA1.HDR - Ok
D:\Driver\CardReader\Setup\DATA2.CAB - Ok
D:\Driver\CardReader\Setup\Dit.dll - Ok
D:\Driver\CardReader\Setup\Dit.ini - Ok
D:\Driver\CardReader\Setup\ICCLR.INF - Ok
D:\Driver\CardReader\Setup\ICSET.INF - Ok
D:\Driver\CardReader\Setup\ICSI2K.INF - Ok
D:\Driver\CardReader\Setup\ICSI98.INF - Ok
>D:\Driver\CardReader\Setup\IKERNEL.EX_ - Ok
D:\Driver\CardReader\Setup\LAYOUT.BIN - Ok
D:\Driver\CardReader\Setup\Readme.txt - Ok
D:\Driver\CardReader\Setup\Setup.bmp - Ok
D:\Driver\CardReader\Setup\Setup.exe - Ok
D:\Driver\CardReader\Setup\Setup.ini - Ok
D:\Driver\CardReader\Setup\Setup.inx - Ok
D:\Driver\Keyboard\setup.exe - Ok
D:\Driver\LAN\diag.exe - Ok
D:\Driver\LAN\DIAG.TXT - Ok
D:\Driver\LAN\FETND.DOS - Ok
D:\Driver\LAN\FETND3.sys - Ok
D:\Driver\LAN\FETND4.sys - Ok
D:\Driver\LAN\FETND5A.sys - Ok
D:\Driver\LAN\FETND5B.sys - Ok
D:\Driver\LAN\FETNDH.HLP - Ok
D:\Driver\LAN\FETNDIS.inf - Ok
D:\Driver\LAN\FETODI.COM - Ok
D:\Driver\LAN\netvt.cat - Ok
D:\Driver\LAN\NTUTIL.DLL - Ok
D:\Driver\LAN\oemsetup.inf - Ok
D:\Driver\LAN\readme.txt - Ok
D:\Driver\LAN\Release.pdf - Ok
D:\Driver\LAN\WIN.txt - Ok
D:\Driver\LAN\WINNDI.DLL - Ok
D:\Driver\LAN\WINNT.txt - Ok
D:\Driver\LAN\winsetup.exe - Ok
D:\Driver\LAN\winsetup.txt - Ok
D:\Driver\LAN\EEPROM\eep6105.doc - Ok
D:\Driver\LAN\EEPROM\eeprom.cfg - Ok
D:\Driver\LAN\EEPROM\EEPROM.EXE - Ok
D:\Driver\LAN\EEPROM\eeprom.txt - Ok
D:\Driver\LAN\FREEBSD\freebsd.tar - archive TAR
D:\Driver\LAN\FREEBSD\freebsd.txt - Ok
D:\Driver\LAN\LANSVR40.DOS\FETND.DOS - Ok
D:\Driver\LAN\LANSVR40.DOS\LSDOS.TXT - Ok
D:\Driver\LAN\LANSVR40.DOS\OEMSETUP.INF - Ok
D:\Driver\LAN\LANTASTI\FETND.DOS - Ok
D:\Driver\LAN\LANTASTI\LANTASTI.TXT - Ok
D:\Driver\LAN\LANTASTI\PROTOCOL.INI - Ok
D:\Driver\LAN\LINUX\linux.txt - Ok
D:\Driver\LAN\LINUX\rhinefet.tgz - archive GZIP
D:\Driver\LAN\MSLANMAN.DOS\DRIVERS\ETHERNET\FETND\FETND.DOS - Ok
D:\Driver\LAN\MSLANMAN.DOS\DRIVERS\ETHERNET\FETND\LMDOS.TXT - Ok
D:\Driver\LAN\MSLANMAN.DOS\DRIVERS\ETHERNET\FETND\PROTOCOL.INI - Ok
D:\Driver\LAN\MSLANMAN.DOS\DRIVERS\NIF\FETND.NIF - Ok
D:\Driver\LAN\NETWARE\CLIENT32\CNT32DOS.TXT - Ok
D:\Driver\LAN\NETWARE\CLIENT32\fetnwsc.lan - Ok
D:\Driver\LAN\NETWARE\CLIENT32\fetnwsc.ldi - Ok
D:\Driver\LAN\NETWARE\DOSODI\DOSODI.TXT - Ok
D:\Driver\LAN\NETWARE\DOSODI\FETODI.COM - Ok
D:\Driver\LAN\NETWARE\DOSODI\FETODI.INS - Ok
D:\Driver\LAN\NETWARE\DOSODI\NET.CFG - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\ETHERTSM.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\FETNWSA.LAN - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\LSLENH.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\MONITOR.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\MSM31X.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\NBI31X.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\Nw311.txt - Ok
D:\Driver\LAN\NETWARE\SRVRODI.311\PATCHMAN.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.312\ETHERTSM.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.312\FETNWSA.LAN - Ok
D:\Driver\LAN\NETWARE\SRVRODI.312\MSM31X.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.312\NBI31X.NLM - Ok
D:\Driver\LAN\NETWARE\SRVRODI.312\Nw312.txt - Ok
D:\Driver\LAN\NETWARE\SRVRODI.4\FETNWSA.LAN - Ok
D:\Driver\LAN\NETWARE\SRVRODI.4\fetnwsa.ldi - Ok
D:\Driver\LAN\NETWARE\SRVRODI.4\Nw4.txt - Ok
D:\Driver\LAN\NETWARE\SRVRODI.56\fetnwsc.lan - Ok
D:\Driver\LAN\NETWARE\SRVRODI.56\fetnwsc.ldi - Ok
D:\Driver\LAN\NETWARE\SRVRODI.56\Nw56.txt - Ok
D:\Driver\LAN\NICSET\NICSET-1.18.exe - Ok
D:\Driver\LAN\PCNFS\FETND.DOS - Ok
D:\Driver\LAN\PCNFS\PCNFS.TXT - Ok
D:\Driver\LAN\PCNFS\PROTOCOL.INI - Ok
D:\Driver\LAN\PKTDRVR\FETPKT.COM - Ok
D:\Driver\LAN\PKTDRVR\FETPKT.SYS - Ok
D:\Driver\LAN\PKTDRVR\packet.txt - Ok
D:\Driver\LAN\PXE\pxe.lom - Ok
D:\Driver\LAN\PXE\pxe.txt - Ok
D:\Driver\LAN\PXE\RIS-note.txt - Ok
D:\Driver\LAN\PXERPL\FETND.CNF - Ok
D:\Driver\LAN\PXERPL\FETND.DOS - Ok
D:\Driver\LAN\PXERPL\PROTOCOL.INI - Ok
D:\Driver\LAN\PXERPL\pxerpl.lom - Ok
D:\Driver\LAN\PXERPL\pxerpl.txt - Ok
D:\Driver\LAN\PXERPL\RIS-note.txt - Ok
D:\Driver\LAN\RPL\FETND.CNF - Ok
D:\Driver\LAN\RPL\FETND.DOS - Ok
D:\Driver\LAN\RPL\PROTOCOL.INI - Ok
D:\Driver\LAN\RPL\RPL.lom - Ok
D:\Driver\LAN\RPL\rpldos.txt - Ok
D:\Driver\LAN\RPLW95\FETND.CNF - Ok
D:\Driver\LAN\RPLW95\FETND.DOS - Ok
D:\Driver\LAN\RPLW95\fetnd3.inf - Ok
D:\Driver\LAN\RPLW95\FETND3.sys - Ok
D:\Driver\LAN\RPLW95\PROTOCOL.INI - Ok
D:\Driver\LAN\RPLW95\RPL.lom - Ok
D:\Driver\LAN\RPLW95\rplwin95.txt - Ok
D:\Driver\LAN\SCO5\SCO5.txt - Ok
D:\Driver\LAN\SCO5\SCO5.VOL - Ok
D:\Driver\LAN\UNATTEND\NT40\unatdnt4.txt - Ok
D:\Driver\LAN\UNATTEND\NT40\Unattend.txt - Ok
D:\Driver\LAN\UNATTEND\W2000\unatdw2k.txt - Ok
D:\Driver\LAN\UNATTEND\W2000\UNATTEND.TXT - Ok
D:\Driver\LAN\UNATTEND\W9x\msbatch.inf - Ok
D:\Driver\LAN\UNATTEND\W9x\unatdw9x.txt - Ok
D:\Driver\LAN\UNATTEND\XP\unatdwxp.txt - Ok
D:\Driver\LAN\UNATTEND\XP\unattend.txt - Ok
D:\Driver\LAN\UNIXWARE\unixware.txt - Ok
D:\Driver\LAN\UNIXWARE\vtD.pkg - Ok
D:\Driver\LAN\WFW311\FETND.DOS - Ok
D:\Driver\LAN\WFW311\FETND3F.386 - Ok
D:\Driver\LAN\WFW311\FETODI.COM - Ok
D:\Driver\LAN\WFW311\OEMSETUP.INF - Ok
D:\Driver\LAN\WFW311\WFW311.TXT - Ok
D:\Driver\LAN\WINSETUP\NTSetup.exe - Ok
D:\Driver\LAN\WINSETUP\NTSetup.inf - Ok
D:\Driver\LAN\WINSETUP\ntsim.sys - Ok
D:\Driver\LAN\WINSETUP\W2KSetup.exe - Ok
D:\Driver\LAN\WINSETUP\W9XSETUP.EXE - Ok
D:\Driver\Monitor\1798oe.cat - Ok
D:\Driver\Monitor\1798Oe.icm - Ok
D:\Driver\Monitor\1798OE.inf - Ok
D:\Driver\Monitor\1998of.cat - Ok
D:\Driver\Monitor\1998Of.icm - Ok
D:\Driver\Monitor\1998OF.inf - Ok
D:\Driver\Monitor\7543.cat - Ok
D:\Driver\Monitor\7543.icm - Ok
D:\Driver\Monitor\7543.inf - Ok
D:\Driver\Monitor\7744.cat - Ok
D:\Driver\Monitor\7744.icm - Ok
D:\Driver\Monitor\7744.inf - Ok
D:\Driver\Monitor\md1786pa.cat - Ok
D:\Driver\Monitor\MD1786PA.icm - Ok
D:\Driver\Monitor\MD1786PA.inf - Ok
D:\Driver\Monitor\md1998lk.cat - Ok
D:\Driver\Monitor\MD1998LK.icm - Ok
D:\Driver\Monitor\MD1998LK.inf - Ok
D:\Driver\Monitor\md1998lm.cat - Ok
D:\Driver\Monitor\MD1998LM.icm - Ok
D:\Driver\Monitor\MD1998LM.inf - Ok
D:\Driver\Monitor\md1998pb.cat - Ok
D:\Driver\Monitor\MD1998PB.icm - Ok
D:\Driver\Monitor\MD1998PB.inf - Ok
D:\Driver\Monitor\md2617tl.cat - Ok
D:\Driver\Monitor\MD2617TL.icm - Ok
D:\Driver\Monitor\MD2617TL.inf - Ok
D:\Driver\Monitor\MD2617TN.icm - Ok
D:\Driver\Monitor\MD2617TN.inf - Ok
D:\Driver\Monitor\md5042oc.cat - Ok
D:\Driver\Monitor\MD5042OC.icm - Ok
D:\Driver\Monitor\MD5042OC.inf - Ok
D:\Driver\Monitor\md5043od.cat - Ok
D:\Driver\Monitor\MD5043OD.icm - Ok
D:\Driver\Monitor\MD5043OD.inf - Ok
D:\Driver\Monitor\md6144.cat - Ok
D:\Driver\Monitor\MD6144AO.ICM - Ok
D:\Driver\Monitor\MD6144AO.inf - Ok
D:\Driver\Monitor\MD6454AP.icm - Ok
D:\Driver\Monitor\MD6454AP.inf - Ok
D:\Driver\Monitor\md7218.cat - Ok
D:\Driver\Monitor\MD7218AR.icm - Ok
D:\Driver\Monitor\MD7218AR.inf - Ok
D:\Driver\Monitor\md7223th.cat - Ok
D:\Driver\Monitor\MD7223TH.icm - Ok
D:\Driver\Monitor\MD7223TH.inf - Ok
D:\Driver\Monitor\md7330tj.cat - Ok
D:\Driver\Monitor\MD7330TJ.ICM - Ok
D:\Driver\Monitor\MD7330TJ.inf - Ok
D:\Driver\Monitor\md7475.cat - Ok

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 232
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 648 Kb/s
Scan time: 00:00:20
-----------------------------------------------------------------------------

Scanning interrupted by user!
=============================================================================
Total session statistics
=============================================================================
Objects scanned: 17852
Infected objects found: 2
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 2
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 1524 Kb/s
Scan time: 00:05:42
=============================================================================

=============================================================================
Dr.Web® Scanner for Windows v4.33 (4.33.0.09262)
Copyright © Igor Daniloff, 1992-2005
Log generated on: 2005-12-15, 21:18:09 [DAMGAARD][Anette Damgaard]
Command-line options: /tb /ts /pr /cu /icd /cnd /spr /upn /lng
=============================================================================
Engine version: 4.33
Engine API version: 2.01
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drwtoday.vdb - 637 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43313.vdb - 842 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43312.vdb - 830 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43311.vdb - 862 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43310.vdb - 853 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43309.vdb - 733 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43308.vdb - 708 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43307.vdb - 839 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43306.vdb - 934 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43305.vdb - 760 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43304.vdb - 721 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43303.vdb - 638 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43302.vdb - 806 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43301.vdb - 504 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw43300.vdb - 24 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drwebase.vdb - 78675 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\dwrtoday.vdb - 224 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drwrisky.vdb - 1271 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\dwntoday.vdb - 660 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drwnasty.vdb - 4886 virus records
Total virus records: 96407
Key file: C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drwebcureit.key
License key number: 0000000010
Registered to: Dr.Web CureIt Project
License key activates: 2005-03-05
License key expires: 2007-03-05
Process in memory: System - Ok
Process in memory: smss.exe - Ok
Process in memory: csrss.exe - Ok
Process in memory: winlogon.exe - Ok
Process in memory: C:\WINDOWS\system32\services.exe - Ok
Process in memory: lsass.exe - Ok
Process in memory: svchost.exe - Ok
Process in memory: svchost.exe - Ok
Process in memory: svchost.exe - Ok
Process in memory: svchost.exe - Ok
Process in memory: svchost.exe - Ok
Process in memory: explorer.exe - Ok
Process in memory: notepad.exe - Ok
Process in memory: C:\Documents and Settings\Anette Damgaard\Skrivebord\drweb-cureit.exe - Ok
Process in memory: drw_start.exe - Ok
Process in memory: C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drweb32w.exe - Ok
[Memory test] No viruses found

[Scan path] C:\WINDOWS\system32\smss.exe
Master Boot Record HDD1 - Ok
Active OS/2 or WinNT Boot Sector HDD1 - Ok
C:\WINDOWS\system32\smss.exe - Ok

[Scan path] C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\csrss.exe - Ok

[Scan path] C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe - Ok

[Scan path] C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\services.exe - Ok

[Scan path] C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\lsass.exe - Ok

[Scan path] C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe - Ok

[Scan path] C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe - Ok

[Scan path] C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe - Ok

[Scan path] C:\Documents and Settings\Anette Damgaard\Skrivebord\drweb-cureit.exe
>C:\Documents and Settings\Anette Damgaard\Skrivebord\drweb-cureit.exe - Ok

[Scan path] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw_start.exe
C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drw_start.exe - Ok

[Scan path] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drweb32w.exe
>>C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX1\drweb32w.exe - Ok

[Scan path] C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\NeroCheck.exe - Ok

[Scan path] C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RunDll32.exe - Ok

[Scan path] C:\WINDOWS\System32\PSDrvCheck.exe
C:\WINDOWS\System32\PSDrvCheck.exe - Ok

[Scan path] C:\WINDOWS\system32\nwiz.exe
C:\WINDOWS\system32\nwiz.exe - Ok

[Scan path] C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe - Ok

[Scan path] C:\WINDOWS\mHotkey.exe
C:\WINDOWS\mHotkey.exe - Ok

[Scan path] C:\Programmer\QuickTime\qttask.exe
C:\Programmer\QuickTime\qttask.exe - Ok

[Scan path] C:\Programmer\D-Tools\daemon.exe
C:\Programmer\D-Tools\daemon.exe - Ok

[Scan path] C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe - Ok

[Scan path] C:\Norman\bin\ZLH.EXE
C:\Norman\bin\ZLH.EXE - Ok

[Scan path] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe - Ok

[Scan path] C:\WINDOWS\Dit.exe
C:\WINDOWS\Dit.exe - Ok

[Scan path] C:\Programmer\Spybot - Search & Destroy\SpybotSD.exe
C:\Programmer\Spybot - Search & Destroy\SpybotSD.exe - Ok

[Scan path] C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\MSN Messenger\msnmsgr.exe - Ok

[Scan path] C:\WINDOWS\System32\CTFMON.EXE
C:\WINDOWS\System32\CTFMON.EXE - Ok

[Scan path] C:\Documents and Settings\Anette Damgaard\Menuen Start\Programmer\Start\desktop.ini
C:\Documents and Settings\Anette Damgaard\Menuen Start\Programmer\Start\desktop.ini - Ok

[Scan path] C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe - Ok

[Scan path] C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\desktop.ini
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\desktop.ini - Ok

[Scan path] C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe - Ok

[Scan path] C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe - Ok

[Scan path] C:\WINDOWS\system32\mmsys.cpl
C:\WINDOWS\system32\mmsys.cpl - Ok

[Scan path] C:\WINDOWS\system32\icmui.dll
C:\WINDOWS\system32\icmui.dll - Ok

[Scan path] C:\WINDOWS\system32\rshx32.dll
C:\WINDOWS\system32\rshx32.dll - Ok

[Scan path] C:\WINDOWS\system32\docprop.dll
C:\WINDOWS\system32\docprop.dll - Ok

[Scan path] C:\WINDOWS\system32\ntshrui.dll
C:\WINDOWS\system32\ntshrui.dll - Ok

[Scan path] C:\WINDOWS\System32\themeui.dll
C:\WINDOWS\System32\themeui.dll - Ok

[Scan path] C:\WINDOWS\system32\deskadp.dll
C:\WINDOWS\system32\deskadp.dll - Ok

[Scan path] C:\WINDOWS\system32\deskmon.dll
C:\WINDOWS\system32\deskmon.dll - Ok

[Scan path] C:\WINDOWS\system32\dssec.dll
C:\WINDOWS\system32\dssec.dll - Ok

[Scan path] C:\WINDOWS\system32\SlayerXP.dll
C:\WINDOWS\system32\SlayerXP.dll - Ok

[Scan path] C:\WINDOWS\system32\shscrap.dll
C:\WINDOWS\system32\shscrap.dll - Ok

[Scan path] C:\WINDOWS\system32\diskcopy.dll
C:\WINDOWS\system32\diskcopy.dll - Ok

[Scan path] C:\WINDOWS\system32\ntlanui2.dll
C:\WINDOWS\system32\ntlanui2.dll - Ok

[Scan path] C:\WINDOWS\system32\printui.dll
C:\WINDOWS\system32\printui.dll - Ok

[Scan path] C:\WINDOWS\system32\dskquoui.dll
C:\WINDOWS\system32\dskquoui.dll - Ok

[Scan path] C:\WINDOWS\system32\syncui.dll
C:\WINDOWS\system32\syncui.dll - Ok

[Scan path] C:\WINDOWS\System32\hticons.dll
C:\WINDOWS\System32\hticons.dll - Ok

[Scan path] C:\WINDOWS\system32\fontext.dll
C:\WINDOWS\system32\fontext.dll - Ok

[Scan path] C:\WINDOWS\system32\deskperf.dll
C:\WINDOWS\system32\deskperf.dll - Ok

[Scan path] C:\WINDOWS\system32\cryptext.dll
C:\WINDOWS\system32\cryptext.dll - Ok

[Scan path] C:\WINDOWS\system32\NETSHELL.dll
C:\WINDOWS\system32\NETSHELL.dll - Ok

[Scan path] C:\WINDOWS\system32\wiashext.dll
C:\WINDOWS\system32\wiashext.dll - Ok

[Scan path] C:\WINDOWS\System32\remotepg.dll
C:\WINDOWS\System32\remotepg.dll - Ok

[Scan path] C:\WINDOWS\System32\wshext.dll
C:\WINDOWS\System32\wshext.dll - Ok

[Scan path] C:\Programmer\Fælles filer\System\Ole DB\oledb32.dll
C:\Programmer\Fælles filer\System\Ole DB\oledb32.dll - Ok

[Scan path] C:\WINDOWS\System32\mstask.dll
C:\WINDOWS\System32\mstask.dll - Ok

[Scan path] C:\WINDOWS\system32\shdocvw.dll
C:\WINDOWS\system32\shdocvw.dll - Ok

[Scan path] C:\WINDOWS\System32\shmedia.dll
C:\WINDOWS\System32\shmedia.dll - Ok

[Scan path] C:\WINDOWS\System32\browseui.dll
C:\WINDOWS\System32\browseui.dll - Ok

[Scan path] C:\WINDOWS\System32\sendmail.dll
C:\WINDOWS\System32\sendmail.dll - Ok

[Scan path] C:\WINDOWS\System32\occache.dll
C:\WINDOWS\System32\occache.dll - Ok

[Scan path] C:\WINDOWS\System32\webcheck.dll
C:\WINDOWS\System32\webcheck.dll - Ok

[Scan path] C:\WINDOWS\System32\appwiz.cpl
C:\WINDOWS\System32\appwiz.cpl - Ok

[Scan path] C:\WINDOWS\System32\shimgvw.dll
C:\WINDOWS\System32\shimgvw.dll - Ok

[Scan path] C:\WINDOWS\System32\netplwiz.dll
C:\WINDOWS\System32\netplwiz.dll - Ok

[Scan path] C:\WINDOWS\System32\zipfldr.dll
C:\WINDOWS\System32\zipfldr.dll - Ok

[Scan path] C:\WINDOWS\System32\cdfview.dll
C:\WINDOWS\System32\cdfview.dll - Ok

[Scan path] C:\WINDOWS\System32\msieftp.dll
C:\WINDOWS\System32\msieftp.dll - Ok

[Scan path] C:\WINDOWS\System32\docprop2.dll
C:\WINDOWS\System32\docprop2.dll - Ok

[Scan path] C:\WINDOWS\System32\dsquery.dll
C:\WINDOWS\System32\dsquery.dll - Ok

[Scan path] C:\WINDOWS\System32\dsuiext.dll
C:\WINDOWS\System32\dsuiext.dll - Ok

[Scan path] C:\WINDOWS\System32\mydocs.dll
C:\WINDOWS\System32\mydocs.dll - Ok

[Scan path] C:\WINDOWS\System32\cscui.dll
C:\WINDOWS\System32\cscui.dll - Ok

[Scan path] C:\WINDOWS\msagent\agentpsh.dll
C:\WINDOWS\msagent\agentpsh.dll - Ok

[Scan path] C:\WINDOWS\System32\dfsshlex.dll
C:\WINDOWS\System32\dfsshlex.dll - Ok

[Scan path] C:\WINDOWS\System32\photowiz.dll
C:\WINDOWS\System32\photowiz.dll - Ok

[Scan path] C:\WINDOWS\System32\mmcshext.dll
C:\WINDOWS\System32\mmcshext.dll - Ok

[Scan path] C:\WINDOWS\system32\cabview.dll
C:\WINDOWS\system32\cabview.dll - Ok

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 81
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 6647 Kb/s
Scan time: 00:00:05
-----------------------------------------------------------------------------

Scanning interrupted by user!
=============================================================================
Total session statistics
=============================================================================
Objects scanned: 81
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 6647 Kb/s
Scan time: 00:00:05
=============================================================================

=============================================================================
Dr.Web® Scanner for Windows v4.33 (4.33.0.09262)
Copyright © Igor Daniloff, 1992-2005
Log generated on: 2005-12-15, 21:55:04 [DAMGAARD][Anette Damgaard]
Command-line options: /tb /ts /pr /cu /icd /cnd /spr /upn /lng
=============================================================================
Engine version: 4.33
Engine API version: 2.01
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drwtoday.vdb - 637 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43313.vdb - 842 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43312.vdb - 830 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43311.vdb - 862 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43310.vdb - 853 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43309.vdb - 733 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43308.vdb - 708 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43307.vdb - 839 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43306.vdb - 934 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43305.vdb - 760 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43304.vdb - 721 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43303.vdb - 638 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43302.vdb - 806 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43301.vdb - 504 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drw43300.vdb - 24 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drwebase.vdb - 78675 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\dwrtoday.vdb - 224 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drwrisky.vdb - 1271 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\dwntoday.vdb - 660 virus records
[Virus base] C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drwnasty.vdb - 4886 virus records
Total virus records: 96407
Key file: C:\DOCUME~1\ANETTE~1\LOKALE~1\Temp\RarSFX2\drwebcureit.key
License key number: 0000000010
Registered to: Dr.Web CureIt Project
License
Avatar billede halvamatoer Nybegynder
15. december 2005 - 22:26 #3
Udemærket - start med:

1. Hent og dobbeltklik på smitRem.exe

http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

Programmet pakker sig ud til mappen smitRem.

2. Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:

http://fromsej.dk/html/xpfejl.html


3. Åbn mappen smitRem, og dobbeltklik på RunThis.bat (Følg vejledningen i vinduet.)

4. Genstart

I HTJ skal følgende fixes:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ltlgv.dll/sp.html#63796%everything4find.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8D169E2E-8319-8F6C-013A-36574F8EC46F} - C:\WINDOWS\appmv32.dll (file missing)
O2 - BHO: Class - {A5B70C48-44FC-EE21-10FB-6B345BD9B634} - C:\WINDOWS\system32\mskh.dll (file missing)
O2 - BHO: Class - {A81A1A73-0ABD-D6BC-44CD-1C5B54E9058A} - C:\WINDOWS\apixm32.dll
O2 - BHO: Class - {D849A7FC-710D-53C7-D561-509D49D3C396} - C:\WINDOWS\system32\atlit.dll (file missing)
O2 - BHO: Class - {F736EFCA-786C-7C51-6EE0-0CFF9B1F763E} - C:\WINDOWS\atlri.dll (file missing)

Nedenstående 09'er - ved jeg ikke om det er nogle hjemmesider du har accepteret på et tidspunkt eller bare fix den også.

O9 - Extra button: Erotik - {95347D30-555E-4534-A05F-2229074E0A88} - http://www.porno.dk (file missing)
O9 - Extra 'Tools' menuitem: Erotik... - {95347D30-555E-4534-A05F-2229074E0A88} - http://www.porno.dk (file missing)
O9 - Extra button: Sol Dating - {D5721FC7-8FBE-4d71-9C65-9718CFA078A8} - http://www.soldating.dk (file missing)
O9 - Extra 'Tools' menuitem: Sol Dating... - {D5721FC7-8FBE-4d71-9C65-9718CFA078A8} - http://www.soldating.dk (file missing)


O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\addfq.exe

Derefter genstart i fejlsikker og led efter + slet følgende filer:
(Ændrer evt i mappeindstillering vis skjulte filer).
C:\WINDOWS\addfq.exe
C:\WINDOWS\atlri.dll
C:\WINDOWS\system32\atlit.dll
C:\WINDOWS\apixm32.dll
C:\WINDOWS\appmv32.dll
C:\WINDOWS\system32\ltlgv.dll

Den du ikke finder er formodentligt blevet slettet af HJT.

Genstart i normal og kom med ny HJT-log.
Avatar billede jdamgaard Nybegynder
17. december 2005 - 16:49 #4
Logfile of HijackThis v1.99.1
Scan saved at 16:55:23, on 17-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Norman\Bin\Zanda.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\bin\NJEEVES.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\Norman\Nvc\BIN\nipsvc.exe
C:\WINDOWS\iebu32.exe
C:\WINDOWS\System32\alg.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\Norman\bin\ZLH.EXE
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Nvc\bin\cclaw.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\system32\javaaf.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\DitExp.exe
C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\Documents and Settings\Anette Damgaard\Skrivebord\hjt.exe

R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {3F508203-C722-9913-5AE6-D4D6D529B196} - C:\WINDOWS\system32\iema32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [javaaf.exe] C:\WINDOWS\system32\javaaf.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\RunOnce: [iebu32.exe] C:\WINDOWS\iebu32.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup:  Labtec Mouse Software 2.0.lnk = C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/15a2f7d5f76aa55c1005/netzip/RdxIE601.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\addfq.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Avatar billede halvamatoer Nybegynder
18. december 2005 - 12:17 #5
Fix følgende linjer:

O2 - BHO: Class - {3F508203-C722-9913-5AE6-D4D6D529B196} - C:\WINDOWS\system32\iema32.dll
O4 - HKLM\..\RunOnce: [iebu32.exe] C:\WINDOWS\iebu32.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\addfq.exe (file missing)

i Fejlsikker:
Find & slet:

C:\WINDOWS\system32\iema32.dll
C:\WINDOWS\iebu32.exe
C:\WINDOWS\addfq.exe

Genstart i normal kom med ny log.
Avatar billede jdamgaard Nybegynder
18. december 2005 - 19:14 #6
Logfile of HijackThis v1.99.1
Scan saved at 19:20:30, on 18-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\Norman\bin\ZLH.EXE
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\Dit.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\DitExp.exe
C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
C:\Norman\Bin\Zanda.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Norman\bin\NJEEVES.EXE
C:\WINDOWS\System32\alg.exe
C:\Norman\Nvc\bin\cclaw.exe
C:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Anette Damgaard\Skrivebord\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jubii.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jubii.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup:  Labtec Mouse Software 2.0.lnk = C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/15a2f7d5f76aa55c1005/netzip/RdxIE601.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\addfq.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Avatar billede halvamatoer Nybegynder
19. december 2005 - 20:04 #7
Beklager jeg ikke har svaret for hurtigt, men mit tr[dl'se net, har v;ret nede, og det har taget lidt opm;rksomhed.

Nå den er åbenbart ikke den nemmeste.

Vi skal havde ram på den hårdt nu. (Citat: Team spywarefri:)

Hent Aboutbuster:
http://www.malwarebytes.biz/AboutBuster.zip
(pak Aboutbuster ud til sin egen mappe på Skrivebordet).

Hent cwsserviceremove.reg her:
http://www.fbeej.dk/Programmer/cwsserviceremove.zip
(pak cwsserviceremove.zip ud til Skrivebordet)

Under dette fix, må du ikke have Internet Explorer åben, så det bedste er at printe instruktionen ud - næstbedst at kopiere den over i Notepad, så du kan læse den derfra.

For at kunne se alle filer:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

Genstart i Fejlsikret tilstand, ved at taste F8 under opstart og vælge Fejlsikret tilstand.

Gå i Start -> Kør og skriv Services.msc

Se om du kan finde én af disse services:

Workstation NetLogon Service
Network Security Service
Remote Procedure Call (RPC) Helper
Remote Access Service

...på listen. Hvis du finder én af dem - Højreklik på den og vælg Egenskaber - klik på "Stop" og vælg Starttype "Deaktiveret" - klik Anvend og OK. Luk service vinduet.

Kør HijackThis, scan og sæt et flueben ud for følgende linier - luk øvrige programvinduer - klik "Fix checked":

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jubii.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jubii.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vygvg.dll/sp.html#63796%everything4find.com
R3 - Default URLSearchHook is missing
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\addfq.exe (file missing)

Find og slet

Filerne:
C:\WINDOWS\addfq.exe
Dobbeltklik på cwsserviceremove.reg, som du hentede i begyndelsen.

Kør AboutBuster - to gange.
- klik OK
- klik Start og OK for at scanne for Alternate Data Streams
- klik Yes for at tillade nedlukning af Explorer.exe
- klik Yes for at tillade nr. 2 scanning.


Gå herefter i Start -> Programmer -> Tilbehør -> Systemværktøjer -> Diskoprydning og slet temp-filer, temporary internet files og papirkurv.

Genstart i Normal tilstand. Kør en Antivirus scanning her:

http://housecall.trendmicro.com/housecall/start_corp.asp

Så burde vi komme den rigtige vej.
Avatar billede halvamatoer Nybegynder
19. december 2005 - 20:08 #8
(+ ny log selvfølgelig)
Avatar billede jdamgaard Nybegynder
20. december 2005 - 19:44 #9
Dette kan ikke lade sig gøre



Hent Aboutbuster:
http://www.malwarebytes.biz/AboutBuster.zip
(pak Aboutbuster ud til sin egen mappe på Skrivebordet).
Avatar billede halvamatoer Nybegynder
20. december 2005 - 19:45 #10
Ups har lige set i anden log: biz=org.

http://www.malwarebytes.org/AboutBuster.zip
Avatar billede jdamgaard Nybegynder
20. december 2005 - 20:30 #11
Jegkunne





Logfile of HijackThis v1.99.1
Scan saved at 20:37:31, on 20-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Norman\Bin\Zanda.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\Norman\bin\ZLH.EXE
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\Dit.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Norman\bin\NJEEVES.EXE
C:\WINDOWS\DitExp.exe
C:\Norman\Nvc\bin\nvcoas.exe
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\alg.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\Norman\Nvc\bin\cclaw.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Anette Damgaard\Skrivebord\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jubii.dk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup:  Labtec Mouse Software 2.0.lnk = C:\Programmer\Labtec\Wireless Mouse\MulMouse.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/15a2f7d5f76aa55c1005/netzip/RdxIE601.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Programmer\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Avatar billede jdamgaard Nybegynder
20. december 2005 - 20:32 #12
Jeg kunne ikke finde følgende

Workstation NetLogon Service
Network Security Service
Remote Procedure Call (RPC) Helper
Remote Access Service

C:\WINDOWS\addfq.exe
Avatar billede halvamatoer Nybegynder
20. december 2005 - 20:34 #13
Buster har taget dem - loggen er ren, kun tilbage at sige GOD JUL!
Avatar billede jdamgaard Nybegynder
20. december 2005 - 20:37 #14
Du skal have tak for hjælpen,men jeg syntes den kører langtsommen ellers føles den ren

Også en god jul til dig
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester