Avatar billede flapz Nybegynder
29. december 2005 - 23:28 Der er 2 kommentarer og
2 løsninger

Hjælp til hijackthis

har fået en trojan ting som jeg ikk kan fjerne. den gør blandt andet så jeg nogle gange ikk kan skrive i login filer i IE og at mit net nogle gange forsviner et kort øjeblik. og generelt bare er ond ved min forbindelse. håber der er en som kan hjælpe :D

Logfile of HijackThis v1.99.1
Scan saved at 23:03:50, on 29-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
E:\Programmer\Norton AntiVirus\navapsvc.exe
E:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
E:\Programmer\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\CTHELPER.EXE
E:\programmer\powerstrip\pstrip.exe
C:\Programmer\Messenger\msmsgs.exe
E:\Programmer\Razer\razerhid.exe
C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
C:\Programmer\Java\jre1.5.0_05\bin\jucheck.exe
E:\Programmer\DAEMON Tools\daemon.exe
E:\Programmer\Razer\razerofa.exe
E:\Programmer\Razer\razertra.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
E:\mIRC2\mirc.exe
E:\Programmer\Steam\steam.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\flapz\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {2BCE6A6A-9F26-4A77-A9A7-A68A6C17068D} - C:\WINDOWS\system32\yaoineou.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] E:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] E:\Programmer\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [CTStartup] C:\Programmer\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [PowerStrip] e:\programmer\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [razer] E:\Programmer\Razer\razerhid.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "E:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] E:\Programmer\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [VoipBuster] "C:\Programmer\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: Messenger - {D8DD8664-175C-0C4E-F83A-A34662036207} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - E:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
Avatar billede arlet Juniormester
30. december 2005 - 00:10 #1
Hent denne scanner:
Ewido kan du downloade her: http://www.ewido.net/en/download/
Klik på Download now. Installer og kør Ewido. Opdater straks efter installationen programmet, (men lad være med at scanne endnu).

Genstart computeren i fejlsikret tilstand(Du skal klikke på f8 tasten under genstarten (ca. lige når der er talt ram), og så vælge fejlsikret tilstand. Er du i tvivl, så klik bare på f8 flere gange.)


Du skal nu til at i gang med at fixe:


Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.


O2 - BHO: (no name) - {2BCE6A6A-9F26-4A77-A9A7-A68A6C17068D} - C:\WINDOWS\system32\yaoineou.dll

Find og slet disse manuelt :

C:\WINDOWS\system32\yaoineou.dll


Kør nu en fuld scanning med Ewido. Når den er færdig trykker du save report og kopier den report herind sammen med en hijackthis log taget efter du har kørt Ewido
Avatar billede flapz Nybegynder
06. januar 2006 - 20:45 #2
Her følger så de 2 logs først hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 20:42:00, on 06-01-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\flapz.RASMUS\Lokale indstillinger\Temporary Internet Files\Content.IE5\09ADS7A3\hijackthis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] E:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] E:\Programmer\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [CTStartup] C:\Programmer\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [PowerStrip] e:\programmer\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "E:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [razer] C:\Programmer\Razer\razerhid.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: Messenger - {D8DD8664-175C-0C4E-F83A-A34662036207} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - E:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe







Og så den log fra Ewido:

---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            20:37:00, 06-01-2006
+ Rapport-Checksum:        34685440

+ Scanningsresultat:
    HKLM\SOFTWARE\Classes\CLSID\{52DC9EC1-35A9-4914-98D9-D568A9854DA2} -> Spyware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{62160EEF-9D84-4C19-B7B8-6AC2526CD726} -> Spyware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{8085E374-ACBB-42F9-873F-49EC7E244F97} -> Spyware.Hijacker.Generic : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{DE3BEBDB-AEE7-4277-8B6E-4EEFFA9508AE} -> Spyware.CoolWebSearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{F2A4407B-FFBC-4A1F-A18A-0F68C3E0FC9E} -> Spyware.CoolWebSearch : Renset med backup
    C:\Documents and Settings\Administrator\Cookies\administrator@adtech[1].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\Administrator\Cookies\administrator@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Renset med backup
    C:\Documents and Settings\Administrator\Cookies\administrator@sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    :mozilla.7:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.8:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.9:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.12:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Mediaplex : Renset med backup
    :mozilla.37:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Doubleclick : Renset med backup
    :mozilla.41:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.42:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.43:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.44:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.45:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.46:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.47:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.48:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexcounter : Renset med backup
    :mozilla.62:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.63:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.64:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Statcounter : Renset med backup
    :mozilla.65:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Sexlist : Renset med backup
    :mozilla.66:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.67:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.68:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.69:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.70:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Casalemedia : Renset med backup
    :mozilla.72:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.73:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.74:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Advertising : Renset med backup
    :mozilla.84:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Masterstats : Renset med backup
    :mozilla.103:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Atdmt : Renset med backup
    :mozilla.130:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Renset med backup
    :mozilla.139:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.140:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    :mozilla.157:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Com : Renset med backup
    :mozilla.158:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Com : Renset med backup
    :mozilla.162:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.163:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.164:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.2o7 : Renset med backup
    :mozilla.169:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Paycounter : Renset med backup
    :mozilla.175:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.176:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.177:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.178:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.179:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Falkag : Renset med backup
    :mozilla.180:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Adserver : Renset med backup
    :mozilla.181:C:\Documents and Settings\flapz\Application Data\Mozilla\Firefox\Profiles\c8hdp28r.default\cookies.txt -> Spyware.Cookie.Adserver : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@2o7[2].txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@advertising[2].txt -> Spyware.Cookie.Advertising : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@as1.falkag[1].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@atdmt[2].txt -> Spyware.Cookie.Atdmt : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@com[1].txt -> Spyware.Cookie.Com : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@counter13.sextracker[2].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@media.fastclick[1].txt -> Spyware.Cookie.Fastclick : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@paycounter[1].txt -> Spyware.Cookie.Paycounter : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@paypopup[2].txt -> Spyware.Cookie.Paypopup : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@sexlist[1].txt -> Spyware.Cookie.Sexlist : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@statcounter[1].txt -> Spyware.Cookie.Statcounter : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Renset med backup
    C:\Documents and Settings\flapz\Cookies\flapz@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@advertising[1].txt -> Spyware.Cookie.Advertising : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@atdmt[1].txt -> Spyware.Cookie.Atdmt : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@fastclick[1].txt -> Spyware.Cookie.Fastclick : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@sexlist[2].txt -> Spyware.Cookie.Sexlist : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\flapz\Lokale indstillinger\Temp\Cookies\flapz@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\flapz.RASMUS\Cookies\flapz@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\flapz.RASMUS\Cookies\flapz@atdmt[2].txt -> Spyware.Cookie.Atdmt : Renset med backup
    C:\Documents and Settings\flapz.RASMUS\Cookies\flapz@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\flapz.RASMUS\Cookies\flapz@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Renset med backup
    C:\Documents and Settings\flapz.RASMUS\Cookies\flapz@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Renset med backup
    C:\Documents and Settings\flapz.RASMUS\Cookies\flapz@sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\flapz.RASMUS\Cookies\flapz@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    C:\RECYCLER\NPROTECT\00002047.TXT -> Spyware.Cookie.Adtech : Renset med backup
    C:\RECYCLER\NPROTECT\00002068.TXT -> Spyware.Cookie.Atdmt : Renset med backup
    C:\RECYCLER\NPROTECT\00002184.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002187.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002189.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002190.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002191.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002192.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002197.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002200.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002201.TXT -> Spyware.Cookie.Sexcounter : Renset med backup
    C:\RECYCLER\NPROTECT\00002202.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002203.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002204.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002205.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002206.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002207.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002208.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\NPROTECT\00002211.TXT -> Spyware.Cookie.Sextracker : Renset med backup
    C:\RECYCLER\S-1-5-21-2052111302-861567501-1801674531-500\Dc1.dll -> Adware.TsAdv : Renset med backup
    E:\InstallFiler\nero6316\Keygen.exe -> Dropper.Delf.gi : Renset med backup


::Rapport slut



Undskyld der er gået lang tid men har været en travl herre på det sidste :D
Avatar billede arlet Juniormester
06. januar 2006 - 22:44 #3
Så er din log ren.

Efter sådan en tur er det altid en god ide og rydde op i dine systemgendannelses filerne.
Deaktiver systemgendannelse ( http://www.arlet.dk/systemgendannelsen.htm ) - genstart din computer - aktiver systemgendannelse.

Generel oprydning: http://www.arlet.dk/oprydning.htm

For at beskytte dig mod snavs har jeg lavet en sikkerhedspakke,
som du kan se her : www.arlet.dk/pakke.htm
Avatar billede arlet Juniormester
06. januar 2006 - 22:45 #4
Når du nu er ny på sitet, så kan du læse her, hvordan man lukker et spørgsmål:

http://expfaq.1go.dk/?id=3#behandling_af_svar
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester