Avatar billede lx2ba Novice
11. april 2006 - 12:46 Der er 12 kommentarer og
1 løsning

Trojan horse Downloader. zlob - hjælp til at fjerne?

Den sidste ugestid har jeg ved skanninger fået en oversigt med adskillige (op til 11) trojanere, - åbenbart af den samme familie, blot med forskellige "fileextensions", som: NB, NW, LX (placeret 7 forskellige steder!), IS og endelig senest: Downloader.Generic.NON
Jeg formoder, at der er noget med systemgendannelse :<?
Er der en venlig sjæl, som vil kaste sig ud i at befri mig fra skidtet.
Jeg formoder, at indtrængen er sket, da jeg kom hjem fra ferie og bevidstløst downloadede den nye udgave af ZoneAlarm, - og GLEMTE at tage kablet fra, medens jeg afinstallerede den gamle og derefter installerede den nye udgave. Win XP, SP2 er OS
Avatar billede joryje Nybegynder
11. april 2006 - 12:57 #1
Er der ikke en funktion i din scanner til at fjerne dem?
Avatar billede joryje Nybegynder
11. april 2006 - 12:59 #2
Avatar billede johnstigers Seniormester
11. april 2006 - 13:01 #3
http://www.eksperten.dk/artikler/755 - kør denne artikel igennem og smid indholdet af div logs herind.
Avatar billede lx2ba Novice
11. april 2006 - 13:51 #4
joryje> tak for kommentar, - det er netop fordi skannerfunktionen nok fjerner dem; MEN da de gendannes næste gang, jeg starter, er jeg nødt til at køre det store program med HiJackThis som anvist af john stigers.
john stigers> tak, jeg er gået i gang!
Melder mig snarest!
Avatar billede lx2ba Novice
11. april 2006 - 18:20 #5
Her kommer så "Mine samlede værker"!

DrWeb:
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 169247
Infected objects found: 2
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 9
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 3
Objects cured: 0
Objects deleted: 2
Objects renamed: 12
Objects moved: 0
Objects ignored: 0
Scan speed: 449 Kb/s
Scan time: 02:16:14

Ewido:
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            18:00:32, 11-04-2006
+ Rapport-Checksum:        700299AC

+ Scanningsresultat:
    HKLM\SOFTWARE\Classes\CLSID\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Renset med backup
    HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22} -> Adware.Generic : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22} -> Adware.Generic : Renset med backup
    HKU\S-1-5-21-4241667002-1156897692-3382820964-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Renset med backup
    HKU\S-1-5-21-4241667002-1156897692-3382820964-1006\Software\Classes\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D} -> Adware.SpywareQuake : Renset med backup
    HKU\S-1-5-21-4241667002-1156897692-3382820964-1006_Classes\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D} -> Adware.SpywareQuake : Renset med backup
    :mozilla.8:C:\Documents and Settings\Birger Andresen\Application Data\Mozilla\Firefox\Profiles\ag37ljod.default\cookies.txt -> TrackingCookie.Adtech : Renset med backup
    :mozilla.9:C:\Documents and Settings\Birger Andresen\Application Data\Mozilla\Firefox\Profiles\ag37ljod.default\cookies.txt -> TrackingCookie.Adtech : Renset med backup
    :mozilla.8:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Mediaplex : Renset med backup
    :mozilla.13:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Adtech : Renset med backup
    :mozilla.14:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Adtech : Renset med backup
    :mozilla.15:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.16:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.17:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.18:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Atdmt : Renset med backup
    :mozilla.19:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.20:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.21:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.22:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.38:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.39:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.40:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.41:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.42:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.43:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.44:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.45:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.46:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Tradedoubler : Renset med backup
    :mozilla.47:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Tradedoubler : Renset med backup
    :mozilla.48:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Tradedoubler : Renset med backup
    :mozilla.49:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Tradedoubler : Renset med backup
    :mozilla.51:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hitslink : Renset med backup
    :mozilla.52:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hitslink : Renset med backup
    :mozilla.53:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hitslink : Renset med backup
    :mozilla.54:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hitslink : Renset med backup
    :mozilla.63:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.64:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.65:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.66:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.70:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Googleadservices : Renset med backup
    :mozilla.72:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Googleadservices : Renset med backup
    :mozilla.80:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Masterstats : Renset med backup
    :mozilla.107:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.108:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.109:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.110:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.111:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.135:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.141:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.142:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.143:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.144:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.145:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.146:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.149:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Specificclick : Renset med backup
    :mozilla.150:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Specificclick : Renset med backup
    :mozilla.151:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Specificclick : Renset med backup
    :mozilla.167:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Coremetrics : Renset med backup
    :mozilla.170:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Tribalfusion : Renset med backup
    :mozilla.227:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hitbox : Renset med backup
    :mozilla.249:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Statcounter : Renset med backup
    :mozilla.250:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Statcounter : Renset med backup
    :mozilla.251:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Statcounter : Renset med backup
    :mozilla.271:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Webtrendslive : Renset med backup
    :mozilla.321:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Myaffiliateprogram : Renset med backup
    :mozilla.328:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hitbox : Renset med backup
    :mozilla.329:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hitbox : Renset med backup
    :mozilla.340:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.345:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Webtrendslive : Renset med backup
    :mozilla.375:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Fastclick : Renset med backup
    :mozilla.376:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Zedo : Renset med backup
    :mozilla.381:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Adserver : Renset med backup
    :mozilla.382:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Adserver : Renset med backup
    :mozilla.383:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Adserver : Renset med backup
    :mozilla.384:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Bluestreak : Renset med backup
    :mozilla.389:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Qksrv : Renset med backup
    :mozilla.390:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Qksrv : Renset med backup
    :mozilla.418:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Hotlog : Renset med backup
    :mozilla.419:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Spylog : Renset med backup
    :mozilla.431:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Adjuggler : Renset med backup
    :mozilla.432:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Adjuggler : Renset med backup
    :mozilla.434:C:\Documents and Settings\Birger Andresen\Application Data\Netscape\NSB\Profiles\75w6pb2i.Default User\cookies.txt -> TrackingCookie.Yadro : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@adtech[2].txt -> TrackingCookie.Adtech : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@advertising[2].txt -> TrackingCookie.Advertising : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@arnoldpalmer.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@as1.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@atdmt[1].txt -> TrackingCookie.Atdmt : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@bluestreak[1].txt -> TrackingCookie.Bluestreak : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@cbs.112.2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@counter.hitslink[2].txt -> TrackingCookie.Hitslink : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@ehg-tiscover.hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@fastclick[1].txt -> TrackingCookie.Fastclick : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@hotlog[1].txt -> TrackingCookie.Hotlog : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@image.masterstats[1].txt -> TrackingCookie.Masterstats : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@qksrv[2].txt -> TrackingCookie.Qksrv : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@sel.as-eu.falkag[1].txt -> TrackingCookie.Falkag : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@spylog[1].txt -> TrackingCookie.Spylog : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@statcounter[1].txt -> TrackingCookie.Statcounter : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@yadro[2].txt -> TrackingCookie.Yadro : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@z1.adserver[1].txt -> TrackingCookie.Adserver : Renset med backup
    C:\Documents and Settings\Birger Andresen\Cookies\birger andresen@zedo[1].txt -> TrackingCookie.Zedo : Renset med backup


::Rapport slut

HJT:
Logfile of HijackThis v1.99.1
Scan saved at 18:17:32, on 11-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NILaunch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\StartupMonitor.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
D:\Programmer\Adobe\Distillr\Acrotray.exe
D:\Programmer\SPAMfighter\SFAgent.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Programmer\Home Cinema\PowerCinema\PCMService.exe
D:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
D:\TOOLS\Downloads\Minimizer\mini-xp\Mini-XP.exe
D:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe
D:\Programmer\QuickStart\quickstart.exe
D:\Programmer\Adobe\Acrobat\acrobat_sl.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\Programmer\PrintKey2000\Printkey2000.exe
D:\Programmer\DreamBreed DreamBirthday\DreamBirthday.exe
D:\Programmer\WinBar\WinBar.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programmer\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Programmer\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\Programmer\ewido anti-malware\ewidoguard.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmer\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Netscape\Netscape Browser\netscape.exe
C:\WINDOWS\Explorer.EXE
D:\TOOLS\Downloads\HiJackThis\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmer\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Skype™ For Internet Explorer - {B13721C7-F507-4982-B2E5-502A71474FED} - D:\Programmer\Skype\toolbars\Skype for Internet Explorer\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\system32\NILaunch.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Programmer\Adobe\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SPAMfighter Agent] "D:\Programmer\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [SpySweeper] "C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PCMService] "C:\Programmer\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [Zone Labs Client] D:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Mini-XP] D:\TOOLS\Downloads\Minimizer\mini-xp\Mini-XP.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] D:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [QuickStart] D:\Programmer\QuickStart\quickstart.exe /minimize
O4 - Startup: DreamBreed DreamBirthday.lnk = D:\Programmer\DreamBreed DreamBirthday\DreamBirthday.exe
O4 - Startup: netscape.lnk = D:\Programmer\Netscape\netscape.exe
O4 - Startup: OUTLOOK.lnk = D:\Programmer\Microsoft Office\Office10\OUTLOOK.EXE
O4 - Startup: WinBar.lnk = D:\Programmer\WinBar\WinBar.exe
O4 - Global Startup: Adobe Acrobat Hurtigstart.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Printkey2000.lnk = D:\Programmer\PrintKey2000\Printkey2000.exe
O8 - Extra context menu item: Download all by Free Download Manager - file://D:\Programmer\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://D:\Programmer\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://D:\Programmer\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://D:\Programmer\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Konverter hyperlinkdestination til Adobe PDF - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter hyperlinkdestination til eksisterende PDF - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter markering til Adobe PDF - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter markering til eksisterende PDF-fil - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter til Adobe PDF - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter til eksisterende PDF-fil - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter valgte hyperlinks til Adobe PDF - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Konverter valgte hyperlinks til eksisterende PDF - res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmer\Fælles filer\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .htm: C:\Programmer\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com/
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130600261343
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136737837796
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Programmer\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Programmer\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmer\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Avatar billede johnstigers Seniormester
11. april 2006 - 20:04 #6
Kigger det igennem :)
Avatar billede johnstigers Seniormester
11. april 2006 - 20:18 #7
Download og gem denne scanner på skrivebordet. (Vi skal bruge den senere)
http://www.spywareinfo.dk/download/mwav.exe

------------------------------

Du skal nu til at i gang med at fixe:

Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.
Dobbelttjek, så alt kommer med.


F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com/

Hvis ikke du ved hvad dette er, så fix denne også: D:\Programmer\DreamBreed DreamBirthday\DreamBirthday.exe

--------------------------------------------------------------------

Hent denne bats fil og kør den :
http://www.spywareinfo.dk/download/cleantempxp2k.bat
den sletter alt i din temp mappe.

------------------------------

Genstart i fejlsikret tilstand:
Klik på mwav.exe som du hentede, programmet pakker sig selv ud og starter.
Sæt flueben i følgende:
Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende:
All local drives og Scan all files
Og så trykker du på Scan Clean
Det tager lidt over en time at scanne

-------------------------------

Så genstarter du computeren normalt og laver en ny hijackthis log, som du lægger herind.
Avatar billede lx2ba Novice
11. april 2006 - 20:54 #8
john_stigers>Lige et lille spørgsmål:
Hvordan "kører" jeg bat-filen?
Avatar billede lx2ba Novice
11. april 2006 - 21:14 #9
Måske en anden lige kunne give mig et tip?
Avatar billede johnstigers Seniormester
11. april 2006 - 21:18 #10
For at "køre" en fil dobbeltklikker man bare på den.
Avatar billede lx2ba Novice
11. april 2006 - 21:35 #11
TAK!
Det KAN godt ske, at jeg er lidt tung; men jeg har gemt filen, som kom i det link, du gav mig, som  en tekstfil, som jeg derefter omdøbte til *.bat og dobbeltklikkede på den.
Der skete ikke meget; men jeg har ikke kunnet finde de steder, hvor der skulle deletes, så derfor kom jeg i tvivl, om jeg havde gjort det rigtige!  :<))
Avatar billede johnstigers Seniormester
11. april 2006 - 23:10 #12
Man når næsten ikke at se den fil køre, så det tror jeg du har :)

Smid en ny log til tjek :)
Avatar billede lx2ba Novice
12. april 2006 - 04:19 #13
Så er mwav skanningen da færdig, den tog over 2 timer, så jeg har været henne og sove lidt!
Her kommer så:
-----------------------------------------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 04:15:36, on 12-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NILaunch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\StartupMonitor.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
D:\Programmer\Adobe\Distillr\Acrotray.exe
D:\Programmer\SPAMfighter\SFAgent.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Programmer\Home Cinema\PowerCinema\PCMService.exe
D:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
D:\TOOLS\Downloads\Minimizer\mini-xp\Mini-XP.exe
D:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe
D:\Programmer\QuickStart\quickstart.exe
D:\Programmer\Adobe\Acrobat\acrobat_sl.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\Programmer\PrintKey2000\Printkey2000.exe
D:\Programmer\DreamBreed DreamBirthday\DreamBirthday.exe
D:\Programmer\WinBar\WinBar.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programmer\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Programmer\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\Programmer\ewido anti-malware\ewidoguard.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmer\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
D:\TOOLS\Downloads\HiJackThis\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

D:\Programmer\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} -

D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Skype™ For Internet Explorer - {B13721C7-F507-4982-B2E5-502A71474FED} -

D:\Programmer\Skype\toolbars\Skype for Internet Explorer\toolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -

D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\system32\NILaunch.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Programmer\Adobe\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SPAMfighter Agent] "D:\Programmer\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PCMService] "C:\Programmer\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [Zone Labs Client] D:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Mini-XP] D:\TOOLS\Downloads\Minimizer\mini-xp\Mini-XP.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] D:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe

/nosplash
O4 - HKCU\..\Run: [QuickStart] D:\Programmer\QuickStart\quickstart.exe /minimize
O4 - Startup: DreamBreed DreamBirthday.lnk = D:\Programmer\DreamBreed

DreamBirthday\DreamBirthday.exe
O4 - Startup: netscape.lnk = D:\Programmer\Netscape\netscape.exe
O4 - Startup: OUTLOOK.lnk = D:\Programmer\Microsoft Office\Office10\OUTLOOK.EXE
O4 - Startup: WinBar.lnk = D:\Programmer\WinBar\WinBar.exe
O4 - Global Startup: Adobe Acrobat Hurtigstart.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0

\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Printkey2000.lnk = D:\Programmer\PrintKey2000\Printkey2000.exe
O8 - Extra context menu item: Download all by Free Download Manager - file://D:\Programmer\Free

Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://D:\Programmer\Free Download

Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://D:\Programmer\Free

Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://D:\Programmer\Free

Download Manager\dlpage.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10

\EXCEL.EXE/3000
O8 - Extra context menu item: Konverter hyperlinkdestination til Adobe PDF -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter hyperlinkdestination til eksisterende PDF -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter markering til Adobe PDF -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter markering til eksisterende PDF-fil -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter til Adobe PDF -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter til eksisterende PDF-fil -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter valgte hyperlinks til Adobe PDF -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Konverter valgte hyperlinks til eksisterende PDF -

res://D:\Programmer\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmer\Fælles

filer\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .htm: C:\Programmer\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130600261343
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136737837796
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll"

(file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1

\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1

\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1

\avgemc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner -

C:\Programmer\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Programmer\Home

Cinema\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmer\Home

Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-

malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-

malware\ewidoguard.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-

Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32

\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner -

C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32

\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10

\Common\x10nets.exe
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester

IT-JOB