Avatar billede sw_red_6 Nybegynder
21. april 2006 - 16:42 Der er 3 kommentarer og
1 løsning

hjælp til hijackthis log

Jeg har en hijackthis log-fil som jeg godt vil have lidt hjælp til. (40 point)

Og så er det måske ikke det rigtige sted jeg spørger men er der nogen der har en ide om hvorfor min PC er mere end 1 min. om at lukke? (60 point)

Logfile of HijackThis v1.99.1
Scan saved at 16:25:36, on 21-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
H:\Apache2\Apache2\bin\Apache.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\WINDOWS\System32\CTsvcCDA.exe
E:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
H:\Apache2\Apache2\bin\Apache.exe
E:\Programmer\Norton Personal Firewall\NISUM.EXE
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\tcpsvcs.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\Norton Personal Firewall\SymProxySvc.exe
E:\WINDOWS\System32\MsPMSPSv.exe
E:\Programmer\Norton Personal Firewall\NISSERV.EXE
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\ctfmon.exe
E:\WINDOWS\system32\CTHELPER.EXE
E:\Programmer\Trust\250S Series\lwbwheel.exe
E:\WINDOWS\system32\rundll32.exe
F:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
E:\Programmer\Norton Personal Firewall\IAMAPP.EXE
E:\Programmer\MessengerPlus! 3\MsgPlus.exe
E:\WINDOWS\VM_STI.EXE
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\Programmer\VVSN\VVSN.exe
E:\Programmer\Lexmark 2300 Series\lxcgmon.exe
E:\Programmer\Lexmark 2300 Series\ezprint.exe
E:\Programmer\DAEMON Tools\daemon.exe
E:\WINDOWS\system32\lxcgcoms.exe
E:\Programmer\FirefoxPreloader\FirefoxPreloader.exe
H:\Apache2\Apache2\bin\ApacheMonitor.exe
F:\Programmer\firefox 1.5\firefox.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Programmer\MSN Messenger\msnmsgr.exe
H:\misc DL\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.dk/0SEDADK/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - g:\Programmer\UnH Solutions\IE Privacy Keeper\IEPKbho.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - f:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {54EA478F-A23A-9D06-3ED5-8892053EA4C3} - E:\PROGRA~1\OOZEBU~1\Show play.exe (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] E:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] E:\Programmer\Creative\SBLive\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [CTStartup] E:\Programmer\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [LWBMOUSE] E:\Programmer\Trust\250S Series\lwbwheel.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "f:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [iamapp] E:\Programmer\Norton Personal Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] E:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [MessengerPlus3] "E:\Programmer\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [BigDogPath] E:\WINDOWS\VM_STI.EXE ZSMC USB PC Camera
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [VVSN] E:\Programmer\VVSN\VVSN.exe
O4 - HKLM\..\Run: [LXCGCATS] rundll32 E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "E:\Programmer\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "E:\Programmer\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "E:\Programmer\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [DAEMON Tools] "E:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "E:\Programmer\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: Microsoft Office.lnk = F:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = E:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Firefox Preloader.lnk = E:\Programmer\FirefoxPreloader\FirefoxPreloader.exe
O4 - Global Startup: Monitor Apache Servers.lnk = H:\Apache2\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = E:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download by NetAnts - E:\PROGRA~1\NETANTS\NAGet.htm
O8 - Extra context menu item: Download &All by NetAnts - E:\PROGRA~1\NETANTS\NAGetAll.htm
O8 - Extra context menu item: Download all by Free Download Manager - file://d:\Programmer\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://d:\Programmer\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://d:\Programmer\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://d:\Programmer\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with X&ML Spy - g:\Programmer\Altova\XMLSPY2004\spy.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programmer\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programmer\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - g:\Programmer\Altova\XMLSPY2004\spy.htm (file missing)
O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - g:\Programmer\Altova\XMLSPY2004\spy.htm (file missing)
O9 - Extra button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - E:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - E:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - f:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - f:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - E:\Programmer\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - E:\Programmer\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {D799B0E4-BEDE-41d2-AEE0-1E3A1C4EF918} - F:\Programmer\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
O9 - Extra 'Tools' menuitem: IE Privacy Keeper - {D799B0E4-BEDE-41d2-AEE0-1E3A1C4EF918} - F:\Programmer\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: http://servedby.advertising.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Apache2 - Unknown owner - H:\Apache2\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - E:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: lxcg_device -  - E:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - E:\Programmer\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - E:\Programmer\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - E:\Programmer\Norton Personal Firewall\SymProxySvc.exe
Avatar billede forevernewbie Nybegynder
21. april 2006 - 17:13 #1
Ja, jeg har da et bud på sagen. Jeg kan se du har IE Privacy keeper, og programmet er tilsyneladende "halt", idet det mangler en fil.

O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - g:\Programmer\UnH Solutions\IE Privacy Keeper\IEPKbho.dll (file missing)

Hvis du på et tidspunkt har sat programmet til at rense ved nedlukning, står det måske nu og "søger", uden du kan se det. Prøv at geninstallere programmet, og se hvordan du har sat den indstilling.

Du har også lidt snavs på maskinen. Fjern Netants, da den er spywareinficeret med Cydoor. Kør også de to scannere som er nævnt her, og kom med en ny HJT log, inklusive loggen fra SuperAntiSpyware http://www.eksperten.dk/artikler/954
Avatar billede sw_red_6 Nybegynder
22. april 2006 - 10:21 #2
OK nu har jeg fulgt det link og gjort det hele så her er de forskellige logs

Dr. Web log:
Scan statistics

Objects scanned: 0
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 0 Kb/s
Scan time: 00:00:00


[Scan path] E:\WINDOWS\system32\smss.exe
[Scan path] E:\WINDOWS\system32\csrss.exe
[Scan path] E:\WINDOWS\system32\winlogon.exe
[Scan path] E:\WINDOWS\system32\services.exe
[Scan path] E:\WINDOWS\system32\lsass.exe
[Scan path] E:\WINDOWS\system32\svchost.exe
[Scan path] E:\WINDOWS\Explorer.EXE
[Scan path] E:\WINDOWS\system32\ctfmon.exe
[Scan path] E:\DOCUME~1\MATHIA~1\LOKALE~1\Temp\RarSFX0\_start.exe
[Scan path] E:\DOCUME~1\MATHIA~1\LOKALE~1\Temp\RarSFX0\cureit.exe
[Scan path] E:\WINDOWS\system32\RUNDLL32.EXE
[Scan path] E:\WINDOWS\system32\nwiz.exe
[Scan path] E:\WINDOWS\system32\CTHELPER.EXE
[Scan path] E:\WINDOWS\UpdReg.EXE
[Scan path] E:\Programmer\Creative\SBLive\PROGRAM\ADGJDet.exe
[Scan path] E:\Programmer\Creative\Splash Screen\CTEaxSpl.EXE
[Scan path] E:\Programmer\Trust\250S Series\lwbwheel.exe
[Scan path] E:\Programmer\QuickTime\qttask.exe
[Scan path] E:\WINDOWS\system32\NeroCheck.exe
[Scan path] f:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
[Scan path] E:\Programmer\Norton Personal Firewall\IAMAPP.EXE
[Scan path] E:\PROGRA~1\SYMNET~1\SNDMon.exe
[Scan path] E:\Programmer\MessengerPlus! 3\MsgPlus.exe
[Scan path] E:\WINDOWS\VM_STI.EXE
[Scan path] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
[Scan path] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
[Scan path] E:\Programmer\VVSN\VVSN.exe
E:\Programmer\VVSN\VVSN.exe is adware program Adware.SaveNow

[Scan path] E:\Programmer\Lexmark 2300 Series\lxcgmon.exe
[Scan path] E:\Programmer\Lexmark 2300 Series\ezprint.exe
[Scan path] E:\Programmer\Lexmark Fax Solutions\fm3032.exe
[Scan path] E:\Programmer\DAEMON Tools\daemon.exe
[Scan path] E:\Programmer\Ahead\Nero BackItUp\NBJ.exe
[Scan path] F:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
[Scan path] E:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
[Scan path] E:\Documents and Settings\Mathias Jakobsen\Menuen Start\Programmer\Start\desktop.ini
[Scan path] E:\Programmer\Microsoft Office\Office10\OSA.EXE
[Scan path] E:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\desktop.ini
[Scan path] E:\Programmer\FirefoxPreloader\FirefoxPreloader.exe
[Scan path] H:\Apache2\Apache2\bin\ApacheMonitor.exe
[Scan path] E:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[Scan path] E:\WINDOWS\system32\nvcpl.dll
[Scan path] E:\WINDOWS\system32\nvshell.dll
[Scan path] E:\WINDOWS\system32\wuaucpl.cpl
[Scan path] E:\PROGRA~1\FÆLLES~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
[Scan path] E:\Programmer\Microsoft Office\Office10\msohev.dll
[Scan path] f:\Programmer\UnH Solutions\IE Privacy Keeper\SecureDelete.dll
[Scan path] E:\WINDOWS\system32\shdocvw.dll
[Scan path] E:\WINDOWS\system32\twext.dll
[Scan path] E:\WINDOWS\system32\extmgr.dll
[Scan path] E:\WINDOWS\system32\wmpshell.dll
[Scan path] E:\WINDOWS\system32\zipfldr.dll
[Scan path] E:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[Scan path] E:\WINDOWS\system32\Audiodev.dll
[Scan path] E:\WINDOWS\system32\mscoree.dll
[Scan path] E:\Programmer\Real\RealOne Player\rpshell.dll
[Scan path] E:\Programmer\WinRAR\rarext.dll
[Scan path] f:\Programmer\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll
[Scan path] E:\WINDOWS\system32\dfshim.dll
[Scan path] E:\Programmer\Grisoft\AVG Free\avgse.dll
[Scan path] E:\WINDOWS\system32\upnpui.dll
[Scan path] E:\WINDOWS\system32\browseui.dll
[Scan path] E:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[Scan path] f:\Programmer\UnH Solutions\IE Privacy Keeper\IEPKbho.dll
[Scan path] f:\Programmer\Spybot - Search & Destroy\SDHelper.dll
[Scan path] E:\WINDOWS\system32\SHELL32.dll
[Scan path] E:\WINDOWS\System32\webcheck.dll
[Scan path] E:\WINDOWS\System32\stobject.dll
[Scan path] E:\WINDOWS\system32\crypt32.dll
[Scan path] E:\WINDOWS\system32\cryptnet.dll
[Scan path] E:\WINDOWS\system32\cscdll.dll
[Scan path] F:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[Scan path] E:\WINDOWS\system32\wlnotify.dll
[Scan path] E:\WINDOWS\system32\sclgntfy.dll
[Scan path] E:\WINDOWS\System32\DRIVERS\ACPI.sys
[Scan path] E:\WINDOWS\system32\drivers\aec.sys
[Scan path] E:\WINDOWS\System32\drivers\afd.sys
[Scan path] E:\WINDOWS\System32\alg.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\amdk7.sys
[Scan path] H:\Apache2\Apache2\bin\Apache.exe
[Scan path] E:\WINDOWS\system32\drivers\aslm75.sys
[Scan path] E:\WINDOWS\Microsoft.NET\Framework\v2.0.50215\aspnet_state.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\asyncmac.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\atapi.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\atmarpc.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\audstub.sys
[Scan path] E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
[Scan path] E:\WINDOWS\System32\Drivers\avg7core.sys
[Scan path] E:\WINDOWS\System32\Drivers\avg7rsw.sys
[Scan path] E:\WINDOWS\System32\Drivers\avg7rsxp.sys
[Scan path] E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
[Scan path] E:\WINDOWS\System32\Drivers\avgtdi.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\CCDECODE.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\cdrom.sys
[Scan path] E:\WINDOWS\system32\cisvc.exe
[Scan path] E:\WINDOWS\system32\clipsrv.exe
[Scan path] E:\WINDOWS\Microsoft.NET\Framework\v2.0.50215\mscorsvw.exe
[Scan path] E:\WINDOWS\System32\dllhost.exe
[Scan path] E:\WINDOWS\System32\CTsvcCDA.exe
[Scan path] E:\WINDOWS\System32\drivers\ctac32k.sys
[Scan path] E:\WINDOWS\system32\drivers\ctaud2k.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ctljystk.sys
[Scan path] E:\WINDOWS\System32\drivers\ctprxy2k.sys
[Scan path] E:\WINDOWS\System32\drivers\ctsfm2k.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\disk.sys
[Scan path] E:\WINDOWS\System32\dmadmin.exe
[Scan path] E:\WINDOWS\System32\drivers\dmboot.sys
[Scan path] E:\WINDOWS\System32\drivers\dmio.sys
[Scan path] E:\WINDOWS\System32\drivers\dmload.sys
[Scan path] E:\WINDOWS\system32\drivers\DMusic.sys
[Scan path] E:\WINDOWS\system32\drivers\drmkaud.sys
[Scan path] E:\WINDOWS\System32\Drivers\dtscsi.sys
E:\WINDOWS\System32\Drivers\dtscsi.sys - read error

[Scan path] E:\WINDOWS\System32\Drivers\ElbyCDIO.sys
[Scan path] E:\WINDOWS\System32\Drivers\ElbyDelay.sys
[Scan path] E:\WINDOWS\system32\drivers\emu10k1m.sys
[Scan path] E:\WINDOWS\system32\drivers\ctlfacem.sys
[Scan path] E:\WINDOWS\System32\drivers\emupia2k.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\fdc.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\flpydisk.sys
[Scan path] E:\WINDOWS\system32\drivers\fltmgr.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ftdisk.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\gameenum.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\msgpc.sys
[Scan path] E:\WINDOWS\system32\drivers\ha10kx2k.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\hidgame.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\hidusb.sys
[Scan path] E:\WINDOWS\System32\Drivers\HTTP.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\i8042prt.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\imapi.sys
[Scan path] E:\WINDOWS\System32\imapi.exe
[Scan path] E:\WINDOWS\system32\drivers\ip6fw.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ipinip.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ipnat.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ipsec.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\irenum.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\isapnp.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\kbdclass.sys
[Scan path] E:\WINDOWS\system32\drivers\kmixer.sys
[Scan path] E:\WINDOWS\system32\lxcgcoms.exe
[Scan path] E:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
[Scan path] E:\WINDOWS\System32\mnmsrvc.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\mouclass.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\mouhid.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\mrxdav.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\mrxsmb.sys
[Scan path] E:\WINDOWS\System32\msdtc.exe
[Scan path] E:\WINDOWS\system32\msiexec.exe
[Scan path] E:\WINDOWS\system32\drivers\MSKSSRV.sys
[Scan path] E:\WINDOWS\system32\drivers\MSPCLOCK.sys
[Scan path] E:\WINDOWS\system32\drivers\MSPQM.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\mssmbios.sys
[Scan path] E:\WINDOWS\system32\drivers\MSTEE.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\NdisIP.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ndistapi.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ndisuio.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ndiswan.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\netbios.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\netbt.sys
[Scan path] E:\WINDOWS\system32\netdde.exe
[Scan path] E:\Programmer\Norton Personal Firewall\NISSERV.EXE
[Scan path] E:\Programmer\Norton Personal Firewall\NISUM.EXE
[Scan path] E:\WINDOWS\System32\DRIVERS\nv4_mini.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\nv4.sys
[Scan path] E:\WINDOWS\system32\nvsvc32.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\nwlnkflt.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys
[Scan path] E:\WINDOWS\system32\drivers\ctoss2k.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\parport.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\pci.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\pciide.sys
[Scan path] E:\WINDOWS\system32\PfModNT.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\raspptp.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\processr.sys
[Scan path] E:\WINDOWS\System32\drivers\prodrv06.sys
[Scan path] E:\WINDOWS\System32\drivers\prohlp02.sys
[Scan path] E:\WINDOWS\System32\drivers\prosync1.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\psched.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\ptilink.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\PxHelp20.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\rasacd.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\rasl2tp.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\raspppoe.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\raspti.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\rdbss.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\RDPCDD.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\rdpdr.sys
[Scan path] E:\WINDOWS\system32\sessmgr.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\redbook.sys
[Scan path] E:\WINDOWS\System32\locator.exe
[Scan path] E:\WINDOWS\System32\rsvp.exe
[Scan path] F:\Programmer\SUPERAntiSpyware\SASDIFSV.SYS
[Scan path] F:\Programmer\SUPERAntiSpyware\SASENUM.SYS
[Scan path] F:\Programmer\SUPERAntiSpyware\SASKUTIL.sys
[Scan path] E:\WINDOWS\System32\SCardSvr.exe
[Scan path] E:\WINDOWS\system32\drivers\scsiport.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\secdrv.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\serenum.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\serial.sys
[Scan path] E:\WINDOWS\System32\drivers\sfhlp01.sys
[Scan path] E:\WINDOWS\system32\drivers\sfmanm.sys
[Scan path] E:\WINDOWS\system32\tcpsvcs.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\sisagp.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\sisnic.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\SLIP.sys
[Scan path] E:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
[Scan path] E:\WINDOWS\system32\drivers\splitter.sys
[Scan path] E:\WINDOWS\system32\spoolsv.exe
[Scan path] E:\WINDOWS\System32\Drivers\sptd.sys
E:\WINDOWS\System32\Drivers\sptd.sys - read error

[Scan path] E:\WINDOWS\System32\DRIVERS\sr.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\srv.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\ss_bus.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\ss_mdm.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\StreamIP.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\swenum.sys
[Scan path] E:\WINDOWS\system32\drivers\swmidi.sys
[Scan path] E:\WINDOWS\System32\Drivers\SYMDNS.SYS
[Scan path] E:\Programmer\Symantec\SYMEVENT.SYS
[Scan path] E:\WINDOWS\System32\Drivers\SYMFW.SYS
[Scan path] E:\WINDOWS\System32\Drivers\SYMIDS.SYS
[Scan path] E:\WINDOWS\System32\Drivers\SYMNDIS.SYS
[Scan path] E:\Programmer\Norton Personal Firewall\SymProxySvc.exe
[Scan path] E:\WINDOWS\System32\Drivers\SYMREDRV.SYS
[Scan path] E:\WINDOWS\System32\Drivers\SYMTDI.SYS
[Scan path] E:\WINDOWS\system32\drivers\sysaudio.sys
[Scan path] E:\WINDOWS\system32\smlogsvc.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\tcpip.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\tcpip6.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\termdd.sys
[Scan path] E:\WINDOWS\System32\tlntsvr.exe
[Scan path] E:\WINDOWS\system32\DRIVERS\tunmp.sys
[Scan path] E:\WINDOWS\system32\wdfmgr.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\update.sys
[Scan path] E:\WINDOWS\System32\ups.exe
[Scan path] E:\WINDOWS\system32\DRIVERS\usbccgp.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\usbhub.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\usbohci.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\usbprint.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\usbscan.sys
[Scan path] E:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
[Scan path] E:\WINDOWS\system32\DRIVERS\VClone.sys
[Scan path] E:\WINDOWS\System32\drivers\vga.sys
[Scan path] E:\WINDOWS\System32\vssvc.exe
[Scan path] E:\WINDOWS\System32\DRIVERS\wanarp.sys
[Scan path] E:\WINDOWS\system32\drivers\wdmaud.sys
[Scan path] E:\WINDOWS\System32\MsPMSPSv.exe
[Scan path] E:\WINDOWS\System32\wbem\wmiapsrv.exe
[Scan path] E:\WINDOWS\System32\drivers\ws2ifsl.sys
[Scan path] E:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
[Scan path] E:\WINDOWS\System32\Drivers\usbVM31b.sys
[Scan path] E:\Documents and Settings\Mathias Jakobsen\Menuen Start\Programmer\Start\Microsoft Office.lnk
[Scan path] E:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\Microsoft Office.lnk
[Scan path] E:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\Firefox Preloader.lnk
[Scan path] E:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\Monitor Apache Servers.lnk
[Scan path] E:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk

Scan statistics

Objects scanned: 262
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 1
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 1879 Kb/s
Scan time: 00:00:27


[Scan path] C:\
C:\pagefile.sys - read error
C:\program files\altnet\download manager\admdloader.dll is adware program Adware.Altnet - renamed
C:\program files\altnet\download manager\adm25.dll is adware program Adware.Altnet - renamed
C:\program files\altnet\download manager\adm.exe is adware program Adware.Altnet - renamed
C:\program files\altnet\download manager\altnetuninstall.exe is adware program Adware.Altnet - renamed
>C:\program files\altnet\Points Manager\Points Manager.exe is adware program Adware.Altnet - renamed

[Scan path] D:\
D:\carrierbot\IRC Bot\mirc.exe is riskware program Program.mIRC.603 - renamed
D:\carrierbot\IRC Bot\backup\mirc.exe is riskware program Program.mIRC.601 - renamed

[Scan path] E:\
E:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT - read error
E:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER~1.LOG - read error
E:\Documents and Settings\NetworkService.NT AUTHORITY\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLASS.DAT - read error
E:\Documents and Settings\NetworkService.NT AUTHORITY\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error
E:\Documents and Settings\Mathias Jakobsen\NTUSER.DAT - read error
E:\Documents and Settings\Mathias Jakobsen\NTUSER~1.LOG - read error
E:\Documents and Settings\Mathias Jakobsen\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLASS.DAT - read error
E:\Documents and Settings\Mathias Jakobsen\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error
E:\Programmer\VVSN\VVSN.exe is adware program Adware.SaveNow - renamed
E:\WINDOWS\system32\H@tKeysH@@k.DLL is hacktool program Tool.Hatkeys - renamed
E:\WINDOWS\system32\config\system.LOG - read error
E:\WINDOWS\system32\config\software.LOG - read error
E:\WINDOWS\system32\config\default.LOG - read error
E:\WINDOWS\system32\config\SECURITY - read error
E:\WINDOWS\system32\config\SAM - read error
E:\WINDOWS\system32\config\SAM.LOG - read error
E:\WINDOWS\system32\config\SECURITY.LOG - read error
E:\WINDOWS\system32\config\SYSTEM - read error
E:\WINDOWS\system32\config\SOFTWARE - read error
E:\WINDOWS\system32\config\DEFAULT - read error
E:\WINDOWS\system32\drivers\sptd6621.sys - read error
E:\WINDOWS\system32\drivers\sptd.sys - read error
E:\WINDOWS\system32\drivers\dtscsi.sys - read error
>>>E:\WINDOWS\system32\P2P Networking\P2P Networking.exe\data001 is adware program Adware.PeerNet
E:\WINDOWS\system32\P2P Networking\P2P Networking.exe - archive contains infected objects - moved
>E:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll is adware program Adware.PeerNet - renamed

[Scan path] F:\
>>F:\spil\Arcanum\arcanum1.dat\data5297 infected with modification of Trojan.Eps.165
F:\spil\Arcanum\arcanum1.dat - archive contains infected objects - user denied moving

[Scan path] H:\

Scan statistics

Objects scanned: 384071
Infected objects found: 0
Objects with modifications found: 1
Suspicious objects found: 0
Adware programs found: 8
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 2
Hacktool programs found: 1
Objects cured: 0
Objects deleted: 0
Objects renamed: 10
Objects moved: 1
Objects ignored: 0
Scan speed: 47 Kb/s
Scan time: 06:17:23



Total session statistics

Objects scanned: 384333
Infected objects found: 0
Objects with modifications found: 1
Suspicious objects found: 0
Adware programs found: 9
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 2
Hacktool programs found: 1
Objects cured: 0
Objects deleted: 0
Objects renamed: 10
Objects moved: 1
Objects ignored: 0
Scan speed: 49 Kb/s
Scan time: 06:17:50

SAS log:
SUPERAntiSpyware Scan Log
Generated 04/22/2006 at 09:39 AM

Core Rules Database Version : 2885
Trace Rules Database Version: 1037

Memory threats detected  : 0
Registry threats detected : 54
File threats detected    : 95

Adware.Casino Games (Golden Palace Casino)
    E:\Programmer\CASINO_G-FED200000\DANISH\casino.exe
    HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\casino.exe
    HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\casino.exe#Path

Adware.Tracking Cookie
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@track.adform[3].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@ads2.jubii[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@ads.deviantart[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@ads.gamespy[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@ads.gorillanation[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@ads.infosdunet.firstream[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@ads.jackpot[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@adv.surinter[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@banner2.ofir[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@cats.megatracker[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ad.yieldmanager[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@usenext[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ads.gorillanation[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@cz3.clickzs[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@cz4.clickzs[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@cz5.clickzs[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@cz6.clickzs[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@cz8.clickzs[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@cz9.clickzs[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@freebannertrade[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@ilead.itrack[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@tradedoubler[3].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@toplist[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@webpower[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@toplist[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@www.highqualitysexmovies[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@www.monstre-de-sexe[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@www.oooxxx[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@www.sex-mission[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias@xiti[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@stat.inleadmedia[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@www.bannercash[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@cz6.clickzs[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@webpower[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@uclick[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@adtech[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@counter[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ads2.jubii[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@revenue[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@uclick[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@atwola[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@atwola[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@toplist[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@sexyeva[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@metareward[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@stats3.porntrack[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@webpower[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@tribalfusion[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@clickxchange[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@www.astaserials[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@bbanner[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@programs.wegcash[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@z1.adserver[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ads2.jubii[3].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@trafficmp[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@adform[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ad.120.tbn[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ad.strict.tbn[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@free.wegcash[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@1xxx.cqcounter[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ad.adition[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@trafficmp[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@www.xxxsupersize[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ads2.jubii[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@www.living-sex[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@z1.adserver[3].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@tradedoubler[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@serving-sys[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@track.adform[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ad1.emediate[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@xiti[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ilead.itrack[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ads.cc214142[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@adserver.banneradministration[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@emarketmakers[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@server.iad.liveperson[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@revenue[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@partypoker[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@as.adwave[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@tribalfusion[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@partypoker.touchclarity[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@login.tracking101[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@statcounter[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@as1.falkag[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@ad.yieldmanager[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@www.livewebstats[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@statcounter[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@citi.bridgetrack[2].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@counter.sexsuche[1].txt
    E:\Documents and Settings\Mathias Jakobsen\Cookies\mathias jakobsen@adfair[1].txt

Adware.IST/ISTBar (Slotch Bar)
    HKU\S-1-5-21-527237240-1606980848-1060284298-1003\Software\IST

Adware.GAIN/Gator
    HKLM\Software\Gator.com
    HKLM\Software\Gator.com\Gator
    HKLM\Software\Gator.com\Gator\dyn
    HKLM\Software\Gator.com\Gator\dyn#PdpFirstStart
    HKLM\Software\Gator.com\Gator\stat
    HKLM\Software\Gator.com\Gator\stat#Guid
    HKLM\Software\Gator.com\Trickler
    HKLM\Software\Gator.com\Trickler#FirstStartValue
    HKLM\Software\Gator.com\Trickler#StartTime
    HKLM\Software\Gator.com\Trickler#FirstStartSent
    HKLM\Software\Gator.com\Trickler\Files
    HKLM\Software\Gator.com\Trickler\Files\Bundle
    HKLM\Software\Gator.com\Trickler\Files\Bundle\chk
    HKLM\Software\Gator.com\Trickler\Files\Bundle\chk#CheckFailures
    HKLM\Software\Gator.com\Trickler\Files\Bundle\chk#Attempts
    HKLM\Software\Gator.com\Trickler\Files\Bundle\chk#Errors
    HKLM\Software\Gator.com\Trickler\Files\Bundle\dl
    HKLM\Software\Gator.com\Trickler\Files\Bundle\dl#Attempts
    HKLM\Software\Gator.com\Trickler\Files\Bundle\dl#Errors
    HKLM\Software\Gator.com\Trickler\Files\Bundle\dl#FileDones
    HKLM\Software\Gator.com\Trickler\Files\Bundle\dl#UrlTime
    HKLM\Software\Gator.com\Trickler\Files\Bundle\dl#UrlSize
    HKLM\Software\Gator.com\Trickler\Files\Bundle\dl#StoredFile
    HKLM\Software\Gator.com\Trickler\Files\OemResDll
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\chk
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\chk#CheckFailures
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\chk#Attempts
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\chk#Errors
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\dl
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\dl#Attempts
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\dl#Errors
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\dl#FileDones
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\dl#UrlTime
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\dl#UrlSize
    HKLM\Software\Gator.com\Trickler\Files\OemResDll\dl#StoredFile
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\chk
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\chk#CheckFailures
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\chk#Attempts
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\chk#Errors
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\dl
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\dl#Attempts
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\dl#Errors
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\dl#FileDones
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\dl#UrlTime
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\dl#UrlSize
    HKLM\Software\Gator.com\Trickler\Files\SilentSetup\dl#StoredFile
    HKLM\Software\Gator.com\Trickler\Files\TricklerInf
    HKLM\Software\Gator.com\Trickler\Files\TricklerInf#Attempts
    HKLM\Software\Gator.com\Trickler\Files\TricklerInf#Errors
    HKLM\Software\Gator.com\Trickler\Files\TricklerInf#FileDones

BearShare File Sharing Client
    F:\Programmer\BearShare\BearShare.exe
    E:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\BearShare.lnk
    E:\Documents and Settings\Mathias Jakobsen\Skrivebord\BearShare.lnk
    E:\WINDOWS\Prefetch\BEARSHARE.EXE-19A426E1.pf

Ny Hijackhtis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:20:10, on 22-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
H:\Apache2\Apache2\bin\Apache.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\WINDOWS\System32\CTsvcCDA.exe
E:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
H:\Apache2\Apache2\bin\Apache.exe
E:\Programmer\Norton Personal Firewall\NISUM.EXE
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\tcpsvcs.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\Norton Personal Firewall\SymProxySvc.exe
E:\WINDOWS\System32\MsPMSPSv.exe
E:\Programmer\Norton Personal Firewall\NISSERV.EXE
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\ctfmon.exe
E:\WINDOWS\system32\CTHELPER.EXE
E:\Programmer\Trust\250S Series\lwbwheel.exe
E:\WINDOWS\system32\rundll32.exe
F:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
E:\Programmer\Norton Personal Firewall\IAMAPP.EXE
E:\WINDOWS\VM_STI.EXE
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\Programmer\Lexmark 2300 Series\lxcgmon.exe
E:\Programmer\Lexmark 2300 Series\ezprint.exe
E:\Programmer\DAEMON Tools\daemon.exe
F:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
E:\Programmer\FirefoxPreloader\FirefoxPreloader.exe
H:\Apache2\Apache2\bin\ApacheMonitor.exe
F:\Programmer\firefox 1.5\firefox.exe
E:\WINDOWS\system32\lxcgcoms.exe
E:\WINDOWS\system32\wuauclt.exe
F:\Programmer\Winamp\winamp.exe
H:\misc DL\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.dk/0SEDADK/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - f:\Programmer\UnH Solutions\IE Privacy Keeper\IEPKbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - f:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {54EA478F-A23A-9D06-3ED5-8892053EA4C3} - E:\PROGRA~1\OOZEBU~1\Show play.exe (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] E:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] E:\Programmer\Creative\SBLive\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [CTStartup] E:\Programmer\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [LWBMOUSE] E:\Programmer\Trust\250S Series\lwbwheel.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "f:\Programmer\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [iamapp] E:\Programmer\Norton Personal Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] E:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [BigDogPath] E:\WINDOWS\VM_STI.EXE ZSMC USB PC Camera
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [LXCGCATS] rundll32 E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "E:\Programmer\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "E:\Programmer\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "E:\Programmer\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [DAEMON Tools] "E:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\RunOnce: [MessengerPlusUninstall] E:\WINDOWS\system32\cmd.exe /C "E:\DOCUME~1\MATHIA~1\LOKALE~1\Temp\MsgPlusUninst.bat"
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "E:\Programmer\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Microsoft Office.lnk = F:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = E:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Firefox Preloader.lnk = E:\Programmer\FirefoxPreloader\FirefoxPreloader.exe
O4 - Global Startup: Monitor Apache Servers.lnk = H:\Apache2\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = E:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download all by Free Download Manager - file://d:\Programmer\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://d:\Programmer\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://d:\Programmer\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://d:\Programmer\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with X&ML Spy - g:\Programmer\Altova\XMLSPY2004\spy.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programmer\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programmer\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - g:\Programmer\Altova\XMLSPY2004\spy.htm (file missing)
O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - g:\Programmer\Altova\XMLSPY2004\spy.htm (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - f:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - f:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - E:\Programmer\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - E:\Programmer\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {D799B0E4-BEDE-41d2-AEE0-1E3A1C4EF918} - F:\Programmer\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
O9 - Extra 'Tools' menuitem: IE Privacy Keeper - {D799B0E4-BEDE-41d2-AEE0-1E3A1C4EF918} - F:\Programmer\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: http://servedby.advertising.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SASWinLogon - F:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apache2 - Unknown owner - H:\Apache2\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - E:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: lxcg_device -  - E:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - E:\Programmer\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - E:\Programmer\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - E:\Programmer\Norton Personal Firewall\SymProxySvc.exe

Forresten har jeg ordnet det med IE Privacy Keeper, det har ikke hjulpet synderligt på tiden desværre
Avatar billede forevernewbie Nybegynder
22. april 2006 - 13:37 #3
Lige lidt oprydning med HJT:

Kør en scanning med HijackThis, så du kan se alle filer. Luk alle vinduer, sæt flueben ved disse linier, og klik fix checked.


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.dk/
O2 - BHO: (no name) - {54EA478F-A23A-9D06-3ED5-8892053EA4C3} - E:\PROGRA~1\OOZEBU~1\Show play.exe (file missing)
O15 - Trusted Zone: http://servedby.advertising.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

Hvis du har fjernet partypoker:

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - f:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - f:\Programmer\PartyPoker\PartyPoker.exe (file missing)

Du har en del processer kørende, som godt kan være et stykke tid om at lukke ned, men du kan måske forbedre det lidt ved at kigge på disse råd http://spywareinfo.dk/#/tip-og-tricks/langsom-op-og-nedlukning-xp.htm
Avatar billede forevernewbie Nybegynder
23. april 2006 - 12:25 #4
Tak for point.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester