Avatar billede ruffe66 Nybegynder
02. maj 2006 - 20:24 Der er 10 kommentarer og
2 løsninger

Tjek venligst denne LOG

Logfile of HijackThis v1.99.1
Scan saved at 20:02:43, on 02-05-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Programmer\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\SYSTEM32\qttask.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\programmer\u-storage tools2.5\ustorage.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Logitech\MediaLife\MediaLifeService.exe
C:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmer\TrojanHunter 4.5\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Programmer\Microsoft Office\Office\Osa.exe
C:\Programmer\Microsoft Office\Office\Findfast.exe
C:\Programmer\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
C:\Programmer\AntiVir PersonalEdition Classic\sched.exe
C:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\HEWLET~1\AIO\SHARED\BIN\HPOEVM07.EXE
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\Programmer\Hewlett-Packard\AiO\Shared\bin\HPOSTS07.exe
C:\Programmer\Fælles filer\Logitech\KHAL\KHALMNPR.EXE
C:\Programmer\Hewlett-Packard\AiO\Shared\bin\HPOFXM07.exe
C:\wincmd\WINCMD32.EXE
c:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://streetammo.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Programmer\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Programmer\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O3 - Toolbar: SearchSafe - {51CE7A05-9C90-433b-8BEC-73973997F6F2} - C:\Programmer\SearchSafe\searchsafe.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [MMTray] C:\Programmer\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [MimBoot] C:\Programmer\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe
O4 - HKLM\..\Run: [UStorag] c:\programmer\u-storage tools2.5\ustorage.exe sys_auto_run C:\Programmer\U-Storage Tools2.5
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Programmer\Logitech\MediaLife\MediaLifeService.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [THGuard] "C:\Programmer\TrojanHunter 4.5\THGuard.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Global Startup: Microsoft Office-start.lnk = C:\Programmer\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Hurtig søgning.lnk = C:\Programmer\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: HPAiODevice(hp psc 900 series) - 1.lnk = C:\Programmer\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
O4 - Global Startup: GStartup.lnk = ?
O4 - Global Startup: PrecisionTime.lnk = C:\Programmer\PrecisionTime\PrecisionTime.exe
O4 - Global Startup: Date Manager.lnk = C:\Programmer\Date Manager\DateManager.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Programmer\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashboard.aspx?GFGHBJBHDIGHDGEJFHJHJCBFHEFBGEJHFFCHG (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashboard.aspx?GFGHBJBHDIGHDGEJFHJHJCBFHEFBGEJHFFCHG (file missing)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Programmer\PokermMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {012F24D4-35B0-11D0-BF2D-0000E8D0D156} (InstallControl Class) - http://activex.casinosupportservice.com/Version3.0/InstallHelper.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://erfyaalsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmicro.com/Dashboard/controls/activex_10/TMSSReportW.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) - http://130.228.2.107/speedtest/SpeedTest_2.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.danskebank.dk/netbank/activex/DanskeSikker.cab
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmer\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
Avatar billede ejvindh Ekspert
02. maj 2006 - 20:39 #1
Jeg kigger på den :-)
Avatar billede ejvindh Ekspert
02. maj 2006 - 20:45 #2
-- Hent "SuperAntiSpyware free" herfra:
http://www.spywarefri.dk/downloads1.htm
Installer, og opdater scannereren. Men vent med at scanne.

Fuld vejledning til superantispyware finder du her:
http://www.spywarefri.dk/manualer/superantispyware-manual.htm

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O3 - Toolbar: SearchSafe - {51CE7A05-9C90-433b-8BEC-73973997F6F2} - C:\Programmer\SearchSafe\searchsafe.dll
O4 - Global Startup: GStartup.lnk = ?
O4 - Global Startup: PrecisionTime.lnk = C:\Programmer\PrecisionTime\PrecisionTime.exe
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Du skal nu til at slette. Som indledning hertil skal du have slået "Udvidet filvisning" til:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

-- Slet herefter følgende (hvis du kan finde dem):
Mapper:
C:\Programmer\SearchSafe\
C:\Programmer\PrecisionTime\

Filer:
C:\WINDOWS\SYSTEM\blank.htm

-- Start SuperAntispyware, klik "Scan your computer", sæt flueben i dine drev, ovre til venstre i vinduet. Ovre til højre i vinduet, sætter du prik i "Perform Complete Scan". Klik "næste", nu scanner den. Når den er færdig, så markerer du det den finder, og lader scannereren fjerne det.

-- Genstart til normal tilstand. Åbn SuperAntispyware-scannereren igen, og klik "preferences"-> "stastics/logs". Marker loggen, og klik "View log". Kopier loggen her ind i tråden, sammen med en ny HijackThis log.
Avatar billede ruffe66 Nybegynder
02. maj 2006 - 21:02 #3
Tak, men jeg arbejder først videre i morgen. Jeg håber det er i orden.
hej
Avatar billede ejvindh Ekspert
02. maj 2006 - 21:33 #4
Det er helt i orden :-)
Avatar billede ruffe66 Nybegynder
03. maj 2006 - 16:55 #5
Hej igen
her er først loggen på Spyware Scan
SUPERAntiSpyware Scan Log
Generated 05/03/2006 at 04:45 PM

Core Rules Database Version : 2910
Trace Rules Database Version: 1042

Memory threats detected  : 0
Registry threats detected : 0
File threats detected    : 147

Adware.Tracking Cookie
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@82763522[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads.realtechnetwork[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@cassava[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@en[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@server.lon.liveperson[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@roiservice[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@partypoker.touchclarity[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@www.bannercamp[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@c.goclick[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.ofir[4].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@forum.pacificpoker[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@track.adform[5].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@adtech[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@38492175[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@xiti[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@yadro[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@alr[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ilead.itrack[5].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@atwola[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@click.cashengines[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@counter.mycomputer[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@server3.web-stat[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@webstat[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads2.jubii[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@stats.manticoretechnology[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@34414543[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@school[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@dk[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@tacoda[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@indextools[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.yieldmanager[4].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@cz6.clickzs[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@globalstat[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@e2.emediate[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@belnk[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@clicks.hmcampaign[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@dk-sex[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads.vg.basefarm[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@partypoker[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.musicmatch[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@83227003[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad1.emediate[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@azjmp[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@pics4clicks.suze[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@18583751[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@59207812[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@3d-sexgames[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@dist.belnk[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@serials[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@www.sextime[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@LPneimanmarcus[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@warlog[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@qnsr[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@1072508508[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@e-2dj6wgmiaod5mbo.stats.esomniture[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@clubpacific[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads.monster[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads.ssl.jubii[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads1.revenue[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@cneteurope.122.2o7[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@1071214352[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@partygaming.122.2o7[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads.realcastmedia[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@banner[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@data2.perf.overture[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@partypoker.pokerfoo[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@toplist[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@adfair[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@vhost.oddcast[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@www.webstat[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@14382979[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@aff888[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@14926679[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@adfarm1.adition[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@S151485[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@www.pokertracker[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@S113288[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@stats2.clicktracks[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@ad.musicmatch[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@ads2.jubii[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@banner2.ofir[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@stats.klsoft[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@ilead.itrack[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@www.sex-clips[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@livestats.mediaclay[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@toplist_[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@www.screensavers4free[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@track.adform[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@www.nextag[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@ads.reklamenet[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@bannere[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@indextools[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@ad1.emediate[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@toplist[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\anyuser@ilead.itrack[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads2.jubii[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.borsen[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad1.emediate[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ilead.itrack[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@counter[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads.gamespy[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@adultrevenueservice[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@counter.mtree[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@toplist[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@banner2.ofir[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@toplist[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@newsexgallery[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@www.newsexgallery[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ilead.itrack[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad1.emediate[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@image.masterstats[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@partypoker.touchclarity[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.adocean[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@oddcast[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@vhost.oddcast[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@banner2.inet-traffic[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@track.adform[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.ofir[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.ofir[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@www.sexaben[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.musicmatch[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlywlczkkqqwdj6x9ny-1seq-2-2.stats.esomniture[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@xiti[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ads2.jubii[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@clickthrutraffic[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@banner1.inet-traffic[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.yieldmanager[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@dist.belnk[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@partypoker[1].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@track.adform[4].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad1.emediate[4].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ilead.itrack[4].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@yadro[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@track.adform[3].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@ad.yieldmanager[2].txt
    C:\Documents and Settings\Ditter og Morten\Cookies\ditter og morten@tradersclub_click_2006_03[1].txt

Spyware.WebSearch (WinTools/Huntbar)
    C:\Programmer\Fælles filer\WinTools\rezasc.wzg
    C:\Programmer\Fælles filer\WinTools
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Web Search Tools\Home.url
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Web Search Tools\Frequently Asked Questions.url
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Web Search Tools\Terms of Use.url
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Web Search Tools\Privacy Policy.url
    C:\Documents and Settings\All Users\Menuen Start\Programmer\Web Search Tools

Trojan.NewDotNet
    C:\Programmer\NewDotNet\newdotnet4_50.dll
    C:\Programmer\NewDotNet\readme.txt
    C:\Programmer\NewDotNet

Her er så loggen på Hijack


Logfile of HijackThis v1.99.1
Scan saved at 16:55:05, on 03-05-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\AntiVir PersonalEdition Classic\sched.exe
C:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmer\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\SYSTEM32\qttask.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\programmer\u-storage tools2.5\ustorage.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Logitech\MediaLife\MediaLifeService.exe
C:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmer\TrojanHunter 4.5\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Microsoft Office\Office\Osa.exe
C:\Programmer\Microsoft Office\Office\Findfast.exe
C:\Programmer\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\Fælles filer\Logitech\KHAL\KHALMNPR.EXE
C:\PROGRA~1\HEWLET~1\AIO\SHARED\BIN\HPOEVM07.EXE
C:\Programmer\Hewlett-Packard\AiO\Shared\bin\HPOSTS07.exe
C:\Programmer\Hewlett-Packard\AiO\Shared\bin\HPOFXM07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\wincmd\WINCMD32.EXE
c:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://streetammo.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Programmer\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Programmer\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [MMTray] C:\Programmer\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [MimBoot] C:\Programmer\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe
O4 - HKLM\..\Run: [UStorag] c:\programmer\u-storage tools2.5\ustorage.exe sys_auto_run C:\Programmer\U-Storage Tools2.5
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Programmer\Logitech\MediaLife\MediaLifeService.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [THGuard] "C:\Programmer\TrojanHunter 4.5\THGuard.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office-start.lnk = C:\Programmer\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Hurtig søgning.lnk = C:\Programmer\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: HPAiODevice(hp psc 900 series) - 1.lnk = C:\Programmer\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
O4 - Global Startup: Date Manager.lnk = C:\Programmer\Date Manager\DateManager.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programmer\EmpirePoker\EmpirePoker.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Programmer\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Programmer\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashboard.aspx?GFGHBJBHDIGHDGEJFHJHJCBFHEFBGEJHFFCHG (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashboard.aspx?GFGHBJBHDIGHDGEJFHJHJCBFHEFBGEJHFFCHG (file missing)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Programmer\PokermMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {012F24D4-35B0-11D0-BF2D-0000E8D0D156} (InstallControl Class) - http://activex.casinosupportservice.com/Version3.0/InstallHelper.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://erfyaalsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmicro.com/Dashboard/controls/activex_10/TMSSReportW.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) - http://130.228.2.107/speedtest/SpeedTest_2.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.danskebank.dk/netbank/activex/DanskeSikker.cab
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmer\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
Avatar billede ejvindh Ekspert
03. maj 2006 - 20:00 #6
Loggen er ren. Har du også fået løst dit problem?

For at gøre arbejdet helt færdig:
Det kan være en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse (http://www.spywarefri.dk/virusscannere.htm#alle) - genstart din computer - aktiver systemgendannelse.
Og så kan det også være en god ide at skjule dine systemfiler og -mapper igen, så du ikke ved en fejl kommer til at slette en vigtig fil. Det gør du samme sted, hvor du satte det til at vise alle filer, denne gang vælger du bare: Vis ikke skjulte filer og mapper.

Det kan også være en god ide at få renset ud i dine midlertidige filer. Det kan gøres på en hurtig og nem måde med denne fil
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------

For at forhindre gentagelser, vil jeg anbefale dig at lægge nogle små programmer ind, som forhindrer spyware i at komme ind i første omgang. Du finder links og gode råd her:
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at du læser denne artikel om hvordan du kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
Avatar billede ruffe66 Nybegynder
03. maj 2006 - 20:30 #7
Jeg ved ikke hvad der er galt med hjemmesiden Danske Netbank. Jeg kan bare ikke komme ind på den.
Ved du noget om det. Jeg har en anden pc, den går fint igennem.
03. maj 2006 - 20:40 #8
http://www.java.com/en/download/download_the_latest.jsp - skal bruges til Netbank ting samt mange andre steder...
Avatar billede ejvindh Ekspert
03. maj 2006 - 20:43 #9
Jeg ved ikke så meget om Netbank, men her er en samlig af gode råd, hvis det ikke virker:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=92&PN=1
Avatar billede ejvindh Ekspert
10. maj 2006 - 10:36 #10
Husk at lukke spørgsmålet efter dig :-)
Avatar billede ruffe66 Nybegynder
10. maj 2006 - 11:06 #11
er nu lukket
Avatar billede ejvindh Ekspert
10. maj 2006 - 11:12 #12
Du skal huske at markere mit navn, inden du klikker på Accepter. Tråden er stadig åben :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester