Avatar billede mf Nybegynder
29. juni 2006 - 01:16 Der er 6 kommentarer og
1 løsning

Er der noget snavs

Hej derude
Sidder lige og roder med naboens pc og tror der er noget der skal fixes, men hvis der lige er en der gider checke HiJack loggen så bliver det jo lidt nemmere.....


Logfile of HijackThis v1.99.1
Scan saved at 01:06:04, on 30-06-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Ulead Systems\Ulead PhotoImpact 5 Bundled Edition\Abmtsr.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\WINDOWS\ioikckgnce.exe
C:\WINDOWS\ioikckgnce.exe
C:\MF\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Album Fast Start.lnk = C:\Programmer\Ulead Systems\Ulead PhotoImpact 5 Bundled Edition\Abmtsr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/download/2006/cabs/ErrorSafeFreeInstall_dk.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/download/2006/cabs/ErrorSafeFreeInstall_dk.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
Avatar billede magictouch Nybegynder
29. juni 2006 - 06:28 #1
Kigger på den
Avatar billede magictouch Nybegynder
29. juni 2006 - 06:34 #2
Den er ikke helt fri for infektioner -

Download free Trial af SuperAntiSpyware Pro til Skrivebordet:

http://www.superantispyware.com/downloads/SUPERAntiSpywarePro1241.exe

Installer den, og lad den opdatere med nyeste opdateringer.

Så vil den spørge om din mail adresse, det er op til dig selv om du vil udfylde det.Tryk så på Næste og Næste igen -Udfør.

Dansk vejledning her:
http://www.spywarefri.dk/manualer/superantispyware-manual.htm

Luk progammet.


Hent Ccleaner: http://www.ccleaner.com/ccdownload.asp
Installer programmet, men lad vær med at køre det endnu!
Husk at vælge dansk ved installationen.
Fjern flueben ved - Tilføj Yahoo Toolbar. Hvis du ikke ønsker den.
Ccleaner programmet fjerner overflødige Temp filer.
Og gør de nedenstående scanninger hurtigere
Dansk manual:
http://www.spywarefri.dk/manualer/ccleaner-manual.htm

Genstart til fejlsikret tilstand. Du trykker f8 nogle gange når Windows starter op.





Kør CCleaner.
Tryk så på "Renser" i menuen i venstre side.
Nu skal du trykke på knappen "Kør Cleaner" - det gør du mindst 2 gange.
Luk programmet.






Start superantispyware ved at højreklikke på den gule og sorte bille ved uret
Tryk på - Scan for, Adware,Malware  - linjen
Tryk på - Preference - Knappen.
Fjern flueben ved -Start SuperAntiSpyware when Windows starts.

tryk på Fanebladet -Scanning control.

ved scanning options, skal der kun være flueben i de to nederste

Fanebladet- Real Time Protections. Fjerner du fluben ved - Enable Real Time Protection

Tryk så på Close

Tryk på - Scan Your computer - Knappen. sæt flueben ved de drev der skal scannes. Det er vigtigt at drev hvor Windows (systemdrevet) ligger, har et  flueben.

Flyt så prikken ved- Perform quick Scan,  ned til - Perform complete Scan.

Tryk på Næste, så går den i gang med at scanne.

Det kan godt tage lang tid hvis du har meget på computeren


Når scanninngen er færdig popper der en boks op, tryk OK.

Sæt flueben ved alt den har fundet- næste. Så vil den fixe/slette infektionerne.

Lad den genstarte.


Efter genstart -

Klik på "Start" - Vælg "Søg".
Klik på linket "Skift indstillinger".
Klik på "Skift søgefunktioner for filer og mapper"
Sæt prik i "Avanceret" og klik OK.
Klik på "Alle filer og mapper"
Klik på "Flere avancerede indstillinger"
Sæt flueben i de tre øverste.
Find:
superantispyware scan log


Send en ny hijackthis herind, sammen med Superantispyware loggen
Avatar billede mf Nybegynder
29. juni 2006 - 18:03 #3
Det tog sørme noget tid...

SUPERAntiSpyware Scan Log
Generated 06/30/2006 at 01:48 PM

Core Rules Database Version : 2997
Trace Rules Database Version: 1079

Memory threats detected  : 1
Registry threats detected : 29
File threats detected    : 191

Adware.Aurora/Nail
    C:\DOCUME~1\JETTE\LOKALE~1\TEMP\AURARECO.EXE
    C:\DOCUME~1\JETTE\LOKALE~1\TEMP\AURARECO.EXE
    HKLM\System\ControlSet001\Services\SvcProc
    C:\WINDOWS\svcproc.exe
    HKLM\System\ControlSet003\Services\SvcProc
    HKLM\System\CurrentControlSet\Services\SvcProc
    C:\Documents and Settings\Jens\Lokale indstillinger\Temp\aurareco.exe
    C:\WINDOWS\Nail.exe
    C:\WINDOWS\Prefetch\AURARECO.EXE-368456B2.pf

Trojan.WinAntiSpyware/WinAntiVirus 2006
    HKCR\WAP6.PCheck
    HKCR\WAP6.PCheck\CLSID
    HKCR\WAP6.PCheck\CurVer
    HKCR\WAP6.PCheck.1
    HKCR\WAP6.PCheck.1\CLSID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version
    HKU\S-1-5-21-515967899-261903793-725345543-1004\Software\WinAntiVirus Pro 2006
    C:\WINDOWS\system32\stera.job
    C:\Documents and Settings\Jette\Application Data\WinAntiVirus Pro 2006\Logs
    C:\Documents and Settings\Jette\Application Data\WinAntiVirus Pro 2006\PGE.dat
    C:\Documents and Settings\Jette\Application Data\WinAntiVirus Pro 2006
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP110\A0062221.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP110\A0062234.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP110\A0062236.exe

Trojan.ErrorSafe
    C:\Documents and Settings\Jens\Lokale indstillinger\Temporary Internet Files\Content.IE5\AXJ49WJ6\ErrorSafeFreeInstall_dk[1].exe
    C:\Documents and Settings\Jette\Lokale indstillinger\Temporary Internet Files\Content.IE5\XCWBXDOH\ErrorSafeFreeInstall_dk[1].exe

Unclassified.Unknown Origin/System
    C:\RECYCLER\NPROTECT\00116424.exe
    C:\RECYCLER\NPROTECT\00117029.exe
    C:\RECYCLER\NPROTECT\00117067.exe
    C:\RECYCLER\NPROTECT\00117272.exe
    C:\RECYCLER\NPROTECT\00117290.exe
    C:\RECYCLER\NPROTECT\00117387.exe
    C:\RECYCLER\NPROTECT\00117424.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP100\A0050089.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP100\A0050297.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP101\A0050363.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP101\A0050377.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP101\A0050383.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP101\A0050576.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP101\A0050655.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0051075.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0051221.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0052546.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0052547.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0052832.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0052833.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0053238.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0053713.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0053746.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0053869.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0053945.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0054549.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP102\A0054550.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0055953.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0055954.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0056105.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0056379.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0056380.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0057422.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0057440.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0057741.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP103\A0057742.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP104\A0057947.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP104\A0057948.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP104\A0058515.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP104\A0058517.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP105\A0059064.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP105\A0059069.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP105\A0059073.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP105\A0059074.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP105\A0059163.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP105\A0059164.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059205.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059206.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059219.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059220.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059407.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059410.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059411.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059412.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059413.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059414.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059415.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059421.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP106\A0059427.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059453.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059513.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059517.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059716.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059791.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059797.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059800.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059802.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059803.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059804.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059805.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059806.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP107\A0059807.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP110\A0062245.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP110\A0062247.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP110\A0062248.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP110\A0062249.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042116.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042117.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042120.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042121.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042131.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042132.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042133.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042172.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042239.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042240.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042241.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042242.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042243.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042244.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP93\A0042252.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042267.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042268.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042274.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042275.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042276.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042277.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042278.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042279.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042280.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042292.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042299.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042316.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042317.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042321.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042323.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042340.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042341.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042489.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042496.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042530.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042531.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042539.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042554.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042555.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042557.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042558.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042559.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042560.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042561.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042568.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042569.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042589.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042590.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042591.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042951.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042952.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042953.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0043051.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0043052.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0043067.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0043070.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0043074.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044226.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044227.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044228.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044229.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044265.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044266.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044267.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044268.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044273.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044274.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044275.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044343.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0044844.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0044971.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0044972.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0045229.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0045435.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0045563.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0045567.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0045946.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0045948.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0046321.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0046322.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0047617.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0047621.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP97\A0047622.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP98\A0047671.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP98\A0048678.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP99\A0049042.dll
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP99\A0049296.dll
    C:\WINDOWS\system32\dkowqv.exe

Adware.Best Offers Network
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042330.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042533.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP94\A0042541.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0042823.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0043061.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0043112.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP95\A0044105.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044113.exe
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044503.exe
    C:\WINDOWS\ioikckgnce.exe
    C:\WINDOWS\Prefetch\IOIKCKGNCE.EXE-12898066.pf

Adware.WinFavorites
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044279.dll

Installed (reportedly) with eBaysMoMoneyMaker
    C:\System Volume Information\_restore{F1F83C07-2443-49AF-8F4A-9429C7833940}\RP96\A0044299.exe
Avatar billede mf Nybegynder
29. juni 2006 - 18:04 #4
Logfile of HijackThis v1.99.1
Scan saved at 17:58:57, on 30-06-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Ulead Systems\Ulead PhotoImpact 5 Bundled Edition\Abmtsr.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\MF\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Album Fast Start.lnk = C:\Programmer\Ulead Systems\Ulead PhotoImpact 5 Bundled Edition\Abmtsr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/download/2006/cabs/ErrorSafeFreeInstall_dk.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/download/2006/cabs/ErrorSafeFreeInstall_dk.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
Avatar billede magictouch Nybegynder
29. juni 2006 - 20:34 #5
Jah, men det var umagen værd, for når du har fixet nedensstående er loggen ren ;)

Kør en scanning med Hijackthis, så du kan se alle filer.

Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked:
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/download/2006/cabs/ErrorSafeFreeInstall_dk.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/download/2006/cabs/ErrorSafeFreeInstall_dk.cab


Efter sådan en oprydning er det altid en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse, læs her hvordan:
http://www.spywareinfo.dk/index.htm#/tip-og-tricks/deaktiver_systemgendannelse.htm





For at sikre din pc fremover ville det være en god idé at bruge nogle af programmerne fra vores lille pakke som du kan se her:
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at du læser denne artikel om hvordan du kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
Avatar billede mf Nybegynder
29. juni 2006 - 21:37 #6
Ang. dine sidste linier, så er det jo stadig naboens pc....nå pyt
Efter scanning med div prog er der renset ud i flere end 300 items og det lader til at den kører fint nu.
Så hvis du lige smider et svar så takker jeg mange gange for hjælpen
Avatar billede magictouch Nybegynder
30. juni 2006 - 04:12 #7
De sidste linjer følger med i den afsluttende standard procedure *S*  Jeg smider lige et svar, og takker
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester