Avatar billede trekkies Juniormester
04. oktober 2006 - 15:06 Der er 29 kommentarer og
1 løsning

Hjælp til HijackThis log

Hej alle sammen

Min kollega har fået MSN virussen, vil I være så venlig at se denne log igennem for mig?

Her kommer loggen:
Logfile of HijackThis v1.99.1
Scan saved at 15:02:34, on 04-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\DSentry.exe
C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\kybrdff_e16.exe
C:\dfndrff_e16.exe
C:\nwnmff_e6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Documents and Settings\børn\Skrivebord\HijackThis.exe
C:\Programmer\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Programmer\SurfSideKick 3\SskBho.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Free Cruise Toolbar - {C5B7140A-CBA6-4C5B-B10D-DF94B5F17AB5} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Programmer\ToolBar888\MyToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
O4 - HKLM\..\Run: [FLMOFFICEKEYBOARD] C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Programmer\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [explorer.exe] C:/Program Files/inetget.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [BearShare] "C:\Programmer\BearShare\BearShare.EXE" /pause
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e16.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_e16.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e6.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Programmer\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Programmer\SurfSideKick 3\Ssk.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O9 - Extra button: (no name) - {3E90E701-A4A6-4a9e-B935-C39519274323} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O9 - Extra 'Tools' menuitem: Free Cruise Toolbar 1.0.0.22 - {3E90E701-A4A6-4a9e-B935-C39519274323} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/247ec5dc14962814a619/netzip/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.kinaweb.dk/plugin/mgaxctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4EA2E1BE-5B64-4D27-81D6-74D700BF70FD}: NameServer = 193.162.153.164 194.239.134.83
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\q8680ijue8o80.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TGVuZQ\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Programmer\Network Monitor\netmon.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
04. oktober 2006 - 15:17 #1
PUHA - virker denne maskine i det hele taget til noget fornuftigt ?

I første omgang følg guiden herfra ->
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=29791
eller
http://www.eksperten.dk/artikler/1021

Det 'snavs'/virus der er ifølge loggen er ikke kun pga "MSN virussen"
- derfor OGSÅ Afinstaller
[BearShare]
Avatar billede trekkies Juniormester
04. oktober 2006 - 15:23 #2
Det prøver jeg.
Avatar billede trekkies Juniormester
04. oktober 2006 - 16:16 #3
Bearshare er slettet, men det hjalp ikke.

Artiklen har jeg, men nogle af programmerne kommer med en fejl, mens andre vil have administrator rettigheder.

Hvad ellers kan jeg gøre?
04. oktober 2006 - 18:23 #4
"...andre vil have administrator rettigheder..." - hvordan viser det sig ?

Du bør =skal) have administrative rettigheder på PC'en ...

Gennemfør det du ka' - og vedlæg omtalte Logs...
Avatar billede trekkies Juniormester
04. oktober 2006 - 19:56 #5
Jeg kigger på det næste gang at jeg er oppe ved min kollega, tak ind til videre...
Avatar billede trekkies Juniormester
06. oktober 2006 - 17:35 #6
Her er loggerne, vil I se dem igennem:

HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 18:28:14, on 06-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SYSTEM~1\soap.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Office keyboard utility\1.1\MMKEYB.EXE
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Programmer\Office keyboard utility\1.1\TrayMon.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\Office keyboard utility\1.1\osd.exe
C:\Programmer\Microsoft Office\Office\OSA.EXE
C:\Documents and Settings\Lene\Skrivebord\hijackthis.exe
C:\WINDOWS\System32\imapi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Free Cruise Toolbar - {C5B7140A-CBA6-4C5B-B10D-DF94B5F17AB5} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
O4 - HKLM\..\Run: [FLMOFFICEKEYBOARD] C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Programmer\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [explorer.exe] C:/Program Files/inetget.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ERS.exe" /scan
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - Startup: Microsoft Hurtig søgning.lnk = C:\Programmer\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office-start.lnk = C:\Programmer\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O9 - Extra button: (no name) - {3E90E701-A4A6-4a9e-B935-C39519274323} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O9 - Extra 'Tools' menuitem: Free Cruise Toolbar 1.0.0.22 - {3E90E701-A4A6-4a9e-B935-C39519274323} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\programmer\newdotnet\newdotnet7_22.dll' missing
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/247ec5dc14962814a619/netzip/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.kinaweb.dk/plugin/mgaxctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe



Ewido:
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            18:08:02, 06-10-2006
+ Rapport-Checksum:        62665809

+ Scanningsresultat:
    [1168] C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Renset med backup
    [1388] C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Fejl under renselse
    [1424] C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Fejl under renselse
    [1612] C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Fejl under renselse
    [1892] C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Fejl under renselse
    [736] C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Fejl under renselse
    [2240] C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Fejl under renselse
    C:\Documents and Settings\børn\Lokale indstillinger\Temporary Internet Files\Content.IE5\8TIJ8H6Z\AppWrap[1].exe -> Adware.AdURL : Renset med backup
    C:\Documents and Settings\børn\Lokale indstillinger\Temporary Internet Files\Content.IE5\8TIJ8H6Z\AppWrap[2].exe -> Adware.Zestyfind : Renset med backup
    C:\Documents and Settings\børn\Lokale indstillinger\Temporary Internet Files\Content.IE5\GLU3OPQN\AppWrap[1].exe -> Adware.AdURL : Renset med backup
    C:\Documents and Settings\Lene\Cookies\lene@web-stat[2].txt -> TrackingCookie.Web-stat : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temp\MyGlobalSearch.exe -> Adware.FunWeb : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temp\NI.UWA6PK_0001_N73M1204\setup.exe -> Trojan.Fakealert : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\2XV414FY\drsmartload45a[1].exe -> Downloader.Adload.ds : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\2XV414FY\MTE3NDI6ODoxNg[1].exe -> Downloader.Small.buy : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\37XFNPWW\nwnmff_e[1].exe -> Downloader.Adload.fs : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\37XFNPWW\nwnmff_e[2].exe -> Downloader.Adload.fz : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\37XFNPWW\sprY[1].exe -> Worm.VB.aj : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\K1QJ8L6F\kybrdff_e[1].exe -> Trojan.VB.asu : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\K1QJ8L6F\SS1001[1].exe -> Dropper.Small.qn : Renset med backup
    C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\TC8ZX1S5\dfndrff_e[1].exe -> Downloader.Adload.fz : Renset med backup
    C:\Documents and Settings\Lene\Skrivebord\sprY.exe -> Worm.VB.aj : Renset med backup
    C:\Documents and Settings\Test\Lokale indstillinger\Temporary Internet Files\Content.IE5\01YR852N\ucmoreiex[1].exe/empty_00000001 -> Adware.Ucmore : Renset med backup
    C:\Documents and Settings\Test\Lokale indstillinger\Temporary Internet Files\Content.IE5\01YR852N\ucmoreiex[1].exe/UCMTSAIE.DLL -> Adware.Ucmore : Renset med backup
    C:\Documents and Settings\Test\Lokale indstillinger\Temporary Internet Files\Content.IE5\01YR852N\ucmoreiex[1].exe/IUCMORE.DLL -> Adware.Ucmore : Renset med backup
    C:\Documents and Settings\Test\Lokale indstillinger\Temporary Internet Files\Content.IE5\2VGPYRS3\Installer[1].exe -> Adware.Look2Me : Renset med backup
    C:\Documents and Settings\Test\Lokale indstillinger\Temporary Internet Files\Content.IE5\2VGPYRS3\Installer[2].exe -> Adware.Look2Me : Renset med backup
    C:\Programmer\Fælles filer\{68CC9833-0952-1030-1022-02081602002d}\Update.exe -> Adware.Agent : Renset med backup
    C:\Programmer\NewDotNet -> Adware.NewDotNet : Renset med backup
    C:\Programmer\NewDotNet\newdotnet7_22.dll -> Adware.NewDotNet : Renset med backup
    C:\Programmer\SurfSideKick 3 -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP833\A0071764.exe/clientax.dll -> Adware.180Solutions : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP833\A0071764.exe/clientax.dll -> Adware.180Solutions : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP853\A0078542.dll -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP853\A0078543.dll -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP853\A0078544.exe -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP861\A0083963.exe -> Downloader.Adload.fg : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0083980.exe -> Worm.Licat.c : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0083986.dll -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085023.exe -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085024.exe -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085025.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085026.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085027.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085028.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085030.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085031.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085033.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP862\A0085034.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP864\A0086132.exe -> Worm.Licat.c : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP864\A0086163.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP864\A0086184.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP864\A0086189.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086223.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086308.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086339.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086344.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086398.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086447.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086518.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086535.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086549.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0086555.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087558.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087577.exe/Plugins\npclntax.dll -> Adware.Zango : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087577.exe/Plugins\npclntax.dll -> Adware.Zango : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087577.exe -> Adware.180Solutions : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087578.dll -> Adware.Zango : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087580.exe -> Downloader.Adload.ds : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087581.exe -> Downloader.Adload.ds : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087582.exe -> Worm.Licat.c : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087585.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087597.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087612.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087621.exe/clientax.dll -> Adware.180Solutions : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087621.exe/clientax.dll -> Adware.180Solutions : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087628.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087633.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087635.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087639.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087643.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087644.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087645.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087646.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087647.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087648.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087649.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087650.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087651.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087652.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087653.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087654.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087655.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087656.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087657.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087658.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087659.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087660.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087661.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087662.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087663.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087665.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087666.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087667.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087668.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087669.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087670.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087671.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087672.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087673.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087674.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087675.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087676.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0087679.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0088688.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP865\A0088701.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0088718.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0088722.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0088736.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0088745.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0089749.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0089751.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0089772.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0089789.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP866\A0089800.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089842.dll -> Adware.Softomate : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089856.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089857.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089861.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089870.exe -> Trojan.VB.asv : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089878.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089884.exe -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089885.exe -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089886.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089887.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089888.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089889.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089890.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089891.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089892.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089893.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089894.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089895.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089896.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089897.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089898.DLL -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089899.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089900.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089901.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089902.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089903.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089904.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089905.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089906.exe -> Adware.NewDotNet : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089907.exe -> Adware.NewDotNet : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089911.exe -> Dropper.Small.qn : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089913.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089916.exe -> Trojan.VB.asu : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089917.exe -> Trojan.VB.asu : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089919.exe -> Downloader.Adload.fz : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089921.exe -> Downloader.Adload.fz : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089922.exe -> Downloader.Adload.fs : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089923.dll -> Adware.Softomate : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089926.dll -> Adware.Ucmore : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089927.dll -> Adware.Ucmore : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089934.exe/empty_00000001 -> Adware.Ucmore : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089934.exe/UCMTSAIE.DLL -> Adware.Ucmore : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089934.exe/IUCMORE.DLL -> Adware.Ucmore : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089935.exe -> Downloader.Small.buy : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089936.exe -> Downloader.Small.buy : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089937.exe -> Downloader.Adload.ds : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089938.exe -> Downloader.Adload.ds : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089939.exe -> Downloader.Adload.ds : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089940.exe -> Downloader.Adload.ds : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089946.dll -> Adware.Softomate : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0089953.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091954.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091955.dll -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091956.exe -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091957.dll -> Adware.SurfSide : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091958.exe -> Adware.CommAd : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091959.dll -> Adware.CommAd : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091960.dll -> Adware.Look2Me : Renset med backup
    C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0091961.dll -> Adware.NewDotNet : Renset med backup
    C:\WINDOWS\SYSTEM32\guard.tmp -> Adware.Look2Me : Renset med backup
    C:\WINDOWS\SYSTEM32\sprY.exe -> Worm.VB.aj : Renset med backup


::Rapport slut

Er det noget som skal fjernes?
Avatar billede trekkies Juniormester
08. oktober 2006 - 07:28 #7
Er der ikke nogle som har tid?
Avatar billede trekkies Juniormester
08. oktober 2006 - 21:35 #8
Jeg skal møde på arbejde i morgen, så hvis I kunne se loggerne igennem til i morgen senest 7:00, så kan jeg sige til min kollega om det er sikkert at komme på nettet eller ej.

På forhånd tak for hjælpen.
09. oktober 2006 - 06:58 #9
Er dette en firma PC - med manglende rettigheder ?

Den er langtfra renset !!!
----------------------------------------
Du bør rense temp med denne fil, det tager kun få sek. Hent den lille batfil, dobbeltklik på filen, og der går et split sek. Så er temp renset.
www.spywareinfo.dk/download/cleantempxp2k.bat
----------------------------------------
Afinstaller
* Error Safe Free
* SpySpotter3
* System Soap Pro
via
[Start][Indstillinger][Kontrolpanel][Tilføj/fjern programmer]
----------------------------------------
Jeg ka' se at du allerede HAR SUPERAntiSpyware instalaret; check at den er opdateret; scan en omgang med den.
Guide herfra: http://www.spywareinfo.dk/#/manualer/superantispyware.htm
Genstart.
----------------------------------------
Så skulle jeg egentlig have en ny HiJackThis log efter ovenstående procedure Men du får den her:

-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe

-- Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere nedenstående indhold ind:


Files to delete:
C:/Program Files/inetget.exe
Folders to delete:
C:\Programmer\Free Cruise Toolbar\
C:\Programmer\SpySpotter3
C:\Programmer\Error Safe Free
c:\programmer\newdotnet


-- Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.
----------------------------------------
Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: Free Cruise Toolbar - {C5B7140A-CBA6-4C5B-B10D-DF94B5F17AB5} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Programmer\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [explorer.exe] C:/Program Files/inetget.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ERS.exe" /scan
O9 - Extra 'Tools' menuitem: Free Cruise Toolbar 1.0.0.22 - {3E90E701-A4A6-4a9e-B935-C39519274323} - C:\Programmer\Free Cruise Toolbar\usetb.dll
O10 - Broken Internet access because of LSP provider 'c:\programmer\newdotnet\newdotnet7_22.dll' missing

Genstart, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

NB: Inden næste kørsel med HiJackThis.exe skal du OMDØBE programfilen HiJackThis.exe til ALTERNATIV.exe , da visse uønskede elmenter har en tendens til at skjule sig når der kører en process ved navn HiJackThis.exe !!!

------------------------------------------------------------------------
09. oktober 2006 - 07:00 #10
Desuden anbefales:

Denne scanner:
Download og gem denne på skrivebordet. Du skal ikke aktivere den endnu.
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Kig denne vejledning grundigt igennem.
http://fromsej.dk/Vejledninger/html/drweb.html

Genstart i fejlsikret tilstand - F8 i opstart.

Dobbeltklik på drweb-cureit.exe, den vil køre en expressscan, det siger du ja til.
Når den skriver Done nederst til venstre, skal du klikke på Options->Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Rename.
Klik så på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de er valgt.

Klik så på den grønne pil ovre til højre på siden, så starter scanningen.
Første gang Dr.Web finder noget, klik "Yes to All", så fjerner den hvad den finder.
Klik så på Start->Søg, find filen drweb32w.log kopier det nederste af teksten herind, startende med:
Scan statistics.
---
Genstart normalt og kopier også en frisk HijackThis-log herind i tråden.
09. oktober 2006 - 07:04 #11
Jeps - der skal alt dette til fordi du har/havde alverdens 'snavs'/virus som invitere hinanden indenfor !!!
Allesammen er desværre 'velkendte' i den verden...

Der er muligvis noget/lidt tilbage bagefter - det vil vise sig ved nævnte Logs - som du selvfølgelig lægger ind i denne tråd ...  >;)
Avatar billede trekkies Juniormester
09. oktober 2006 - 07:18 #12
drweb-cureit virker ikke, den kommer med en fejl meddelse hver gang den startes.
09. oktober 2006 - 07:50 #13
... så gennemfør den procedure EFTER alt det andet...
09. oktober 2006 - 07:50 #14
NB: Er dette en firma PC - med manglende rettigheder ?
Avatar billede trekkies Juniormester
09. oktober 2006 - 13:18 #15
Det er en almindelig privat pc, men den er delt i 2, 1 til moderen og 1 til børnene.
Moderen er administrator og børnene har "gæstekonto".
Avatar billede trekkies Juniormester
09. oktober 2006 - 13:46 #16
Her de 2 logs:

Avenger:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\nhlxfrlo

*******************

Script file located at: \??\C:\WINDOWS\system32\bfkehhyn.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\Program Files\inetget.exe not found!
Deletion of file C:\Program Files\inetget.exe failed!

Could not process line:
C:\Program Files\inetget.exe
Status: 0xc0000034

Folder C:\Programmer\Free Cruise Toolbar deleted successfully.


Folder C:\Programmer\Spyspotter3 not found!
Deletion of folder C:\Programmer\Spyspotter3 failed!

Could not process line:
C:\Programmer\Spyspotter3
Status: 0xc0000034



Folder C:\Programmer\Error Safe Free not found!
Deletion of folder C:\Programmer\Error Safe Free failed!

Could not process line:
C:\Programmer\Error Safe Free
Status: 0xc0000034



Folder C:\Programmer\newdotnet not found!
Deletion of folder C:\Programmer\newdotnet failed!

Could not process line:
C:\Programmer\newdotnet
Status: 0xc0000034


Completed script processing.

*******************

Finished!  Terminate.



HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 14:30:14, on 09-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Office keyboard utility\1.1\MMKEYB.EXE
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Office keyboard utility\1.1\TrayMon.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\Office keyboard utility\1.1\osd.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Documents and Settings\Test\Skrivebord\ALTERNATIVE.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
O4 - HKLM\..\Run: [FLMOFFICEKEYBOARD] C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\programmer\newdotnet\newdotnet7_22.dll' missing
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/247ec5dc14962814a619/netzip/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.kinaweb.dk/plugin/mgaxctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe

Hvad siger du nu?
Avatar billede trekkies Juniormester
09. oktober 2006 - 14:19 #17
Loggen fra Dr. Web kommer senere...
Avatar billede trekkies Juniormester
09. oktober 2006 - 16:30 #18
Den første log glemte jeg at gemme, så skulle den køres en gang til, men her kommer den:

Installer[1].#xe;C:\Documents and Settings\børn\Lokale indstillinger\Temp\Temporary Internet Files\Content.IE5\NH0FOCX2;Adware.Look2me;Renamed.;
drsmartload849a[2].#xe;C:\Documents and Settings\Lene\Lokale indstillinger\Temporary Internet Files\Content.IE5\37XFNPWW;Adware.DollarRevenue;Renamed.;
TOTALLY HIP TRACK.#ma;C:\Documents and Settings\Lene\Skrivebord\min mappe (Mathias)\musik;Adware.nCase;Renamed.;
S4BAR.#LL;C:\Programmer\MySearch\bar\1.bin;Adware.MySearch;Renamed.;
sdcmon.dll;C:\Programmer\Support.com\bin;Probably DLOADER.Trojan;;
tgupdate.exe;C:\Programmer\Support.com\bin;Probably DLOADER.Trojan;;
soap.exe;C:\Programmer\System Soap Pro;Probably BACKDOOR.Trojan;;
A0089912.#xe;C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868;Adware.Surfside;Renamed.;
A0092978.#xe;C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868;Adware.Ucmore;Renamed.;
A0092979.#xe;C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868;Adware.Look2me;Renamed.;
A0092980.#xe;C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868;Adware.Look2me;Renamed.;
A0092986.#ll;C:\System Volume Information\_restore{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868;Adware.NewDotNet;Renamed.;
10. oktober 2006 - 06:57 #19
Lige lidt tilbage:

Afinstall
* newdotnet
i Kontrolpanel - Tilføj/Fjern programmer (hvis den er der?)

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er denne, som skal fixes:
O10 - Broken Internet access because of LSP provider 'c:\programmer\newdotnet\newdotnet7_22.dll' missing

Genstart, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.
Avatar billede trekkies Juniormester
10. oktober 2006 - 19:11 #20
Den nye log kommer i morgen eftermiddag...
Avatar billede trekkies Juniormester
13. oktober 2006 - 15:32 #21
Undskyld ventetiden.

Her er den nyeste log:
Logfile of HijackThis v1.99.1
Scan saved at 15:08:32, on 13-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Office keyboard utility\1.1\MMKEYB.EXE
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Office keyboard utility\1.1\TrayMon.exe
C:\Programmer\Office keyboard utility\1.1\osd.exe
C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\Microsoft Office\Office\OSA.EXE
C:\Documents and Settings\Lene\Skrivebord\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
O4 - HKLM\..\Run: [FLMOFFICEKEYBOARD] C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ERS.exe" /scan
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Microsoft Hurtig søgning.lnk = C:\Programmer\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office-start.lnk = C:\Programmer\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/247ec5dc14962814a619/netzip/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.kinaweb.dk/plugin/mgaxctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
Avatar billede trekkies Juniormester
19. oktober 2006 - 17:23 #22
Er denne log bedre dr1?
21. oktober 2006 - 00:05 #23
NEJ ...


Underligt at nogle/flere elementer stadig er der / kommet tilbage...
Hvad har du haft gang i i mellemtiden ?



Afinstaller
* ErrorSafe (http://www.grineflip.dk/support/errorsafe - er det sådan noget du oplever?)
* System Soap Pro (Hvis den er der)
via
[Start][Indstillinger][Konrolpanel][Tilføj/Fjern programmer]
------------------------------------------------------------

-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe

-- Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere nedenstående linier ind:


Files to delete:
C:\PROGRA~1\SYSTEM~1\soap.exe
Folders to delete:
C:\Programmer\Error Safe Free\


-- Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

------------------------------------------------------------

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ERS.exe" /scan

Genstart normalt.

------------------------------------------------------------

Du HAR allerede "SUPERAntiSpyware" instaleret - check at den er opdateret.

Genstart i Fejlsikret tilstand -> http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm

Start superantispyware ved at højreklikke på den gule og sorte bille ved uret

Tryk på - Scan for, Adware,Malware - linjen
Tryk på - Preference - Knappen.
Fjern flueben ved - Start SuperAntiSpyware when Windows starts.

Tryk på Fanebladet - Scanning control.

Ved scanning options, skal der kun være flueben i de to nederste

Fanebladet - Real Time Protections. Fjerner du fluben ved - Enable Real Time Protection

Tryk så på Close

Tryk på - Scan Your computer - Knappen. sæt flueben ved de drev der skal scannes. Det er vigtigt at drev hvor Windows (systemdrevet) ligger, har et flueben.

Flyt så prikken ved- Perform quick Scan, ned til - Perform complete Scan.

Tryk på Næste, så går den i gang med at scanne.

Det kan godt tage lang tid hvis du har meget på computeren

Når scanninngen er færdig popper der en boks op, tryk OK.

Sæt flueben ved alt den har fundet - næste. Så vil den fixe/slette infektionerne.

Lad den genstarte.

------------------------------------------------------------

Efter genstart -

Klik på "Start" - Vælg "Søg".
Klik på linket "Skift indstillinger".
Klik på "Skift søgefunktioner for filer og mapper"
Sæt prik i "Avanceret" og klik OK.
Klik på "Alle filer og mapper"
Klik på "Flere avancerede indstillinger"
Sæt flueben i de tre øverste.
Find:
superantispyware scan log


Kør en ny scanning med HiJackThis, og kopier en frisk log herind til tjek sammen med loggen fra Avengers samt Superantispyware.

NB: Inden næste kørsel med HiJackThis.exe skal du OMDØBE programfilen HiJackThis.exe til ALTERNATIV.exe , da visse uønskede elmenter har en tendens til at skjule sig når der kører en process ved navn HiJackThis.exe !!!
24. oktober 2006 - 17:11 #24
Feedback ?
29. oktober 2006 - 23:43 #25
Feedback ? [2]
Avatar billede trekkies Juniormester
05. november 2006 - 12:19 #26
Undskyld ventetiden, jeg har ikke været hos min kollega i nu, men det bliver i næste uge.
Avatar billede trekkies Juniormester
17. november 2006 - 22:08 #27
Nu kommer loggerne endeligt:

HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 17:26:54, on 17-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Lene\Skrivebord\Alternative.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.naturesown.se/country/?NoSSID=53f1800d91b9cfc18531744f25bd28ac
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/dk/dan/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
O4 - HKLM\..\Run: [FLMOFFICEKEYBOARD] C:\Programmer\Office keyboard utility\1.1\OFFICEKB.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - Startup: Microsoft Hurtig søgning.lnk = C:\Programmer\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office-start.lnk = C:\Programmer\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Programmer\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/247ec5dc14962814a619/netzip/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.kinaweb.dk/plugin/mgaxctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmer\Office keyboard utility\1.1\nhksrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe



Averger:
//////////////////////////////////////////
  Avenger Pre-Processor log
//////////////////////////////////////////

Error:  could not create zip file.
Error code: 0


//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\ioswiuwi

*******************

Script file located at: ndwnqolx

Could not open script file!  Error

Could not open script file!  Status: 0xc000003b  Abort!



Superantispyware:
SUPERAntiSpyware Scan Log
Generated 11/17/2006 at 05:15 PM

Application Version : 3.3.1020

Core Rules Database Version : 3106
Trace Rules Database Version: 1132

Scan type      : Complete Scan
Total Scan Time : 01:26:38

Memory items scanned      : 406
Memory threats detected  : 0
Registry items scanned    : 5099
Registry threats detected : 0
File items scanned        : 102614
File threats detected    : 4

Adware.SurfSideKick
    C:\DOCUMENTS AND SETTINGS\LENE\LOKALE INDSTILLINGER\TEMP\U19C.BAT

Trojan.WinAntiSpyware/WinAntiVirus 2006
    C:\DOCUMENTS AND SETTINGS\LENE\LOKALE INDSTILLINGER\TEMP\~WA6PSETUP.EXE

Adware.ToolBar888
    C:\PROGRAMMER\SUPERANTISPYWARE\LOGS\SUPERANTISPYWARE SCAN LOG - 10-06-2006 - 16-05-45.LOG

Trojan.NewDotNet
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{3E467700-12DF-408C-BEEC-9B40E8A4FCCE}\RP868\A0092980.#LL


Igen undskyld ventetiden.
Avatar billede trekkies Juniormester
23. februar 2008 - 18:09 #28
Undskyld ventetiden.

Hvis I vil have point, så skal I lægge et svar.
24. februar 2008 - 17:47 #29
Ping...
Avatar billede trekkies Juniormester
26. februar 2008 - 21:38 #30
Tak for hjælpen.
Bedre sent end aldrig :)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester