Avatar billede kim-h Novice
25. oktober 2006 - 22:58 Der er 14 kommentarer og
1 løsning

Hijackthis.log

Min PC er begyndt at opføre sig mærkeligt.
Når den skal hente mails, får jeg meget tit besked om fejl ved modtalse af mails.
Når jeg surfer på nettet, skal jeg tit opdatere siden før den bliver hentet færdig. Hvis jeg downloader en fil fra nettet, så stopper den tit midt i downloadningen og jeg må prøve igen.
Har prøvet div spyprogrammer. Kan pludselig ikke mere køre Spybot - Search & Destroy ???
Her er min logfil.

Logfile of HijackThis v1.99.1
Scan saved at 22:37:20, on 25-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\NetLimiter\NetLimiter.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\Picasa2\PicasaMediaDetector.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
C:\Programmer\Google\Gmail Notifier\gnotify.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Documents and Settings\Kim\Skrivebord\Spy\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ka-net.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NetLimiter] C:\Programmer\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\system32\Sys\Explorer.exe
O4 - HKLM\..\Run: [kav] "C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AWMON] "C:\Programmer\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [WeatherBug] C:\Program Files\AWS\WeatherBug\WeatherBug.exe
O4 - Startup: Gmail Notifier.lnk = C:\Programmer\Google\Gmail Notifier\gnotify.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sputnik.dk
O15 - Trusted Zone: *.tv2.dk
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://130.228.229.80/homeskyline/TEInstall/TE.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120165337000
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) - http://foto.tdconline.dk/upload-classes/Uploader.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://light.gabs.dk/imageuploader/ImageUploader3.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://fotomail.billedbutikken.dk/upload/xupload/XUpload2101.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{CE624C37-E23A-4A1D-A87B-866CE2EA5CB9}: NameServer = 192.168.1.3,192.168.1.9
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\Player\__CDS2.dll (file missing)
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Unknown owner - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
26. oktober 2006 - 08:36 #1
Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\system32\Sys\Explorer.exe
O4 - HKCU\..\Run: [WeatherBug] C:\Program Files\AWS\WeatherBug\WeatherBug.exe
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\Player\__CDS2.dll (file missing)  (Hvis du selv 100% ved hvad dette er så lad den være...)

For at kunne se alle filer og mapper, så følg denne vejledning:
[url="http://www.spywareinfo.dk/tip-og-tricks/mappeindstillinger.htm"][b][black]Se alle filer og mapper[/black][/url]

Genstart i [url="http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm"][b][black]fejlsikret tilstand[/black][/url]

Søg og slet de markerede filer/mapper hvis de stadig findes. Ellers fortsætter du bare vejledningen. De kan være røget i fixet.

C:\WINDOWS\system32\Sys\  <- Hele mappen
C:\Program Files\AWS\WeatherBug\  <- Hele mappen
D:\Player\__CDS2.dll  (Hvis du selv 100% ved hvad dette er så lad den være...)



Genstart normalt, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

Og fortæl om PC'en kører bedre nu...


------------------------------------------------------------------------
Avatar billede kim-h Novice
26. oktober 2006 - 17:08 #2
Kan ikke se de 2 mapper.
C:\WINDOWS\system32\Sys\  <- Hele mappen
C:\Program Files\AWS\WeatherBug\  <- Hele mappen
Har sat den til at kunne se alle filer  og mapper. Men der er der stadig i en ny log.
Der er stadig lidt problemer med at hente mails. Jeg får stadig en gang imellem fejlmeddelse om at mails ikke kan hentes. Forbindelsen blev afbrudt.
Her er en ny log.

Logfile of HijackThis v1.99.1
Scan saved at 16:58:09, on 26-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\NetLimiter\NetLimiter.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
C:\Programmer\Google\Gmail Notifier\gnotify.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Programmer\Maxthon\Maxthon.exe
C:\Documents and Settings\Kim\Skrivebord\Spy\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ka-net.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NetLimiter] C:\Programmer\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [kav] "C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\system32\Sys\Explorer.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AWMON] "C:\Programmer\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [WeatherBug] C:\Program Files\AWS\WeatherBug\WeatherBug.exe
O4 - Startup: Gmail Notifier.lnk = C:\Programmer\Google\Gmail Notifier\gnotify.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sputnik.dk
O15 - Trusted Zone: *.tv2.dk
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://130.228.229.80/homeskyline/TEInstall/TE.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120165337000
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) - http://foto.tdconline.dk/upload-classes/Uploader.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://light.gabs.dk/imageuploader/ImageUploader3.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://fotomail.billedbutikken.dk/upload/xupload/XUpload2101.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{CE624C37-E23A-4A1D-A87B-866CE2EA5CB9}: NameServer = 192.168.1.3,192.168.1.9
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Unknown owner - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
28. oktober 2006 - 19:47 #3
-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe

-- Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere nendestående indhold ind


Folders to delete:
C:\WINDOWS\system32\Sys\
C:\Program Files\AWS\



-- Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\system32\Sys\Explorer.exe
O4 - HKCU\..\Run: [WeatherBug] C:\Program Files\AWS\WeatherBug\WeatherBug.exe

Genstart computeren, og lav en ny log med Hijackthis, som du lægger herind sammen med loggen fra Avenger.
Avatar billede kim-h Novice
29. oktober 2006 - 10:47 #4
Så lykkedes det endeligt.
Jeg måtte køre Avenger et par gange før det virkede.
1. gang kom der ingen logfil.
2. gang kom der en tom fejl log.
3. gang lykkedes det hvis, her er logfilen:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\axrygwnn

*******************

Script file located at: \??\C:\WINDOWS\bwfovhmr.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Folder C:\WINDOWS\system32\Sys not found!
Deletion of folder C:\WINDOWS\system32\Sys failed!

Could not process line:
C:\WINDOWS\system32\Sys
Status: 0xc0000034



Folder C:\Program Files\AWS not found!
Deletion of folder C:\Program Files\AWS failed!

Could not process line:
C:\Program Files\AWS
Status: 0xc0000034


Completed script processing.

*******************

Finished!  Terminate.


Og her er så en ny logfil fra hijackhis, hvor det endeligt ser ud til at de to linier er fjernet :-)

Logfile of HijackThis v1.99.1
Scan saved at 10:38:19, on 29-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\NetLimiter\NetLimiter.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
C:\Programmer\Google\Gmail Notifier\gnotify.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Kim\Skrivebord\Spy\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ka-net.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NetLimiter] C:\Programmer\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [kav] "C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Gmail Notifier.lnk = C:\Programmer\Google\Gmail Notifier\gnotify.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sputnik.dk
O15 - Trusted Zone: *.tv2.dk
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://130.228.229.80/homeskyline/TEInstall/TE.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120165337000
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) - http://foto.tdconline.dk/upload-classes/Uploader.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://light.gabs.dk/imageuploader/ImageUploader3.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://fotomail.billedbutikken.dk/upload/xupload/XUpload2101.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{CE624C37-E23A-4A1D-A87B-866CE2EA5CB9}: NameServer = 192.168.1.3,192.168.1.9
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Unknown owner - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
29. oktober 2006 - 23:12 #5
Inden jeg evt. tager mere 'værktøj' igang - hvor kører computteren nu ?
Avatar billede kim-h Novice
30. oktober 2006 - 10:53 #6
Der er stadig problemer med at sende mail. Det er ikke hver gang mailen bliver sendt, selvom mailprogrammet siger at mailen er sendt.
Det ser umidelbart ud til at problemet med modtagelse af mail er løst.
Ligeledes skal jeg stadig opdatere mange hjemmesider før end alt er indlæst.

Skal programmer ewido køre selvom jeg ikke har startet det op ? Kan se i loggen at det køre.

Så kan du gøre noget ved ovenstående problemer, så vil det være dejligt :-)
30. oktober 2006 - 11:48 #7
Så tager vi lidt "vildskud" værktøj i brug:

---------------------------------------------------------------------

Hent denne engangsscanner:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe (Gem programmet på skrivebordet, så du let kan finde det til senere brug)

Hvis din firewall blokerer for ftp adresser, kan du hente programmet her:
http://spywareinfo.dk/download/drweb-cureit.exe
(Du skal ikke aktivere den endnu)
---------------------------------------------------------------------

http://www.spywarefri.dk/downloads1/ewido-setup.exe
http://www.spywarefri.dk/manualer/ewido-manual.htm

Opdater straks efter installationen programmet. Lad være med at slette noget med Ewido fra normal tilstand. Vent til du kommer i fejlsikret tilstand. Du kan evt. højreklikke på ikonet E nede ved uret, og klikke på shutdown guard,  så er du sikker på, at programmet venter med at fjerne snavs, til du er i fejlsikret tilstand.
(Du skal ikke aktivere den endnu)
---------------------------------------------------------------------

Download free Trial af SuperAntiSpyware Proff til Skrivebordet, http://www.superantispyware.com/downloads/SUPERAntiSpyware1241.exe
Installer den, og lad den opdatere med nyeste opdateringer.
Så vil den spørge om din mail adresse, det er op til dig selv om du vil udfylde det.Tryk så på Næste og Næste igen -Udfør.
Dansk vejledning http://www.spywarefri.dk/manualer/superantispyware-manual.htm
(Du skal ikke aktivere den endnu)
---------------------------------------------------------------------

Genstart i fejlsikret tilstand http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm
---------------------------------------------------------------------

Kør en fuld scanning med Ewido, og tillad programmet at fixe de ting, som det finder. Programmet laver en lille log, som du skal kopiere herind.
Programmet opretter en lille log, som du skal kopiere herind i dit næste svar. Du kan se hvordan du skal oprette og gemme rapporten her: http://www.spywarefri.dk/manualer/ewido-manual.htm Hvis du er i tvivl. Se punkt: 19 og 20
---------------------------------------------------------------------

DrWeb - Dobbeltklik på cureit exe filen laver den en kort startup/express scan.
Lad den fixe hvad den finder (Say Yes to all)
Derefter skal du klikke på Options -> Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Move.
Fjern flueben ved - Prompt on action.
Ved Move Path sletter du hvad der står, og skriver: c:\infected
Tryk på Anvend og derefter på OK.

Klik så på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de er valgt.
Tryk så på den grønne pil nederst  til højre, så scanner den, og fixer problemerne.

Når scanningen er færdig, gå op i file - Tryk på - Save Report list.
Så ligger der en en fil der her hedder drweb.csv (åbnes med Notebook/Notepad) - på skrivebordet.
Luk Programmet
---------------------------------------------------------------------

Start superantispyware ved at højreklikke på den gule og sorte bille ved uret

Tryk på - Scan for, Adware,Malware - linjen
Tryk på - Preference - Knappen.
Fjern flueben ved - Start SuperAntiSpyware when Windows starts.

Tryk på Fanebladet - Scanning control.
Ved scanning options, skal der kun være flueben i de to nederste
Fanebladet - Real Time Protections. Fjerner du fluben ved - Enable Real Time Protection
Tryk så på Close

Tryk på - Scan Your computer - Knappen. sæt flueben ved de drev der skal scannes. Det er vigtigt at drev hvor Windows (systemdrevet) ligger, har et flueben.
Flyt så prikken ved - Perform quick Scan, ned til - Perform complete Scan.
Tryk på Næste, så går den i gang med at scanne.

Det kan godt tage lang tid hvis du har meget på computeren

Når scanninngen er færdig popper der en boks op, tryk OK.
Sæt flueben ved alt den har fundet - næste. Så vil den fixe/slette infektionerne.

Lad den genstarte.
---------------------------------------------------------------------

Efter genstart -

Åben SuperAntiSpyware igen
Tryk på Preferences, vælg Statistics/Logs
Marker loggen i det lille vindue og tryk på View Log.
Kopier teksten herind sammen med loggen fra Ewido og loggen fra DrWeb (drweb csv)

Sammen med en frisk Log fra HiJackThis...
Avatar billede kim-h Novice
31. oktober 2006 - 21:08 #8
Så kom jeg igennem listen.
Her er resultaterne.

SUPERAntiSpyware Scan Log
Generated 10/31/2006 at 12:56 PM

Application Version : 3.3.1020

Core Rules Database Version : 3107
Trace Rules Database Version: 1139

Scan type      : Complete Scan
Total Scan Time : 06:27:41

Memory items scanned      : 182
Memory threats detected  : 0
Registry items scanned    : 7149
Registry threats detected : 14
File items scanned        : 228384
File threats detected    : 1

Trojan.Unknown Origin
    HKLM\SOFTWARE\Microsoft\MSSMGR
    HKLM\SOFTWARE\Microsoft\MSSMGR#Data
    HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
    HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
    HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
    HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
    HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
    HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
    HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
    HKLM\SOFTWARE\Microsoft\MSSMGR#BPTV
    HKLM\SOFTWARE\Microsoft\MSSMGR#PID
    HKLM\SOFTWARE\Microsoft\MSSMGR#Rid
    HKLM\SOFTWARE\Microsoft\MSSMGR#LID
    HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV

Adware.ClickSpring/Yazzle
    C:\PROGRAMMER\FæLLES FILER\YAZZLE1196OINUNINSTALLER.EXE



---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            20:17:41, 30-10-2006
+ Rapport-Checksum:        67CA5C16

+ Scanningsresultat:
    :mozilla.8:C:\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Adbrite : Renset med backup
    :mozilla.9:C:\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Adbrite : Renset med backup
    :mozilla.21:C:\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.110:C:\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.132:C:\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Tradedoubler : Renset med backup
    :mozilla.163:C:\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.164:C:\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@adbrite[1].txt -> TrackingCookie.Adbrite : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@admarketplace[2].txt -> TrackingCookie.Admarketplace : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@h.starware[2].txt -> TrackingCookie.Starware : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@kmpads[2].txt -> TrackingCookie.Kmpads : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@tacoda[2].txt -> TrackingCookie.Tacoda : Renset med backup
    C:\Documents and Settings\Familien\Cookies\familien@try.starware[1].txt -> TrackingCookie.Starware : Renset med backup
    :mozilla.19:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Adbrite : Renset med backup
    :mozilla.20:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Adbrite : Renset med backup
    :mozilla.21:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Adbrite : Renset med backup
    :mozilla.49:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.50:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.51:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.52:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.82:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Com : Renset med backup
    :mozilla.89:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Sexcounter : Renset med backup
    :mozilla.90:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Sexcounter : Renset med backup
    :mozilla.91:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Clickzs : Renset med backup
    :mozilla.92:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Clickzs : Renset med backup
    :mozilla.215:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.216:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.217:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.218:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.219:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.220:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.221:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.222:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.285:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.286:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.287:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.290:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Zedo : Renset med backup
    :mozilla.291:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Zedo : Renset med backup
    :mozilla.298:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Texttbnru : Renset med backup
    :mozilla.299:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.300:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.304:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Clickhype : Renset med backup
    :mozilla.329:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Counted : Renset med backup
    :mozilla.360:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Sitestat : Renset med backup
    :mozilla.361:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Sitestat : Renset med backup
    :mozilla.384:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Liveperson : Renset med backup
    :mozilla.385:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Liveperson : Renset med backup
    :mozilla.386:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Liveperson : Renset med backup
    :mozilla.394:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Reliablestats : Renset med backup
    :mozilla.395:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Reliablestats : Renset med backup
    :mozilla.396:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Reliablestats : Renset med backup
    :mozilla.397:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Reliablestats : Renset med backup
    :mozilla.398:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Reliablestats : Renset med backup
    :mozilla.405:C:\Documents and Settings\Kim\Application Data\Mozilla\Firefox\Profiles\w5g738ca.default\cookies.txt -> TrackingCookie.Cqcounter : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@adbrite[2].txt -> TrackingCookie.Adbrite : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@admarketplace[1].txt -> TrackingCookie.Admarketplace : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@cz11.clickzs[1].txt -> TrackingCookie.Clickzs : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@cz3.clickzs[1].txt -> TrackingCookie.Clickzs : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@cz4.clickzs[2].txt -> TrackingCookie.Clickzs : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@cz7.clickzs[2].txt -> TrackingCookie.Clickzs : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@oewabox[2].txt -> TrackingCookie.Oewabox : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Renset med backup
    C:\Documents and Settings\Kim\Cookies\kim@tacoda[1].txt -> TrackingCookie.Tacoda : Renset med backup
    C:\Documents and Settings\Spil\Cookies\spil@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : Renset med backup
    C:\Documents and Settings\Spil\Cookies\spil@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Spil\Cookies\spil@adbrite[1].txt -> TrackingCookie.Adbrite : Renset med backup
    C:\Documents and Settings\Spil\Cookies\spil@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Renset med backup
    C:\Documents and Settings\Spil\Cookies\spil@b.casalemedia[1].txt -> TrackingCookie.Casalemedia : Renset med backup
    C:\Documents and Settings\Spil\Cookies\spil@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Renset med backup
    C:\Documents and Settings\Spil\Cookies\spil@tacoda[1].txt -> TrackingCookie.Tacoda : Renset med backup
    C:\Programmer\Fælles filer\Real\WeatherBug\MiniBugTransporter.#ll -> Adware.Minibug : Renset med backup
    C:\Programmer\KKeeper\KKeeper.exe -> Not-A-Virus.Monitor.Win32.StonsKeyKeeper : Renset med backup
    C:\Programmer\Mozilla Firefox\plugins\npclntax.#ll -> Adware.Zango : Renset med backup
    C:\WINDOWS\Downloaded Program Files\UERSK_0001_N91M2407NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Renset med backup
    :mozilla.26:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Falkag : Renset med backup
    :mozilla.31:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.32:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.33:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Tradedoubler : Renset med backup
    :mozilla.34:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Adbrite : Renset med backup
    :mozilla.35:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Adbrite : Renset med backup
    :mozilla.49:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Revenue : Renset med backup
    :mozilla.59:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.60:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.61:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.71:F:\Bacup\Documents and Settings\Familien\Application Data\Mozilla\Firefox\Profiles\gwm2my0x.default\cookies.txt -> TrackingCookie.Atdmt : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@adbrite[1].txt -> TrackingCookie.Adbrite : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@admarketplace[2].txt -> TrackingCookie.Admarketplace : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@com[1].txt -> TrackingCookie.Com : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@h.starware[2].txt -> TrackingCookie.Starware : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@kmpads[2].txt -> TrackingCookie.Kmpads : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@tacoda[2].txt -> TrackingCookie.Tacoda : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@try.starware[1].txt -> TrackingCookie.Starware : Renset med backup
    F:\Bacup\Documents and Settings\Familien\Cookies\familien@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@tacoda[1].txt -> TrackingCookie.Tacoda : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@adbrite[2].txt -> TrackingCookie.Adbrite : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@adbrite[1].txt -> TrackingCookie.Adbrite : Renset med backup
    F:\Bacup\Documents and Settings\Spil\Cookies\spil@b.casalemedia[1].txt -> TrackingCookie.Casalemedia : Renset med backup
   

::Rapport slut


DrWeb

backup-20050115-201040-984.#ll;C:\Documents and Settings\All Users\Dokumenter\Hijack\backups;Adware.SpywareStorm;Moved.;
vncviewer.#xe;C:\Documents and Settings\All Users\Dokumenter\Programmer;Program.RemoteAdmin;Moved.;
winvnc.#xe;C:\Documents and Settings\All Users\Dokumenter\Programmer;Program.RemoteAdmin;Moved.;
WinAVI.exe;C:\Programmer\WinAVIVideoConverter;Trojan.Click.1586;Deleted.;
A0820213.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP412;Trojan.Click.1586;Deleted.;
A0850305.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP420;Trojan.Click.1586;Deleted.;
A0861871.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP423;Trojan.Click.1586;Deleted.;
A0863026.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP426;Program.Ardamax;Moved.;
A0865900.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP427;Trojan.Click.1586;Deleted.;
A0889993.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP427;Program.Ardamax;Moved.;
A0890123.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP430;Program.Ardamax;Moved.;
A0890508.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP437;Program.Ardamax;Moved.;
A0890511.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP437;Adware.Ezula;Moved.;
A0890513.exe;C:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP437;Trojan.Click.1586;Deleted.;
A0890510.exe;F:\System Volume Information\_restore{B1829B26-DD2F-4063-B395-DB9B61FBA91D}\RP437;Program.Ardamax;Moved.;
backup-20050115-201040-984.dll;F:\Bacup\Documents and Settings\All Users\Dokumenter\Hijack\backups;Adware.SpywareStorm;Moved.;
vncviewer.exe;F:\Bacup\Documents and Settings\All Users\Dokumenter\Programmer;Program.RemoteAdmin;Moved.;
winvnc.exe;F:\Bacup\Documents and Settings\All Users\Dokumenter\Programmer;Program.RemoteAdmin;Moved.;
vncviewer.exe;F:\Bacup\Documents and Settings\All Users\Delte programmer;Program.RemoteAdmin;Moved.;
winvnc.exe;F:\Bacup\Documents and Settings\All Users\Delte programmer;Program.RemoteAdmin;Moved.;
backup-20050115-201040-984.dll;F:\Bacup\Documents and Settings\All Users\Delte programmer\Hijack\backups;Adware.SpywareStorm;Moved.;
backup-20050509-214258-504.dll;F:\Bacup\Documents and Settings\Kim\Skrivebord\Spy\backups;Trojan.DownLoader.665;Deleted.;


Logfile of HijackThis v1.99.1
Scan saved at 20:58:12, on 31-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\NetLimiter\NetLimiter.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Programmer\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\Google\Gmail Notifier\gnotify.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
C:\Documents and Settings\Kim\Skrivebord\Spy\hjt.exe
C:\Programmer\ewido\security suite\ewidoguard.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ka-net.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NetLimiter] C:\Programmer\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [kav] "C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programmer\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: Gmail Notifier.lnk = C:\Programmer\Google\Gmail Notifier\gnotify.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programmer\Desktop Sidebar\sbhelp.dll (file missing)
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sputnik.dk
O15 - Trusted Zone: *.tv2.dk
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://130.228.229.80/homeskyline/TEInstall/TE.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120165337000
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) - http://foto.tdconline.dk/upload-classes/Uploader.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://light.gabs.dk/imageuploader/ImageUploader3.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://fotomail.billedbutikken.dk/upload/xupload/XUpload2101.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{CE624C37-E23A-4A1D-A87B-866CE2EA5CB9}: NameServer = 192.168.1.3,192.168.1.9
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmer\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Unknown owner - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Avatar billede kim-h Novice
31. oktober 2006 - 21:45 #9
Har lige konstateret, at nå jeg logger på en af brugerne på min pc(familiens), så kommer diise to fejlmeddelser fra AD-watch og Spywareguard på en anden bruger (min private)
Så der må stadig være noget snavs :-(
Link til billeder af fejlmeddelser: http://www.akki.dk\PC-fejl\PC-fejl.html
Avatar billede kim-h Novice
31. oktober 2006 - 21:47 #10
UPS fejl i link.
her er det rigtige: http://www.akki.dk/PC-fejl/PC-fejl.html
01. november 2006 - 07:25 #11
... det må (=skal) den gøre.

Du vil formegentlig gerne have www.google.dk til startside istedet for Microsoft Reklame siden HVERGANG ?

Vælg bare [Accept] ...
07. november 2006 - 08:15 #12
Feedback ?
Avatar billede kim-h Novice
07. november 2006 - 08:37 #13
Det ser ud til at det har hjulpet en del.
Det sker dog stadig at en download stopper, og skal genstartes.
Og i går frøs word programmet midt under en stor skoleopgave. ØV forfra.
Men det er blevet meget bedre. :-)
07. november 2006 - 21:04 #14
Du er velkommen en anden gang...

Åbn en mappe, klik på Funktioner >Mappeindstillinger >Vis.
Sæt flueben ved "Skjul beskyttede operativsystemfiler".
Sæt prik i "Vis ikke skjulte filer og mapper".

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...
Avatar billede kim-h Novice
07. november 2006 - 21:41 #15
Det er hermed gjort.
Tak for hjælpen. :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester