Avatar billede ghostweb Nybegynder
18. november 2006 - 00:26 Der er 7 kommentarer og
1 løsning

Har næsten lige formatert og alligevel virus

Min startside bliver lavet om og jeg får popups :(

Logfile of HijackThis v1.99.1
Scan saved at 00:20:02, on 18-11-2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\pokz\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {192c5b4a-3efd-40c7-9f99-c472deb8efc0} - C:\Programmer\Perfect Codec\isaddon.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Programmer\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Programmer\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162652864032
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: featherweed - {ab340860-fd81-4a65-b345-82eb77a66b5e} - C:\WINDOWS\System32\jbtazy.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
Avatar billede levich Nybegynder
18. november 2006 - 01:10 #1
Øjeblik, så kommer jeg med en vejledning.
Avatar billede levich Nybegynder
18. november 2006 - 01:16 #2
Læs alle punkterne inden du gør noget.

(1)
Hent http://www.spywarefri.dk/downloads1/ewido-setup.exe (Ewido).
Installer programmer og opdater det, men vent med at scanne.

(2)
Genstart computeren i fejlsikret tilstand (tryk F8 når Windows starter op), og fix følgende linjer med HijackThis:
O2 - BHO: (no name) - {192c5b4a-3efd-40c7-9f99-c472deb8efc0} - C:\Programmer\Perfect Codec\isaddon.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll
O21 - SSODL: featherweed - {ab340860-fd81-4a65-b345-82eb77a66b5e} - C:\WINDOWS\System32\jbtazy.dll (file missing)

(3)
Scan med Ewido, fix de ting som den finder og gem loggen, f.eks. på skrivebordet.

(4)
Åbn "denne computer", i menuen skal du klikke på Funktioner -> Mappeindstillinger -> Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler" og ved "Skjul filtypenavne for kendte filtyper", sæt prik i "Vis skjulte filer og mapper". Husk at trykke på knappen "Anvend på alle mapper" i stedet for "ok".

søg efter og slet følgende fil(er):
C:\WINDOWS\VirtualDNS.dll
C:\WINDOWS\System32\jbtazy.dll
... og følgende mappe(r):
C:\Programmer\Perfect Codec\

(5)
Start -> kør -> skriv "cleanmgr" -> Slet Temporary internet files, papirkurv og midlertidige filer. Gentag for alle dine drev.

(6)
Genstart computeren normalt. Lav en ny log med HijackThis, og send den herind sammen med loggen fra Ewido.
Avatar billede ghostweb Nybegynder
18. november 2006 - 13:45 #3
Ewido log :

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            13:43:05, 18-11-2006
+ Report-Checksum:        1693640

+ Scan result:

    HKLM\SOFTWARE\Classes\WUSN.1 -> Spyware.SaveNow : Cleaned with backup
    :mozilla.6:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.7:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.8:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.9:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.24:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.27:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.28:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.29:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.30:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.31:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.32:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.33:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.34:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.35:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.37:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.44:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.45:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.46:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.47:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.48:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.49:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.59:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
    :mozilla.64:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    :mozilla.86:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.93:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.94:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.95:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.96:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.97:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.98:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
    :mozilla.100:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
    :mozilla.122:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    :mozilla.123:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    :mozilla.130:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
    :mozilla.132:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.133:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.134:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.135:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
    :mozilla.144:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.145:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.146:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.147:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.148:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.149:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.150:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.151:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.152:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.153:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.159:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
    :mozilla.160:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
    :mozilla.177:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
    :mozilla.178:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.179:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.180:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.181:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.196:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    :mozilla.197:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    :mozilla.215:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.216:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.217:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Clickhype : Cleaned with backup
    :mozilla.218:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Clickhype : Cleaned with backup
    :mozilla.269:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.280:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.282:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.283:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.284:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.316:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
    :mozilla.325:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Itrack : Cleaned with backup
    :mozilla.326:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Itrack : Cleaned with backup
    :mozilla.327:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Itrack : Cleaned with backup
    :mozilla.328:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Itrack : Cleaned with backup
    :mozilla.329:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Itrack : Cleaned with backup
    :mozilla.330:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Itrack : Cleaned with backup
    :mozilla.331:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.337:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.339:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.340:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.364:C:\Documents and Settings\pokz\Application Data\Mozilla\Firefox\Profiles\x77kxo4h.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@adbrite[2].txt -> Spyware.Cookie.Adbrite : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@microsoftwga.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    C:\Documents and Settings\pokz\Cookies\pokz@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    C:\Documents and Settings\pokz\Lokale indstillinger\Temporary Internet Files\Content.IE5\SS9KHZPK\SetupInstRe[1].exe -> Adware.SaveNow : Cleaned with backup
    C:\WINDOWS\system32\MRT.exe -> Heuristic.Win32.AVKiller : Cleaned with backup


::Report End



Hijackthis log :

Logfile of HijackThis v1.99.1
Scan saved at 13:46:37, on 18-11-2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Programmer\PCI Audio Applications\Bin\EchoCtrl.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Steam\Steam.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\pokz\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Programmer\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Programmer\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162652864032
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
Avatar billede ejvindh Ekspert
18. november 2006 - 20:49 #4
-- Hent S!Ri's SmitfraudFix.zip og pak det ud til dit Skrivebord.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Programmet pakker sig ud i en mappe, der hedder SmitfraudFix.

NB: Filen "process.exe" som ligger i dette værktøj bliver af visse antivirus-programmer identificeret som "RiskTool". Det har dog ikke noget på sig!

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Åbn mappen SmitfraudFix som du fik på Skrivebordet, og dobbeltklik på SmitfraudFix.cmd og tast 2 - svar ja til at rense (y=yes). Lad programmet gennemføre en rensning. Det vil også checke om systemfilen wininet.dll er inficeret. Hvis den er det, vil du blive bedt om tilladelse til at erstatte den med en anden. Her skal du vælge "Yes", ved at taste "y".

Programmet bliver muligvis nødt til at genstarte undervejs. Herefter vil der dukke en liste med resultaterne af rensningen op . Kopiér denne liste ind i tråden.

-- Genstart og læg en frisk Hijackthislog herind, sammen med loggen fra SmitfraudFix (C:\rapport.txt).
18. november 2006 - 21:08 #5
Ka' ikke la' være med at skrive det:

*** Det er du selv ude om !!! ***

Du har ikke opdateret dit Windows XP til ServicePack2 (SP2).
"Ubeskyttede pc’er holder i 20 minutter]":
http://forum.mib-eu.dk/forum_posts.asp?TID=44

Det er ikke så godt, for så er du ikke sikret mod mange af de vira, der suser rundt på nettet og kigger efter uopdaterede maskiner. Som du er et godt eksempel på !!!

Bedst vil jeg sige  - BEGYND FORFRA og følg guiden herfra ->
http://www.spywareinfo.dk/manualer/xp-installation.htm +
http://www.spywareinfo.dk/manualer/xp-installation-side2.htm +
http://www.spywareinfo.dk/manualer/xp-opsaetning.htm

http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=29193
23. november 2006 - 16:01 #6
???
30. november 2006 - 16:30 #7
??? [2] ...
Avatar billede ghostweb Nybegynder
19. januar 2009 - 04:58 #8
..
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester