computersystem går ned efter jeg downl. en fil (hijackthis log)
i går downloade jeg en fil som jeg skulle bruge til at se en video med. Det var så ikke lige en ActiveX.fil som der stod.Lige siden er min computer begyndt at komme med sådanne små "OBS", hvor der står at mit computersystem-"et eller andet" er på 43%, og at mit internetsystem står på 38%..
1. først kommer der en log fra hijackthis
2. norton finder dette, men den får det ikke fjernet. Det kommer igen hele tiden
1.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 18:42:42, on 24-08-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Video ActiveX Access\imsmain.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Java\jre1.5.0_03\bin\jusched.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\programmer\powerstrip\pstrip.exe
C:\Programmer\Java\jre1.5.0_03\bin\jucheck.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Video ActiveX Access\imsmn.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Steam\Steam.exe
C:\Programmer\Xfire\xfire.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Programmer\MSN Messenger\usnsvc.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Patrick Hoffmann\Lokale indstillinger\Temporary Internet Files\Content.IE5\03TN6YJH\HiJackThis_v2[1].exe
C:\Programmer\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://basilmarket.com/"); (C:\Documents and Settings\PATRICK HOFFMANN\Application Data\Mozilla\Profiles\default\on84od4t.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgrammer%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\PATRICK HOFFMANN\Application Data\Mozilla\Profiles\default\on84od4t.slt\prefs.js)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CDE8EAB9-CEF3-4885-B12F-26960A25C800} - C:\Programmer\Video ActiveX Access\iesplg.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Protection Bar - {DF4E7A0C-E233-4906-B4C1-A404356541FF} - C:\Programmer\Video ActiveX Access\iesbpl.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Programmer\Fælles filer\Symantec Shared\SymProbe.exe -r "C:\Programmer\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [pviever] "C:\Program Files\Gay-Lesbian-Photo\Gay-Lesbian-Photo.exe" hide
O4 - HKLM\..\Run: [PowerStrip] c:\programmer\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [PC Adware-Spware Removal] C:\Programmer\PC Adware-Spyware Removal\PCAdwareSpywareRemoval.exe /quick
O4 - HKLM\..\Run: [RelevantKnowledge] c:\windows\system32\rlvknlg.exe -boot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AdobeUpdater] C:\Programmer\Fælles filer\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Steam] "C:\Programmer\Steam\Steam.exe" -silent
O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Programmer\Video ActiveX Access\imsmain.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Programmer\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Patrick Hoffmann\Menuen Start\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Patrick Hoffmann\Menuen Start\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - C:\Programmer\MANSION\Villa\MANSION.exe
O9 - Extra 'Tools' menuitem: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - C:\Programmer\MANSION\Villa\MANSION.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: crawley - {8bbe40fd-0416-4c3f-80ea-0c7ad5fb1aab} - C:\WINDOWS\system32\igpfced.dll (file missing)
O22 - SharedTaskScheduler: falsism - {6e886df7-914d-48f0-86b3-a5cf24385361} - C:\WINDOWS\system32\fwrkqfl.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Cycling Manager 2007 Drivers Auto Removal (pr2akt6c) (pr2akt6c) - Cyanide - C:\WINDOWS\system32\pr2akt6c.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 10089 bytes
----------------------------------------------------------------------------------------------------------------------------------
2.
Her er hvad mit norton antivirus finder:
Source: Manual Scanner,Risk category: Virus,Action taken: Deleted,Description: Affected areas:
1 Files:
C:\RECYCLER\S-1-5-21-484763869-2111687655-839522115-500\Dc1\Gay-Lesbian-Photo.exe - Deleted
1 Processes:
C:\Programmer\Internet Explorer\iexplore.exe - Terminated
25 Registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\CustomizeSearch - Repaired
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-1003\Software\Microsoft\Internet Explorer\Main\\Start Page - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-500\Software\Microsoft\Internet Explorer\Main\\Start Page - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-1003\Software\Microsoft\Internet Explorer\Main\Search Page - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\Search Page - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\Search Page - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-500\Software\Microsoft\Internet Explorer\Main\Search Page - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\Search Page - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-1003\Software\Microsoft\Internet Explorer\Main\Search Bar - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\Search Bar - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\Search Bar - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-500\Software\Microsoft\Internet Explorer\Main\Search Bar - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\Search Bar - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-1003\Software\Microsoft\Internet Explorer\Main\Use Search Asst - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\Use Search Asst - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\Use Search Asst - Repaired
HKEY_USERS\S-1-5-21-484763869-2111687655-839522115-500\Software\Microsoft\Internet Explorer\Main\Use Search Asst - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\Use Search Asst - Repaired
1 Additional areas:
Unknown - Deleted
Source: Manual Scanner,Risk category: Spyware,Overall Risk Impact: Low,Performance: Low,Privacy: High,Removal: Low,Stealth: Low,Action taken: Removed,Description: Affected areas:
2 Files:
c:\windows\system32\rk.bin - Deleted
c:\windows\system32\rlls.dll - Deleted
1 Additional areas:
Unknown - Deleted
Source: Manual Scanner,Risk category: Security risk,Overall Risk Impact: Medium,Performance: Medium,Privacy: Medium,Removal: Medium,Stealth: Medium,Action taken: Removed,Description: Affected areas:
135 Files:
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~df44e1.tmp - Reboot required
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~df4ac6.tmp - Reboot required
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfad9b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfadec.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfaeb6.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfaeec.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfaf09.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfaf31.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb0e6.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb12b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb22b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb26f.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb320.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb40f.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb4e3.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb528.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb678.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb6e9.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb7b6.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb7f1.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb83d.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb879.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb93a.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb9d2.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfb9e1.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfba30.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfba75.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbac5.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbb26.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbb84.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbc12.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbc57.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbc86.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbdee.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbe43.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbe8d.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbea6.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbedf.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbf41.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfbf66.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc022.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc02c.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc067.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc09c.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc0a3.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc0ce.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc0f5.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc127.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc16c.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc18b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc220.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc25d.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc25f.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc2a4.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc2a6.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc2ac.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc2f1.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc2fb.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc340.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc359.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc3a4.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc3d7.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc454.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc473.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc498.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc4b8.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc4c6.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc531.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc558.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc59a.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc5b7.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc5df.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc632.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc635.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc7a3.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc81c.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc84c.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc861.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc921.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc934.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc981.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfc9f8.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfca37.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfca39.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfca3d.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfca5a.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfcac5.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfcb38.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfcb4b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfcb55.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfcb7e.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfcbb9.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfccb3.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfccd4.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfd12b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfd214.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfd258.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfd3be.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfd456.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfd5b5.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfdb81.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfdcc9.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfdf4b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe275.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe338.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe4a1.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe4e6.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe544.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe5f7.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe623.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe6e2.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe715.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe727.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe771.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe7c2.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe8c0.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe99d.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfe9eb.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfee10.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfeef8.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfef3c.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dfefae.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff06e.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff0ab.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff1df.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff574.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff7a8.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff804.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff897.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff96b.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dff9af.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\~dffe0c.tmp - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\ni.uga6pk_0001_n105m2704\settings.ini - Deleted
c:\documents and settings\patrick hoffmann\lokale indstillinger\temp\ni.uga6pk_0001_n105m2704\setup.len - Deleted
C:\Documents and Settings\Patrick Hoffmann\Lokale indstillinger\Temp\NI.UGA6PK_0001_N105M2704 - Deleted
3 Registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Antiviruspcpakke - Deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride - Repaired
Source: Manual Scanner,Risk category: Security risk,Overall Risk Impact: Medium,Performance: Medium,Privacy: Medium,Removal: Medium,Stealth: Medium,Action taken: Removed,Description: Affected areas:
1 Additional areas:
Unknown - Deleted
Source: C:\Documents and Settings\Patrick Hoffmann\Lokale indstillinger\Temporary Internet Files\Content.IE5\ELKZI1M5\vl_setup[1].exe,Risk category: Security risk,Action taken: Access denied
Source: C:\Documents and Settings\Patrick Hoffmann\Lokale indstillinger\Temporary Internet Files\Content.IE5\RAW7VHGH\DrAntispySetup_177[1].exe,Risk category: Security risk,Action taken: Access denied
Source: Manual Scanner,Risk category: Virus,Action taken: Repaired,Description: Affected areas:
1 Additional areas:
Unknown - Deleted
Source: Manual Scanner,Risk category: Virus,Action taken: Repaired,Description: Affected areas:
1 Registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\user32.dll - Deleted
1 Additional areas:
Unknown - Deleted
Source: C:\WINDOWS\system32\fwrkqfl.dll,Action taken: Repair failed,Action taken: Access denied
Source: C:\Programmer\Video ActiveX Access\iesbpl.dll,Action taken: Repair failed,Action taken: Access denied
Source: C:\Programmer\Video ActiveX Access\imsunst.exe,Action taken: Repair failed,Action taken: Access denied
Source: C:\Programmer\Video ActiveX Access\iesunst.exe,Action taken: Repair failed,Action taken: Access denied
Source: C:\Programmer\Video ActiveX Access\iesmn.exe,Action taken: Repair failed,Action taken: Access denied
