Avatar billede Slettet bruger
27. september 2007 - 21:28 Der er 30 kommentarer og
1 løsning

HijackThis - Eksperter

Mit barnebarn på bare 15 er på efterskole og er løbet ind i problemer, nu har jeg kørt programmer efter Eks.Artikel 1021 (fromsej).

Nu mangler jeg så bare at i vil kigge logfilerne igennem og fortælle mig om der er noget/og hvad der skal slettes/ændres

Det er vist en være en, det burde ikke kunne ske igen.
-.-.-.-.-.-.-.-.-.-.-.-

drweb.csv
..............
SonicLicenseManager.dll;C:\Program Files\Common Files\Sonic Shared;Trojan.DownLoader.origin;Incurable.Moved.;
A0009836.exe;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP49;Trojan.Packed.149;Incurable.Moved.;
A0012677.exe;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP61;Trojan.Packed.149;Incurable.Moved.;
A0012678.exe;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP61;Trojan.Packed.149;Incurable.Moved.;
A0012679.exe;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP61;Trojan.Packed.149;Incurable.Moved.;
A0012680.exe;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP61;Trojan.Packed.149;Incurable.Moved.;
A0012681.exe;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP61;Trojan.Packed.149;Incurable.Moved.;
A0012682.exe;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP61;Trojan.Packed.149;Incurable.Moved.;
A0013294.dll;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP66;Adware.Softomate.origin;Renamed.;
A0017894.dll;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP82;Adware.Zango;Renamed.;
A0018165.dll;C:\System Volume Information\_restore{8A6E0DCF-04FF-4752-8465-1C935F3B92FF}\RP86;Trojan.DownLoader.origin;Incurable.Moved.;

--------------------------------






SUPERAntiSpyware Scan Log
Generated 09/27/2007 at 08:35 PM

Application Version : 3.5.1016

Core Rules Database Version : 3314
Trace Rules Database Version: 1316

Scan type      : Quick Scan
Total Scan Time : 00:26:32

Memory items scanned      : 569
Memory threats detected  : 0
Registry items scanned    : 871
Registry threats detected : 265
File items scanned        : 29746
File threats detected    : 277

Adware.Tracking Cookie
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@bs.serving-sys[2].txt
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@atdmt[2].txt
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@serving-sys[2].txt
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@toplist[1].txt

Adware.180solutions/Seekmo
    HKCR\HostIE.Bho
    HKCR\HostIE.Bho\CLSID
    HKCR\HostIE.Bho\CurVer
    HKCR\HostIE.Bho.1
    HKCR\HostIE.Bho.1\CLSID
    HKCR\Seekmo.DesktopFlash
    HKCR\Seekmo.DesktopFlash\CLSID
    HKCR\Seekmo.DesktopFlash\CurVer
    HKCR\Seekmo.DesktopFlash.1
    HKCR\Seekmo.DesktopFlash.1\CLSID
    HKCR\SeekmoAX.ClientDetector
    HKCR\SeekmoAX.ClientDetector\CLSID
    HKCR\SeekmoAX.ClientDetector\CurVer
    HKCR\SeekmoAX.ClientDetector.1
    HKCR\SeekmoAX.ClientDetector.1\CLSID
    HKCR\SeekmoAX.UserProfiles
    HKCR\SeekmoAX.UserProfiles\CLSID
    HKCR\SeekmoAX.UserProfiles\CurVer
    HKCR\SeekmoAX.UserProfiles.1
    HKCR\SeekmoAX.UserProfiles.1\CLSID
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\0
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\0\win32
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\FLAGS
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\HELPDIR
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\0
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\0\win32
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\FLAGS
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\HELPDIR
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\0
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\0\win32
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\FLAGS
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\HELPDIR
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\ProxyStubClsid
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\ProxyStubClsid32
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\TypeLib
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\TypeLib#Version
    HKCR\AppId\SeekmoSA_df.exe
    HKCR\AppId\SeekmoSA_df.exe#AppID
    HKCR\AppId\{4A40E8FC-C7E4-4F57-9FA4-85DD77402897}
    HKU\S-1-5-21-650876143-2147640222-147680849-1005\Software\seekmosa
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}
    HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}
    HKU\S-1-5-21-650876143-2147640222-147680849-1005\Software\Microsoft\Internet Explorer\Explorer Bars\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}
    HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07AA283A-43D7-4CBE-A064-32A21112D94D} [ Seekmo ]
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\IESkins
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOI\dynamic
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOI\static
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOI
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOL\dynamic
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOL\static
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOL
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\1.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\1403294.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\221540.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\2221934.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\2789033.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\2883915.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3251993.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3423589.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3442551.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3852962.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3855415.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\499697.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\512217.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\805478.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\880604.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\965273.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\11213
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13562
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13581
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13617
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\16087
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\16204
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\17025
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\17040
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\17923
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\2020
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\20478
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\20517
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\20570
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\22254
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\241510
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\247701
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\26664
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\281064
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\28812
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\290893
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29115
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29425
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29536
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\31327
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\32242
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\34174
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\34237
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\34388
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\36735
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\398397
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\40999
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\43254
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44228
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44293
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44458
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44571
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44878
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\459338
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\50830
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\51233
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\528235
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\531510
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\53312
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\53813
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\5393
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\53933
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\54473
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\561686
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\56815
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\578081
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\578150
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\57918
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\57980
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\58197
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\5828
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\59287
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\62133
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\64434
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\64646
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\65843
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\66836
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\66855
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67226
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67464
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\6873
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\69556
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\703336
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\70611
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\70907
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\713199
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\73506
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\73670
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\738022
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\74398
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\7482
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\749354
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\78220
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\81830
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\82292
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\86173
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\86379
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\86654
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\87385
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\89623
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\90358
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\91589
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\92573
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93110
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\94272
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\94407
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\95645
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\95704
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97499
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97507
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97518
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97524
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\98248
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\99795
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\35cc.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\35d7.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans.idx
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans1.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\buttondir.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\components.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\cursors.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\default.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_511745-514279.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_categorize.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_comparison.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-Mails.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-people.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_favorites.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Games.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hide.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hotbarcom.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hotmail.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hsskin.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Mails.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_new.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_premium.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchfor.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchgo.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_weather.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_yellowpages.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_1000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_2000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_3000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bar.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bbar1.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_logos.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_other.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_weather.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-548964.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-9595.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\email-t1-bg.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\icons2.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_games_icon.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_video.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords.idx
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords1.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\layout.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\linkpathlegal.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\progress.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\sales_buttons.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo_ie_menu.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\s_icons_buttons.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\t2_bg.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\theweb.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\top7.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Top7_theweb.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\tsd_bg.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans.idx
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans1.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\buttondir.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\components.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\cursors.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\default.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_511745-514279.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_categorize.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_comparison.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-Mails.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-people.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_favorites.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Games.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hide.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hotbarcom.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hotmail.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hsskin.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Mails.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_new.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_premium.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchfor.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchgo.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_weather.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_yellowpages.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_1000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_2000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_3000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bar.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bbar1.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_logos.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_other.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_weather.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-548964.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-9595.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\email-t1-bg.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\icons2.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_games_icon.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_video.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords.idx
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords1.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\layout.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\linkpathlegal.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\progress.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\sales_buttons.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo_ie_menu.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\s_icons_buttons.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\t2_bg.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\theweb.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\top7.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\Top7_theweb.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2\tsd_bg.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\2
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans1.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\buttondir.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\cursors.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\default.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_1000.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_2000.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_3000.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bar.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bbar1.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_logos.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_other.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_weather.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\email-t1-bg.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\icons2.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_games_icon.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_video.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords1.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\layout.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\linkpathlegal.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\progress.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\sales_buttons.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo_ie_menu.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\s_icons_buttons.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\t2_bg.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\top7.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\tsd_bg.xip
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo
    C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Reset Cursor.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Customer Support Center.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Uninstall Instructions.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo

Adware.Zango Toolbar/Hb
    HKCR\CoreSrv.CoreServices
    HKCR\CoreSrv.CoreServices\CLSID
    HKCR\CoreSrv.CoreServices\CurVer
    HKCR\CoreSrv.CoreServices.1
    HKCR\CoreSrv.CoreServices.1\CLSID
    HKCR\CoreSrv.LfgAx
    HKCR\CoreSrv.LfgAx\CLSID
    HKCR\CoreSrv.LfgAx\CurVer
    HKCR\CoreSrv.LfgAx.1
    HKCR\CoreSrv.LfgAx.1\CLSID
    HKCR\HBMain.CommBand
    HKCR\HBMain.CommBand\CLSID
    HKCR\HBMain.CommBand\CurVer
    HKCR\HBMain.CommBand.1
    HKCR\HBMain.CommBand.1\CLSID
    HKCR\hbr.HbMain
    HKCR\hbr.HbMain\CLSID
    HKCR\hbr.HbMain\CurVer
    HKCR\hbr.HbMain.1
    HKCR\hbr.HbMain.1\CLSID
    HKCR\HostOL.MailAnim
    HKCR\HostOL.MailAnim\CLSID
    HKCR\HostOL.MailAnim\CurVer
    HKCR\HostOL.MailAnim.1
    HKCR\HostOL.MailAnim.1\CLSID
    HKCR\HostOL.WebmailSend
    HKCR\HostOL.WebmailSend\CLSID
    HKCR\HostOL.WebmailSend\CurVer
    HKCR\HostOL.WebmailSend.1
    HKCR\HostOL.WebmailSend.1\CLSID
    HKCR\InstIE.HbInstObj
    HKCR\InstIE.HbInstObj\CLSID
    HKCR\InstIE.HbInstObj\CurVer
    HKCR\InstIE.HbInstObj.1
    HKCR\InstIE.HbInstObj.1\CLSID
    HKCR\Srv.CoreServices
    HKCR\Srv.CoreServices\CLSID
    HKCR\Srv.CoreServices\CurVer
    HKCR\Srv.CoreServices.1
    HKCR\Srv.CoreServices.1\CLSID
    HKCR\Toolbar.HtmlMenuUI
    HKCR\Toolbar.HtmlMenuUI\CLSID
    HKCR\Toolbar.HtmlMenuUI\CurVer
    HKCR\Toolbar.HtmlMenuUI.1
    HKCR\Toolbar.HtmlMenuUI.1\CLSID
    HKCR\Toolbar.ToolbarCtl
    HKCR\Toolbar.ToolbarCtl\CLSID
    HKCR\Toolbar.ToolbarCtl\CurVer
    HKCR\Toolbar.ToolbarCtl.1
    HKCR\Toolbar.ToolbarCtl.1\CLSID
    HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}
    HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories
    HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories\{63821032-AAA6-4DEE-8053-CB3F35CD3D7E}
    HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}
    HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0
    HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\0
    HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\0\win32
    HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\FLAGS
    HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\HELPDIR
    HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}
    HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0
    HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\0
    HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\0\win32
    HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\FLAGS
    HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\HELPDIR
    HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}
    HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0
    HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\0
    HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\0\win32
    HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\FLAGS
    HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\HELPDIR
    HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}
    HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0
    HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\0
    HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\0\win32
    HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\FLAGS
    HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\HELPDIR
    HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}
    HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}\1.0
    HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}\1.0\0
    HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}\1.0\0\win32
    HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}\1.0\FLAGS
    HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}\1.0\HELPDIR
    HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}
    HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0
    HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\0
    HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\0\win32
    HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\FLAGS
    HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\HELPDIR
    HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}
    HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid
    HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid32
    HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib
    HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib#Version
    HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}
    HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid
    HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid32
    HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib
    HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib#Version
    HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}
    HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid
    HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid32
    HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib
    HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib#Version
    HKCR\Interface\{2B81F920-6660-4F76-93BF-B1C67BF5D1A0}
    HKCR\Interface\{2B81F920-6660-4F76-93BF-B1C67BF5D1A0}\ProxyStubClsid
    HKCR\Interface\{2B81F920-6660-4F76-93BF-B1C67BF5D1A0}\ProxyStubClsid32
    HKCR\Interface\{2B81F920-6660-4F76-93BF-B1C67BF5D1A0}\TypeLib
    HKCR\Interface\{2B81F920-6660-4F76-93BF-B1C67BF5D1A0}\TypeLib#Version
    HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}
    HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\ProxyStubClsid
    HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\ProxyStubClsid32
    HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\TypeLib
    HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\TypeLib#Version
    HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}
    HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid
    HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid32
    HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib
    HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib#Version
    HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}
    HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid
    HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid32
    HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib
    HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib#Version
    HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}
    HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid
    HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid32
    HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib
    HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib#Version
    HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}
    HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\ProxyStubClsid
    HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\ProxyStubClsid32
    HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\TypeLib
    HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\TypeLib#Version
    HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}
    HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\ProxyStubClsid
    HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\ProxyStubClsid32
    HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\TypeLib
    HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\TypeLib#Version
    HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}
    HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid
    HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid32
    HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib
    HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib#Version
    HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}
    HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid
    HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid32
    HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib
    HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib#Version
    HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}
    HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid
    HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid32
    HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib
    HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib#Version
    HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}
    HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\ProxyStubClsid
    HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\ProxyStubClsid32
    HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\TypeLib
    HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\TypeLib#Version
    HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}
    HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid
    HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid32
    HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib
    HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib#Version
    HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}
    HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid
    HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid32
    HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib
    HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib#Version
    HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}
    HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid
    HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid32
    HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib
    HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib#Version
    HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}
    HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid
    HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid32
    HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib
    HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib#Version
    HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}
    HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid
    HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid32
    HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib
    HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib#Version
    HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}
    HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid
    HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid32
    HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib
    HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib#Version
    HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}
    HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid
    HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid32
    HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib
    HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib#Version
    HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}
    HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid
    HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid32
    HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib
    HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib#Version
    HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}
    HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid
    HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid32
    HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib
    HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib#Version
    HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}
    HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid
    HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid32
    HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib
    HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib#Version
    HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}
    HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid
    HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid32
    HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib
    HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib#Version


SUPERAntiSpyware Scan Log
Generated 09/27/2007 at 08:35 PM

Application Version : 3.5.1016

Core Rules Database Version : 3314
Trace Rules Database Version: 1316

Scan type      : Quick Scan
Total Scan Time : 00:26:32

Memory items scanned      : 569
Memory threats detected  : 0
Registry items scanned    : 871
Registry threats detected : 265
File items scanned        : 29746
File threats detected    : 277

Adware.Tracking Cookie
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@bs.serving-sys[2].txt
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@atdmt[2].txt
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@serving-sys[2].txt
    C:\Documents and Settings\Kiki Neelam\Cookies\kiki_neelam@toplist[1].txt

Adware.180solutions/Seekmo
    HKCR\HostIE.Bho
    HKCR\HostIE.Bho\CLSID
    HKCR\HostIE.Bho\CurVer
    HKCR\HostIE.Bho.1
    HKCR\HostIE.Bho.1\CLSID
    HKCR\Seekmo.DesktopFlash
    HKCR\Seekmo.DesktopFlash\CLSID
    HKCR\Seekmo.DesktopFlash\CurVer
    HKCR\Seekmo.DesktopFlash.1
    HKCR\Seekmo.DesktopFlash.1\CLSID
    HKCR\SeekmoAX.ClientDetector
    HKCR\SeekmoAX.ClientDetector\CLSID
    HKCR\SeekmoAX.ClientDetector\CurVer
    HKCR\SeekmoAX.ClientDetector.1
    HKCR\SeekmoAX.ClientDetector.1\CLSID
    HKCR\SeekmoAX.UserProfiles
    HKCR\SeekmoAX.UserProfiles\CLSID
    HKCR\SeekmoAX.UserProfiles\CurVer
    HKCR\SeekmoAX.UserProfiles.1
    HKCR\SeekmoAX.UserProfiles.1\CLSID
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\0
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\0\win32
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\FLAGS
    HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\HELPDIR
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\0
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\0\win32
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\FLAGS
    HKCR\TypeLib\{995E885E-3FF5-4F66-A107-8BFB3A0F8F12}\1.0\HELPDIR
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\0
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\0\win32
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\FLAGS
    HKCR\TypeLib\{FBB40FDF-B715-4342-AB82-244ECC66E979}\1.0\HELPDIR
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\ProxyStubClsid
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\ProxyStubClsid32
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\TypeLib
    HKCR\Interface\{BD5258AF-20AE-4BD3-B748-B2851ACA7335}\TypeLib#Version
    HKCR\AppId\SeekmoSA_df.exe
    HKCR\AppId\SeekmoSA_df.exe#AppID
    HKCR\AppId\{4A40E8FC-C7E4-4F57-9FA4-85DD77402897}
    HKU\S-1-5-21-650876143-2147640222-147680849-1005\Software\seekmosa
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}
    HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}
    HKU\S-1-5-21-650876143-2147640222-147680849-1005\Software\Microsoft\Internet Explorer\Explorer Bars\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}
    HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07AA283A-43D7-4CBE-A064-32A21112D94D} [ Seekmo ]
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\IESkins
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOI\dynamic
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOI\static
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOI
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOL\dynamic
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOL\static
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\HostOL
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\1.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\1403294.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\221540.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\2221934.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\2789033.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\2883915.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3251993.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3423589.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3442551.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3852962.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\3855415.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\499697.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\512217.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\805478.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\880604.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\965273.sdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\11213
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13562
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13581
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13617
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\16087
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\16204
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\17025
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\17040
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\17923
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\2020
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\20478
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\20517
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\20570
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\22254
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\241510
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\247701
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\26664
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\281064
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\28812
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\290893
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29115
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29425
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29536
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\31327
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\32242
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\34174
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\34237
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\34388
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\36735
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\398397
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\40999
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\43254
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44228
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44293
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44458
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44571
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\44878
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\459338
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\50830
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\51233
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\528235
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\531510
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\53312
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\53813
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\5393
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\53933
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\54473
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\561686
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\56815
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\578081
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\578150
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\57918
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\57980
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\58197
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\5828
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\59287
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\62133
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\64434
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\64646
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\65843
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\66836
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\66855
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67226
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67464
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\6873
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\69556
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\703336
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\70611
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\70907
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\713199
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\73506
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\73670
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\738022
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\74398
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\7482
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\749354
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\78220
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\81830
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\82292
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\86173
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\86379
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\86654
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\87385
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\89623
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\90358
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\91589
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\92573
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93110
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\94272
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\94407
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\95645
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\95704
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97499
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97507
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97518
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97524
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\98248
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\99795
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\35cc.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\35d7.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\dynamic
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans.idx
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans1.dat
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\buttondir.txt
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\components.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\cursors.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\default.cdf
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_511745-514279.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_categorize.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_comparison.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-Mails.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-people.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_favorites.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Games.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hide.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hotbarcom.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hotmail.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hsskin.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Mails.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_new.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_premium.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchfor.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchgo.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_weather.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_yellowpages.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_1000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_2000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_3000.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bar.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bbar1.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_logos.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_other.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_weather.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-548964.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-9595.mnu
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\email-t1-bg.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\icons2.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_games_icon.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_video.res
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords.idx
    C:\Documents and Settings\Kiki Neelam\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords1.dat
    C:\Documents and Settings\Kiki Neelam\Applic
Avatar billede arlet Juniormester
27. september 2007 - 21:31 #1
Avatar billede Slettet bruger
27. september 2007 - 21:35 #2
Double SuperAnti og ingen Hijack, ved ikke hvad der gik galt men her er HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:02:46, on 27-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe
C:\PROGRA~1\SONYER~1\MOBILE~1\EPMWOR~1.EXE
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Arto\Notifier\ArtoNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
F:\clear-computer\Hijack\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [XTNDConnect PC - ErPhn2] C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ArtoNotifier] C:\Program Files\Arto\Notifier\ArtoNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Hurtig start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?dfe531e1fde14a5d8a96c549aabdf80a
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?dfe531e1fde14a5d8a96c549aabdf80a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed660/yg91.gif
O24 - Desktop Component 1: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed660/yg97.gif
O24 - Desktop Component 2: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed660/yg79.gif
O24 - Desktop Component 3: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed440/gem76.gif
O24 - Desktop Component 4: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed440/new4b.gif

--
End of file - 10191 bytes
Avatar billede arlet Juniormester
27. september 2007 - 21:42 #3
De scannere du har brugt har taget rigtig meget, så umiddelbart er der ikke mere i hijackthis loggen, så har det hjulpet??, eller skal vi grave dybere for om vi kan finde noget??
Avatar billede Slettet bruger
27. september 2007 - 21:49 #4
Som jeg skriver i indledningen har jeg brugt fromseej's manual, men her er logfil fra ROOTCHK - jeg syntes så ikke den fortæller meget forståeligt for mig ?

********************************* ROOTCHK-(21-09-07)-LOG, by ejvindh
27-09-2007 21:45:28,93

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-27 21:45:29
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0
Avatar billede Slettet bruger
27. september 2007 - 21:50 #5
Jeg ville bare være sikker på om den nu var så ren så jeg kunne aflevere den igen
Avatar billede Slettet bruger
27. september 2007 - 21:57 #6
Jeg har brugt flere andre end dem der er nævnt i fromsej's aktikel

Norman_Malware_Cleaner
CCleaner
Spybot-Search-Destroy

alle har fundet noget
Avatar billede arlet Juniormester
28. september 2007 - 07:21 #7
Ja, det er småting de scannere finder, men vi kan da godt kigge på et combofix:

-- Hent Combofix fra et af disse links, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

-- Kør så combofix.exe, som du hentede tidligere, og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.

BEMÆRK at Combofix af nogle virusscannere bliver detekteret som inficeret. Dette har dog intet på sig.
Avatar billede Slettet bruger
28. september 2007 - 07:42 #8
ComboFix 07-09-21.2 - "Kiki Neelam" 2007-09-28  7:31:47.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.616 [GMT 2:00]
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1\SeekmoSA
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SeekmoSA\SeekmoSA.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SeekmoSA\SeekmoSA_kyf.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SeekmoSA\SeekmoSAEULA.mht
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SeekmoSA\SeekmoSAAbout.mht
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SeekmoSA\SeekmoSAau.dat
C:\WINDOWS\system32\_000009_.tmp.dll
D:\Autorun.inf

.
(((((((((((((((((((((((((  Files Created from 2007-08-28 to 2007-09-28  )))))))))))))))))))))))))))))))
.

2007-09-28 07:31    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-09-28 05:39    <DIR>    d--------    C:\Program Files\UnH Solutions
2007-09-28 05:39    <DIR>    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\UnH Solutions
2007-09-27 22:01    <DIR>    d--------    C:\Program Files\HDCleaner
2007-09-27 18:44    <DIR>    d--------    C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 16:31    <DIR>    d--------    C:\DOCUME~1\ADMINI~1\DoctorWeb
2007-09-27 16:24    <DIR>    d--------    C:\Program Files\SUPERAntiSpyware
2007-09-27 16:24    <DIR>    d--------    C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 16:24    <DIR>    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 16:24    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 15:25    95,608    --a------    C:\WINDOWS\system32\AvastSS.scr
2007-09-27 15:25    94,416    --a------    C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-27 15:25    92,848    --a------    C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-27 15:25    801,144    --a------    C:\WINDOWS\system32\aswBoot.exe
2007-09-27 15:25    42,912    --a------    C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-27 15:25    26,624    --a------    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-27 15:25    23,152    --a------    C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-27 15:25    <DIR>    d--------    C:\Program Files\Alwil Software
2007-09-27 14:08    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-27 13:34    <DIR>    d--------    C:\WINDOWS\pss
2007-09-27 11:42    <DIR>    d--------    C:\WINDOWS\Twain32
2007-09-27 11:04    <DIR>    d--------    C:\Program Files\MSXML 6.0
2007-09-27 11:01    <DIR>    d--------    C:\Program Files\MSBuild
2007-09-27 10:58    <DIR>    d--------    C:\WINDOWS\system32\XPSViewer
2007-09-27 10:58    <DIR>    d--------    C:\Program Files\Reference Assemblies
2007-09-27 10:57    14,048    ---------    C:\WINDOWS\system32\spmsg2.dll
2007-09-27 10:57    <DIR>    d--------    C:\b94951b1bee1c07ea0e6
2007-09-27 10:49    36,352    ---------    C:\WINDOWS\system32\tsgqec.dll
2007-09-27 10:49    288,768    ---------    C:\WINDOWS\system32\rhttpaa.dll
2007-09-27 10:49    116,736    ---------    C:\WINDOWS\system32\aaclient.dll
2007-09-27 10:30    33,792    --a------    C:\WINDOWS\system32\dllcache\custsat.dll
2007-09-27 08:59    <DIR>    d--------    C:\Program Files\CCleaner
2007-09-27 08:36    21,504    --a------    C:\WINDOWS\system32\hidserv.dll
2007-09-27 08:36    21,504    --a------    C:\WINDOWS\system32\dllcache\hidserv.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-27 20:02    ---------    d--------    C:\Program Files\LimeWire
2007-09-27 17:06    ---------    d--------    C:\Program Files\Common Files\Sonic Shared
2007-09-27 15:09    ---------    d--------    C:\Program Files\Common Files\Symantec Shared
2007-09-27 15:09    ---------    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-09-27 11:41    ---------    d--------    C:\Program Files\microsoft frontpage
2007-09-27 10:01    ---------    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\LimeWire
2007-09-21 17:49    ---------    d--------    C:\Program Files\BearShare Applications
2007-09-21 17:49    ---------    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\BearShare
2007-09-06 12:00    26624    --a------    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-06 22:30    ---------    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-08-04 15:31    ---------    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\32chichope
2007-08-04 15:23    ---------    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mode owns army play
2007-08-04 14:51    ---------    d--------    C:\Program Files\XTNDConnect PC
2007-08-04 14:51    ---------    d--------    C:\Program Files\NetWaiting
2007-08-04 14:18    10344    --a------    C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-04-22 19:03:29    22    --sha-w    C:\WINDOWS\SMINST\HPCD.sys
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 21:56]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 22:58]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 21:03]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 10:00]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-18 10:00]
"nwiz"="nwiz.exe" [2006-08-18 10:00 C:\WINDOWS\system32\nwiz.exe]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 11:33]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 16:02]
"XTNDConnect PC - ErPhn2"="C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe" [2003-02-13 09:41]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 07:01]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 10:23]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-11 21:55]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 02:02 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-16 06:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 16:19]
"ArtoNotifier"="C:\Program Files\Arto\Notifier\ArtoNotifier.exe" [2006-10-10 17:33]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-01-10 15:14]
"IE Privacy Keeper"="C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" [2005-12-03 14:52]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Hurtigstart.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
HP Photosmart Premier Hurtig start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 09:39:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2006-10-19 09:12 258048 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R2 MSMQ;Message Queuing;C:\WINDOWS\system32\mqsvc.exe
R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\system32\mqtgsvc.exe
R3 HBtnKey;HBtnKey;C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\system32\drivers\mqac.sys
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys
R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\system32\drivers\RMCast.sys
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam  ;C:\WINDOWS\system32\Drivers\5U870CAP.sys
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys
S3 P1120VID;Creative WebCam NX Ultra;C:\WINDOWS\system32\DRIVERS\P1120Vid.sys
S4 viaagp;VIA AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\viaagp.sys

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-28 07:36:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????<?@? ???hV??????Y?@?????<?@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Aavmker4]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\viaagp]
"ImagePath"="\SystemRoot\system32\DRIVERS\viaagp.sys"
.
Completion time: 2007-09-28  7:38:12 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-28 07:38
.
    --- E O F ---
Avatar billede arlet Juniormester
28. september 2007 - 07:52 #9
Så fik den også fjernet lidt snavs, så må vi være der. Eneste problem jeg ser er at der var været benyttet en masse fildelingsprogrammer og med fildelingsprogrammer kommer alt det her skidt, så min anbefaling er at droppe det fildeling..

Kør lige trin 5 og 6 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11

Her kan du læse om vores skudsikre sikkerhedspakke: http://www.malwarecheck.dk/forum/viewtopic.php?t=156 . Hvis du har nogle spørgsmål, så spørger du bare..
Avatar billede Slettet bruger
28. september 2007 - 10:16 #10
Så kan det vist ikke gøre bedre dennegang

Tak for hjælpen
Avatar billede fromsej Praktikant
29. september 2007 - 11:01 #11
Hvad med Lop, skal den bare køre upåagtet?
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mode owns army play
C:\DOCUME~1\KIKINE~1\APPLIC~1\32chichope

Årsagen er her:
C:\DOCUME~1\KIKINE~1\APPLIC~1\LimeWire
C:\Program Files\BearShare Applications
Avatar billede Slettet bruger
29. september 2007 - 11:24 #12
@..fromsej...det er sort snak for mig

Nu har jeg afleveret computeren, men den er da til at få fat i igen, er det noget der kan give problemer.

Er LimeWire ikke noget de unge bruger til at dele filer med ?

Er det ikke noget ComboFix har rettet ?
Avatar billede fromsej Praktikant
29. september 2007 - 11:58 #13
LimeWire og Bearshare er fildelingsprogrammer, de er finansieret af reklamefirmaer, der propper deres forp..... Adware ind.
Her er det C2Media/Lop der er på spil. sammen med Zango og Seekmo.
Derudover kommer der alskens skidt ind, når der hentes musik, film, spil, programmer osv.
Især programmer, da man er nødt til at finde et crack eller en keychanger til mange af dem, disse er der som hovedregel en trojan gemt i, så maskinen kan overtages udefra og bruges til lyssky formål, hvoraf de mest! uskyldige er distribution af Porno, i de grimme tilfælde bruges de til børneporno, og det er altså dig der har et forklaringsproblem den dag politiet henter maskinen og tager dig med.
I de rigtig grelle tilfælde bliver maskinen brugt til et DDoS angreb på en internetudbyder eller et stort firma, hvorefter hackerne presser penge af firmaerne for at stoppe angrebet, det er en kæmpeproblem og umuligt at stoppe fordi det er så nemt at få folks maskiner inficeret.
Her kan du læse mere om DoS og DDoS angreb:
https://www.cert.dk/artikler/artikler/000300A003.shtml

Nej, combofix har ikke fjernet Bearshare og Limewire, eller for den sags skyld de sidste rester af Lop.
Avatar billede arlet Juniormester
29. september 2007 - 16:27 #14
Ja, det er noget skidt, at jeg har overset de 2 filer, for de skal væk..

ibtage-> Kan du få fat i computeren igen, for så kan jeg lave en vejledning til dig..
Avatar billede Slettet bruger
29. september 2007 - 17:02 #15
Jeg henter lige computeren og laver en ny HijackThis
Avatar billede arlet Juniormester
29. september 2007 - 17:37 #16
Det er en ny combofix vi skal bruge, men jeg er desværre nok ikke mere på i dag..
Avatar billede fromsej Praktikant
29. september 2007 - 17:46 #17
Jeg kan snuppe det i aften så.
Avatar billede fromsej Praktikant
29. september 2007 - 20:00 #18
Kopiér indholdet mellem de bølgede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt. Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

Folder::
C:\Program Files\LimeWire
C:\DOCUME~1\KIKINE~1\APPLIC~1\LimeWire
C:\Program Files\BearShare Applications
C:\DOCUME~1\KIKINE~1\APPLIC~1\BearShare
C:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
C:\DOCUME~1\KIKINE~1\APPLIC~1\32chichope
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mode owns army play

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Vi skal se en frisk Combofixlog og en frisk Hijackthislog.
Avatar billede Slettet bruger
29. september 2007 - 20:00 #19
Jeg har nu fået computeren og vender tilbage senere med en Combofix
Avatar billede Slettet bruger
29. september 2007 - 20:18 #20
ComboFix 07-09-21.2 - "Kiki Neelam" 2007-09-29 20:01:56.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.583 [GMT 2:00]
.

(((((((((((((((((((((((((  Files Created from 2007-08-28 to 2007-09-29  )))))))))))))))))))))))))))))))
.

2007-09-29 17:54    <DIR>    d--------    C:\Install
2007-09-28 07:31    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-09-28 05:39    <DIR>    d--------    C:\Program Files\UnH Solutions
2007-09-28 05:39    <DIR>    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\UnH Solutions
2007-09-27 22:01    <DIR>    d--------    C:\Program Files\HDCleaner
2007-09-27 18:44    <DIR>    d--------    C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 16:31    <DIR>    d--------    C:\DOCUME~1\ADMINI~1\DoctorWeb
2007-09-27 16:24    <DIR>    d--------    C:\Program Files\SUPERAntiSpyware
2007-09-27 16:24    <DIR>    d--------    C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 16:24    <DIR>    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 16:24    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 15:25    95,608    --a------    C:\WINDOWS\system32\AvastSS.scr
2007-09-27 15:25    94,416    --a------    C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-27 15:25    92,848    --a------    C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-27 15:25    801,144    --a------    C:\WINDOWS\system32\aswBoot.exe
2007-09-27 15:25    42,912    --a------    C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-27 15:25    26,624    --a------    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-27 15:25    23,152    --a------    C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-27 15:25    <DIR>    d--------    C:\Program Files\Alwil Software
2007-09-27 14:08    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-27 13:34    <DIR>    d--------    C:\WINDOWS\pss
2007-09-27 11:42    <DIR>    d--------    C:\WINDOWS\Twain32
2007-09-27 11:04    <DIR>    d--------    C:\Program Files\MSXML 6.0
2007-09-27 11:01    <DIR>    d--------    C:\Program Files\MSBuild
2007-09-27 10:58    <DIR>    d--------    C:\WINDOWS\system32\XPSViewer
2007-09-27 10:58    <DIR>    d--------    C:\Program Files\Reference Assemblies
2007-09-27 10:57    14,048    ---------    C:\WINDOWS\system32\spmsg2.dll
2007-09-27 10:57    <DIR>    d--------    C:\b94951b1bee1c07ea0e6
2007-09-27 10:49    36,352    ---------    C:\WINDOWS\system32\tsgqec.dll
2007-09-27 10:49    288,768    ---------    C:\WINDOWS\system32\rhttpaa.dll
2007-09-27 10:49    116,736    ---------    C:\WINDOWS\system32\aaclient.dll
2007-09-27 10:30    33,792    --a------    C:\WINDOWS\system32\dllcache\custsat.dll
2007-09-27 08:59    <DIR>    d--------    C:\Program Files\CCleaner
2007-09-27 08:36    21,504    --a------    C:\WINDOWS\system32\hidserv.dll
2007-09-27 08:36    21,504    --a------    C:\WINDOWS\system32\dllcache\hidserv.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-27 17:06    ---------    d--------    C:\Program Files\Common Files\Sonic Shared
2007-09-27 15:09    ---------    d--------    C:\Program Files\Common Files\Symantec Shared
2007-09-27 11:41    ---------    d--------    C:\Program Files\microsoft frontpage
2007-09-21 17:49    ---------    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\BearShare
2007-09-06 12:00    26624    --a------    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-06 22:30    ---------    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-08-04 15:31    ---------    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\32chichope
2007-08-04 14:51    ---------    d--------    C:\Program Files\XTNDConnect PC
2007-08-04 14:51    ---------    d--------    C:\Program Files\NetWaiting
2007-08-04 14:18    10344    --a------    C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19    43352    --a------    C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19    271224    --a------    C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19    207736    --a------    C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\wups.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\dllcache\wups.dll
2007-07-19 08:59    3583488    --a------    C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 01:31    765952    --a------    C:\WINDOWS\system32\dllcache\vgx.dll
2005-09-24 08:49    12288    --a------    C:\WINDOWS\Fonts\RandFont.dll
2007-04-22 19:03:29    22    --sha-w    C:\WINDOWS\SMINST\HPCD.sys
.

(((((((((((((((((((((((((((((  snapshot_2007-09-28_ 73750.90  )))))))))))))))))))))))))))))))))))))))))
.
----atw            16,384 2007-09-29 15:31:45  C:\WINDOWS\Temp\Perflib_Perfdata_66c.dat
.
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 21:56]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 22:58]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 21:03]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 10:00]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-18 10:00]
"nwiz"="nwiz.exe" [2006-08-18 10:00 C:\WINDOWS\system32\nwiz.exe]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 11:33]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 16:02]
"XTNDConnect PC - ErPhn2"="C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe" [2003-02-13 09:41]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 07:01]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 10:23]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-11 21:55]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 02:02 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-16 06:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 16:19]
"ArtoNotifier"="C:\Program Files\Arto\Notifier\ArtoNotifier.exe" [2006-10-10 17:33]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-01-10 15:14]
"IE Privacy Keeper"="C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" [2005-12-03 14:52]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Hurtigstart.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
HP Photosmart Premier Hurtig start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 09:39:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2006-10-19 09:12 258048 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R2 MSMQ;Message Queuing;C:\WINDOWS\system32\mqsvc.exe
R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\system32\mqtgsvc.exe
R3 HBtnKey;HBtnKey;C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\system32\drivers\mqac.sys
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys
R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\system32\drivers\RMCast.sys
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam  ;C:\WINDOWS\system32\Drivers\5U870CAP.sys
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys
S3 P1120VID;Creative WebCam NX Ultra;C:\WINDOWS\system32\DRIVERS\P1120Vid.sys
S4 viaagp;VIA AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\viaagp.sys

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-29 20:02:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????<?@? ???hV??????Y?@?????<?@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Aavmker4]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\viaagp]
"ImagePath"="\SystemRoot\system32\DRIVERS\viaagp.sys"
.
Completion time: 2007-09-29 20:03:34
C:\ComboFix-quarantined-files.txt ... 2007-09-29 20:03
C:\ComboFix2.txt ... 2007-09-28 07:38
.
    --- E O F ---
Avatar billede fromsej Praktikant
29. september 2007 - 20:41 #21
Har du gjort det jeg foreslog 29/09-2007 20:00:14 ?
Avatar billede Slettet bruger
29. september 2007 - 20:48 #22
Ja det har jeg
Avatar billede arlet Juniormester
30. september 2007 - 09:15 #23
Prøv lige en gang til som Fromsej skrev: 29/09-2007 20:00:14

ellers må vi ty til andre værktøjer
Avatar billede Slettet bruger
30. september 2007 - 11:59 #24
en gang til som Fromsej skrev: 29/09-2007 20:00:14

Ny ComboFix.txt (der er også en der hedder ComboFix-quarantined-files.txt)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ComboFix 07-09-21.2 - "Kiki Neelam" 2007-09-30 11:44:57.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.605 [GMT 2:00]
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
C:\DOCUME~1\KIKINE~1\APPLIC~1\32chichope
C:\DOCUME~1\KIKINE~1\APPLIC~1\32chichope\5A01C95D

.
(((((((((((((((((((((((((  Files Created from 2007-08-28 to 2007-09-30  )))))))))))))))))))))))))))))))
.

2007-09-30 10:04    <DIR>    d--------    C:\Program Files\jv16 PowerTools
2007-09-29 17:54    <DIR>    d--------    C:\Install
2007-09-28 07:31    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-09-28 05:39    <DIR>    d--------    C:\Program Files\UnH Solutions
2007-09-28 05:39    <DIR>    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\UnH Solutions
2007-09-27 22:01    <DIR>    d--------    C:\Program Files\HDCleaner
2007-09-27 18:44    <DIR>    d--------    C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 16:31    <DIR>    d--------    C:\DOCUME~1\ADMINI~1\DoctorWeb
2007-09-27 16:24    <DIR>    d--------    C:\Program Files\SUPERAntiSpyware
2007-09-27 16:24    <DIR>    d--------    C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 16:24    <DIR>    d--------    C:\DOCUME~1\KIKINE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 16:24    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-27 15:25    95,608    --a------    C:\WINDOWS\system32\AvastSS.scr
2007-09-27 15:25    94,416    --a------    C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-27 15:25    92,848    --a------    C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-27 15:25    801,144    --a------    C:\WINDOWS\system32\aswBoot.exe
2007-09-27 15:25    42,912    --a------    C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-27 15:25    26,624    --a------    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-27 15:25    23,152    --a------    C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-27 15:25    <DIR>    d--------    C:\Program Files\Alwil Software
2007-09-27 14:08    <DIR>    d--------    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-27 13:34    <DIR>    d--------    C:\WINDOWS\pss
2007-09-27 11:42    <DIR>    d--------    C:\WINDOWS\Twain32
2007-09-27 11:04    <DIR>    d--------    C:\Program Files\MSXML 6.0
2007-09-27 11:01    <DIR>    d--------    C:\Program Files\MSBuild
2007-09-27 10:58    <DIR>    d--------    C:\WINDOWS\system32\XPSViewer
2007-09-27 10:58    <DIR>    d--------    C:\Program Files\Reference Assemblies
2007-09-27 10:57    14,048    ---------    C:\WINDOWS\system32\spmsg2.dll
2007-09-27 10:57    <DIR>    d--------    C:\b94951b1bee1c07ea0e6
2007-09-27 10:49    36,352    ---------    C:\WINDOWS\system32\tsgqec.dll
2007-09-27 10:49    288,768    ---------    C:\WINDOWS\system32\rhttpaa.dll
2007-09-27 10:49    116,736    ---------    C:\WINDOWS\system32\aaclient.dll
2007-09-27 10:30    33,792    --a------    C:\WINDOWS\system32\dllcache\custsat.dll
2007-09-27 08:59    <DIR>    d--------    C:\Program Files\CCleaner
2007-09-27 08:36    21,504    --a------    C:\WINDOWS\system32\hidserv.dll
2007-09-27 08:36    21,504    --a------    C:\WINDOWS\system32\dllcache\hidserv.dll
2007-08-22 11:29    <DIR>    d--h-----    C:\_rpcs
2007-08-12 10:55    70,144    --a------    C:\WINDOWS\system32\Winerr32.dll
2007-08-12 10:55    40,960    --a------    C:\WINDOWS\system32\Mfc40loc.dll
2007-08-12 10:55    26,768    --a------    C:\WINDOWS\system32\Ctl3d.dll
2007-08-12 10:55    13,312    --a------    C:\WINDOWS\system32\Wwspell.dll
2007-08-12 10:53    <DIR>    d--------    C:\Polob32
2007-08-12 10:52    302,080    --a------    C:\WINDOWS\unin0406.exe
2007-08-12 10:52    <DIR>    d--------    C:\DOCUME~1\KIKINE~1\WINDOWS
2007-08-04 12:31    10,344    --a------    C:\WINDOWS\system32\drivers\symlcbrd.sys

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-27 17:06    ---------    d--------    C:\Program Files\Common Files\Sonic Shared
2007-09-27 11:41    ---------    d--------    C:\Program Files\microsoft frontpage
2007-09-06 12:00    26624    --a------    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-04 14:51    ---------    d--------    C:\Program Files\XTNDConnect PC
2007-08-04 14:51    ---------    d--------    C:\Program Files\NetWaiting
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19    92504    --a------    C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19    549720    --a------    C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19    53080    --a------    C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19    43352    --a------    C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19    325976    --a------    C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19    271224    --a------    C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19    207736    --a------    C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19    203096    --a------    C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19    1712984    --a------    C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\wups.dll
2007-07-30 19:18    33624    --a------    C:\WINDOWS\system32\dllcache\wups.dll
2007-07-19 08:59    3583488    --a------    C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 01:31    765952    --a------    C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 16:34    823808    --a------    C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 16:34    671232    --a------    C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 16:34    6058496    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 16:34    52224    ---------    C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 16:34    477696    --a------    C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 16:34    459264    ---------    C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 16:34    44544    ---------    C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 16:34    384512    ---------    C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 16:34    383488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 16:34    27648    --a------    C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 16:34    267776    ---------    C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 16:34    232960    ---------    C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 16:34    230400    ---------    C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 16:34    193024    --a------    C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 16:34    153088    ---------    C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 16:34    132608    --a------    C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 16:34    124928    ---------    C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 16:34    1152000    --a------    C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 16:34    105984    ---------    C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 16:34    102400    ---------    C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 10:27    63488    ---------    C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 10:27    625152    ---------    C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 10:27    13824    ---------    C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 09:00    161792    ---------    C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 08:08    1104896    --a------    C:\WINDOWS\system32\msxml3.dll
2007-06-26 08:08    1104896    ---------    C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 15:31    282112    --a------    C:\WINDOWS\system32\gdi32.dll
2007-06-19 15:31    282112    ---------    C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-15 18:04    108144    --a------    C:\WINDOWS\system32\CmdLineExt.dll
2007-06-15 10:12    474112    ---------    C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-15 10:12    151040    ---------    C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-15 10:12    1498112    ---------    C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-15 10:12    1054208    ---------    C:\WINDOWS\system32\dllcache\danim.dll
2007-06-15 10:12    1022976    ---------    C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-13 12:23    1033216    --a------    C:\WINDOWS\explorer.exe
2007-06-13 12:23    1033216    ---------    C:\WINDOWS\system32\dllcache\explorer.exe
2005-09-24 08:49    12288    --a------    C:\WINDOWS\Fonts\RandFont.dll
2007-04-22 19:03:29    22    --sha-w    C:\WINDOWS\SMINST\HPCD.sys
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 21:56]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 22:58]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 21:03]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 10:00]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-18 10:00]
"nwiz"="nwiz.exe" [2006-08-18 10:00 C:\WINDOWS\system32\nwiz.exe]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 11:33]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 16:02]
"XTNDConnect PC - ErPhn2"="C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe" [2003-02-13 09:41]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 07:01]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 10:23]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-11 21:55]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 02:02 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 16:19]
"ArtoNotifier"="C:\Program Files\Arto\Notifier\ArtoNotifier.exe" [2006-10-10 17:33]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-01-10 15:14]
"IE Privacy Keeper"="C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" [2005-12-03 14:52]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-16 06:00]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Hurtigstart.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
HP Photosmart Premier Hurtig start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 09:39:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2006-10-19 09:12 258048 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R2 MSMQ;Message Queuing;C:\WINDOWS\system32\mqsvc.exe
R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\system32\mqtgsvc.exe
R3 HBtnKey;HBtnKey;C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\system32\drivers\mqac.sys
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys
R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\system32\drivers\RMCast.sys
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam  ;C:\WINDOWS\system32\Drivers\5U870CAP.sys
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys
S3 P1120VID;Creative WebCam NX Ultra;C:\WINDOWS\system32\DRIVERS\P1120Vid.sys
S4 viaagp;VIA AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\viaagp.sys

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-30 11:46:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????<?@? ???hV??????Y?@?????<?@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Aavmker4]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\viaagp]
"ImagePath"="\SystemRoot\system32\DRIVERS\viaagp.sys"
.
Completion time: 2007-09-30 11:47:14
C:\ComboFix-quarantined-files.txt ... 2007-09-30 11:47
.
    --- E O F ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Ny hijackthis.log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:51:56, on 30-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Arto\Notifier\ArtoNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SONYER~1\MOBILE~1\EPMWOR~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Kiki Neelam\Desktop\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [XTNDConnect PC - ErPhn2] C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ArtoNotifier] C:\Program Files\Arto\Notifier\ArtoNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [IE Privacy Keeper] "C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Hurtig start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?dfe531e1fde14a5d8a96c549aabdf80a
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?dfe531e1fde14a5d8a96c549aabdf80a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O24 - Desktop Component 0: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed660/yg91.gif
O24 - Desktop Component 1: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed660/yg97.gif
O24 - Desktop Component 2: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed660/yg79.gif
O24 - Desktop Component 3: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed440/gem76.gif
O24 - Desktop Component 4: (no name) - http://www.ani3.dk/kaerlighed02/kaerlighed440/new4b.gif

--
End of file - 9633 bytes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Avatar billede fromsej Praktikant
30. september 2007 - 13:50 #25
Der dukker mere og mere op, efterhånden som vi får has på noget af det, hmmm.
Spørgsmålet er om en OMèr ville være at foretrække?

Upload disse filer hos Jotti eller Virustotal:
C:\WINDOWS\system32\Winerr32.dll
C:\WINDOWS\system32\Mfc40loc.dll
C:\WINDOWS\system32\Ctl3d.dll
C:\WINDOWS\system32\Wwspell.dll
http://virusscan.jotti.org/ http://www.virustotal.com/en/indexf.html
Fortæl resultatet.
Avatar billede Slettet bruger
30. september 2007 - 14:45 #26
Fra http://virusscan.jotti.org/

Winerr32.dll - Found nothing
Mfc40loc.dll - Found nothing
Ctl3d.dll - Found nothing
Wwspell.dll - Found nothing

Ja men skal vi ikke bare sige at det er ok som det er nu og så se hvad tiden bringer af problemer, bare der ikke er noget tilbage af det ulovlige
Avatar billede fromsej Praktikant
30. september 2007 - 15:26 #27
Fix denne med Hijackthis:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Så er der ikke mere synligt i nogle af logfilerne.
Avatar billede Slettet bruger
30. september 2007 - 15:34 #28
Er slettet
Tak for hjælpen

Må jeg afsætte et nyt spm. med point til dig ?
Avatar billede arlet Juniormester
30. september 2007 - 15:43 #29
ibtage-> Nej, det må du ikke*S*

Fromsej får af mig i stedet for, for hans indsats..
Avatar billede arlet Juniormester
30. september 2007 - 15:45 #30
Fromsej kan hente sine velfortjente point her: http://www.eksperten.dk/spm/798858
Avatar billede Slettet bruger
30. september 2007 - 15:47 #31
Ja.... det er jo så dit valg, men mange tak for hjælpen endnu engang
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester