Avatar billede magkat Novice
30. oktober 2007 - 18:08 Der er 14 kommentarer og
1 løsning

pop up "søgeresultater"

hej sa 
jeg har fået et problem ...når jeg surfer så popper der hele tiden ruder op med søgeresulteter ...som jeg søger noget på min egen pc...der poppede 32 op bare for at jeg kom på her...det er noget træls og tager tid og pc styrke ...håber det er noget man kan fixe .....jeg ar prøvet med ad aware og xoftspyse.....
Avatar billede arlet Juniormester
30. oktober 2007 - 18:23 #1
Lad ccleaner lave en oprydning : www.arlet.dk/ccleaner.htm

Kør trin 1 her http://www.malwarecheck.dk/forum/viewtopic.php?t=11 og læg loggen ind

derudover skal du hente:
Combofix fra et af disse links, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

-- Kør så combofix.exe, som du hentede tidligere, og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.

BEMÆRK at Combofix af nogle virusscannere bliver detekteret som inficeret. Dette har dog intet på sig.
Avatar billede magkat Novice
31. oktober 2007 - 07:08 #2
ComboFix 07-10-29.1** - Finn 2007-10-31  6:53:37.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.78 [GMT 1:00]
Running from: C:\Documents and Settings\Finn\Lokale indstillinger\Temporary Internet Files\Content.IE5\LR5I6EZX\ComboFix[1].exe
* Created a new restore point
.

(((((((((((((((((((((((((  Files Created from 2007-09-28 to 2007-10-31  )))))))))))))))))))))))))))))))
.

2007-10-31 06:51    51,200    --a------    C:\WINDOWS\NirCmd.exe
2007-10-30 20:24    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-30 20:23    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-10-30 20:23    <DIR>    d--------    C:\Programmer\Fælles filer\Wise Installation Wizard
2007-10-30 20:23    <DIR>    d--------    C:\Documents and Settings\Finn\Application Data\SUPERAntiSpyware.com
2007-10-30 20:01    <DIR>    d--------    C:\Programmer\CCleaner
2007-10-11 08:34    582,656    -----c---    C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-09-27 20:22    <DIR>    d--------    C:\Programmer\TrackMania Nations ESWC
2007-09-04 21:44    <DIR>    d--------    C:\Documents and Settings\Finn\Phone Browser

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-30 19:07    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-30 15:55    ---------    d-----w    C:\Programmer\XoftSpySE
2007-10-07 14:51    ---------    d-----w    C:\Programmer\Norton Utilities
2007-10-06 07:04    ---------    d-----w    C:\Programmer\Google
2007-09-13 21:20    ---------    d-----w    C:\Programmer\MSN Messenger
2007-09-10 18:51    ---------    d-----w    C:\Programmer\Avast antivirus
2007-09-07 15:32    ---------    d-----w    C:\Documents and Settings\Finn\Application Data\Skype
2007-09-06 10:09    801,144    ----a-w    C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:05    94,416    ----a-w    C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05    92,848    ----a-w    C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03    23,152    ----a-w    C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02    42,912    ----a-w    C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00    95,608    ----a-w    C:\WINDOWS\system32\AVASTSS.scr
2007-09-06 10:00    26,624    ----a-w    C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-21 06:17    683,520    ----a-w    C:\WINDOWS\system32\inetcomm.dll
2007-07-30 17:19    92,504    ----a-w    C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19    549,720    ----a-w    C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19    53,080    ----a-w    C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19    43,352    ----a-w    C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19    325,976    ----a-w    C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19    203,096    ----a-w    C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19    1,712,984    ----a-w    C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18    33,624    ----a-w    C:\WINDOWS\system32\wups.dll
2007-07-09 13:19    582,656    ----a-w    C:\WINDOWS\system32\rpcrt4.dll
2007-01-07 15:08    1,035,271    ----a-w    C:\Programmer\wrar362.exe
2007-01-07 13:09    18,046,088    ----a-w    C:\Programmer\tdcnetsupport.exe
2006-02-06 21:12    17,952,344    ----a-w    C:\Programmer\nuvi350_270.exe
2005-12-15 09:58    44,640    ----a-w    C:\Documents and Settings\Finn\Application Data\GDIPFONTCACHEV1.DAT
2004-02-21 11:16    560    ----a-w    C:\Documents and Settings\Finn\PCDOC.BAT
2004-01-16 18:51    6,660,608    ----a-w    C:\Programmer\avg6562fu_free.exe
2003-07-10 16:54    10,504,000    ----a-w    C:\Programmer\stjerne.xxx.txt
2003-07-08 21:38    297,528    ----a-w    C:\Programmer\dxwebsetup.exe
2003-06-17 20:30    3,750,576    ----a-w    C:\Programmer\zaSetup_37_143.exe
2003-05-13 17:07    1,438,467    ----a-w    C:\Programmer\dwyco297.exe
2003-04-16 21:06    16,434,414    ----a-w    C:\Programmer\JMeeting.exe
2003-04-13 16:32    13,263,480    ----a-w    C:\Programmer\AcroReader51_DAN_full.exe
2003-04-13 15:46    9,440,776    ----a-w    C:\Programmer\AcroReader51_DAN.exe
2002-04-26 11:23    49,152    ----a-w    C:\Programmer\PopupKiller.exe
2001-09-15 20:56    258,048    ----a-w    C:\Programmer\SETUP1.EXE
2000-07-14 22:00    73,216    ----a-w    C:\Programmer\ST6UNST.EXE
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-24 09:04]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-03-24 09:04]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2004-07-01 12:33]
"nwiz"="nwiz.exe" [2004-03-24 09:04 C:\WINDOWS\system32\nwiz.exe]
"LVCOMS"="C:\Programmer\Fælles filer\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 16:54]
"LogitechVideoTray"="C:\Programmer\Logitech\Video\LogiTray.exe" [2004-10-08 12:24]
"LogitechVideoRepair"="C:\Programmer\Logitech\Video\ISStart.exe" [2004-10-08 12:31]
"LogitechImageStudioTray"="C:\Programmer\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 17:31]
"LogitechGalleryRepair"="C:\Programmer\Logitech\ImageStudio\ISStart.exe" [2002-12-10 17:32]
"C-Media Mixer"="Mixer.exe" [2002-10-15 17:00 C:\WINDOWS\mixer.exe]
"avast!"="C:\PROGRA~1\AVASTA~1\ashDisp.exe" [2007-09-06 11:06]
"TkBellExe"="C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" [2006-05-03 22:20]
"PCSuiteTrayApplication"="C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WebCamRT.exe"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 01:53]
"Eyeball Chat"="C:\Programmer\Eyeball\Eyeball Chat\EyeballChat.exe" [2002-10-11 14:52]
"Yahoo! Pager"="C:\Programmer\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 13:08]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
S3 Amps2prt;Addison Technology PS/2 Port Mouse Driver;C:\WINDOWS\system32\DRIVERS\Amps2prt.sys
S3 NtApm;NT Apm/Ældre grænsefladedriver;C:\WINDOWS\system32\DRIVERS\NtApm.sys

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-31 03:07:01 C:\WINDOWS\Tasks\Symantec NetDetect.job"
"2007-06-12 20:26:49 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Programmer\XoftSpySE\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-31 06:57:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
"ServiceDll"="%SystemRoot%\System32\browser.dll"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\C:]
.
Completion time: 2007-10-31  6:58:53
.
    --- E O F ---
Avatar billede arlet Juniormester
31. oktober 2007 - 07:36 #3
Mangler: Kør trin 1 her http://www.malwarecheck.dk/forum/viewtopic.php?t=11 og læg loggen ind

derudover vil jeg gerne se en hijackthis log: http://www.malwarecheck.dk/forum/viewtopic.php?t=9
Avatar billede magkat Novice
31. oktober 2007 - 08:28 #4
Den er kørt 2 gange ...tog lidt længere en jeg havde regnet med*S*


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/31/2007 at 00:42 AM

Application Version : 3.9.1008

Core Rules Database Version : 3333
Trace Rules Database Version: 1334

Scan type      : Complete Scan
Total Scan Time : 02:08:50

Memory items scanned      : 503
Memory threats detected  : 0
Registry items scanned    : 6283
Registry threats detected : 0
File items scanned        : 42734
File threats detected    : 25

Adware.Tracking Cookie
    C:\Documents and Settings\Finn\Cookies\finn@atdmt[3].txt
    C:\Documents and Settings\Finn\Cookies\finn@adtech[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@track.adform[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@ad.ofir[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@doubleclick[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@ad1.emediate[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@tradedoubler[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@advertising[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@mediaplex[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@imrworldwide[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@ad.ofir[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@ad1.emediate[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@adtech[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@advertising[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@atdmt[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@doubleclick[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@imrworldwide[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@mediaplex[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@sexkanaler[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@track.adform[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@tradedoubler[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@tribalfusion[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@www.liderligporno[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@www.sex-sex-sex[1].txt

Adware.Casino Games (Golden Palace Casino)
    C:\PROGRAMMER\CASINO ELEGANCE\CASINO.EXE


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/30/2007 at 10:33 PM

Application Version : 3.9.1008

Core Rules Database Version : 3333
Trace Rules Database Version: 1334

Scan type      : Complete Scan
Total Scan Time : 00:00:06

Memory items scanned      : 0
Memory threats detected  : 0
Registry items scanned    : 0
Registry threats detected : 0
File items scanned        : 0
File threats detected    : 0


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/30/2007 at 10:11 PM

Application Version : 3.9.1008

Core Rules Database Version : 3333
Trace Rules Database Version: 1334

Scan type      : Complete Scan
Total Scan Time : 01:44:46

Memory items scanned      : 488
Memory threats detected  : 0
Registry items scanned    : 6283
Registry threats detected : 0
File items scanned        : 13636
File threats detected    : 23

Adware.Tracking Cookie
    C:\Documents and Settings\Finn\Cookies\finn@atdmt[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@adtech[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@track.adform[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@doubleclick[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@ad1.emediate[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@advertising[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@mediaplex[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@imrworldwide[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@ad.ofir[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@ad1.emediate[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@adtech[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@advertising[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@atdmt[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@doubleclick[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@imrworldwide[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@mediaplex[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@sexkanaler[2].txt
    C:\Documents and Settings\Finn\Cookies\finn@track.adform[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@tradedoubler[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@tribalfusion[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@www.liderligporno[1].txt
    C:\Documents and Settings\Finn\Cookies\finn@www.sex-sex-sex[1].txt

Adware.Casino Games (Golden Palace Casino)
    C:\PROGRAMMER\CASINO ELEGANCE\CASINO.EXE
Avatar billede magkat Novice
31. oktober 2007 - 08:32 #5
Logfile of HijackThis v1.99.1
Scan saved at 08:31:56, on 31-10-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Avast antivirus\aswUpdSv.exe
C:\Programmer\Avast antivirus\ashServ.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Fælles filer\Logitech\QCDriver3\LVCOMS.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\Mixer.exe
C:\PROGRA~1\AVASTA~1\ashDisp.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Eyeball\Eyeball Chat\EyeballChat.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Avast antivirus\ashMaiSv.exe
C:\Programmer\Avast antivirus\ashWebSv.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\internet explorer\iexplore.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Programmer\Logitech\ImageStudio\LowLight.exe
C:\Programmer\Microsoft Office\Office10\WINWORD.EXE
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Finn\Skrivebord\HI JACK\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ni.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMS] C:\Programmer\Fælles filer\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programmer\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programmer\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\AVASTA~1\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eyeball Chat] "C:\Programmer\Eyeball\Eyeball Chat\EyeballChat.exe" -min
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Programmer\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\programmer\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\programmer\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\programmer\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} - http://netsupport2.tdconline.dk/sdccommon/download/tgctlar.cab
O16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} - http://netsupport2.tdconline.dk/sdccommon/download/tgctlsi.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/dk/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} - http://scanner.virus112.com/cabs/cssweb.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IP-Uploader Control) - http://asp07.photoprintit.de/microsite/10021/defaults/activex/ImageUploader3.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - http://chat.msn.com/controls/msnchat45.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Avast antivirus\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Avast antivirus\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Avast antivirus\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Avast antivirus\ashWebSv.exe" /service (file missing)
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Programmer\Speed Disk\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
Avatar billede magkat Novice
31. oktober 2007 - 08:34 #6
********************************* ROOTCHK-(21-09-07)-LOG, by ejvindh
31-10-2007  8:33:33,63

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-31 08:33:34
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000001ec

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0
Avatar billede arlet Juniormester
01. november 2007 - 07:30 #7
Du har stadig ikke kørt en hijackthis fra mit link: 31/10-2007 07:36:58

Det er en gammel version af hijackthis, du bruger..

Hvordan kører computeren nu??
Avatar billede magkat Novice
01. november 2007 - 20:53 #8
så skulle den være der*SS*


men puter kører noget bedre end før vi startede alt det her....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:49:36, on 01-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Avast antivirus\aswUpdSv.exe
C:\Programmer\Avast antivirus\ashServ.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Fælles filer\Logitech\QCDriver3\LVCOMS.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\Mixer.exe
C:\PROGRA~1\AVASTA~1\ashDisp.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Eyeball\Eyeball Chat\EyeballChat.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Logitech\ImageStudio\LowLight.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Yahoo!\Messenger\ymsgr_tray.exe
C:\Programmer\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Avast antivirus\ashMaiSv.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\Avast antivirus\ashWebSv.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\HJTrenamed.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ni.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMS] C:\Programmer\Fælles filer\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programmer\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programmer\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\AVASTA~1\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eyeball Chat] "C:\Programmer\Eyeball\Eyeball Chat\EyeballChat.exe" -min
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Programmer\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\programmer\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\programmer\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\programmer\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} - http://netsupport2.tdconline.dk/sdccommon/download/tgctlar.cab
O16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} - http://netsupport2.tdconline.dk/sdccommon/download/tgctlsi.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/dk/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} - http://scanner.virus112.com/cabs/cssweb.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IP-Uploader Control) - http://asp07.photoprintit.de/microsite/10021/defaults/activex/ImageUploader3.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - http://chat.msn.com/controls/msnchat45.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Avast antivirus\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Avast antivirus\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Avast antivirus\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Avast antivirus\ashWebSv.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Programmer\Speed Disk\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 8711 bytes
Avatar billede arlet Juniormester
01. november 2007 - 21:40 #9
Kør Hijackthis, scan, sæt flueben ved linien/linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.

O2 - BHO: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - AutorunsDisabled - (no file)

derefter er der ikke mere snavs..

Du bør lige opdatere dit java, som er forældet. Tjek evt også for opdateringer til dine andre programmer http://www.malwarecheck.dk/forum/viewtopic.php?t=54
Avatar billede magkat Novice
01. november 2007 - 22:10 #10
Så er jeg en meget glad mand ..igen har jeg fået dejlig hjælp herinde tusinde tak for det
Avatar billede magkat Novice
01. november 2007 - 22:51 #11
øhhh hvordan giver jeg dig point ???
Avatar billede arlet Juniormester
02. november 2007 - 07:17 #12
Kør lige trin 5 og 6 herfra: http://www.malwarecheck.dk/forum/viewtopic.php?t=11

Her kan du læse om vores skudsikre sikkerhedspakke: http://www.malwarecheck.dk/forum/viewtopic.php?t=156 .
Hvis du har nogle spørgsmål, så spørger du bare..

Ang point: Du marker mit navn i boksen og accepter
Avatar billede magkat Novice
03. november 2007 - 21:59 #13
punkt 5 og 6 er gjort men det med 6'eren er ikke forstået......og desuden er mit problem vendt tilbage men mest i mit mail program.......ved at skrive en mail på 5 linier...popper den skid...... spørgeskærm og 50 gange......
Avatar billede arlet Juniormester
04. november 2007 - 09:48 #14
Kan du tage et screenshot af problemet eller skrive præcist hvad der står i den spørgeskærm
Avatar billede magkat Novice
04. november 2007 - 17:04 #15
jamen der er som om jeg højre klikker på START og så på SØG ...den skærm popper så op en 40- 50 gange ...i træk og tager al kraft i min pc......man kan godt lukke dem ned men det tager tid meget tid.....
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester