Avatar billede mamloo Nybegynder
28. december 2007 - 22:08 Der er 22 kommentarer og
2 løsninger

Hjælp med at ordne min pcer

Hej!
Jeg har lidt bøvl med min pc´er(popups),og håber at en af jer kvikke hoveder kan hjælpe mig:)

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:07:50, on 28-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Get-Torrent\wakeservice.exe
C:\Programmer\HPQ\Shared\hpqwmi.exe
C:\Programmer\MSN Messenger\usnsvc.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q305&bd=pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Option Bib Logo Log] C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB\Jugs Dash.exe
O4 - HKCU\..\Run: [Drawmath] C:\DOCUME~1\TANGGA~1.PAV\APPLIC~1\BROWSE~1\Copypeak1.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://frbsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparlolland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (Snapfish Drag and Drop upload plugin) - http://www.pixaco.dk/static/download/pixacodndupload.cab
O16 - DPF: {4445EA6A-9008-40D5-9160-035FDE5214C4} (MultiUpload Class) - http://www.123hjemmeside.dk/builder/pages/Mpu-dk-1-0-0-8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://frbsrv02.udd.sembsc.dk/dwa7W.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\Shared\hpqwmi.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7664 bytes
28. december 2007 - 22:20 #1
Der er allerede flere synlige (U)ønskede elementer i din log...
... Nu er det ikke alle (u)ønskede elementer som viser sig med en HiJackThis Log; hvis du har 'mod' på det så gennemfør proceduren herfra -> http://www.eksperten.dk/artikler/1123
Avatar billede gurly Praktikant
28. december 2007 - 23:50 #2
hvorfor fik du aldrig uddelt point i dette her spørgsmål ?
http://www.eksperten.dk/spm/790617
selv om du havde fået hjælp / brugbart svar, så accepterede du aldrig svaret !
pudsigt nok er det jo karise_larry du skylder lidt point
men det er aldrig for sent at se at få accepteret svaret så han får sine point  c",)
Avatar billede mamloo Nybegynder
29. december 2007 - 18:28 #3
Tak, for påmindelsen qurly! ;) Karise larry jeg er dig evig taknemlig, for al den hjælp jeg har fået indtil videre!
29. december 2007 - 20:06 #4
... og så fortsætter vi her ikk' ?

http://www.eksperten.dk/artikler/1123
Avatar billede mamloo Nybegynder
29. december 2007 - 20:49 #5
Super. Her er de forskellige logs! ;)

Logfile of HijackThis v1.99.1
Scan saved at 20:25:51, on 29-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\HPQ\Shared\hpqwmi.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\alternativ.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q305&bd=pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Option Bib Logo Log] C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB\Jugs Dash.exe
O4 - HKCU\..\Run: [Drawmath] C:\DOCUME~1\TANGGA~1.PAV\APPLIC~1\BROWSE~1\Copypeak1.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://frbsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparlolland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (Snapfish Drag and Drop upload plugin) - http://www.pixaco.dk/static/download/pixacodndupload.cab
O16 - DPF: {4445EA6A-9008-40D5-9160-035FDE5214C4} (MultiUpload Class) - http://www.123hjemmeside.dk/builder/pages/Mpu-dk-1-0-0-8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://frbsrv02.udd.sembsc.dk/dwa7W.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\Shared\hpqwmi.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe




********************************* ROOTCHK-(28-12-07)-LOG, by ejvindh
l› 29-12-2007 20:27:43,31

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-29 20:27:44
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\\24\xe1\21]
"DisplayName"="\xdbe0\x3a4\xdbe0\x3a4\1"
"DeviceDesc"="\xdbe0\x3a4\xdbe0\x3a4\1"
"ProviderName"="\xfed4\21\xee18\x7c90\xff44\21\b"
"MFG"="\x558"
"ReinstallString"="C:\WINDOWS\System32\ReinstallBackups\\xe114\21\x80\xc010\DriverFiles\.INF"
"DeviceInstanceIds"=str(7):"d:\swsetup\video\sbdrv\smbus\smbusati.inf"

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0




ComboFix 07-12-21.4 - Tanggaard Wulff 2007-12-29 20:31:01.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.572 [GMT 1:00]
Running from: C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\ComboFix.exe
* Created a new restore point
.

(((((((((((((((((((((((((  Files Created from 2007-11-28 to 2007-12-29  )))))))))))))))))))))))))))))))
.

2007-12-29 19:34 . 2007-12-29 19:34    <DIR>    d--------    C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Skrivebord
2007-12-29 19:29 . 2007-03-14 19:44    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Skabeloner
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Printere
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    dr-------    C:\Documents and Settings\Administrator\Menuen Start
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Lokale indstillinger
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Foretrukne
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Dokumenter
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Andre computere
2007-12-29 19:22 . 2007-12-29 20:29    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-12-29 19:22 . 2007-12-29 19:22    <DIR>    d--------    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\SUPERAntiSpyware.com
2007-12-29 19:22 . 2007-12-29 19:22    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2007-12-27 23:34 . 2007-12-27 23:34    <DIR>    d--------    C:\Programmer\Browsefirstbird
2007-12-27 23:34 . 2007-12-27 23:34    <DIR>    d--------    C:\My Downloads
2007-12-27 23:34 . 2007-12-27 23:34    <DIR>    d--------    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Browsefirstbird
2007-12-27 23:34 . 2007-12-27 23:34    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB
2007-12-07 21:47 . 2007-12-07 21:47    0    --a------    C:\WINDOWS\iPlayer.INI

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-29 18:22    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2007-12-29 16:41    ---------    d-----w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\AVG7
2007-12-28 21:19    ---------    d-----w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus
2007-12-28 18:46    ---------    d-----w    C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-12-28 08:14    ---------    d-----w    C:\Programmer\HAM
2007-12-27 17:36    ---------    d-----w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\AdobeUM
2007-11-19 21:00    149,685    ----a-w    C:\WINDOWS\HAM Uninstaller.exe
2007-11-13 10:25    20,480    ----a-w    C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:44    1,291,776    ----a-w    C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28    222,720    ----a-w    C:\WINDOWS\system32\wmasf.dll
2007-04-10 11:59    46,608    ----a-w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\GDIPFONTCACHEV1.DAT
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Drawmath"="C:\DOCUME~1\TANGGA~1.PAV\APPLIC~1\BROWSE~1\Copypeak1.exe" [2007-12-27 23:34]
"msnmsgr"="C:\Programmer\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 13:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 21:05]
"Cpqset"="C:\Programmer\HPQ\Default Settings\cpqset.exe" [2005-02-17 14:01]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 13:12]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 13:11]
"eabconfg.cpl"="C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 13:24]
"hpWirelessAssistant"="C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 15:21]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 15:28]
"LogitechCommunicationsManager"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 00:12]
"LVCOMSX"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe" [2007-02-06 16:43]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-03-14 20:21]
"Option Bib Logo Log"="C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB\Jugs Dash.exe" [2007-12-29 20:23]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-23 20:57]
29. december 2007 - 23:07 #6
Joooo - der er nogle sjove (?) elementer ifølge ovenstående ...

Lader denne tygge på det (først) ->

Download http://siri.urz.free.fr/Fix/SmitfraudFix.exe (by S!Ri)
Til roden af C:\

Genstart i fejlsikret tilstand, hvis du ikke ved hvordan så kig her:
http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm

Dobbeltklik på C:\Smitfraud.exe. Vælg punkt [2]. Lad programmet gennemføre en rensning. Det vil også checke om systemfilen wininet.dll er inficeret. Hvis den er det, vil du blive bedt om tilladelse til at erstatte den med en anden. Her skal du vælge "Yes", ved at taste "y".

Programmet bliver muligvis nødt til at genstarte undervejs. Herefter vil der dukke en liste med resultaterne af rensningen op . Kopiér denne liste ind i tråden.

Genstart og læg en frisk Hijackthislog herind, loggen fra SmitfraudFix (C:\rapport.txt) og fortæl hvordan computeren kører.

NB: Filen "process.exe" som ligger i dette værktøj bliver af visse antivirus-programmer identificeret som "RiskTool". Det har dog ikke noget på sig!
29. december 2007 - 23:09 #7
Du har vist også på et tidspunkt haft gang i [Azureus] og lign. programmer -> *SUK*
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=40284
Avatar billede mamloo Nybegynder
30. december 2007 - 20:02 #8
Tænkte nok det var nogle "sjove" elementer, ingen af mine programmer kunne få bugt med dem!! ;)Der kommer stadig popups og den kører ikke super godt endnu!

SmitFraudFix v2.274

Scan done at 16:36:43,68, s› 30-12-2007
Run from C:\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1  localhost
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5C5A125C-A92B-4C80-934E-677C77D8280D}: DhcpNameServer=212.242.40.3 212.242.40.51
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5C5A125C-A92B-4C80-934E-677C77D8280D}: DhcpNameServer=212.242.40.3 212.242.40.51
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5C5A125C-A92B-4C80-934E-677C77D8280D}: DhcpNameServer=212.242.40.3 212.242.40.51
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.242.40.3 212.242.40.51
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.242.40.3 212.242.40.51
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.242.40.3 212.242.40.51


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


Logfile of HijackThis v1.99.1
Scan saved at 20:00, on 30-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\internet explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\HPQ\Shared\hpqwmi.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\alternativ.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Option Bib Logo Log] C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB\Jugs Dash.exe
O4 - HKCU\..\Run: [Drawmath] C:\DOCUME~1\TANGGA~1.PAV\APPLIC~1\BROWSE~1\Copypeak1.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://frbsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparlolland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (Snapfish Drag and Drop upload plugin) - http://www.pixaco.dk/static/download/pixacodndupload.cab
O16 - DPF: {4445EA6A-9008-40D5-9160-035FDE5214C4} (MultiUpload Class) - http://www.123hjemmeside.dk/builder/pages/Mpu-dk-1-0-0-8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://frbsrv02.udd.sembsc.dk/dwa7W.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\Shared\hpqwmi.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Avatar billede mamloo Nybegynder
30. december 2007 - 20:11 #9
Du falder også over alt, og det er absolut også sidste gang jeg installerer sådanne programmer;) Hvordan sletter jeg de resterende filer fra Azureus???
Avatar billede fromsej Praktikant
30. december 2007 - 21:45 #10
Det undrer mig lidt at SuperAntiSpyware ikke har pelset Lop, huskede du at opdatere, inden du scannede med den?

Hent Ccleaner her:
http://www.filehippo.com/download_ccleaner/
Installer Ccleaner, husk at fjerne fluebenet udfor installation af Yahoo toolbar.
Start programmet, fjern fluebenet i cookies.
Klik på kør Cleaner og lad den fjerne hvad den finder.
Klik så på Register ovre i venstre side (den blå terning), klik på Skan efter problemer, når den er færdig, klik på Udbedre valgte problemer, lav evt. en backup af registreringsdatabasen, klik så på udbedre alle valgte problemer.
Klik på OK, klik på Luk når den er færdig.
Genstart.
---------------------------------------
Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

---------------------------------------
Kopiér indholdet mellem de bølgede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt. Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

Killall::

Folder::
C:\Programmer\Browsefirstbird
"C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Browsefirstbird"
"C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB"
"C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus"

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Drawmath"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Option Bib Logo Log"=-

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
---------------------------------------
Vi skal se en frisk hijackthislog, samt den nye combofixlog.
Avatar billede mamloo Nybegynder
01. januar 2008 - 14:04 #11
Godt nytår! Det tog sindsygt lang tid for at køre combofix over et døgn!!! her er de nye logs.

Logfile of HijackThis v1.99.1
Scan saved at 14:01, on 1-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\HPQ\Shared\hpqwmi.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\alternativ.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://frbsrv03.udd.sembsc.dk/qp2.cab
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparlolland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (Snapfish Drag and Drop upload plugin) - http://www.pixaco.dk/static/download/pixacodndupload.cab
O16 - DPF: {4445EA6A-9008-40D5-9160-035FDE5214C4} (MultiUpload Class) - http://www.123hjemmeside.dk/builder/pages/Mpu-dk-1-0-0-8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://frbsrv02.udd.sembsc.dk/dwa7W.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\Shared\hpqwmi.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programmer\fælles filer\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


ComboFix 07-12-21.4 - Tanggaard Wulff 2007-12-31 10:24:59.3 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.666 [GMT 1:00]
Running from: C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\CFScript.txt
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB
C:\Documents and Settings\All Users.WINDOWS\Application Data\LICENSE ADMIN OPTION BIB\Jugs Dash.exe
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\.certs
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\.keystore
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\.lock
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\0EBC38B09278DDF60FE14631A2079DF3336ECB33.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\0EBC38B09278DDF60FE14631A2079DF3336ECB33.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\1C672DCE4BE5656F278AE4C12D0F3EC3851A6A23.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\1C672DCE4BE5656F278AE4C12D0F3EC3851A6A23.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\2ABE2B873E48ABEED19B16B9389ED75BDDDEDF14.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\2ABE2B873E48ABEED19B16B9389ED75BDDDEDF14.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\3606102B7130002C3275C25D280FB23D2442B087.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\3606102B7130002C3275C25D280FB23D2442B087.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\4E8057DD6639FFDDF5B80ABAB0151D1B5190EF54.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\4E8057DD6639FFDDF5B80ABAB0151D1B5190EF54.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\5630D88F7142A5577FD3D88F15347CB6BB44B27B.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\5630D88F7142A5577FD3D88F15347CB6BB44B27B.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\69BC0E57283F601A6B09663C7C9C4C100554BAB7.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\69BC0E57283F601A6B09663C7C9C4C100554BAB7.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\6EDC718F14CC6E718C456E7C9CCEA40C00E1F801.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\6EDC718F14CC6E718C456E7C9CCEA40C00E1F801.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\76C0929C3AB46C3946A5213852FB4009159E1F97.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\76C0929C3AB46C3946A5213852FB4009159E1F97.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile0.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile1.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile10.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile11.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile12.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile13.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile14.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile15.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile2.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile3.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile4.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile5.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile7.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile8.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B22AA35F87CB01D974BBB26DF607CDF7BF3AD60\fmfile9.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B8DD66D3DDD01F62C166A4686CF0D1DEF2D06B5.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\7B8DD66D3DDD01F62C166A4686CF0D1DEF2D06B5.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\8B9C97EA8019EC38A22BD56E6B7A0455401A60C8.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\8B9C97EA8019EC38A22BD56E6B7A0455401A60C8.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\8EA2F5F997971BEF18E0A19FDBC29E900AFF6B2B.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\8EA2F5F997971BEF18E0A19FDBC29E900AFF6B2B.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\983BA97570B6EDA1916145208FC632BEE988C882.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\983BA97570B6EDA1916145208FC632BEE988C882.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\9E4D984B53EA9E5E6CF3FCD7B97217502C0A3E53.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\9E4D984B53EA9E5E6CF3FCD7B97217502C0A3E53.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\B38965736335C9A617A4321374FA39892E96E1CE.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\B38965736335C9A617A4321374FA39892E96E1CE.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\B7FE4F8CDC90E8621E8593D0894DFD6F41E6AD65.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\B7FE4F8CDC90E8621E8593D0894DFD6F41E6AD65.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\BD1871E3D0E2F2D5C8D2A28660D57C44C85D1FEC.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\BD1871E3D0E2F2D5C8D2A28660D57C44C85D1FEC.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\C579D7D58E6A7272CB8D683C00E765BBD159FC41.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\C579D7D58E6A7272CB8D683C00E765BBD159FC41.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\cache.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\CBED9363554F7378BDDBFD0EC0B1040103E5E156.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\CBED9363554F7378BDDBFD0EC0B1040103E5E156.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\CCCF774EB3FD2676D3AACF4409D8BCAC1AAA850E.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\CCCF774EB3FD2676D3AACF4409D8BCAC1AAA850E.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\D98AB3BD902FBA4BADF13E16B226379FF798F8E1.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\D98AB3BD902FBA4BADF13E16B226379FF798F8E1.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\DC5F1794BA0C0DC22CAD148C493EEC559A7A624C.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\active\DC5F1794BA0C0DC22CAD148C493EEC559A7A624C.dat.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\azureus.config
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\azureus.config.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\azureus.statistics
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\azureus.statistics.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\banips.config
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\banips.config.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\debug.zip
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\debug\evidence.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\debug\image-0.jpg
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\debug\usermessage.txt
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\dht\addresses.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\dht\contacts.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\dht\diverse.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\dht\general.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\dht\version.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\downloads.config
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\downloads.config.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\ipfilter.cache
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\alerts_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\AutoSpeed_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\debug_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\debug_2.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_alerts_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_AutoSpeed_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_debug_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_debug_2.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_seltrace_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_SpeedMan_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_thread_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\save\1198264663734_thread_2.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\seltrace_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\seltrace_2.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\SpeedMan_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\thread_1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\logs\thread_2.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\net\pm_6785.dat
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.jar
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.zip
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.jar
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.zip
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\plugins\azupnpav\plugin.properties
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.3
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.7
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\sharing.config
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\sharing.config.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tmp\AZU9157.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tmp\AZU9158.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tmp\AZU9159.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tmp\AZU9160.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tmp\AZU9161.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tmp\AZU9162.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tmp\AZU9163.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[Dance_2007]__Rihanna-Umbrella_(Seamus_Haji_and_Paul_Emanuel_Rad.3737037.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[Dance_2007]__Rihanna-Umbrella_(Seamus_Haji_and_Paul_Emanuel_Radio_Edit_ft._Jay-Z)__-mininova.org-_[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[Demonoid.com]-50_Cent_Guess_Who's_Back_[Covers_Tagged]_656388.1444[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_300.avi[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_300.DVDSCR.XViD-NEPTUNE[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_398e7c985940bf1d3365cfbae2d9be1e48c22336[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Alex_feat._Nik__Jay_Hvad_Nu_Hvis.mp3[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Alex_Feat._Nik_Og_Jay_-_Hvad_nu_Hvis.mp3[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Anden_P___Coke_.3568436.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Bee.Movie.[2007.Eng].TS.DivX-LTT.3887489.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Den.Sorte.Madonna.READ.NFO.DVDSCR.DANISH.PAL.DVDR-ByMe[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Eastern_Promises[2007]DvDrip[Eng]-FXG[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Fall_Out_Boy_-_Infinity_on_High___(Full_Album).rar.3716597.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Good_Charlotte_-_Good_Morning_Revival_[2007][www.emwreloaded.com][1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Interpol[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Keane_-_Little_Broken_Words_(2007)[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Lidt_god_dansk_rap.3786394.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Linkin_Park_-_Live_Earth_2007[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Magtens_Korridorer_-_Frivaerdi_DK_2005.1354065.SN[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Mere_dansk..__Suspekt_-_Prima_Notce_(prerelease).3748487.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Natasja-_-_I_Danmark_Er_Jeg_Fodt_2007.1263235.SN[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Nephew_feat_L.O.C._-_Hospital_(Live_fra_Roskilde_07.07.07).mp3[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Poul_Potts_-_One_Chance_(NizeGuy).3791660.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Robyn_-_Robyn_[UK_Edition]_[2007][CD+SkidVid+Cov]192Kbps[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Saybia-Eyes_On_The_Highway-2007-SMO.3783281.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Spiderman_3_CAM.VCD-CANALSTREET_(A_UKB_KVCD_By_Skagman)[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Timberland_-_Apologize[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Tina_Dickow_-_Count_To_Ten_(2007)_-_Pop_.3790703.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Top_100_Hot-Pop_Billboard_06-09-07_Charts_@224_Torrent-Tatty[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Top_40_-UK-_Billboard_07-08-07_Charts__224_Torrent-Tatty.3736484.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_TV2-for_dig_ku_jeg_gøre_alting.1328337.SN[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_VA_-_Dance_Chart_vol._18[2007][DK][Covers].3721922.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Vista_Transformation_Pack_7.0.3724535.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Volbeat_-_The_Strength_The_Sound_The_Songs_[smaragdtorrent.org][1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\[isoHunt]_Wyclef_Jean-Sweetest_Girl_Ft_Akon_Lil_Wayne_And_Niia-Promo_CDS-2.1328370.SN[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Anden_P__Coke_.3568436.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU23675.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU36258.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU42952.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU43062.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU43066.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU45451.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU45454.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU48369.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\AZU6960.tmp
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Brother_Ali_-_The_Undisputed_Truth_(2007)_-_Hip_Hop_.3658760.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Gwen_Stefani_feat._Akon_-_The_Sweet_Escape.mp3__-mininova.org-_[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\KNA_Connected_-_Fibs_Løgn_og_Latin.mp3_-[www.bitenova.nl]-_[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Linkin_Park_-_What_I________ve_Done_MP3_Good_quailty_Vany.K.3653577.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Maroon_5_-_It_Won__t_Be_Soon_Before_Long_(256Kbps_covers).3693783.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Mere_dansk__Nephew_-_Interkom_Kom_Ind.3558859.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Nelly_Furtado-Loose_(Album)(2007)-FUTURE.3696523.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\SuspekT-Ingen.Slukker.The.Stars_[myBittorrent.com][1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Timbaland_Feat_Nelly_Furtado_And_Justin_Timberlake-Give_It_To_Me.3608612.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Timbaland_Nelly_Justin_Give_it_to_me_-_Blackbones_Holiday_mix.mp.3684373.TPB[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\Volbeat_-_The_Strength_The_Sound_The_Songs_-[www.bitenova.nl]-_[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\torrents\www.torrents-and-more.to...Justin_Timberlake-What_Goes_Around_Comes_Around-UKCDM-2007-UKP__-mininova.org-_[1].torrent
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tracker.config
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\tracker.config.bak
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\update.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\update.properties
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Azureus\upnp_trace1.log
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Browsefirstbird
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Browsefirstbird\0
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Browsefirstbird\nmurixyw.exe
C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\Browsefirstbird\Window64One.exe
C:\Programmer\Browsefirstbird

.
(((((((((((((((((((((((((  Files Created from 2007-12-01 to 2008-01-01  )))))))))))))))))))))))))))))))
.

2007-12-30 14:17 . 2007-12-30 16:36    3,368    --a------    C:\WINDOWS\system32\tmp.reg
2007-12-30 14:16 . 2007-12-30 16:37    <DIR>    d--------    C:\SmitfraudFix
2007-12-30 14:03 . 2007-12-30 14:03    1,129,580    --a------    C:\SmitfraudFix.exe
2007-12-29 19:34 . 2007-12-29 19:34    <DIR>    d--------    C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Skrivebord
2007-12-29 19:29 . 2007-03-14 19:44    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Skabeloner
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Printere
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    dr-------    C:\Documents and Settings\Administrator\Menuen Start
2007-12-29 19:29 . 2007-12-29 20:34    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Lokale indstillinger
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Foretrukne
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Dokumenter
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Andre computere
2007-12-29 19:22 . 2007-12-29 21:11    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-12-29 19:22 . 2007-12-29 19:22    <DIR>    d--------    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\SUPERAntiSpyware.com
2007-12-29 19:22 . 2007-12-29 19:22    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2007-12-27 23:34 . 2007-12-30 21:09    <DIR>    d--------    C:\My Downloads
2007-12-07 21:47 . 2007-12-07 21:47    0    --a------    C:\WINDOWS\iPlayer.INI

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 07:49    ---------    d-----w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\AVG7
2007-12-30 19:20    ---------    d-----w    C:\Programmer\HAM
2007-12-29 18:22    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2007-12-28 18:46    ---------    d-----w    C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-12-27 17:36    ---------    d-----w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\AdobeUM
2007-11-19 21:00    149,685    ----a-w    C:\WINDOWS\HAM Uninstaller.exe
2007-11-13 10:25    20,480    ----a-w    C:\WINDOWS\system32\drivers\secdrv.sys
2007-04-10 11:59    46,608    ----a-w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\GDIPFONTCACHEV1.DAT
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Programmer\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 13:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 21:05]
"Cpqset"="C:\Programmer\HPQ\Default Settings\cpqset.exe" [2005-02-17 14:01]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 13:12]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 13:11]
"eabconfg.cpl"="C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 13:24]
"hpWirelessAssistant"="C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 15:21]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 15:28]
"LogitechCommunicationsManager"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" []
"LVCOMSX"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe" []
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-03-14 20:21]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-23 20:57]

C:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-03-22 15:39]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 12:01:18 C:\WINDOWS\Tasks\AFE5CD10918A7E20.job"
- c:\docume~1\tangga~1.pav\applic~1\browse~1\Window64One.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-01 13:04:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Programmer\HPQ\Default Settings\cpqset.exe???????????3?1?2?1??????? ???B????????? ???hLC????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-01 13:07:48 - machine was rebooted [Tanggaard Wulff]
.
2007-12-13 20:45:09    --- E O F ---
Avatar billede fromsej Praktikant
01. januar 2008 - 14:49 #12
Den er sejlivet min "ven" Lop.
Nå, det er sikkert kun en rest.

Hent Schtasks her:
http://fromsej.dk/download/schtasks.exe
Den skal ligge i C:\windows\system32\
Hvis du bliver spurgt om den skal overskrives, så annuller download, så har du filen allerede.

Hent fl.zip, pak den ud og kør fl.bat - programmet laver en lille tekst fil, som du også skal kopiere herind:
http://www.ctrlaltdel.dk/Programmer/fl.zip

Klik på Start->Kør skriv CMD og klik OK.
I "DOS"vinduet skriver du følgende: (tryk på <Enter> efter hver linie)
schtasks /query>C:\tasks.txt
notepad C:\tasks.txt
Kopier indholdet herind.
Avatar billede mamloo Nybegynder
01. januar 2008 - 17:28 #13
Den er sq for sejlivet!


Opgavenavn                          N‘ste k›rsel            Status       
==================================== ======================== ===============
AFE5CD10918A7E20                    18:00:00, 1-01-2008      Kunne ikke star
Avatar billede mamloo Nybegynder
01. januar 2008 - 17:32 #14
ups, mangler lidt!

Disken i drev C har ikke noget navn.
Diskens serienummer er 08EA-296E

Indhold af C:\Documents and Settings\Administrator\Application Data

29-12-2007  19:34    <DIR>          SUPERAntiSpyware.com
              0 fil(er)                0 byte
              1 mappe(r)  59,181,494,272 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er 08EA-296E

Indhold af C:\Documents and Settings\All Users\Application Data

03-12-2006  13:00    <DIR>          Adobe
02-03-2006  02:31    <DIR>          Apple Computer
02-03-2006  19:02    <DIR>          e-Safekey
06-11-2006  14:12    <DIR>          HP
02-03-2006  02:31    <DIR>          hpqwmi
07-11-2006  15:31              869 hpzinstall.log
02-03-2006  02:31    <DIR>          InstallShield
12-09-2006  14:48                0 ISxBA.tmp
16-02-2007  17:00    <DIR>          Microsoft Corporation
31-08-2006  15:56    <DIR>          QuickTime
14-03-2007  11:51    <DIR>          Spybot - Search & Destroy
08-05-2006  17:55    <DIR>          Symantec
05-05-2006  08:16    <DIR>          Trymedia
25-03-2006  23:53    <DIR>          Windows Genuine Advantage
03-02-2007  14:40    <DIR>          Windows Live Toolbar
              2 fil(er)              869 byte
              13 mappe(r)  59,181,490,176 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er 08EA-296E

Indhold af C:\Documents and Settings\Tanggaard Wulff\Application Data

06-10-2006  21:49    <DIR>          .BitTornado
04-12-2006  09:25    <DIR>          Adobe
23-01-2007  20:55    <DIR>          AdobeUM
02-03-2006  02:31    <DIR>          Apple Computer
02-03-2007  13:22    <DIR>          Azureus
05-10-2006  17:34    <DIR>          BitTorrent
30-07-2006  19:00    <DIR>          Help
07-11-2006  15:29    <DIR>          HP
02-03-2006  02:31    <DIR>          Identities
07-11-2006  15:18    <DIR>          Image Zone Express
29-05-2006  20:54    <DIR>          InterVideo
17-09-2006  07:31    <DIR>          Leadertech
01-03-2006  20:03    <DIR>          Macromedia
06-12-2006  19:42    <DIR>          Microgaming
19-07-2006  07:38    <DIR>          Mozilla
27-07-2006  21:22    <DIR>          Sereniti
17-09-2006  07:31    <DIR>          Sonic
02-03-2006  19:44    <DIR>          Sun
01-03-2006  20:33    <DIR>          Symantec
31-07-2006  21:10    <DIR>          vlc
15-02-2007  09:45    <DIR>          WholeSecurity
              0 fil(er)                0 byte
              21 mappe(r)  59,181,490,176 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er 08EA-296E

Indhold af C:\Documents and Settings\Default User\Application Data

02-03-2006  02:31    <DIR>          .
02-03-2006  02:31    <DIR>          ..
17-09-2004  13:14                62 desktop.ini
              1 fil(er)              62 byte
              2 mappe(r)  59,181,490,176 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er 08EA-296E

Indhold af C:\Documents and Settings\LocalService\Application Data

Disken i drev C har ikke noget navn.
Diskens serienummer er 08EA-296E

Indhold af C:\Documents and Settings\NetworkService\Application Data
Avatar billede fromsej Praktikant
01. januar 2008 - 18:00 #15
Der mangler lidt oprydning.

Kopiér indholdet mellem de bølgede linier ind i et notepad-vindue, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt. Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

File::
C:\WINDOWS\Tasks\AFE5CD10918A7E20.job

Folder::
"C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado"
"C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus"
"C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent"

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen. - http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Vi skal se den nye, og forhåbentlig sidste, Combofixlog.
Avatar billede mamloo Nybegynder
02. januar 2008 - 09:49 #16
Denne gang gik combofix som smurt, håber dette er et tegn på at min pcer er frisk igen.

ComboFix 07-12-31.4 - Tanggaard Wulff 2008-01-02  9:37:03.4 - NTFSx86
Running from: C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Skrivebord\Scanprogrammer\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\Tasks\AFE5CD10918A7E20.job
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\_install.exe blev ikke fundet.
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\config.gui.ini
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\alloc.gif
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\black.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\black1.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\blue.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\green.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\green1.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\icon_bt.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\icon_done.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\red.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\white.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\yellow.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\.BitTornado\icons\yellow1.ico
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\.certs
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\.keystore
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\.lock
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\05C218B912B069657E5A237108E98B0FFD645BE4.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\05C218B912B069657E5A237108E98B0FFD645BE4.dat.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\7320DDCF8B74DC6AB2641B5A2D3F4FAF0D17E98B.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\7320DDCF8B74DC6AB2641B5A2D3F4FAF0D17E98B.dat.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\977C66385AB1E688C222F0FF685D681746B77EC4.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\977C66385AB1E688C222F0FF685D681746B77EC4.dat.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\A663CAD9FDC3045EE72CEF13D8A92F858939FE9E.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\A663CAD9FDC3045EE72CEF13D8A92F858939FE9E.dat.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\active\cache.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\azureus.config
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\azureus.config.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\azureus.statistics
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\azureus.statistics.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\banips.config
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\banips.config.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\dht\addresses.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\dht\contacts.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\dht\diverse.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\dht\general.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\dht\version.dat
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\downloads.config
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\downloads.config.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\ipfilter.cache
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\sharing.config
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\sharing.config.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tmp\AZU63890.tmp
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tmp\AZU63891.tmp
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tmp\AZU63892.tmp
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tmp\AZU63893.tmp
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tmp\AZU63894.tmp
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tmp\AZU63895.tmp
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tracker.config
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\tracker.config.bak
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\update.log
C:\Documents and Settings\Tanggaard Wulff\Application Data\Azureus\update.properties
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\bittorrent.log
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\bittorrent.log.1
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\042be877c228433c4539f479610a3cf59992cb6e
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\0743f40f2d7e6c121f8cb2cb07e4498a02094196
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\27e7aa46d32ce8cb1bf269714d56a5b6eb1c2301
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\2c4482019f6f11b0077383ad8e52386bb561a8d9
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\33811647421a8a8cdb71d6ff3a19afceb0a60d86
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\4a2e62fd7144700d0884c1867606256cfe9c6e3d
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\4dcba9e1515298fd5b1746157fe042197512c506
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\4f8c7d30473842e899468d9be0bc33f218553fb8
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\58d8aeb502e83543cfbc19a2fa2b167c9eae26b2
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\59e83d7df38723c73c6f6421b3794a0dfd567fe5
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\67f059b32fe5b44b02728c1b5945fdec143b3e7c
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\818af3dc0691601e3947f5a38e67db69ec4eaa8b
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\8399ce1a4f08c22c06dff7551fb5747df54ee255
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\8e0b7b065c429e00677896bed7daac567dc5c1e6
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\9ac0252d16e3f5aba0a0897179b9cd5bb17c9c10
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\a370ce73f25811434ac8d50eab6786953ebebbf6
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\b74de80711947d71a1deabf7d3c595041306ee7f
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\b88cff5ac4c066ef8f3d45b82c01701303e93c7a
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\ba141c9b9977d03aab89a90b2f02c9c08f508ef2
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\c3f901f24d02a2cae1762ec3ca3721212a0df7fb
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\c69b7758ea8e348f63773657230d1bd6dc14f5fe
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\cc416da6e6107ebb896177407e1124c5b6fd4a28
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\cf0faf84db6295de8e5401a566b30f8fff403087
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\cfe501d9ae69d4e1c3bbb1f9e7608f6de84ad401
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\d035a92872ec567e213a46b790c1a17e26a008c6
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\d3ef04b28074c6ea7960eff18a2474a1a94e18fd
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\d5ec105c71189caba31db978723a8994d83ad30f
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\da4665382788988f019a8af56f0773627dbf3e7e
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\ddf69d208dd2451b7354fb8f4df78a81231237c3
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\f04fd8ccb528a13742f8abeea90893e898908e8a
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\metainfo\fac589ce306974f59086ef9a85f357453c0709bf
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\resume\27e7aa46d32ce8cb1bf269714d56a5b6eb1c2301
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\resume\da4665382788988f019a8af56f0773627dbf3e7e
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\routing_table
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\torrents\27e7aa46d32ce8cb1bf269714d56a5b6eb1c2301
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\torrents\da4665382788988f019a8af56f0773627dbf3e7e
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\ui_config
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\data\ui_state
C:\Documents and Settings\Tanggaard Wulff\Application Data\BitTorrent\incomplete\27e7aa46-e599
C:\WINDOWS\Tasks\AFE5CD10918A7E20.job

.
(((((((((((((((((((((((((  Files Created from 2007-12-02 to 2008-01-02  )))))))))))))))))))))))))))))))
.

2008-01-02 09:35 . 2000-08-31 08:00    51,200    --a------    C:\WINDOWS\NirCmd.exe
2008-01-01 17:18 . 2008-01-01 17:26    125,440    --a------    C:\WINDOWS\system32\schtasks.exe
2007-12-30 14:17 . 2007-12-30 16:36    3,368    --a------    C:\WINDOWS\system32\tmp.reg
2007-12-30 14:16 . 2007-12-30 16:37    <DIR>    d--------    C:\SmitfraudFix
2007-12-30 14:03 . 2007-12-30 14:03    1,129,580    --a------    C:\SmitfraudFix.exe
2007-12-29 19:34 . 2007-12-29 19:34    <DIR>    d--------    C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Skrivebord
2007-12-29 19:29 . 2007-03-14 19:44    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Skabeloner
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Printere
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    dr-------    C:\Documents and Settings\Administrator\Menuen Start
2007-12-29 19:29 . 2008-01-01 13:07    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Lokale indstillinger
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Foretrukne
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--------    C:\Documents and Settings\Administrator\Dokumenter
2007-12-29 19:29 . 2007-03-14 20:33    <DIR>    d--h-----    C:\Documents and Settings\Administrator\Andre computere
2007-12-29 19:22 . 2008-01-01 14:06    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2007-12-29 19:22 . 2007-12-29 19:22    <DIR>    d--------    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\SUPERAntiSpyware.com
2007-12-29 19:22 . 2007-12-29 19:22    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2007-12-27 23:34 . 2007-12-30 21:09    <DIR>    d--------    C:\My Downloads
2007-12-07 21:47 . 2007-12-07 21:47    0    --a------    C:\WINDOWS\iPlayer.INI

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-02 08:17    ---------    d-----w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\AVG7
2007-12-30 19:20    ---------    d-----w    C:\Programmer\HAM
2007-12-29 18:22    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2007-12-28 18:46    ---------    d-----w    C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-12-27 17:36    ---------    d-----w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\AdobeUM
2007-11-19 21:00    149,685    ----a-w    C:\WINDOWS\HAM Uninstaller.exe
2007-11-13 10:25    20,480    ----a-w    C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:44    1,291,776    ----a-w    C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28    222,720    ----a-w    C:\WINDOWS\system32\wmasf.dll
2007-04-10 11:59    46,608    ----a-w    C:\Documents and Settings\Tanggaard Wulff.PAVILIONZV6000\Application Data\GDIPFONTCACHEV1.DAT
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Programmer\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00 15360]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46 1318128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 13:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 13:00 455168]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 21:05 339968]
"Cpqset"="C:\Programmer\HPQ\Default Settings\cpqset.exe" [2005-02-17 14:01 233534]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 13:12 102492]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 13:11 692316]
"eabconfg.cpl"="C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 13:24 290816]
"hpWirelessAssistant"="C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 15:21 794624]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 15:28 579072]
"LogitechCommunicationsManager"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 00:12 488984]
"LVCOMSX"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\LVComSX.exe" [2007-02-06 16:43 252704]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-03-14 20:21 98304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-23 20:57 219136]

C:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-03-22 15:39]

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-02 09:40:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Programmer\HPQ\Default Settings\cpqset.exe???????????3?1?2?1??????? ???B????????? ???hLC????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-02  9:40:59
C:\qoobox\ComboFix-quarantined-files.txt  2008-01-02 08:40:36
C:\qoobox\ComboFix2.txt  2008-01-01 12:07:48
.
2007-12-13 20:45:09    --- E O F ---
Avatar billede fromsej Praktikant
02. januar 2008 - 16:22 #17
Der er lige en tilbage, se om du kan slette den normalt:
C:\WINDOWS\iPlayer.INI
Udover den er loggen ren. :-)
Avatar billede mamloo Nybegynder
04. januar 2008 - 08:30 #18
Tusind tak for hjælpen fromsej. Send et svar og du kan få dine meget velfortjente point!
Avatar billede fromsej Praktikant
04. januar 2008 - 16:01 #19
Det kommer her. :-)
Men det må være en deler mellem mig og Karise_larry.
Avatar billede mamloo Nybegynder
04. januar 2008 - 18:13 #20
ja, helt sikkert venter bare på et svar fra ham!
04. januar 2008 - 22:52 #21
Ping...
Avatar billede mamloo Nybegynder
14. januar 2008 - 18:34 #22
Tusind tak for hjælpen i to!!! ;=)
Avatar billede fromsej Praktikant
14. januar 2008 - 18:50 #23
Velbekomme, tak for point. :-)
14. januar 2008 - 19:20 #24
Ditto ...
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester