Avatar billede bubbaa Nybegynder
23. august 2008 - 21:20 Der er 9 kommentarer og
2 løsninger

Popups fra Cid

Hej
Jeg har nu fulgt denne guide: http://www.eksperten.dk/artikler/954

Og derefter skal jeg poste mine logfiler her.

Håber i kan hjælpe mig:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:08:23, on 23-08-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\WINDOWS\system32\IFXTCS.exe
c:\programmer\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IfxPsdSv.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\RealVNC\VNC4\WinVNC4.exe
c:\programmer\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Quick Launch Button\QLButton.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Ahead\InCD\InCD.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Infineon\Security Platform Software\PSDrt.exe
C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmer\Infineon\Security Platform Software\SpTna.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Programmer\Microsoft Firewall Client 2004\FwcMgmt.exe
C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
C:\Programmer\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Programmer\Microsoft Office\Office12\WINWORD.EXE
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ekstrabladet.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = isa2:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programmer\TEXTware\QUICKfind\PlugIns\IEHelp.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [QLButton] C:\Programmer\Quick Launch Button\QLButton.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmer\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\IFXSPMGT.exe /NotifyLogon
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmer\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programmer\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LanguageShortcut] C:\Programmer\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Programmer\Fælles filer\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Programmer\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: Gyldendals Røde Ordbøger.lnk = C:\Programmer\TEXTware\Illuminator 2\Illview02.exe
O4 - Global Startup: Microsoft Firewall Client Management.lnk = C:\Programmer\Microsoft Firewall Client 2004\FwcMgmt.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: SYSTRAN Lookup - res://C:\Programmer\SYSTRAN\6\\GUIres.dll/lookup.js
O8 - Extra context menu item: SYSTRAN Translate - res://C:\Programmer\SYSTRAN\6\\GUIres.dll/translate.js
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmer\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Programmer\RealVNC\VNC4\WinVNC4.exe

--
End of file - 11099 bytes

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/23/2008 at 02:56 PM

Application Version : 4.15.1000

Core Rules Database Version : 3545
Trace Rules Database Version: 1534

Scan type      : Complete Scan
Total Scan Time : 00:20:59

Memory items scanned      : 243
Memory threats detected  : 0
Registry items scanned    : 5511
Registry threats detected : 0
File items scanned        : 18578
File threats detected    : 26

Adware.Tracking Cookie
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@doubleclick[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@fastclick[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@new-pcp[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@scan.free-antispyware-scanner[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@partypoker[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@banner.joylandcasino[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@ad.yieldmanager[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@serving-sys[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@ad.zanox[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@pacificpoker[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@eas.apm.emediate[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@atdmt[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@888[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@track.adform[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@advertising[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@bs.serving-sys[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@zedo[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@sr2.livemediasrv[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@cassava[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@apmebf[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@www.adserver5[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@adultfriendfinder[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@microsoftwlmessengermkt.112.2o7[1].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@wsp[2].txt
    C:\Documents and Settings\Johan-Sebastian\Cookies\johan-sebastian@ads.react2media[1].txt
    .adtech.de [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adtech.de [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adtech.de [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ad1.emediate.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .2o7.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .2o7.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ad1.emediate.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .aller.112.2o7.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ad1.emediate.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ad1.emediate.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    track.adform.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    track.adform.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .borsen.112.2o7.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .stepstone.112.2o7.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .doubleclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    statse.webtrendslive.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .mediaplex.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    bold.adservinginternational.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    bold.adservinginternational.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    server.iad.liveperson.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    server.iad.liveperson.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .apmebf.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    eas.apm.emediate.eu [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .advertising.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .advertising.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .advertising.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .advertising.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .edsa.122.2o7.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    eas4.emediate.eu [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .advertising.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .serving-sys.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .bs.serving-sys.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .serving-sys.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .serving-sys.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .serving-sys.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .serving-sys.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .serving-sys.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tradedoubler.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tradedoubler.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tradedoubler.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tradedoubler.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tradedoubler.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    banner2.fynskemedier.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    banner2.fynskemedier.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    banner2.fynskemedier.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    banner2.fynskemedier.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    qxl.adservinginternational.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    qxl.adservinginternational.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    qxl.banneradministration.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    qxl.banneradministration.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    adserver.banneradministration.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    adserver.banneradministration.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .socialmedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .fastclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .fastclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .fastclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .fastclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .fastclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ads2.myp2p.eu [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .valueclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .indextools.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tacoda.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tacoda.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tacoda.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tacoda.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tacoda.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .imrworldwide.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .imrworldwide.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ads2.jubii.dk [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .atdmt.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .247realmedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ad.yieldmanager.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ad.yieldmanager.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .realmedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .realmedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .tribalfusion.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .burstnet.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .zedo.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adopt.specificclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adopt.specificclick.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adrevolver.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .zedo.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    ads.revsci.net [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    media.adrevolver.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adopt.euroclick.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adopt.euroclick.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .adrevolver.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .realmedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .realmedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .casalemedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .casalemedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .casalemedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]
    .casalemedia.com [ C:\Documents and Settings\Johan-Sebastian\Application Data\Mozilla\Firefox\Profiles\y3zg87dn.default\cookies.txt ]

Rogue.AntiVirus 2009/Installer
    C:\DOCUMENTS AND SETTINGS\JOHAN-SEBASTIAN\LOKALE INDSTILLINGER\TEMPORARY INTERNET FILES\CONTENT.IE5\XCPTZ993\AV2009INSTALL_880657[1].EXE





stream000\SASWINLO.dll    C:\Programmer\Fælles filer\Wise Installation Wizard\WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_0_0_1154.MSI\stream000    Trojan.Fakealert.1239   
stream000    C:\Programmer\Fælles filer\Wise Installation Wizard\WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_0_0_1154.MSI    Archive contains infected objects   
WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_0_0_1154.MSI    C:\Programmer\Fælles filer\Wise Installation Wizard    Archive contains infected objects    Moved.
vncviewer.exe    C:\Programmer\RealVNC\VNC4    Program.RemoteAdmin.51    Renamed.
A0035631.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP118    Trojan.Swizzor.based    Deleted.
A0035652.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP118    Trojan.Swizzor.based    Deleted.
A0035701.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035718.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035736.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035750.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035771.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035787.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035807.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035818.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035842.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP120    Trojan.Swizzor.based    Deleted.
A0035852.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP121    Trojan.Swizzor.based    Deleted.
A0035895.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP122    Trojan.Swizzor.based    Deleted.
A0035910.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP122    Trojan.Swizzor.based    Deleted.
A0035927.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP122    Trojan.Swizzor.based    Deleted.
A0035945.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP122    Trojan.Swizzor.based    Deleted.
A0035962.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP123    Trojan.Swizzor.based    Deleted.
A0035976.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP123    Trojan.Swizzor.based    Deleted.
A0035989.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP123    Trojan.Swizzor.based    Deleted.
A0036002.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP123    Trojan.Swizzor.based    Deleted.
A0036014.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP123    Trojan.Swizzor.based    Deleted.
A0036033.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP124    Trojan.Swizzor.based    Deleted.
A0036046.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP124    Trojan.Swizzor.based    Deleted.
A0036078.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP125    Trojan.Swizzor.based    Deleted.
A0036094.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP125    Trojan.Swizzor.based    Deleted.
A0037094.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP125    Trojan.Swizzor.based    Deleted.
A0037114.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP125    Trojan.Swizzor.based    Deleted.
A0037136.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0037151.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0038150.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0038167.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0038184.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039184.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039200.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039217.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039234.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039251.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039279.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039301.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039322.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039344.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039366.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP126    Trojan.Swizzor.based    Deleted.
A0039369.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP127    Trojan.Swizzor.based    Deleted.
A0039381.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP127    Trojan.Swizzor.based    Deleted.
A0039410.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP127    Trojan.Swizzor.based    Deleted.
A0039433.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP127    Trojan.Swizzor.based    Deleted.
A0039448.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP127    Trojan.Swizzor.based    Deleted.
A0039454.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP128    Trojan.Swizzor.based    Deleted.
A0039467.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP128    Trojan.Swizzor.based    Deleted.
A0039823.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP128    Trojan.Swizzor.based    Deleted.
A0039838.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP128    Trojan.Swizzor.based    Deleted.
A0039862.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0039876.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0039903.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0039923.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0039941.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0039959.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0039975.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0039989.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0040004.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP129    Trojan.Swizzor.based    Deleted.
A0040010.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP130    Trojan.Swizzor.based    Deleted.
A0040025.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP130    Trojan.Swizzor.based    Deleted.
A0040042.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP130    Trojan.Swizzor.based    Deleted.
A0040050.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP131    Trojan.Swizzor.based    Deleted.
A0040063.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP131    Trojan.Swizzor.based    Deleted.
A0040096.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP131    Trojan.Swizzor.based    Deleted.
A0040111.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP131    Trojan.Swizzor.based    Deleted.
A0040169.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP132    Trojan.Swizzor.based    Deleted.
A0040285.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040317.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040328.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040357.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040384.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040411.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040444.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040460.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040478.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Trojan.Swizzor.based    Deleted.
A0040569.exe\data011    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133\A0040569.exe    Trojan.Swizzor.based   
A0040569.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP133    Archive contains infected objects    Moved.
A0041224.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP134    Trojan.Swizzor.based    Deleted.
A0041237.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP134    Trojan.Swizzor.based    Deleted.
A0041258.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP134    Trojan.Swizzor.based    Deleted.
A0041299.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP134    Trojan.Swizzor.based    Deleted.
A0041333.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP134    Trojan.Swizzor.based    Deleted.
A0041367.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP135    Trojan.Swizzor.based    Deleted.
A0041379.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP135    Trojan.Swizzor.based    Deleted.
A0041453.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP136    Trojan.Swizzor.based    Deleted.
A0041468.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP136    Trojan.Swizzor.based    Deleted.
A0041481.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP136    Trojan.Swizzor.based    Deleted.
A0041499.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP136    Trojan.Swizzor.based    Deleted.
A0041524.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP136    Trojan.Swizzor.based    Deleted.
A0041552.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0041567.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0041584.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0041608.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0041639.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0041695.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0041727.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0041744.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0042767.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0042801.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP137    Trojan.Swizzor.based    Deleted.
A0042852.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP138    Trojan.Swizzor.based    Deleted.
A0042869.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP138    Trojan.Swizzor.based    Deleted.
A0042899.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP138    Trojan.Swizzor.based    Deleted.
A0042916.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP138    Trojan.Swizzor.based    Deleted.
A0042958.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139    Trojan.Swizzor.based    Deleted.
A0042977.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139    Trojan.Swizzor.based    Deleted.
A0043003.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139    Trojan.Swizzor.based    Deleted.
A0043004.dll    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139    Trojan.Fakealert.1239    Deleted.
stream000\SASWINLO.dll    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139\A0043020.MSI\stream000    Trojan.Fakealert.1239   
stream000    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139\A0043020.MSI    Archive contains infected objects   
A0043020.MSI    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139    Archive contains infected objects    Moved.
A0043021.exe    C:\System Volume Information\_restore{706C4E77-FD51-435C-9F3E-B2848E924EDB}\RP139    Program.RemoteAdmin.51    Renamed.
23. august 2008 - 22:50 #1
Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Lad programmet foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...
Avatar billede bubbaa Nybegynder
24. august 2008 - 10:55 #2
Jeg er også begyndt at have andre problemer. Det tager mig lang tid at komme ind på fx. eb.dk, eksperten.dk og dba.dk. Synes også det tager min computer lang tid at komme forbi velkommenskiltet når den tænder op.
- Alt det jeg gør nu, hjælper det også imod dette?


Malwarebytes' Anti-Malware 1.25
Database version: 1080
Windows 5.1.2600 Service Pack 2

10:23:45 24-08-2008
mbam-log-08-24-2008 (10-23-45).txt

Skan type: Fuldstændig skanning (C:\|I:\|)
Objekter skannet: 97467
Tid tilbagelagt: 38 minute(s), 25 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 1
Inficerede Registeringsdatabase Værdier: 4
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
HKEY_CURRENT_USER\SOFTWARE\WakeNet (Trojan.Adware) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Værdier:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\netsearchsoft.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.netsearchsoft.com (Malware.Trace) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:48, on 24-08-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\WINDOWS\system32\IFXTCS.exe
c:\programmer\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IfxPsdSv.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
c:\programmer\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\system32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Programmer\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Quick Launch Button\QLButton.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
c:\programmer\mcafee.com\agent\mcagent.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Ahead\InCD\InCD.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Infineon\Security Platform Software\PSDrt.exe
C:\Programmer\Infineon\Security Platform Software\SpTna.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Programmer\Microsoft Firewall Client 2004\FwcMgmt.exe
C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
C:\Programmer\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Programmer\SYSTRAN\6\SystranToolbar.exe
C:\Programmer\SYSTRAN\6\Dicts\SystranTranslationEngine.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmer\TEXTware\QUICKfind\QFServer.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ekstrabladet.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = isa2:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmer\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programmer\TEXTware\QUICKfind\PlugIns\IEHelp.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [QLButton] C:\Programmer\Quick Launch Button\QLButton.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmer\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\IFXSPMGT.exe /NotifyLogon
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmer\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programmer\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LanguageShortcut] C:\Programmer\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Programmer\Fælles filer\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: Gyldendals Røde Ordbøger.lnk = C:\Programmer\TEXTware\Illuminator 2\Illview02.exe
O4 - Global Startup: Microsoft Firewall Client Management.lnk = C:\Programmer\Microsoft Firewall Client 2004\FwcMgmt.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: SYSTRAN Lookup - res://C:\Programmer\SYSTRAN\6\\GUIres.dll/lookup.js
O8 - Extra context menu item: SYSTRAN Translate - res://C:\Programmer\SYSTRAN\6\\GUIres.dll/translate.js
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmer\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Programmer\RealVNC\VNC4\WinVNC4.exe

--
End of file - 11235 bytes
24. august 2008 - 11:51 #3
Afinstall
* TEXTware QUICKfind
gør nogle gange ballade...

--------

Har du gennemført CCleaner's oprydning ?

--------

Husk WindowsUpdate -
http://update.microsoft.com/windowsupdate/v6/default.aspx?ln=da (du mangler vist en del ?) samt
Husk M$ ServicePack3 til XP -> http://www.microsoft.com/downloads/details.aspx?FamilyID=5b33b5a8-5e76-401f-be08-1e1555d4f3d4&displaylang=da
Avatar billede bubbaa Nybegynder
25. august 2008 - 21:48 #4
Jeg kan ikke finde Textware quickfind i tilføj/fjern programmer, og heller ikke afinstallationsfilen i programmappen.

Jeg har gennemført CCleaner flere gange og har nu brugt de to links
25. august 2008 - 21:57 #5
Lidt generel oprydning - behøver ikke at være med i din opstart...

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programmer\TEXTware\QUICKfind\PlugIns\IEHelp.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

Genstart normalt...

Og så vil jeg gerne se en fuld opdateret XP's HiJackThis Log ... Incl nævnte XP SP3 ...

------------------------------------------------------------------------
Avatar billede bubbaa Nybegynder
25. august 2008 - 22:33 #6
Sådan, så er de fjernet og der er genstartet

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:31:05, on 25-08-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\WINDOWS\system32\IFXTCS.exe
c:\programmer\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IfxPsdSv.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\RealVNC\VNC4\WinVNC4.exe
c:\programmer\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Quick Launch Button\QLButton.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
c:\programmer\mcafee.com\agent\mcagent.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Infineon\Security Platform Software\PSDrt.exe
C:\Programmer\Infineon\Security Platform Software\SpTna.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Microsoft Firewall Client 2004\FwcMgmt.exe
C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Windows Live\Messenger\usnsvc.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ekstrabladet.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = isa2:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmer\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [QLButton] C:\Programmer\Quick Launch Button\QLButton.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmer\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\IFXSPMGT.exe /NotifyLogon
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmer\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programmer\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LanguageShortcut] C:\Programmer\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Programmer\Fælles filer\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Programmer\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: Gyldendals Røde Ordbøger.lnk = C:\Programmer\TEXTware\Illuminator 2\Illview02.exe
O4 - Global Startup: Microsoft Firewall Client Management.lnk = C:\Programmer\Microsoft Firewall Client 2004\FwcMgmt.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: SYSTRAN Lookup - res://C:\Programmer\SYSTRAN\6\\GUIres.dll/lookup.js
O8 - Extra context menu item: SYSTRAN Translate - res://C:\Programmer\SYSTRAN\6\\GUIres.dll/translate.js
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmer\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Programmer\RealVNC\VNC4\WinVNC4.exe

--
End of file - 11017 bytes
26. august 2008 - 06:57 #7
Nøøøj som du ka' *S*

Hvordan kører PC'en så nu ?
Avatar billede bubbaa Nybegynder
26. august 2008 - 09:11 #8
hehe, i lige måde :D

Jeg har ikke fået popups lige inden for det sidste stykke tid, men den tar stadigvæk lang tid om at komme eksempelvis ind på denne side, og også lang tid om at starte op og komme forbi velkommen skiltet.
26. august 2008 - 21:59 #9
Har du måske lidt RAM mangel ?
26. august 2008 - 22:00 #10
Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Safe Surfing...

--------------
30. august 2008 - 22:19 #11
Ping?
(Det var et [svar]...)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester