Avatar billede svammi Nybegynder
13. december 2008 - 12:37 Der er 10 kommentarer og
2 løsninger

HijackThis log - har jeg snavs? II

Jeg fik accepteret et svar fra mig selv i den tråd jeg oprettede igår - det var bestemt ikke meningen. Jeg beklager over dor de som prøvede at hjælpe mig - håber de vil kigge med her :)

CC log:
RENSNING FÆRDIG - (0.737 sek)
------------------------------------------------------------------------------------------
11,6MB fjernet.
------------------------------------------------------------------------------------------

Detaljer om de slettede filer
------------------------------------------------------------------------------------------
IE midlertidige Internet filer (717 filer) 5,55MB
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ad.yieldmanager[2].txt 201 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@adtech[2].txt 257 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@advertising[1].txt 283 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@atdmt[2].txt 103 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@banner.jv[2].txt 284 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@bluestreak[1].txt 139 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@bold[1].txt 323 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ccleaner[2].txt 339 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@chart[1].txt 94 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@d1.openx[1].txt 105 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@delivery-ads.surftown[1].txt 118 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@doubleclick[1].txt 122 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@efb[2].txt 345 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@eksperten[1].txt 505 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ekstrabladet[2].txt 368 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@facebook[1].txt 588 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@google[1].txt 131 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@hit.gemius[2].txt 221 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@nuggad[1].txt 139 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@one[1].txt 325 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@openx[1].txt 103 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@server.iad.liveperson[2].txt 218 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@statistik-gallup[1].txt 125 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@track.adform[2].txt 186 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@tradedoubler[2].txt 485 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.bold[1].txt 84 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.google[1].txt 471 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.jv[1].txt 331 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db 1,00MB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db 3,97KB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db 24 bytes
Fjern Cookie: filehippo.com
Fjern Cookie: doubleclick.net
Fjern Cookie: ccleaner.com
Fjern Cookie: www.google.com
Fjern Cookie: yahoo.com
Fjern Cookie: google.com
Firefox/Mozilla midlertidige Internet filer (10 filer) 5,02MB
C:\Users\Nygade5\AppData\Roaming\Mozilla\Firefox\Profiles\p7452iy5.default\history.dat 371 bytes
C:\Users\Nygade5\AppData\Roaming\Mozilla\Firefox\Profiles\p7452iy5.default\downloads.rdf 1,01KB
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\QLF5GMNP\bin.clearspring.com\clearspring.sol 61 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol 89 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 442 bytes


/////////////////////////////////////////////////////////////////

Det lykkedes mig at få kørt Malwarebytes' Anti-Malware i fejlsikret tilstand:


Malwarebytes' Anti-Malware 1.31
Database version: 1492
Windows 6.0.6001 Service Pack 1

12-12-2008 16:04:07
mbam-log-2008-12-12 (16-04-07).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 145373
Tid tilbagelagt: 21 minute(s), 35 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)


//////////////////////////////////////////////////////////////////

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:36:40, on 13-12-2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Users\Nygade5\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Nygade5\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.igoogle.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://da.intl.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://da.intl.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
O16 - DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} (IlosoftMultipleImageCtrl Class) - https://www.one.com/static/controls/IlosoftMultipleImageUpload.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7841 bytes
13. december 2008 - 12:51 #1
(Oprindelige tråd -> http://www.eksperten.dk/spm/856255 )
13. december 2008 - 12:53 #2
Hvad mener du med "Lever sit eget liv ?" ...

(Der er dog lidt oprydning + 'rester' efter Symantec/Norton + ...)
Avatar billede Jensen DK Novice
13. december 2008 - 12:57 #3
Der er ikke noget rigtigt at komme efter andet det med norton, kør en komplet scanning med denne.
http://onecare.live.com/site/da-DK/default.htm
Avatar billede svammi Nybegynder
13. december 2008 - 13:01 #4
Det startede med at den lukkede ned uden årsag - først troede jeg den var varm, men det er den altså ikke. Generelt er den også blevet langsom.

Den har låst hver gang jeg har forsøgt at køre en anti-virus scan. Har benytte AVG, men den har været helt umuligt at køre.

Derudover scanner jeg jævlingt med Ad-aware og der har ingen problemer været

Efter jeg havde fået kørt Malwarebytes' Anti-Malware i fejlsikret tilstand igår kunne jeg ikke starte op igen før jeg havde været inde og ændre boot sekvensen tilbage til default

Dog skal det siges at den efter de forskellige scanninger de sidste par dage iøjeblikket kører helt anstendigt.
13. december 2008 - 13:26 #5
Klik på Start->Kør skriv Services.msc og klik OK.
Find Tjenesten (Hvis den er der)
* Symantec Lic NetConnect service (CLTNetCnService)
stop den hvis den kører, højreklik på den og vælg Starttype Deaktiveret.

------------------------------------------------------------------------

Lidt generel oprydning - behøver ikke at være med i din opstart...

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)

O4 - HKUS\S-1-5-18\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'Default user')

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

Genstart normalt...

------------------------------------------------------------------------

En (gen)oprydning med nævnte CCleaner..
Avatar billede svammi Nybegynder
13. december 2008 - 13:53 #6
CC log:

RENSNING FÆRDIG - (24.080 sek)
------------------------------------------------------------------------------------------
40,6MB fjernet.
------------------------------------------------------------------------------------------

Detaljer om de slettede filer
------------------------------------------------------------------------------------------
IE midlertidige Internet filer (2092 filer) 17,5MB
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@one[1].txt 326 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@atdmt[1].txt 105 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@www.google[1].txt 434 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@ad.yieldmanager[1].txt 202 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@server.iad.liveperson[2].txt 218 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@google[1].txt 131 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@advertising[2].txt 283 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\nygade5@facebook[2].txt 399 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@2o7[2].txt 149 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ad.yieldmanager[2].txt 202 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@adtech[1].txt 258 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@advertising[1].txt 297 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@atdmt[2].txt 103 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@banner.jv[2].txt 303 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@bold[1].txt 319 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@c.live[1].txt 69 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@chart[1].txt 92 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@d1.openx[2].txt 104 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@delivery-ads.surftown[1].txt 119 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@doubleclick[2].txt 119 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@efb[2].txt 339 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@eksperten[2].txt 485 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ekstrabladet[1].txt 370 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@facebook[2].txt 1,24KB
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@google[1].txt 222 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@google[3].txt 356 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@hit.gemius[2].txt 345 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@live[2].txt 94 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@mail.google[2].txt 331 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@msnservices.112.2o7[1].txt 127 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@msn[1].txt 99 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@nuggad[2].txt 192 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@onecare.live[2].txt 163 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@one[1].txt 323 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@openx[1].txt 102 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@php.ekstrabladet[2].txt 444 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@server.iad.liveperson[2].txt 217 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@statistik-gallup[1].txt 124 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@track.adform[2].txt 186 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@tradedoubler[2].txt 697 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.bold[1].txt 83 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.google[1].txt 105 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.google[2].txt 235 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.google[3].txt 472 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.google[5].txt 353 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.holstedgolfklub[1].txt 78 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.jv[2].txt 327 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008121220081213\index.dat 32,00KB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat 64,00KB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012008121220081213\index.dat 32,00KB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012008121320081214\index.dat 48,00KB
Markeret til sletning: C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
Markeret til sletning: C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
Markeret til sletning: C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
Markeret til sletning: C:\Users\Nygade5\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
Markeret til sletning: C:\Users\Nygade5\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
Markeret til sletning: C:\Users\Nygade5\AppData\Local\Microsoft\Windows\History\Low\History.IE5\desktop.ini
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db 1,00MB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db 1,00MB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db 7,91KB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db 24 bytes
Tømte Papirskurv (2 filer) 2,62MB
C:\Windows\system32\wbem\Logs\FrameWork.log 860 bytes
C:\Windows\system32\wbem\Logs\wmiprov.log 17,16KB
C:\Windows\system32\wbem\Logs\WMITracing.log 16,0MB
C:\Windows\msxml4-KB954430-enu.LOG 0,27MB
C:\Windows\WindowsUpdate.log 1,04MB
C:\Windows\Debug\mrt.log 868 bytes
C:\Windows\Debug\mrteng.log 584 bytes
C:\Windows\Debug\UserMode\ChkAcc.log 0 bytes
C:\Windows\Debug\UserMode\ChkAcc.bak 0 bytes
Fjern Cookie: msnservices.112.2o7.net
Fjern Cookie: c.live.com
Fjern Cookie: live.com
Fjern Cookie: rad.msn.com
Fjern Cookie: msn.com
Fjern Cookie: google.com
Fjern Cookie: atdmt.com
Fjern Cookie: yahoo.com
Fjern Cookie: www.google.com
Firefox/Mozilla midlertidige Internet filer (14 filer) 0,89MB
C:\Users\Nygade5\AppData\Roaming\Mozilla\Firefox\Profiles\p7452iy5.default\history.dat 371 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\XCPB2K4T\bin.clearspring.com\clearspring.sol 61 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\XCPB2K4T\mail.google.com\wakeup.sol 37 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol 89 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mail.google.com\settings.sol 85 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 461 bytes
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{9BE0AD6D-BF95-449E-A804-04D977ECA8AC} 5,76KB
------------------------------------------------------------------------------------------


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:51:15, on 13-12-2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\taskeng.exe
C:\Users\Nygade5\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\Nygade5\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.igoogle.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://da.intl.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://da.intl.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETVÆRKSTJENESTE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
O16 - DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} (IlosoftMultipleImageCtrl Class) - https://www.one.com/static/controls/IlosoftMultipleImageUpload.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7230 bytes


Mit CPU brug ser betydeligt mere stabilt ud nu end det gjorde igår - hvor det enten lå på max eller svingede voldsomt.
13. december 2008 - 15:47 #7
Nogle af elementerne fra [13/12-2008 13:26:19] guiden er der stadig ?
Kør HiJackThis igen - MEN HøjreMusseTast - "Kør som Administrator..."

Check med en frisk log at de er ædt...

(PS: Jeg har aldrig skrevet at skulle se loggen fra CCleaner)
Avatar billede svammi Nybegynder
13. december 2008 - 17:47 #8
Så lykkedes det vist. Væk er de ihvertfald og den bærbare spinder som en mis, så noget har ihvertfald hjulpet
Avatar billede Jensen DK Novice
14. december 2008 - 06:56 #9
Det var da glædeligt, så kan larry og mig bare dele pointne.
14. december 2008 - 10:39 #10
Ping... ( [svar] fra mig...)
Avatar billede svammi Nybegynder
14. december 2008 - 11:09 #11
Tak for hjælpen til jer begge.
Avatar billede Jensen DK Novice
14. december 2008 - 14:26 #12
God jul.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester