HijackThis log - har jeg snavs? II
Jeg fik accepteret et svar fra mig selv i den tråd jeg oprettede igår - det var bestemt ikke meningen. Jeg beklager over dor de som prøvede at hjælpe mig - håber de vil kigge med her :)CC log:
RENSNING FÆRDIG - (0.737 sek)
------------------------------------------------------------------------------------------
11,6MB fjernet.
------------------------------------------------------------------------------------------
Detaljer om de slettede filer
------------------------------------------------------------------------------------------
IE midlertidige Internet filer (717 filer) 5,55MB
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ad.yieldmanager[2].txt 201 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@adtech[2].txt 257 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@advertising[1].txt 283 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@atdmt[2].txt 103 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@banner.jv[2].txt 284 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@bluestreak[1].txt 139 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@bold[1].txt 323 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ccleaner[2].txt 339 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@chart[1].txt 94 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@d1.openx[1].txt 105 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@delivery-ads.surftown[1].txt 118 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@doubleclick[1].txt 122 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@efb[2].txt 345 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@eksperten[1].txt 505 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@ekstrabladet[2].txt 368 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@facebook[1].txt 588 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@google[1].txt 131 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@hit.gemius[2].txt 221 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@nuggad[1].txt 139 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@one[1].txt 325 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@openx[1].txt 103 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@server.iad.liveperson[2].txt 218 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@statistik-gallup[1].txt 125 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@track.adform[2].txt 186 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@tradedoubler[2].txt 485 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.bold[1].txt 84 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.google[1].txt 471 bytes
C:\Users\Nygade5\AppData\Roaming\Microsoft\Windows\Cookies\low\nygade5@www.jv[1].txt 331 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db 1,00MB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db 24 bytes
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db 3,97KB
C:\Users\Nygade5\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db 24 bytes
Fjern Cookie: filehippo.com
Fjern Cookie: doubleclick.net
Fjern Cookie: ccleaner.com
Fjern Cookie: www.google.com
Fjern Cookie: yahoo.com
Fjern Cookie: google.com
Firefox/Mozilla midlertidige Internet filer (10 filer) 5,02MB
C:\Users\Nygade5\AppData\Roaming\Mozilla\Firefox\Profiles\p7452iy5.default\history.dat 371 bytes
C:\Users\Nygade5\AppData\Roaming\Mozilla\Firefox\Profiles\p7452iy5.default\downloads.rdf 1,01KB
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\QLF5GMNP\bin.clearspring.com\clearspring.sol 61 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol 89 bytes
C:\Users\Nygade5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 442 bytes
/////////////////////////////////////////////////////////////////
Det lykkedes mig at få kørt Malwarebytes' Anti-Malware i fejlsikret tilstand:
Malwarebytes' Anti-Malware 1.31
Database version: 1492
Windows 6.0.6001 Service Pack 1
12-12-2008 16:04:07
mbam-log-2008-12-12 (16-04-07).txt
Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 145373
Tid tilbagelagt: 21 minute(s), 35 second(s)
Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0
Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)
Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)
Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)
Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)
Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)
Inficerede Mapper:
(Ingen mistænkelige filer fundet)
Inficerede Filer:
(Ingen mistænkelige filer fundet)
//////////////////////////////////////////////////////////////////
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:36:40, on 13-12-2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Users\Nygade5\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Nygade5\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.igoogle.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://da.intl.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://da.intl.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
O16 - DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} (IlosoftMultipleImageCtrl Class) - https://www.one.com/static/controls/IlosoftMultipleImageUpload.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 7841 bytes