Avatar billede nrickardsson Nybegynder
23. april 2009 - 17:43 Der er 13 kommentarer

kan ikke fjerne spyware

Er der mon nogle der kan hjælpe? Min computer er ramt af spyware som jeg ikke kan få fjernet. Har prøvet malware, superantispyware og spybot uden held...
Avatar billede arkil Nybegynder
23. april 2009 - 17:50 #1
Hej ;-)

Hent Ccleaner her > Klik ude til højre på "Download Latest Version".
http://www.filehippo.com/download_ccleaner/
Der er en manual her > http://www.spywarefri.dk/manualer/ccleaner-manual.htm
Der er en lille forskel "Problemer" er udskiftet med "Register".
Sæt de flueben som vist i manualen punkt 11 inden du kører "Renser".
PS.: Dette program vil  jeg anbefale dig at beholde, det er fremragende til at rydde op med.

Under installationen får du tilbudt [Yahoo Toolbar]. Sig "Nej"  til den.
Lad programmer foretage en oprydning i Renser og Register, og lad den slette det den finder.
Vi skal ikke se log fra Ccleaner.

>>

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...

Manual for HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

PS: (Vistabrugere skal klikke med højre-musetast på filen og vælge (Kør som administrator)
Avatar billede nrickardsson Nybegynder
23. april 2009 - 19:24 #2
Så er det gjort. Her er de så:

Malwarebytes' Anti-Malware 1.36
Database version: 2031
Windows 5.1.2600 Service Pack 3

23-04-2009 18:57:16
mbam-log-2009-04-23 (18-57-16).txt

Skan type: Fuldstændig skanning (C:\|D:\|)
Objekter skannet: 90127
Tid tilbagelagt: 44 minute(s), 49 second(s)

Inficerede Hukommelses Processer: 1
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 6
Inficerede Registeringsdatabase Værdier: 1
Inficerede Registeringsdatabase Filer: 3
Inficerede Mapper: 8
Inficerede Filer: 210

Inficerede Hukommelses Processer:
C:\Programmer\ErrorFix\ErrorFix.exe (Rogue.ErrorFix) -> Unloaded process successfully.

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
HKEY_CLASSES_ROOT\Typelib\{a44b024a-ce32-4bda-0075-c799a4bff141} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CD205D52-1C73-4C6C-BAF6-C2190EB69357} (Rogue.ErrorFix) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Værdier:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\errorfix (Rogue.RegTool) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Filer:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Inficerede Mapper:
C:\Documents and Settings\nikki\Application Data\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Logs (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450 (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Results (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{CD205D52-1C73-4C6C-BAF6-C2190EB69357} (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Programmer\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Programmer\Downloaded Installers\{CD205D52-1C73-4C6C-BAF6-C2190EB69357} (Rogue.ErrorFix) -> Quarantined and deleted successfully.

Inficerede Filer:
C:\Programmer\ErrorFix\ErrorFix.exe (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Skrivebord\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Logs\2009-04-23 01-41-200.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Logs\2009-04-23 02-21-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Logs\2009-04-23 16-54-130.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\filelist.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-0.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-1.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-10.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-100.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-101.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-102.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-103.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-104.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-105.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-106.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-107.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-108.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-109.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-11.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-110.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-111.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-112.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-113.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-114.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-115.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-116.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-117.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-118.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-119.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-12.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-120.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-121.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-122.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-123.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-124.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-125.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-126.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-127.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-128.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-129.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-13.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-130.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-131.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-132.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-133.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-134.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-135.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-136.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-137.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-138.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-139.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-14.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-140.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-141.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-142.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-143.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-144.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-145.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-146.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-147.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-148.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-149.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-15.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-150.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-151.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-152.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-153.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-154.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-155.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-156.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-157.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-158.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-159.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-16.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-160.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-161.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-162.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-163.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-164.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-165.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-166.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-167.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-168.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-169.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-17.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-170.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-171.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-172.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-173.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-174.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-175.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-176.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-177.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-178.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-179.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-18.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-180.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-181.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-182.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-183.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-184.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-185.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-186.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-187.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-188.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-189.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-19.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-190.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-191.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-2.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-20.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-21.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-22.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-23.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-24.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-25.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-26.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-27.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-28.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-29.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-3.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-30.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-31.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-32.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-33.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-34.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-35.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-36.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-37.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-38.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-39.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-4.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-40.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-41.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-42.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-43.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-44.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-45.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-46.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-47.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-48.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-49.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-5.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-50.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-51.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-52.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-53.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-54.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-55.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-56.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-57.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-58.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-59.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-6.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-60.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-61.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-62.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-63.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-64.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-65.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-66.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-67.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-68.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-69.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-7.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-70.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-71.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-72.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-73.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-74.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-75.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-76.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-77.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-78.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-79.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-8.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-80.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-81.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-82.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-83.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-84.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-85.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-86.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-87.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-88.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-89.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-9.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-90.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-91.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-92.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-93.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-94.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-95.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-96.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-97.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-98.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\QuarantineW\2009-04-23 01-48-450\regb-99.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Results\Evidence.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Results\Junk.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Results\Registry.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\nikki\Application Data\ErrorFix\Results\Update.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{CD205D52-1C73-4C6C-BAF6-C2190EB69357}\Icon.exe (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Programmer\ErrorFix\definitions.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Programmer\ErrorFix\ErrorFix.url (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Programmer\ErrorFix\privacy.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Programmer\Downloaded Installers\{CD205D52-1C73-4C6C-BAF6-C2190EB69357}\setup.msi (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Skrivebord\ErrorFix.lnk (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\ErrorFix Scan.job (Rogue.ErrorFix) -> Quarantined and deleted successfully.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:14:33, on 23-04-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programmer\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Apoint2K\Apoint.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\khooker.exe
C:\Programmer\Analog Devices\SoundMAX\SMTray.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Apps\Powercinema\PCMService.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Apoint2K\HidFind.exe
C:\Programmer\Apoint2K\Apntex.exe
C:\Programmer\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\nikki\Skrivebord\HiJackThis202.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dk.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dk.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmer\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmer\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\dan.htm
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A35BC99-C122-4DC6-B997-F9EC360B4C64}: NameServer = 10.204.1.1,212.54.64.170
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 7371 bytes
Avatar billede johnstigers Seniormester
23. april 2009 - 20:42 #3
Afinstaller programmet errorfix

Ny hjt log
Avatar billede johnstigers Seniormester
23. april 2009 - 20:45 #4
P.s. svar er forbeholdt dem der hjælper, så venligst nøjes med at kommentere :)
Avatar billede arkil Nybegynder
23. april 2009 - 21:18 #5
Gå i Start=>Kør og skriv: msconfig. Klik OK og gå i fanebladet Start. Fjern vingen til venstre for flg. programmer:

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE



Skulle du på et senere tidspunkt fortryde at have fravalgt noget af det i opstart, kan du bare gå ind samme sted og sæt flueben ved programmet igen.

Genstart PC.
OBS! Du får nu en advarsel om, at "Start" er lavet om. Sæt et flueben i Vis ikke denne advarsel - klik ok.



--Hent Combofix, og gem den på dit skrivebord:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Luk alle andre vinduer ned.

Kør så Combofix.exe, og følg anvisningerne. (Vistabrugere skal klikke med højre-musetast på filen og vælge (Kør som administrator)

Vigtigt-> Deaktiver dit antivirus/antispyware program. Da det/de kan "forstyrre" og konflikte med Combofix, eller fjerne vigtige Combofix filer, hvilket kan få computeren til fryse.

Du må ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt som ligger her C:\ Combofix txt

Hvis logfilen ikke åbnes så finder du den her c:\combofix.txt
Indholdet af denne fil må du gerne lægge herind.
23. april 2009 - 21:28 #6
PS: Du ka' gøre samme [MSConfig] trix med
* [WinampAgent]
Avatar billede nrickardsson Nybegynder
23. april 2009 - 21:32 #7
Ups, beklager - ny bruger.  Hvordan afinstallerer jeg errorfix? Jeg kan ikke i ´tilføj - fjern programmer´...?
23. april 2009 - 21:42 #8
(Den ER allerede blevet fixet i ovenstående [Malwarebytes] procedure...)
Avatar billede nrickardsson Nybegynder
23. april 2009 - 22:02 #9
Kan ikke finde de programmer du nævner. Jeg kan finde nogle der har nogle af de samme ord som dem du nævner?
23. april 2009 - 22:22 #10
I denne forbindelse skal det gennemføres med Hijackthis, mest i oprydnings øjemed...
Kør HiJackThis og du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE

Genstart normalt...

------------------------------------------------------------------------

Hvordan kører PC'en så nu ?
Avatar billede nrickardsson Nybegynder
23. april 2009 - 23:51 #11
Ser umiddelbart ud til spyware er væk, her er logfilen:

ComboFix 09-04-23.A3 - nikki 23-04-2009 23:18:59.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.45.1030.18.446.250 [GMT 2:00]
Kører fra: C:\Documents and Settings\nikki\Skrivebord\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Dannede nyt systemgendannelsespunkt
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

[color=blue]Inficeret kopi af C:\WINDOWS\system32\userinit.exe blev fundet og desinficeret
Genskabt kopi fra - C:\WINDOWS\$NtServicePackUninstall$\userinit.exe[/COLOR]

.
(((((((((((((((((((((((((((((  Filer skabt fra 2009-05-23 til 2009-4-23  )))))))))))))))))))))))))))))))))))
.

2009-04-22 23:35:39 . 2009-04-23 16:57:16    0    d-----w    C:\Programmer\Downloaded Installers
2009-04-22 22:40:47 . 2009-04-22 22:40:47    0    d-sh--w    C:\Documents and Settings\nikki\IECompatCache
2009-04-22 21:41:58 . 2009-04-23 21:11:09    0    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-22 21:41:58 . 2009-04-22 21:47:55    0    d-----w    C:\Programmer\Spybot - Search & Destroy
2009-04-20 20:39:30 . 2009-04-20 20:39:32    0    d-sh--w    C:\Documents and Settings\nikki\PrivacIE
2009-04-20 20:36:37 . 2009-04-20 20:36:37    0    d-sh--w    C:\Documents and Settings\nikki\IETldCache
2009-04-20 20:31:55 . 2009-04-20 20:31:55    0    d-----w    C:\WINDOWS\ie8updates
2009-04-20 20:24:56 . 2009-04-20 20:27:31    0    dc-h--w    C:\WINDOWS\ie8
2009-04-20 20:23:48 . 2009-04-20 20:32:25    0    d--h--w    C:\WINDOWS\msdownld.tmp
2009-04-20 20:19:47 . 2009-02-28 04:55:00    105984    ------w    C:\WINDOWS\system32\dllcache\iecompat.dll
2009-04-17 21:41:54 . 2009-04-17 21:41:27    410984    ----a-w    C:\WINDOWS\system32\deploytk.dll
2009-04-15 12:27:10 . 2009-02-06 10:10:02    227840    ------w    C:\WINDOWS\system32\dllcache\wmiprvse.exe
2009-04-15 12:27:03 . 2009-03-06 14:20:58    284672    ------w    C:\WINDOWS\system32\dllcache\pdh.dll
2009-04-15 12:27:02 . 2009-02-09 11:25:40    110592    ------w    C:\WINDOWS\system32\dllcache\services.exe
2009-04-15 12:27:02 . 2009-02-09 10:53:27    401408    ------w    C:\WINDOWS\system32\dllcache\rpcss.dll
2009-04-15 12:26:58 . 2009-02-09 10:53:27    473600    ------w    C:\WINDOWS\system32\dllcache\fastprox.dll
2009-04-15 12:26:58 . 2009-02-06 10:39:08    35328    ------w    C:\WINDOWS\system32\dllcache\sc.exe
2009-04-15 12:26:56 . 2009-02-09 10:53:27    682496    ------w    C:\WINDOWS\system32\dllcache\advapi32.dll
2009-04-15 12:26:54 . 2009-02-09 10:53:28    730624    ------w    C:\WINDOWS\system32\dllcache\lsasrv.dll
2009-04-15 12:26:53 . 2009-02-09 10:53:26    453120    ------w    C:\WINDOWS\system32\dllcache\wmiprvsd.dll
2009-04-15 12:26:52 . 2009-02-09 10:53:27    719360    ------w    C:\WINDOWS\system32\dllcache\ntdll.dll
2009-04-15 12:24:59 . 2009-03-27 06:53:33    1203922    ------w    C:\WINDOWS\system32\dllcache\sysmain.sdb
2009-04-15 12:24:58 . 2008-04-21 21:15:43    217088    ------w    C:\WINDOWS\system32\dllcache\wordpad.exe
2009-04-15 01:55:26 . 2009-04-15 01:53:03    102664    ----a-w    C:\WINDOWS\system32\drivers\tmcomm.sys
2009-04-15 01:52:44 . 2009-04-15 01:56:28    0    d-----w    C:\Documents and Settings\nikki\.housecall6.6
2009-04-14 21:59:19 . 2009-04-14 21:59:19    0    d-----w    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-14 21:58:26 . 2009-04-22 23:03:29    0    d-----w    C:\Documents and Settings\nikki\Application Data\SUPERAntiSpyware.com
2009-04-14 21:58:26 . 2009-04-22 23:02:15    0    d-----w    C:\Programmer\SUPERAntiSpyware
2009-04-14 21:32:11 . 2009-04-14 23:12:13    0    d---a-w    C:\Documents and Settings\All Users\Application Data\TEMP
2009-04-14 01:22:23 . 2009-04-14 01:22:23    0    d-----w    C:\WINDOWS\system32\CatRoot_bak
2009-04-13 18:18:23 . 2009-04-13 18:18:23    0    d-----w    C:\Documents and Settings\All Users\Application Data\00070271
2009-04-13 15:09:13 . 2009-04-13 15:09:13    0    d-----w    C:\Documents and Settings\All Users\Application Data\00092092
2009-04-12 20:07:55 . 2009-04-15 12:19:12    0    d-----w    C:\Documents and Settings\All Users\Application Data\21831069
2009-04-12 20:05:46 . 2009-04-13 20:43:48    0    d-----w    C:\Documents and Settings\All Users\Application Data\21830069
2009-03-27 10:24:52 . 2008-04-13 18:45:36    26112    ----a-w    C:\WINDOWS\system32\drivers\usbser.sys
2009-03-27 10:24:52 . 2008-04-13 18:45:36    26112    ----a-w    C:\WINDOWS\system32\dllcache\usbser.sys
2009-03-27 09:57:28 . 2009-03-27 09:57:28    0    ---ha-w    C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-03-27 09:57:08 . 2009-03-27 09:57:08    0    ---ha-w    C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 16:03:50 . 2009-03-02 19:36:13    0    d-----w    C:\Programmer\Malwarebytes' Anti-Malware
2009-04-22 23:12:15 . 2007-01-17 20:49:24    0    d-----w    C:\Programmer\Canon
2009-04-22 23:00:29 . 2006-01-12 18:07:30    0    d-----w    C:\Documents and Settings\nikki\Application Data\Lavasoft
2009-04-17 21:41:18 . 2005-02-01 09:54:59    0    d-----w    C:\Programmer\Java
2009-04-15 16:46:57 . 2004-09-14 14:37:53    62862    ----a-w    C:\WINDOWS\system32\perfc006.dat
2009-04-15 16:46:57 . 2004-09-14 14:37:53    395314    ----a-w    C:\WINDOWS\system32\perfh006.dat
2009-04-06 13:32:54 . 2009-03-02 19:36:16    38496    ----a-w    C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32:46 . 2009-03-02 19:36:19    15504    ----a-w    C:\WINDOWS\system32\drivers\mbam.sys
2009-03-21 14:08:56 . 2009-03-21 14:08:56    1006080    ------w    C:\WINDOWS\system32\dllcache\kernel32.dll
2009-03-08 12:09:26 . 2006-11-07 02:27:10    391536    ----a-w    C:\WINDOWS\system32\dllcache\iedkcs32.dll
2009-03-08 12:09:26 . 2006-10-17 11:04:40    638816    ----a-w    C:\WINDOWS\system32\dllcache\iexplore.exe
2009-03-08 02:41:16 . 2006-05-19 15:10:00    5937152    ----a-w    C:\WINDOWS\system32\dllcache\mshtml.dll
2009-03-08 02:39:48 . 2007-05-09 08:10:39    11063808    ----a-w    C:\WINDOWS\system32\dllcache\ieframe.dll
2009-03-08 02:34:58 . 2006-05-10 05:25:17    914944    ----a-w    C:\WINDOWS\system32\dllcache\wininet.dll
2009-03-08 02:34:58 . 2004-09-14 14:37:42    914944    ----a-w    C:\WINDOWS\system32\wininet.dll
2009-03-08 02:34:56 . 2006-05-10 05:25:17    1206784    ----a-w    C:\WINDOWS\system32\dllcache\urlmon.dll
2009-03-08 02:34:48 . 2006-11-07 20:03:36    236544    ----a-w    C:\WINDOWS\system32\dllcache\webcheck.dll
2009-03-08 02:34:30 . 2006-10-17 11:05:10    43008    ----a-w    C:\WINDOWS\system32\dllcache\licmgr10.dll
2009-03-08 02:34:30 . 2004-09-14 14:36:38    43008    ----a-w    C:\WINDOWS\system32\licmgr10.dll
2009-03-08 02:34:28 . 2006-10-17 11:05:22    105984    ----a-w    C:\WINDOWS\system32\dllcache\url.dll
2009-03-08 02:34:18 . 2006-10-17 11:04:46    109568    ----a-w    C:\WINDOWS\system32\dllcache\occache.dll
2009-03-08 02:34:18 . 2006-05-10 05:25:16    193536    ----a-w    C:\WINDOWS\system32\dllcache\msrating.dll
2009-03-08 02:33:48 . 2006-09-18 14:15:14    759296    ----a-w    C:\WINDOWS\system32\dllcache\VGX.dll
2009-03-08 02:33:40 . 2009-03-08 02:33:40    18944    ------w    C:\WINDOWS\system32\dllcache\corpol.dll
2009-03-08 02:33:40 . 2004-09-14 14:36:02    18944    ----a-w    C:\WINDOWS\system32\corpol.dll
2009-03-08 02:33:26 . 2006-05-10 05:25:15    25600    ----a-w    C:\WINDOWS\system32\dllcache\jsproxy.dll
2009-03-08 02:33:16 . 2008-05-09 10:55:39    726528    ----a-w    C:\WINDOWS\system32\dllcache\jscript.dll
2009-03-08 02:33:08 . 2006-11-07 02:27:02    229376    ----a-w    C:\WINDOWS\system32\dllcache\ieaksie.dll
2009-03-08 02:33:06 . 2008-05-09 10:55:39    420352    ----a-w    C:\WINDOWS\system32\dllcache\vbscript.dll
2009-03-08 02:33:06 . 2004-09-14 14:37:34    420352    ----a-w    C:\WINDOWS\system32\vbscript.dll
2009-03-08 02:33:02 . 2006-11-07 02:26:56    125952    ----a-w    C:\WINDOWS\system32\dllcache\ieakeng.dll
2009-03-08 02:32:56 . 2006-11-07 02:26:44    72704    ----a-w    C:\WINDOWS\system32\dllcache\admparse.dll
2009-03-08 02:32:56 . 2004-09-14 14:35:54    72704    ----a-w    C:\WINDOWS\system32\admparse.dll
2009-03-08 02:32:54 . 2006-11-07 02:26:28    173056    ----a-w    C:\WINDOWS\system32\dllcache\ie4uinit.exe
2009-03-08 02:32:52 . 2006-11-07 02:25:14    163840    ----a-w    C:\WINDOWS\system32\dllcache\ieakui.dll
2009-03-08 02:32:50 . 2006-11-07 02:26:42    71680    ----a-w    C:\WINDOWS\system32\dllcache\iesetup.dll
2009-03-08 02:32:50 . 2006-11-07 02:26:28    55808    ----a-w    C:\WINDOWS\system32\dllcache\iernonce.dll
2009-03-08 02:32:50 . 2004-09-14 14:36:32    71680    ----a-w    C:\WINDOWS\system32\iesetup.dll
2009-03-08 02:32:48 . 2006-11-07 02:26:24    128512    ----a-w    C:\WINDOWS\system32\dllcache\advpack.dll
2009-03-08 02:32:46 . 2006-05-10 05:25:15    94720    ----a-w    C:\WINDOWS\system32\dllcache\inseng.dll
2009-03-08 02:32:26 . 2007-05-09 08:10:40    594432    ----a-w    C:\WINDOWS\system32\dllcache\msfeeds.dll
2009-03-08 02:32:22 . 2007-05-09 08:10:42    1985024    ----a-w    C:\WINDOWS\system32\dllcache\iertutil.dll
2009-03-08 02:32:04 . 2006-05-10 05:25:16    611840    ----a-w    C:\WINDOWS\system32\dllcache\mstime.dll
2009-03-08 02:24:28 . 2006-10-17 10:44:36    68608    ----a-w    C:\WINDOWS\system32\dllcache\hmmapi.dll
2009-03-08 02:22:38 . 2006-11-07 20:03:36    156160    ----a-w    C:\WINDOWS\system32\dllcache\msls31.dll
2009-03-08 02:22:38 . 2004-09-14 14:36:50    156160    ----a-w    C:\WINDOWS\system32\msls31.dll
2009-03-08 02:11:12 . 2007-05-09 08:10:40    445952    ----a-w    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2009-03-06 14:20:58 . 2004-09-14 14:37:10    284672    ----a-w    C:\WINDOWS\system32\pdh.dll
2009-03-03 02:44:26 . 2004-09-14 15:02:21    76487    ----a-w    C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
2009-03-03 02:27:34 . 2004-09-14 14:37:58    250576    --sha-r    C:\ntldr
2009-03-03 00:32:30 . 2005-02-01 10:03:56    0    d-----w    C:\Programmer\Fælles filer\Symantec Shared
2009-03-02 19:36:40 . 2009-03-02 19:36:40    0    d-----w    C:\Documents and Settings\nikki\Application Data\Malwarebytes
2009-03-02 19:36:14 . 2009-03-02 19:36:14    0    d-----w    C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-03-02 19:29:39 . 2009-03-02 19:29:29    0    d-----w    C:\Programmer\CCleaner
2009-03-02 00:42:26 . 2009-03-02 00:42:26    0    d-----w    C:\Documents and Settings\LocalService\Application Data\Symantec
2009-02-28 22:35:45 . 2008-08-16 17:46:17    0    d-----w    C:\Documents and Settings\nikki\Application Data\Azureus
2009-02-20 17:12:22 . 2006-05-10 05:25:15    133120    ----a-w    C:\WINDOWS\system32\dllcache\extmgr.dll
2009-02-20 10:20:49 . 2007-05-09 08:10:40    13824    ------w    C:\WINDOWS\system32\dllcache\ieudinit.exe
2009-02-10 17:08:50 . 2008-10-16 13:16:32    2068608    ------w    C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2009-02-10 17:08:50 . 2004-08-26 16:50:08    2068608    ----a-w    C:\WINDOWS\system32\ntkrnlpa.exe
2009-02-09 14:07:12 . 2008-10-16 13:16:35    1846784    ------w    C:\WINDOWS\system32\dllcache\win32k.sys
2009-02-09 14:07:12 . 2004-09-14 14:37:40    1846784    ----a-w    C:\WINDOWS\system32\win32k.sys
2009-02-09 11:26:05 . 2008-10-16 13:16:30    2191616    ------w    C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2009-02-09 11:26:05 . 2004-09-14 14:37:01    2191616    ----a-w    C:\WINDOWS\system32\ntoskrnl.exe
2009-02-09 11:26:00 . 2008-10-16 13:16:31    2026496    ------w    C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2009-02-09 11:25:42 . 2008-10-16 13:16:33    2147840    ------w    C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2009-02-09 11:25:40 . 2004-09-14 14:37:17    110592    ----a-w    C:\WINDOWS\system32\services.exe
2009-02-09 10:53:28 . 2004-09-14 14:36:39    730624    ----a-w    C:\WINDOWS\system32\lsasrv.dll
2009-02-09 10:53:27 . 2004-09-14 14:37:14    401408    ----a-w    C:\WINDOWS\system32\rpcss.dll
2009-02-09 10:53:27 . 2004-09-14 14:37:00    719360    ----a-w    C:\WINDOWS\system32\ntdll.dll
2009-02-09 10:53:27 . 2004-09-14 14:35:54    682496    ----a-w    C:\WINDOWS\system32\advapi32.dll
2009-02-06 19:07:58 . 2007-05-09 08:10:41    3698584    ----a-w    C:\WINDOWS\system32\dllcache\ieapfltr.dat
2009-02-06 10:39:08 . 2004-09-14 14:37:17    35328    ----a-w    C:\WINDOWS\system32\sc.exe
2009-02-03 19:58:19 . 2009-02-03 19:58:19    56832    ------w    C:\WINDOWS\system32\dllcache\secur32.dll
2009-02-03 19:58:19 . 2004-09-14 14:37:17    56832    ----a-w    C:\WINDOWS\system32\secur32.dll
2009-01-29 17:17:10 . 2008-10-10 15:14:29    10520    ----a-w    C:\WINDOWS\system32\avgrsstx.dll
2008-08-16 17:46:27 . 2005-02-27 18:31:32    43672    ----a-w    C:\Documents and Settings\nikki\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2005-03-15 17:23:27 . 2005-03-15 17:23:27    134    ----a-w    C:\Documents and Settings\nikki\Lokale indstillinger\Application Data\fusioncache.dat
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 16:05:45 15360]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 14:07:20 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Programmer\Apoint2K\Apoint.exe" [2003-07-18 21:51:38 135168]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 17:15:12 106496]
"SiS Tray"="C:\WINDOWS\system32\sistray.EXE" [2003-06-26 10:35:36 303104]
"SiS KHooker"="C:\WINDOWS\system32\khooker.exe" [2003-05-29 02:23:50 294912]
"Smapp"="C:\Programmer\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 07:57:30 143360]
"SunJavaUpdateSched"="C:\Programmer\Java\jre6\bin\jusched.exe" [2009-04-17 21:41:29 148888]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2004-10-04 14:42:24 81920]
"SSBkgdUpdate"="C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 23:14:58 155648]
"OpwareSE4"="C:\Programmer\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 12:19:40 69632]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2009-01-29 17:14:23 1601304]
"AGRSMMSG"="AGRSMMSG.exe" - C:\WINDOWS\AGRSMMSG.exe [2003-04-29 08:58:08 88363]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 16:05:45 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-29 17:17:10    10520    ----a-w    C:\WINDOWS\system32\avgrsstx.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"MIDI1"= SYNCOR11.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\StubInstaller.exe"=
"C:\\Programmer\\Real\\RealOne Player\\realplay.exe"=
"C:\\Programmer\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\AVG\\AVG8\\avgemc.exe"=
"C:\\Programmer\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Programmer\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R1 SASKUTIL;SASKUTIL; [x]
S1 Asapi;Asapi; [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-01-29 17:17:06 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-01-29 17:16:58 107272]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-01-29 17:14:52 903960]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-01-29 17:15:30 298264]

.
- - - - TOMME GENVEJE FJERNET - - - -

Notify-WgaLogon - (no file)


.
------- Yderligere scanning -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
TCP: {5A35BC99-C122-4DC6-B997-F9EC360B4C64} = 10.204.1.1,212.54.64.170
FF - ProfilePath - C:\Documents and Settings\nikki\Application Data\Mozilla\Firefox\Profiles\26c5wbgy.default\
FF - component: C:\Programmer\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: C:\Programmer\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: C:\Programmer\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: C:\Programmer\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: C:\Programmer\Real\RealOne Player\Netscape6\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-23 23:26:17
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-3425514897-3168837576-3064886018-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'explorer.exe'(980)
C:\Programmer\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
C:\Programmer\CyberLink\Shared Files\CLRCEngine.dll
C:\WINDOWS\system32\ieframe.dll
C:\WINDOWS\system32\msls31.dll
C:\WINDOWS\system32\webcheck.dll
.
------------------------ Andre kørende processer ------------------------
.
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmer\Apoint2K\HidFind.exe
C:\Programmer\Apoint2K\ApntEx.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Gennemført tid: 2009-04-23 23:35:18 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-04-23 21:35:14

Pre-Kørsel: 10.753.261.568 byte ledig
Post-Kørsel: 10.746.880.000 byte ledig

238    --- E O F ---    2009-04-15 14:34:41
24. april 2009 - 07:04 #12
<arkil>: Du fortsætter bare - du startede jo *S*
Avatar billede arkil Nybegynder
24. april 2009 - 10:37 #13
Åbn et Notesblokvindue, kopiér indholdet med fed skrift ind i dokumentet, og gem indholdet samme sted, som Combofix ligger med navnet CFScript.txt Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".


Killall::
Snapshot::
DirLook::
C:\Documents and Settings\All Users\Application Data\00070271
C:\Documents and Settings\All Users\Application Data\00092092
C:\Documents and Settings\All Users\Application Data\21831069
C:\Documents and Settings\All Users\Application Data\21830069
Folder::
C:\Programmer\Fælles filer\Symantec Shared
C:\Documents and Settings\LocalService\Application Data\Symantec
Driver::
SASKUTIL



Tag så fat i den nye fil med musen, og før den hen over ikonet for Combofix, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den logfil  herind.

Vi skal også se en ny log fra HijackThis efter du har udført dette [23. april 2009 kl. 22:22:51]

PS: Når man kører fildelingsprogrammer får man mange gange en "bonus" i form af spyware.
Jeg vil anbefale dig at afinstaller Azureus og slette denne mappe.

C:\Documents and Settings\nikki\Application Data\Azureus

PS: Jeg går ud fra pc´n kører som den skal nu?
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester