Avatar billede PeterFjelstrup Juniormester
19. oktober 2013 - 20:25 Der er 12 kommentarer og
1 løsning

Kan ikke slette arkivfiler - System Volume Information

For en uge siden var mit Avast virusprogram forsvundet, og da jeg geninstallerede det, havde jeg en virus, der identificerede sig selv som eraseme.exe.
Avast kan ikke åbne og slette en lang række filer, heller ikke i fejlsikker og med deaktiveret systemgenoprettelse.
En stor del af de fundne filer befinder sig i System Volume Information i en mappe der hedder eraseme.
C:\System Volume Information_\restore{XxxxX-xxXx-xXxxxX-XxxxxXx}\RP63\AOO11974.exe|>images\nnButton.png.

en HiJack viser følgende, og jeg kan ikke se nogen mistænkelige services eller registre:

vh Peter

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Programmer\IObit\Advanced SystemCare 6\ASCService.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Programmer\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Lenovo\tvt_reg_monitor_svc.exe
C:\Programmer\Fælles filer\Lenovo\Scheduler\tvtsched.exe
C:\Programmer\Fælles filer\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe
C:\Programmer\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Programmer\Fælles filer\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe
c:\programmer\lenovo\system update\suservice.exe
C:\Programmer\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\IObit\Advanced SystemCare 6\Monitor.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Fælles filer\Java\Java Update\jusched.exe
C:\Programmer\Fælles filer\Lenovo\Scheduler\scheduler_proxy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
C:\Programmer\Brother\ControlCenter3\brccMCtl.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\ThinkPad\ConnectUtilities\ACTray.exe
C:\Programmer\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Programmer\AVAST Software\Avast\avastUI.exe
C:\Programmer\AVG Secure Search\vprot.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Peter\Lokale indstillinger\Application Data\Akamai\netsession_win.exe
C:\Programmer\Fælles filer\Ahead\lib\NMBgMonitor.exe
C:\Documents and Settings\Peter\Lokale indstillinger\Application Data\Akamai\netsession_win.exe
C:\Programmer\IObit\Advanced SystemCare 6\ASCTray.exe
C:\Programmer\Sony\Sony PC Companion\PCCompanion.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\IObit\IObit Malware Fighter\IMF.exe
C:\Programmer\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Programmer\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\svchost.exe
C:\HiJackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmer\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programmer\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmer\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programmer\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Programmer\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Fælles filer\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Programmer\Fælles filer\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Programmer\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Programmer\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Programmer\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ACTray] C:\Programmer\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Programmer\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Programmer\ThinkVantage Fingerprint Software\launcher.exe" /startup
O4 - HKLM\..\Run: [avast] "C:\Programmer\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [vProt] "C:\Programmer\AVG Secure Search\vprot.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Documents and Settings\Peter\Lokale indstillinger\Application Data\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Programmer\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Programmer\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-21-117609710-1965331169-1417001333-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Administrator')
O4 - HKUS\S-1-5-21-117609710-1965331169-1417001333-500\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - S-1-5-18 Startup: Yahoo! Widgets.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Yahoo! Widgets.lnk = ? (User 'Default user')
O4 - Startup: Yahoo! Widgets.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - http://buttons.weatherblink.com/one-toolbaredits/menusearch.jhtml?s=100000413&p2=^XN^xdm101^S06157^dk&si=COab5ZaM67gCFXR7cAodzCMAPQ&a=717205CD-4995-4F86-A0F7-AB7C9D6DF8FF&n=2013081503&cv=1
O14 - IERESET.INF: START_PAGE_URL=http://google.com/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Programmer\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Programmer\Fælles filer\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo  - C:\Programmer\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo  - C:\Programmer\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Programmer\IObit\Advanced SystemCare 6\ASCService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Programmer\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Programmer\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmer\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmer\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Programmer\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Programmer\Sony\Sony PC Companion\PCCService.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\programmer\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Programmer\Fælles filer\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Programmer\Fælles filer\Lenovo\Scheduler\tvtsched.exe
O23 - Service: vToolbarUpdater17.0.12 - Unknown owner - C:\Programmer\Fælles filer\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe
19. oktober 2013 - 22:30 #1
Lige en hurtig ...

Omtalte mappe

C:\System Volume Information_

kan DU ikke slette/pille i !!!

Du skal DEAKTIVERE Systemgendannelse -> Genstart - AKTIVERE Systemgendannelse ...
Avatar billede 220661 Ekspert
19. oktober 2013 - 23:45 #2
Kør to programmer:

Hent Malwarebytes Anti-Malware herfra:
http://downloads.malwarebytes.org/mbam-download.php

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde.
Når programmet har scannet færdigt tryk på "Vis resultater"  - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen. Kopier loggen herind.
Mht.: Vista/Win7/Win8 - HøjreMusseTast - "Kør som Administrator..."
http://www.bleepingcomputer.com/download/adwcleaner/dl/125/
(Der går lige 5 sek før du skal trykke på gem)
Start programmet, og når det er startet trykker du på [Scan]
Pc scannes, og ved endt scanning skal du trykke på [Clean].
Og derefter (automatisk) genstart...
Tilbage fra genstart kommer en log, som du gerne må kopiere herind.

Nu siger en log ikke det hele, men kopieres den ind i log viseren er punktet 08 markeret med rødt kryds. Jeg ved ikke lige hvad det er, men den bør måske slettes.
Avatar billede PeterFjelstrup Juniormester
20. oktober 2013 - 19:26 #3
system restore har været deaktiveret siden jeg fandt virus (malware) for en uge siden.


Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.10.20.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Peter :: PETER-T61 [administrator]

20-10-2013 17:27:44
mbam-log-2013-10-20 (17-27-44).txt

Skanningstype: Fuldstændig skanning (C:\|D:\|)
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 263236
Tid gået: 40 minut(ter), 49 sekund(er)

Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret: 14
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Ingen handling valgt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} (PUP.Optional.QuickShare.A) -> Ingen handling valgt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} (PUP.Optional.QuickShare.A) -> Ingen handling valgt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{323420B6-65E5-4657-8106-A27392D4D4AA} (PUP.Optional.LinkSwift.A) -> Ingen handling valgt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{323420B6-65E5-4657-8106-A27392D4D4AA} (PUP.Optional.LinkSwift.A) -> Ingen handling valgt.
HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Ingen handling valgt.
HKCR\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Ingen handling valgt.
HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Ingen handling valgt.
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1 (PUP.Optional.SweetIM) -> Ingen handling valgt.
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook (PUP.Optional.SweetIM) -> Ingen handling valgt.
HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
HKLM\SOFTWARE\Updater By Sweetpacks (PUP.Optional.SweetPacks.A) -> Ingen handling valgt.
HKLM\SOFTWARE\Wow6432Node\Updater By Sweetpacks (PUP.Optional.SweetPacks.A) -> Ingen handling valgt.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Ingen handling valgt.

Registreringsdatabaseværdier Inficeret: 4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAMMER\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGHELPERAPP.EXE (PUP.Optional.SweetIM) -> Data: 1 -> Ingen handling valgt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAMMER\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGTOOLBARPROXY.DLL (PUP.Optional.SweetIM) -> Data: 1 -> Ingen handling valgt.
HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {9BB2DDB3-3769-11E3-A6E3-001CBF6E5692} -> Ingen handling valgt.
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {9BB2DDB3-3769-11E3-A6E3-001CBF6E5692} -> Ingen handling valgt.

Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)

Inficerede Mapper: 9
C:\Programmer\SweetIM\Toolbars (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\conf (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\flavours (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange (PUP.Optional.SweetIM.A) -> Ingen handling valgt.

Inficerede Filer: 118
C:\Documents and Settings\Peter\Dokumenter\Downloads\Drivers_XP_7_Update 24.09.2013\Windows 7 Drivers\USB 3.0 Host Controller\VIA\VIA_USB3_V4.20B_WHQL.exe (PUP.Optional.BundleInstaller) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Dokumenter\Downloads\Drivers_XP_7_Update 24.09.2013\Windows XP Drivers\USB 3.0 Host Controller\VIA\VIA_USB3_V1.90A_WHQL\VIA_USB3_V4.20B_WHQL.exe (PUP.Optional.BundleInstaller) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Dokumenter\Hentede filer\flvplayer-setup.exe (PUP.DownloadAdmin) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Dokumenter\Hentede filer\PowerISO5.exe (PUP.Optional.OpenCandy) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Dokumenter\Hentede filer\SoftonicDownloader_for_pocket-killbox.exe (PUP.Optional.Softonic.A) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\1382041304_28497703_937_4.tmp (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\mgsqlite3.7z (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\mgsqlite3.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\spacksyahoo_717_active.exe (PUP.Optional.SweetPacks.A) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\WSSetup.exe (PUP.Optional.Perion.A) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\Shortcut_bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temporary Internet Files\Content.IE5\PP9EZ3C5\mgsqlite3[1].7z (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\HiJackThis\backups\backup-20131018-033127-339.dll (PUP.Optional.SweetPacks) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\ClearHist.exe (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgcommon.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgconfig.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mghooking.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mglogger.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll (PUP.Optional.SweetIM) -> Ingen handling valgt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP76\A0017673.dll (PUP.Optional.LinkSwift.A) -> Ingen handling valgt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024056.exe (PUP.Optional.InstallBrain.A) -> Ingen handling valgt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024059.exe (PUP.Optional.Perion) -> Ingen handling valgt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024063.exe (PUP.Optional.Perion) -> Ingen handling valgt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024066.exe (PUP.Optional.SweetPacks.A) -> Ingen handling valgt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024121.dll (PUP.Optional.SweetPacks) -> Ingen handling valgt.
C:\WINDOWS\system32\roboot.exe (PUP.Optional.PCPerformer.A) -> Ingen handling valgt.
C:\WINDOWS\Installer\1b252aa.msi (PUP.Optional.SweetIM) -> Ingen handling valgt.
D:\Småprogrammer\coretemp_1236.exe (PUP.Optional.InstallIQ) -> Ingen handling valgt.
D:\Småprogrammer\flvplayer-setup.exe (PUP.DownloadAdmin) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\default.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\conf\logger.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcm90.dll (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcp90.dll (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcr90.dll (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\eye_icon.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\about.html (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\affid.dat (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\basis.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\bing.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\clear-history.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim-over.gif (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim.gif (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\content-notifier.js (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\dating.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\dictionary.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\eye_icon_over.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\e_cards.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\find.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\free_stuff.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\games.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\glitter.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\google.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\help.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\highlight.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\locales.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\logo_16x16.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\logo_21x18.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\logo_32x32.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\logo_about.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\MenuExt.html (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\more-search-providers.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\music.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\news.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\onstart.js (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\options.html (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\photos.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\search-current-site.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\shopping.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\SmileySmile.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\SmileyWink.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\sweetim_text.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\toolbar.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\video.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\web-search.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_bing.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_blank.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_current.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_dictionary.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_google.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_hover.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_left.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_photo.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_video.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_web.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_yahoo.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\flavours\toolbar_bng.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\flavours\toolbar_ggl.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\flavours\toolbar_yho.xml (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_bing.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_current.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_dictionary.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_google.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_hover.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_left.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_photo.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_video.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_web.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_yahoo.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_bing.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_current.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_dictionary.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_google.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_hover.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_left.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_photo.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_video.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_web.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.
C:\Programmer\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_yahoo.png (PUP.Optional.SweetIM.A) -> Ingen handling valgt.

(færdig)

# AdwCleaner v3.009 - Report created 20/10/2013 at 19:12:53
# Updated 19/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Peter - PETER-T61
# Running from : C:\HiJackThis\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : vToolbarUpdater17.0.12

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG Secure Search
Folder Deleted : C:\Programmer\AVG Secure Search
Folder Deleted : C:\Programmer\SweetIM
Folder Deleted : C:\Programmer\Fælles filer\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Peter\Lokale indstillinger\Application Data\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Peter\Lokale indstillinger\Application Data\iac
Folder Deleted : C:\Documents and Settings\Peter\Application Data\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Peter\Application Data\PerformerSoft
File Deleted : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Deleted : C:\WINDOWS\system32\roboot.exe
File Deleted : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\searchplugins\avg-secure-search.xml
File Deleted : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\searchplugins\SweetIm.xml
File Deleted : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\searchplugins\Sweetpacks Search.xml
File Deleted : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\searchplugins\Web Search.xml
File Deleted : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\user.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Programmer\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{323420B6-65E5-4657-8106-A27392D4D4AA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{323420B6-65E5-4657-8106-A27392D4D4AA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\WINDOWS\system32\ARFC\wrtc.exe]
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\smartbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Updater By Sweetpacks
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F4E33CE5-A7AB-4F68-A7E7-F0AA84EF2D9E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F4E33CE5-A7AB-4F68-A7E7-F0AA84EF2D9E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LinkSwift
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5EC33E4FBA7A86F47A7E0FAA48FED2E9
Key Deleted : HKLM\Software\Classes\Installer\Features\5EC33E4FBA7A86F47A7E0FAA48FED2E9
Key Deleted : HKLM\Software\Classes\Installer\Products\5EC33E4FBA7A86F47A7E0FAA48FED2E9
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v24.0 (da)

[ File : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\prefs.js ]

Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.BUTTON_STRUCTURE", "[{\"b\":212767156,\"p\":\"L.0\"},{\"b\":212767157,\"p\":\"L.0.0\"},{\"b\":212767159,\"p\":\"L.0.1\"},{\"b\":212767163,\"p\":\"L.[...]
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=717205CD-4995-4F86-A0F7-AB7C9D6DF8FF&n=77fd2c88&p2=^XN^xdm101^S06157^dk&si=COab5ZaM67gCFXR7cAodzC[...]
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.hp.user.defined", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.contextKey", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.installDate", "2013080712");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerId", "^XN^xdm101^S06157^dk");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerSubId", "COab5ZaM67gCFXR7cAodzCMAPQ");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.success", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.toolbarId", "717205CD-4995-4F86-A0F7-AB7C9D6DF8FF");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.lastActivePing", "1382277736136");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.lastKnownVersion", "5.25.1.60433");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.defaultSearch", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.homePageEnabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.keywordEnabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.tabEnabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.toolbarCollapsed", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.weather.location", "10001");
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "weatherblink@mindspark.com");
Line Deleted : user_pref("keyword.URL", "hxxp://mysearch.sweetpacks.com/?src=2&st=12&crg=3.5000006.10061&barid={9BB2DDB3-3769-11E3-A6E3-001CBF6E5692}&q=");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "Web Search");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Line Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Line Deleted : user_pref("sweetim.toolbar.urls.homepage", "hxxp://mysearch.sweetpacks.com/?src=10&st=12&crg=3.5000006.10061&barid={9BB2DDB3-3769-11E3-A6E3-001CBF6E5692}");

*************************

AdwCleaner[R0].txt - [14176 octets] - [20/10/2013 18:57:35]
AdwCleaner[S0].txt - [14388 octets] - [20/10/2013 19:12:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14449 octets] ##########
20. oktober 2013 - 19:39 #4
MalwareBytes - du 'glemte' vist denne 'detalje' ->

har scannet færdigt tryk på "Vis resultater"  - og herefter tryk på "Fjern det valgte" -

Om igen med MalwareBytes
Avatar billede PeterFjelstrup Juniormester
20. oktober 2013 - 20:09 #5
Det vil sige, jeg skal tjekke alle linier?
Avatar billede 220661 Ekspert
20. oktober 2013 - 21:05 #6
Nej du vælger at fjerne alt det Malwarebytes finder.
Avatar billede PeterFjelstrup Juniormester
20. oktober 2013 - 21:33 #7
Det gjorde jeg ved at sætte tjek i alle firkanterne ud for hver linie.

Det ser godt ud.
ewido er igennem WIN/System32/ uden at finde noget, så jeg tror den er clean.

Her er scan.

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.10.20.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Peter :: PETER-T61 [administrator]

20-10-2013 20:04:46
mbam-log-2013-10-20 (20-04-46).txt

Skanningstype: Fuldstændig skanning (C:\|D:\|)
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 262776
Tid gået: 44 minut(ter), 17 sekund(er)

Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret: 1
HKLM\SOFTWARE\Wow6432Node\Updater By Sweetpacks (PUP.Optional.SweetPacks.A) -> Sat i karantæne og slettet succesfuldt.

Registreringsdatabaseværdier Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)

Inficerede Mapper: 0
(Ingen skadelige objekter blev fundet)

Inficerede Filer: 45
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\ClearHist.exe.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mgcommon.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mgconfig.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mgHelper.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mghooking.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mglogger.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\Programmer\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll.vir (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\AdwCleaner\Quarantine\C\WINDOWS\system32\roboot.exe.vir (PUP.Optional.PCPerformer.A) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Dokumenter\Downloads\Drivers_XP_7_Update 24.09.2013\Windows 7 Drivers\USB 3.0 Host Controller\VIA\VIA_USB3_V4.20B_WHQL.exe (PUP.Optional.BundleInstaller) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Dokumenter\Downloads\Drivers_XP_7_Update 24.09.2013\Windows XP Drivers\USB 3.0 Host Controller\VIA\VIA_USB3_V1.90A_WHQL\VIA_USB3_V4.20B_WHQL.exe (PUP.Optional.BundleInstaller) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Dokumenter\Hentede filer\flvplayer-setup.exe (PUP.DownloadAdmin) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Dokumenter\Hentede filer\PowerISO5.exe (PUP.Optional.OpenCandy) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Dokumenter\Hentede filer\SoftonicDownloader_for_pocket-killbox.exe (PUP.Optional.Softonic.A) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\1382041304_28497703_937_4.tmp (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\mgsqlite3.7z (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\mgsqlite3.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\spacksyahoo_717_active.exe (PUP.Optional.SweetPacks.A) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\WSSetup.exe (PUP.Optional.Perion.A) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temp\Shortcut_bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\Documents and Settings\Peter\Lokale indstillinger\Temporary Internet Files\Content.IE5\PP9EZ3C5\mgsqlite3[1].7z (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\HiJackThis\backups\backup-20131018-033127-339.dll (PUP.Optional.SweetPacks) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP76\A0017673.dll (PUP.Optional.LinkSwift.A) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024056.exe (PUP.Optional.InstallBrain.A) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024059.exe (PUP.Optional.Perion) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024063.exe (PUP.Optional.Perion) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024066.exe (PUP.Optional.SweetPacks.A) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP87\A0024121.dll (PUP.Optional.SweetPacks) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024559.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024557.exe (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024558.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024560.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024561.exe (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024562.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024563.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024564.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024565.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024566.dll (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
C:\System Volume Information\_restore{B5A24766-AE90-46BB-90D3-C1A9EA0FE2F0}\RP90\A0024585.exe (PUP.Optional.PCPerformer.A) -> Sat i karantæne og slettet succesfuldt.
C:\WINDOWS\Installer\1b252aa.msi (PUP.Optional.SweetIM) -> Sat i karantæne og slettet succesfuldt.
D:\Småprogrammer\coretemp_1236.exe (PUP.Optional.InstallIQ) -> Sat i karantæne og slettet succesfuldt.
D:\Småprogrammer\flvplayer-setup.exe (PUP.DownloadAdmin) -> Sat i karantæne og slettet succesfuldt.

(færdig)

# AdwCleaner v3.009 - Report created 20/10/2013 at 21:01:43
# Updated 19/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Peter - PETER-T61
# Running from : C:\HiJackThis\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v24.0 (da)

[ File : C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\t3p90o18.default\prefs.js ]

Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.BUTTON_STRUCTURE", "[{\"b\":212767156,\"p\":\"L.0\"},{\"b\":212767157,\"p\":\"L.0.0\"},{\"b\":212767159,\"p\":\"L.0.1\"},{\"b\":212767163,\"p\":\"L.[...]
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?n=77fd7fc3&p2=^XN^xpi000^S06157^");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.contextKey", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.installDate", "2013102019");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerId", "^XN^xpi000^S06157^");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerSubId", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.installation.success", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.lastKnownVersion", "5.25.1.60433");
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.defaultSearch", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.homePageEnabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.keywordEnabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.options.tabEnabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._gcMembers_.toolbarCollapsed", true);
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "weatherblink@mindspark.com");

*************************

AdwCleaner[R0].txt - [14176 octets] - [20/10/2013 18:57:35]
AdwCleaner[R1].txt - [2557 octets] - [20/10/2013 21:00:03]
AdwCleaner[S0].txt - [14530 octets] - [20/10/2013 19:12:53]
AdwCleaner[S1].txt - [2508 octets] - [20/10/2013 21:01:43]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2568 octets] ##########

Mange tak for hjælpen.
Avatar billede 220661 Ekspert
20. oktober 2013 - 21:44 #8
Velbekomme.
Men hvorfor tager du så point tilbage, når du har fået hjælp til dit problem?
Avatar billede PeterFjelstrup Juniormester
20. oktober 2013 - 22:16 #9
Hovsa, det her har jeg aldrig lært.

Hvad kan jeg gøre? Jeg vil med glæde give 500 point for at få min PC renset.

Det er rigtigt, at jeg vist tjekkede to steder for at udløse dusøren.

Er det der, hvor der står afvist svar? Eller er jeg kommet til at give mig selv point?
Avatar billede 220661 Ekspert
20. oktober 2013 - 22:28 #10
Ja du har selv lagt et svar og accepteret dette, og taget point tilbage.

Det normale er at hele forløbet i tråden skrives i kommentar. Når man kommer til en løsning beder du som spørger om at hjælperen eller flere hjælpere lægger svar du kan lukke med.
Er der flere svar skal alle svar accepteres.

Man kan for at råde bod på det oprette et point spørgsmål hvor man uddeler point i stedet.
Dette gøres i samme kategori som det oprindelige spørgsmål.
Her skrives i overskrift hvem der skal have point, og en henvisning til oprindelig tråd.
I den gamle tråd henvises til ny point spørgsmål.
Avatar billede Slettet bruger
20. oktober 2013 - 22:51 #11
Hej Peter. Bare til din orientering. Du maglede lige at lægge et link ind her, til dit nye indlæg med point til 220661. Ellers ser han det maske ikke.
Jeg har skrevet det til ham, så det er mere for en anden gangs skyld:)
Avatar billede 220661 Ekspert
20. oktober 2013 - 22:54 #12
Tak for intern mail til min gode ven H339 :-)
Point spørgsmål: http://www.eksperten.dk/spm/987116
Avatar billede Slettet bruger
20. oktober 2013 - 22:56 #13
OK:)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester