<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/">
    
    <channel>
    
    <title>Spywarefri Forum</title>
    <link>http://www.spywarefri.dk/forum/</link>
    <description>Spywarefri Forum</description>
    <dc:language>en</dc:language>
    <dc:rights>Copyright 2009</dc:rights>
    <dc:date>2009-12-06T14:10:09+01:00</dc:date>
    <admin:generatorAgent rdf:resource="http://spywarefri.dk/" />
    

    <item>
      <title>MEGET sløv pc +</title>
      <link>http://www.spywarefri.dk/forum/viewthread/41305/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/41305/#When:12:46:52Z</guid>
      <description>&lt;p&gt;Hej, &lt;br /&gt;
Jeg har da fået et problem der vil noget, som skrevet er min pc blevet meget langsom, det er ikke længe siden jeg var her sidst men kort tid efter blev min pc meget sløv, men så nu hvor jeg vil gemme HijackThis og de andre kommer der en fejlmelding med &#8220;The filepicker was unexpectedly closed by windows&#8221;, det kommer når jeg vil gemme dem på skrivebordet?, det har jeg aldrig set før, jeg har prøvet at genstarte men der kommer det samme op, håber i kender problemet.&lt;/p&gt;

&lt;p&gt;Mvh,&lt;br /&gt;
Henrik
&lt;/p&gt;</description>
      <dc:date>2007-09-13T12:46:52+01:00</dc:date>
    </item>

    <item>
      <title>System</title>
      <link>http://www.spywarefri.dk/forum/viewthread/49678/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/49678/#When:11:19:23Z</guid>
      <description>&lt;p&gt;HJÆLP ! ! !&lt;br /&gt;
Jeg har haft en virus/orm inde på min computer, selv om jeg har et virus program, ( Avast antivirus ).&lt;br /&gt;
Jeg har vist fået fjernet det hele.&lt;br /&gt;
Jeg kan dog ikke komme i: Registrerings databasen, Ms config, Joblisten, eller få lov til at rette noget som helst i skærm menuen, bliver hele tiden mindet om at Administrator har forhindret brug af disse menuer, Jeg har prøvet at oprette mig selv som adninistrator men det hjælper ikke.&lt;br /&gt;
Så mit spørgsmål går ud på:&lt;br /&gt;
Kan jeg rette fejlen uden at skulle formatere hele harddisken&lt;br /&gt;
Venlig hilsen&lt;br /&gt;
Bruno AHlgren
&lt;/p&gt;</description>
      <dc:date>2008-08-05T11:19:23+01:00</dc:date>
    </item>

    <item>
      <title>Kernel&#45;Rootkit</title>
      <link>http://www.spywarefri.dk/forum/viewthread/52767/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/52767/#When:13:06:45Z</guid>
      <description>&lt;p&gt;Hejsa! Jeg sad og researchede lidt om hjælp til spyware, og fandt dette forum. Jeg er ikke den helt store computer ekspert, men er rimelig sikker på jeg har fået et Kernel&#45;Rootkit. I mappen &#8216;Acer Arcade Deluxe&#8217; som er et helt almindelig Windows Vista multimedie program ligger mappen &#8216;PlayMovie&#8217; og filen &#8216;PCMGUIDs&#8217; som åbnes med notesblok. Inde i den står:&lt;/p&gt;

&lt;p&gt;[GUID List]&lt;br /&gt;
&#123;aa4bf92b&#45;2aaf&#45;11da&#45;9d78&#45;000129760d75&#125;&lt;br /&gt;
&#123;a450831d&#45;25f6&#45;4f42&#45;9662&#45;d000b25e0d82&#125;&lt;br /&gt;
&#123;2637C347&#45;9DAD&#45;11D6&#45;9EA2&#45;00055D0CA761&#125;&lt;/p&gt;

&lt;p&gt;Ved ikke om det har noget med et rootkit at gøre, men jeg prøvede ihvertfald at åbne mappen &#8216;PlayMovie&#8217;. Inde i den ligger der overnaturligt mange mapper / filer en af dem hedder &#8216;Kernel&#8217;. Inde i den ligger yderlige 3 mapper, en af dem ved navnet &#8216;KoanBox&#8217;. Derinde ligger der filer som &#8216;KoanBox.dll&#8217;, &#8216;psycho.rar&#8217; og alle mulige andre mystiske og umystiske filer. Idet jeg ikke er den store computer ekspert, ville det være rart med noget hjælp! Skal jeg tage det her alvorligt, eller ikke? Jeg prøvede at køre en Spyware Doctor skan, men Spyware Doctor gjorde mit system utroligt langsomt, og slet ikke til at være på. Den fandt imidlertidigt 5 trusler, heraf 2 &#8216;Mellemalvorlige&#45;Trusler&#8217;, men kunne ikke gøre noget idet det er et købe program. Jeg uninstallede det derfor igen, og nu er min computer hurtig som lynet.&lt;/p&gt;

&lt;p&gt;Hjælp mig, tak!
&lt;/p&gt;</description>
      <dc:date>2008-11-15T13:06:45+01:00</dc:date>
    </item>

    <item>
      <title>Svchost problem</title>
      <link>http://www.spywarefri.dk/forum/viewthread/53059/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/53059/#When:13:55:12Z</guid>
      <description>&lt;p&gt;Hej Jeg har et problem, med at min svchost.exe bruger 100.000 KB Hukommelse, og ofte rimelig meget CPU forbrug, selvom den lige er startet op og jeg intet laver. Jeg har været her inde og læse nogen ting om svchost. Men jeg kan ikke rigtigt finde synderen til den er så høj. [xx(]&lt;/p&gt;

&lt;p&gt;Jeg har skannet den med Bullguard og Spybot S&amp;amp;D. Og jeg har diskdefragmenteret den. Og jeg har brugt Process Explorer til at finde synderen, Men den viser bare at det eneste der kører over svchost.exe er wuauclt.exe. &lt;/p&gt;

&lt;p&gt;Jeg har også brugt CCleaner til at ryde op her på, men det hjalp heller ik.&lt;/p&gt;

&lt;p&gt;Er der nogen der ved hvad jeg kan gøre? Eller skal den bare formateres igen? &lt;/p&gt;

&lt;p&gt;Mvh Kasper
&lt;/p&gt;</description>
      <dc:date>2008-11-28T13:55:12+01:00</dc:date>
    </item>

    <item>
      <title>Combofix finder rootkit efter webhancer removal</title>
      <link>http://www.spywarefri.dk/forum/viewthread/51619/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/51619/#When:15:51:01Z</guid>
      <description>&lt;p&gt;Hej Team spywarefri&lt;/p&gt;

&lt;p&gt;Jeg har fjernet Webhancer med MalwareByte og LSPFix. Når jeg kører Combofix, meddeles at:&lt;br /&gt;
&#8220;Combofix has found .. presens og af rootkit and need to restart&#8221;.&lt;br /&gt;
Efter genstart kommer samme fejl igen igen, når jeg kører combofix&lt;br /&gt;
Der bliver aldrig lavet en logfil. Computeren er ikke på netværket og opdaterer ikke combifix.&lt;/p&gt;

&lt;p&gt;
&lt;/p&gt;</description>
      <dc:date>2008-10-05T15:51:01+01:00</dc:date>
    </item>

    <item>
      <title>wallpaper1</title>
      <link>http://www.spywarefri.dk/forum/viewthread/51163/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/51163/#When:21:16:40Z</guid>
      <description>&lt;p&gt;Hej.&lt;br /&gt;
da jeg åbnede en mail den anden dag væltede det ind med virus, og min norman opfangede en del af det. Der blev dog ved med at være en meddelelse på skærmen om virus, det fandt jeg senere ud af var en ny skrivebordsbaggrund der hed wallpaper1?? Underligt, men jeg er i tvivl om alt er væk, så vil i kigge på disse logs?&lt;/p&gt;

&lt;p&gt;Malwarebytes&#8217; Anti&#45;Malware 1.28&lt;br /&gt;
Database version: 1164&lt;br /&gt;
Windows 5.1.2600 Service Pack 3&lt;/p&gt;

&lt;p&gt;17&#45;09&#45;2008 18:54:05&lt;br /&gt;
mbam&#45;log&#45;2008&#45;09&#45;17 (18&#45;54&#45;05).txt&lt;/p&gt;

&lt;p&gt;Skan type: Fuldstændig skanning (C:|)&lt;br /&gt;
Objekter skannet: 81847&lt;br /&gt;
Tid tilbagelagt: 16 minute(s), 33 second(s)&lt;/p&gt;

&lt;p&gt; Inficerede Hukommelses Processer: 0&lt;br /&gt;
 Inficerede Hukommelses Moduler: 0&lt;br /&gt;
 Inficerede Registeringsdatabase Nøgler: 0&lt;br /&gt;
Inficerede Registeringsdatabase Værdier: 0&lt;br /&gt;
Inficerede Registeringsdatabase Filer: 0&lt;br /&gt;
Inficerede Mapper: 0&lt;br /&gt;
Inficerede Filer: 0&lt;/p&gt;

&lt;p&gt; Inficerede Hukommelses Processer:&lt;br /&gt;
(Ingen mistænkelige filer fundet)&lt;/p&gt;

&lt;p&gt; Inficerede Hukommelses Moduler:&lt;br /&gt;
(Ingen mistænkelige filer fundet)&lt;/p&gt;

&lt;p&gt; Inficerede Registeringsdatabase Nøgler:&lt;br /&gt;
(Ingen mistænkelige filer fundet)&lt;/p&gt;

&lt;p&gt;Inficerede Registeringsdatabase Værdier:&lt;br /&gt;
(Ingen mistænkelige filer fundet)&lt;/p&gt;

&lt;p&gt;Inficerede Registeringsdatabase Filer:&lt;br /&gt;
(Ingen mistænkelige filer fundet)&lt;/p&gt;

&lt;p&gt;Inficerede Mapper:&lt;br /&gt;
(Ingen mistænkelige filer fundet)&lt;/p&gt;

&lt;p&gt;Inficerede Filer:&lt;br /&gt;
(Ingen mistænkelige filer fundet)&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
ComboFix 08&#45;09&#45;16.05 &#45; niels peter 2008&#45;09&#45;17 18:55:28.1 &#45; &lt;span style=&quot;color:red;&quot;&gt;&lt;b&gt;FAT32&lt;/b&gt;&lt;/span&gt;x86&lt;br /&gt;
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1030.18.199 [GMT 2:00]&lt;br /&gt;
Running from: C:Documents and Settingsniels peterSkrivebordSpywarefriComboFix.exe&lt;br /&gt;
 * Created a new restore point&lt;br /&gt;
 * Resident AV is active&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;span style=&quot;color:red;&quot;&gt;&lt;b&gt;WARNING &#45;THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
.&lt;/p&gt;

&lt;p&gt;(((((((((((((((((((((((((((((((((((((((&amp;nbsp;  Other Deletions &amp;nbsp; )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;
.&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsAll UsersMenuen StartProgrammerPCPrivacyCleaner&lt;br /&gt;
C:Documents and SettingsAll UsersMenuen StartProgrammerPCPrivacyCleanerPCPrivacyCleaner.lnk&lt;br /&gt;
C:Documents and SettingsAll UsersMenuen StartProgrammerPCPrivacyCleanerUninstall PCPrivacyCleaner.lnk&lt;br /&gt;
C:WINDOWSsystem32160281.exe&lt;br /&gt;
C:WINDOWSsystem32vyIjSvut.ini&lt;br /&gt;
C:WINDOWSsystem32vyIjSvut.ini2&lt;/p&gt;

&lt;p&gt;.&lt;br /&gt;
(((((((((((((((((((((((((((((((((((((((&amp;nbsp;  Drivers/Services &amp;nbsp; )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;
.&lt;/p&gt;

&lt;p&gt;&#8212;&#8212;&#8212;&#45;Legacy_NSESVC&lt;br /&gt;&#8212;&#8212;&#8212;&#45;Legacy_TDSSSERV&lt;br /&gt;&#8212;&#8212;&#8212;&#45;Service_nsesvc&lt;br /&gt;&#8212;&#8212;&#8212;&#45;Service_TDSSserv&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
(((((((((((((((((((((((((&amp;nbsp;  Files Created from 2008&#45;08&#45;17 to 2008&#45;09&#45;17  )))))))))))))))))))))))))))))))&lt;br /&gt;
.&lt;/p&gt;

&lt;p&gt;2008&#45;09&#45;17 18:35 . 2008&#45;09&#45;17 18:35 &amp;lt;DIR&amp;gt; d&#8212;&#8212;&#8212;&#8212;C:ProgrammerMalwarebytes&#8217; Anti&#45;Malware&lt;br /&gt;
2008&#45;09&#45;17 18:35 . 2008&#45;09&#45;10 00:04 38,528&#8212;a&#8212;&#8212;&#8212;C:WINDOWSsystem32driversmbamswissarmy.sys&lt;br /&gt;
2008&#45;09&#45;17 18:35 . 2008&#45;09&#45;10 00:03 17,200&#8212;a&#8212;&#8212;&#8212;C:WINDOWSsystem32driversmbam.sys&lt;br /&gt;
2008&#45;09&#45;17 18:29 . 2008&#45;09&#45;17 18:29 &amp;lt;DIR&amp;gt; d&#8212;&#8212;&#8212;&#8212;C:ProgrammerCCleaner&lt;br /&gt;
2008&#45;09&#45;16 16:12 . 2008&#45;09&#45;16 16:12 61,440&#8212;a&#8212;&#8212;&#8212;C:WINDOWSsystem32driversatbymz.sys&lt;br /&gt;
2008&#45;08&#45;25 17:28 . 2008&#45;08&#45;25 18:45 144&#8212;ahs&#8212;&#8212;C:WINDOWSsystem32688789246.dat&lt;/p&gt;

&lt;p&gt;.&lt;br /&gt;
((((((((((((((((((((((((((((((((((((((((&amp;nbsp;  Find3M Report &amp;nbsp; ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;
.&lt;br /&gt;
2008&#45;09&#45;02 10:48 19,512&#8212;&#8212;a&#45;w C:WINDOWSsystem32driversnvcw32mf.sys&lt;br /&gt;
2008&#45;07&#45;18 20:10 94,920&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachecdm.dll&lt;br /&gt;
2008&#45;07&#45;18 20:10 94,920&#8212;&#8212;a&#45;w C:WINDOWSsystem32cdm.dll&lt;br /&gt;
2008&#45;07&#45;18 20:10 53,448&#8212;&#8212;a&#45;w C:WINDOWSsystem32wuauclt.exe&lt;br /&gt;
2008&#45;07&#45;18 20:10 53,448&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachewuauclt.exe&lt;br /&gt;
2008&#45;07&#45;18 20:10 45,768&#8212;&#8212;a&#45;w C:WINDOWSsystem32wups2.dll&lt;br /&gt;
2008&#45;07&#45;18 20:10 36,552&#8212;&#8212;a&#45;w C:WINDOWSsystem32wups.dll&lt;br /&gt;
2008&#45;07&#45;18 20:10 36,552&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachewups.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 563,912&#8212;&#8212;a&#45;w C:WINDOWSsystem32wuapi.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 563,912&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachewuapi.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 325,832&#8212;&#8212;a&#45;w C:WINDOWSsystem32wucltui.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 325,832&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachewucltui.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 205,000&#8212;&#8212;a&#45;w C:WINDOWSsystem32wuweb.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 205,000&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachewuweb.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 1,811,656&#8212;&#8212;a&#45;w C:WINDOWSsystem32wuaueng.dll&lt;br /&gt;
2008&#45;07&#45;18 20:09 1,811,656&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachewuaueng.dll&lt;br /&gt;
2008&#45;07&#45;18 20:07 270,880&#8212;&#8212;a&#45;w C:WINDOWSsystem32mucltui.dll&lt;br /&gt;
2008&#45;07&#45;18 20:07 210,976&#8212;&#8212;a&#45;w C:WINDOWSsystem32muweb.dll&lt;br /&gt;
2008&#45;07&#45;07 20:29 253,952&#8212;&#8212;a&#45;w C:WINDOWSsystem32es.dll&lt;br /&gt;
2008&#45;07&#45;07 20:29 253,952&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcachees.dll&lt;br /&gt;
2008&#45;06&#45;24 16:44 74,240&#8212;&#8212;a&#45;w C:WINDOWSsystem32mscms.dll&lt;br /&gt;
2008&#45;06&#45;24 16:44 74,240&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcachemscms.dll&lt;br /&gt;
2008&#45;06&#45;24 16:12 295,936&#8212;&#8212;&#8212;w C:WINDOWSsystem32wmpeffects.dll&lt;br /&gt;
2008&#45;06&#45;24 08:33 3,592,192&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcachemshtml.dll&lt;br /&gt;
2008&#45;06&#45;23 09:20 13,824&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcacheieudinit.exe&lt;br /&gt;
2008&#45;06&#45;23 09:19 70,656&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcacheie4uinit.exe&lt;br /&gt;
2008&#45;06&#45;23 09:19 625,664&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcacheiexplore.exe&lt;br /&gt;
2008&#45;06&#45;21 05:23 161,792&#8212;&#8212;a&#45;w C:WINDOWSsystem32dllcacheieakui.dll&lt;br /&gt;
2008&#45;06&#45;20 17:48 246,784&#8212;&#8212;a&#45;w C:WINDOWSsystem32mswsock.dll&lt;br /&gt;
2008&#45;06&#45;20 17:48 246,784&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcachemswsock.dll&lt;br /&gt;
2008&#45;06&#45;20 17:48 147,968&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcachednsapi.dll&lt;br /&gt;
2008&#45;06&#45;20 11:51 361,600&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcachetcpip.sys&lt;br /&gt;
2008&#45;06&#45;20 11:40 138,496&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcacheafd.sys&lt;br /&gt;
2008&#45;06&#45;20 11:08 225,856&#8212;&#8212;&#8212;w C:WINDOWSsystem32dllcachetcpip6.sys&lt;br /&gt;
2001&#45;07&#45;26 14:58 47&#8212;&#8212;a&#45;w C:ProgrammerACMonitor_X73.ini&lt;br /&gt;
2001&#45;07&#45;05 10:46 8,116&#8212;&#8212;a&#45;w C:ProgrammerOSLO3071b2.USB&lt;br /&gt;
2001&#45;05&#45;11 09:39 53,248&#8212;&#8212;a&#45;w C:ProgrammerACMonitor_X73.exe&lt;br /&gt;
2001&#45;05&#45;08 14:36 114,688&#8212;&#8212;a&#45;w C:Programmerlxarscan.dll&lt;br /&gt;
2001&#45;04&#45;23 12:22 1,437&#8212;&#8212;a&#45;w C:Programmergtx73.ini&lt;br /&gt;
2001&#45;02&#45;22 07:54 768&#8212;&#8212;a&#45;w C:Programmerx73_lut.dat&lt;br /&gt;
2008&#45;05&#45;11 19:12 32,768&#8212;sha&#45;w C:WINDOWSsystem32configsystemprofileLokale indstillingerOversigtHistory.IE5MSHist012008051120080512index.dat&lt;br /&gt;
.&lt;/p&gt;

&lt;p&gt;&#8212;&#8212;&#8212;&#45; Sigcheck&#8212;&#8212;&#8212;&#45;&lt;/p&gt;

&lt;p&gt;2008&#45;06&#45;20 13:51  361600  9425b72f40257b45d45d24773273dad0 C:WINDOWSsystem32driverstcpip.sys&lt;br /&gt;
2008&#45;06&#45;20 13:51  361600  9425b72f40257b45d45d24773273dad0 C:WINDOWSsystem32dllcachetcpip.sys&lt;br /&gt;
2005&#45;05&#45;25 21:04  359808  88763a98a4c26c409741b4aa162720c9 C:WINDOWS$NtUninstallKB913446$tcpip.sys&lt;br /&gt;
2004&#45;08&#45;04 07:14  359040  9f4b36614a0fc234525ba224957de55c C:WINDOWS$NtUninstallKB893066$tcpip.sys&lt;br /&gt;
2005&#45;05&#45;25 21:07  359936  63fdfea54eb53de2d863ee454937ce1e C:WINDOWS$hf_mig$KB893066SP2QFEtcpip.sys&lt;br /&gt;
2006&#45;01&#45;13 18:07  360448  5562cc0a47b2aef06d3417b733f3c195 C:WINDOWS$hf_mig$KB913446SP2QFEtcpip.sys&lt;br /&gt;
2006&#45;04&#45;20 14:18  360576  b2220c618b42a2212a59d91ebd6fc4b4 C:WINDOWS$hf_mig$KB917953SP2QFEtcpip.sys&lt;br /&gt;
2007&#45;10&#45;30 17:53  360832  64798ecfa43d78c7178375fcdd16d8c8 C:WINDOWS$hf_mig$KB941644SP2QFEtcpip.sys&lt;br /&gt;
2008&#45;06&#45;20 13:59  361600  ad978a1b783b5719720cff204b666c8e C:WINDOWS$hf_mig$KB951748SP3QFEtcpip.sys&lt;br /&gt;
2006&#45;01&#45;13 03:28  359808  583e063fdc888ca30d05c2724b0d7ef4 C:WINDOWS$NtUninstallKB917953$tcpip.sys&lt;br /&gt;
2007&#45;10&#45;30 18:20  360064  90caff4b094573449a0872a0f919b178 C:WINDOWS$NtServicePackUninstall$tcpip.sys&lt;br /&gt;
2008&#45;04&#45;13 21:20  361344  accf5a9a1ffaa490f33dba1c632b95e1 C:WINDOWSServicePackFilesi386tcpip.sys&lt;br /&gt;
2006&#45;04&#45;20 13:51  359808  1dbf125862891817f374f407626967f4 C:WINDOWS$NtUninstallKB941644$tcpip.sys&lt;br /&gt;
2008&#45;04&#45;13 21:20  361344  93ea8d04ec73a85db02eb8805988f733 C:WINDOWS$NtUninstallKB951748$tcpip.sys&lt;br /&gt;
.&lt;br /&gt;
(((((((((((((((((((((((((((((((((((((&amp;nbsp;  Reg Loading Points &amp;nbsp; ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;
.&lt;br /&gt;
.&lt;br /&gt;
*Note* empty entries &amp;amp; legit default entries are not shown &lt;br /&gt;
REGEDIT4&lt;/p&gt;

&lt;p&gt;[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]&lt;br /&gt;
&#8220;CTFMON.EXE&#8221;=&#8220;C:WINDOWSsystem32ctfmon.exe&#8221; [2008&#45;04&#45;14 15360]&lt;br /&gt;
&#8220;swg&#8221;=&#8220;C:ProgrammerGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe&#8221; [2008&#45;04&#45;08 68856]&lt;br /&gt;
&#8220;updateMgr&#8221;=&#8220;C:ProgrammerAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe&#8221; [2006&#45;03&#45;30 313472]&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]&lt;br /&gt;
&#8220;SunJavaUpdateSched&#8221;=&#8220;C:ProgrammerJavaj2re1.4.2_01binjusched.exe&#8221; [2003&#45;08&#45;19 32873]&lt;br /&gt;
&#8220;PrinTray&#8221;=&#8220;C:WINDOWSSystem32spoolDRIVERSW32X863printray.exe&#8221; [2001&#45;10&#45;12 36864]&lt;br /&gt;
&#8220;hcenter&#8221;=&#8220;C:ProgrammerSupport.combintgcmd.exe&#8221; [2003&#45;07&#45;07 1916928]&lt;br /&gt;
&#8220;PaperPort PTD&#8221;=&#8220;C:ProgrammerScanSoftPaperPortpptd40nt.exe&#8221; [2005&#45;03&#45;18 57393]&lt;br /&gt;
&#8220;Norman ZANDA&#8221;=&#8220;C:NormanNpmBinZLH.EXE&#8221; [2008&#45;06&#45;02 277616]&lt;br /&gt;
&#8220;Disk Monitor&#8221;=&#8220;C:ProgrammerGenericUSB Card Reader Driver v1.9e3Disk_Monitor.exe&#8221; [2003&#45;06&#45;18 466944]&lt;br /&gt;
&#8220;IndexSearch&#8221;=&#8220;C:ProgrammerScanSoftPaperPortIndexSearch.exe&#8221; [2005&#45;03&#45;18 40960]&lt;br /&gt;
&#8220;SoundMan&#8221;=&#8220;SOUNDMAN.EXE&#8221; [2003&#45;09&#45;23 C:WINDOWSSOUNDMAN.EXE]&lt;/p&gt;

&lt;p&gt;[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]&lt;br /&gt;
&#8220;CTFMON.EXE&#8221;=&#8220;C:WINDOWSSystem32CTFMON.EXE&#8221; [2008&#45;04&#45;14 15360]&lt;br /&gt;
&#8220;NvMediaCenter&#8221;=&#8220;C:WINDOWSSystem32NVMCTRAY.DLL&#8221; [2003&#45;07&#45;23 49152]&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsAll UsersMenuen StartProgrammerStart&lt;br /&gt;
Adobe Reader Hurtigstart.lnk &#45; C:ProgrammerAdobeAcrobat 7.0Readerreader_sl.exe [2005&#45;09&#45;23 29696]&lt;/p&gt;

&lt;p&gt;[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciessystem]&lt;br /&gt;
&#8220;NoDispSettingPage&#8221;= 1 (0x1)&lt;/p&gt;

&lt;p&gt;[hkey_local_machinesoftwaremicrosoftwindowscurrentversionexplorerShellExecuteHooks]&lt;br /&gt;
&#8220;&#123;5AE067D3&#45;9AFB&#45;48E0&#45;853A&#45;EBB7F4A000DA&#125;&#8221;= &#8220;C:ProgrammerSUPERAntiSpywareSASSEH.DLL&#8221; [2006&#45;02&#45;16 77824]&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogonnotifySASWinLogon]&lt;br /&gt;
2006&#45;03&#45;08 11:32 258048 C:ProgrammerSUPERAntiSpywareSASWINLO.dll&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimallpS14.sys]&lt;br /&gt;
@=&#8220;Driver&#8221;&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalnqT81.sys]&lt;br /&gt;
@=&#8220;Driver&#8221;&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalquX71.sys]&lt;br /&gt;
@=&#8220;Driver&#8221;&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalruX13.sys]&lt;br /&gt;
@=&#8220;Driver&#8221;&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalvyC24.sys]&lt;br /&gt;
@=&#8220;Driver&#8221;&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalvyC47.sys]&lt;br /&gt;
@=&#8220;Driver&#8221;&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalydF57.sys]&lt;br /&gt;
@=&#8220;Driver&#8221;&lt;/p&gt;

&lt;p&gt;[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]&lt;br /&gt;
&#8220;AntiVirusDisableNotify&#8221;=dword:00000001&lt;/p&gt;

&lt;p&gt;[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]&lt;br /&gt;
&#8220;%windir%\system32\sessmgr.exe&#8221;=&lt;br /&gt;
&#8220;C:\Programmer\Messenger\MSMSGS.EXE&#8221;=&lt;br /&gt;
&#8220;%windir%\Network Diagnostic\xpnetdiag.exe&#8221;=&lt;br /&gt;
&#8220;C:\Programmer\Support.com\TDCKabel\hcenter.exe&#8221;=&lt;br /&gt;
&#8220;C:\Programmer\Support.com\BIN\TGCMD.EXE&#8221;=&lt;/p&gt;

&lt;p&gt;R1 msikbd2k;Multimedia Keyboard Filter Driver;C:WINDOWSsystem32DRIVERSmsikbd2k.sys [2006&#45;09&#45;24 6656]&lt;br /&gt;
R2 Ndiskio;Ndiskio;C:NormanNsebinNDISKIO.SYS [2007&#45;01&#45;02 20448]&lt;br /&gt;
R2 nhksrv;Netropa NHK Server;C:ProgrammerOffice keyboard utility1.1nhksrv.exe [2006&#45;09&#45;24 28672]&lt;br /&gt;
R2 NVOY;Norman&#8217;s Very Own supplY of resources;C:Normannpmbinnvoy.exe [2008&#45;02&#45;07 121912]&lt;br /&gt;
R3 C4C_BSC2;C4C_BSC2;C:WINDOWSsystem32DRIVERSC4C_BSC2.sys [2002&#45;07&#45;08 84788]&lt;br /&gt;
R3 NvcMFlt;NvcMFlt;C:WINDOWSsystem32DRIVERSnvcw32mf.sys [2008&#45;09&#45;02 19512]&lt;br /&gt;
R3 nvcoas;Norman Virus Control on&#45;access component;C:NormanNvcbinnvcoas.exe [2008&#45;04&#45;30 191544]&lt;br /&gt;
R3 NVCScheduler;Norman Virus Control Scheduler;C:NormanNpmbinNVCSCHED.EXE [2007&#45;09&#45;18 154680]&lt;br /&gt;
S3 nvcfsr;nvcfsr;C:NormanNvcbinnvcfsr.sys [2007&#45;01&#45;09 6712]&lt;br /&gt;
S3 nvcoafl51;nvcoafl51;C:NormanNvcbinnvcoafl51.sys [2007&#45;01&#45;09 30264]&lt;br /&gt;
S3 nvcoaft51;nvcoaft51;C:NormanNvcbinnvcoaft51.sys [2007&#45;01&#45;09 129848]&lt;br /&gt;
S3 nvcoarc51;nvcoarc51;C:NormanNvcbinnvcoarc51.sys [2007&#45;01&#45;09 23224]&lt;br /&gt;
.&lt;br /&gt;
Contents of the &#8216;Scheduled Tasks&#8217; folder&lt;br /&gt;
.&lt;br /&gt;
&#45; &#45; &#45; &#45; ORPHANS REMOVED &#45; &#45; &#45; &#45;&lt;/p&gt;

&lt;p&gt;BHO&#45;&#123;1329689F&#45;1D87&#45;41A5&#45;80B9&#45;B5D0377707D1&#125; &#45; (no file)&lt;br /&gt;
HKLM&#45;Run&#45;SSBkgdUpdate &#45; C:ProgrammerFælles filerScansoft SharedSSBkgdUpdateSSBkgdupdate.exe&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
.&lt;br /&gt;&#8212;&#8212;&#8212;&#45; Supplementary Scan&#8212;&#8212;&#8212;&#45;&lt;br /&gt;
.&lt;br /&gt;
R0 &#45;: HKCU&#45;Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p=&#123;searchTerms&#125;&amp;amp;ei=utf&#45;8&amp;amp;fr=b1ie7&lt;br /&gt;
R0 &#45;: HKCU&#45;Main,Start Page = hxxp://tv2.dk/&lt;br /&gt;
R1 &#45;: HKCU&#45;Internet Connection Wizard,ShellNext = iexplore&lt;/p&gt;

&lt;p&gt;O16 &#45;: Microsoft XML Parser for Java &#45; file://C:WINDOWSJavaclassesxmldso.cab&lt;br /&gt;
C:WINDOWSDownloaded Program FilesMicrosoft XML Parser for Java.osd&lt;/p&gt;

&lt;p&gt;O16 &#45;: &#123;07D09E9E&#45;C667&#45;45DD&#45;B035&#45;217BC2A61A3B&#125; &#45; hxxps://www.himmerland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware&#45;prod&#45;1.20.cab&lt;br /&gt;
C:WINDOWSDownloaded Program Filescomp.inf&lt;br /&gt;
C:WINDOWSDownloaded Program FilesEBJSecurity_2.dll&lt;br /&gt;
C:WINDOWSDownloaded Program FilesActiveXSikkerhedssoftware.ocx&lt;br /&gt;
C:WINDOWSDownloaded Program FilesEBJSecurity_3.dll&lt;br /&gt;
.&lt;/p&gt;

&lt;p&gt;**************************************************************************&lt;/p&gt;

&lt;p&gt;catchme 0.3.1361 W2K/XP/Vista &#45; rootkit/stealth malware detector by Gmer, &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fwww.gmer.net&quot;&gt;http://www.gmer.net&lt;/a&gt;&lt;br /&gt;
Rootkit scan 2008&#45;09&#45;17 19:00:36&lt;br /&gt;
Windows 5.1.2600 Service Pack 3 FAT NTAPI&lt;/p&gt;

&lt;p&gt;scanning hidden processes ... &lt;/p&gt;

&lt;p&gt;scanning hidden autostart entries ...&lt;/p&gt;

&lt;p&gt;scanning hidden files ... &lt;/p&gt;

&lt;p&gt;scan completed successfully&lt;br /&gt;
hidden files: 0&lt;/p&gt;

&lt;p&gt;**************************************************************************&lt;br /&gt;
.&lt;br /&gt;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;Other Running Processes&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&lt;br /&gt;
.&lt;br /&gt;
C:NORMANNPMBINELOGSVC.EXE&lt;br /&gt;
C:NORMANNPMBINZANDA.EXE&lt;br /&gt;
C:WINDOWSSYSTEM32LEXBCES.EXE&lt;br /&gt;
C:WINDOWSSYSTEM32BRSS01A.EXE&lt;br /&gt;
C:PROGRAMMEREWIDOSECURITY SUITEEWIDOCTRL.EXE&lt;br /&gt;
C:NORMANNPMBINNJEEVES.EXE&lt;br /&gt;
C:NormanNvcBinNip.exe&lt;br /&gt;
C:NormanNvcBincclaw.exe&lt;br /&gt;
.&lt;br /&gt;
**************************************************************************&lt;br /&gt;
.&lt;br /&gt;
Completion time: 2008&#45;09&#45;17 19:02:50 &#45; machine was rebooted&lt;br /&gt;
ComboFix&#45;quarantined&#45;files.txt  2008&#45;09&#45;17 17:02:46&lt;/p&gt;

&lt;p&gt;Pre&#45;Run: 149,372,928,000 byte ledig&lt;br /&gt;
Post&#45;Run: 149,398,683,648 byte ledig&lt;/p&gt;

&lt;p&gt;202&#8212;&#45; E O F&#8212;&#45; 2008&#45;09&#45;10 17:14:45&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;
Scan saved at 19:11:07, on 17&#45;09&#45;2008&lt;br /&gt;
Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;
MSIE: Internet Explorer v7.00 (7.00.6000.16705)&lt;br /&gt;
Boot mode: Normal&lt;/p&gt;

&lt;p&gt;Running processes:&lt;br /&gt;
C:WINDOWSSystem32smss.exe&lt;br /&gt;
C:WINDOWSsystem32csrss.exe&lt;br /&gt;
C:WINDOWSsystem32winlogon.exe&lt;br /&gt;
C:WINDOWSsystem32services.exe&lt;br /&gt;
C:WINDOWSsystem32lsass.exe&lt;br /&gt;
C:NormanNpmbinELOGSVC.EXE&lt;br /&gt;
C:WINDOWSsystem32svchost.exe&lt;br /&gt;
C:WINDOWSsystem32svchost.exe&lt;br /&gt;
C:WINDOWSSystem32svchost.exe&lt;br /&gt;
C:NormanNpmBinZanda.exe&lt;br /&gt;
C:Normannpmbinnvoy.exe&lt;br /&gt;
C:WINDOWSSystem32svchost.exe&lt;br /&gt;
C:WINDOWSsystem32svchost.exe&lt;br /&gt;
C:WINDOWSsystem32LEXBCES.EXE&lt;br /&gt;
C:WINDOWSsystem32brss01a.exe&lt;br /&gt;
C:WINDOWSsystem32spoolsv.exe&lt;br /&gt;
C:ProgrammerOffice keyboard utility1.1nhksrv.exe&lt;br /&gt;
C:Programmerewidosecurity suiteewidoctrl.exe&lt;br /&gt;
C:WINDOWSSystem32svchost.exe&lt;br /&gt;
C:NormanNpmbinNVCSCHED.EXE&lt;br /&gt;
C:NormanNpmbinNJEEVES.EXE&lt;br /&gt;
C:WINDOWSSystem32alg.exe&lt;br /&gt;
C:NormanNvcbinnvcoas.exe&lt;br /&gt;
C:WINDOWSSOUNDMAN.EXE&lt;br /&gt;
C:ProgrammerJavaj2re1.4.2_01binjusched.exe&lt;br /&gt;
C:ProgrammerSupport.combintgcmd.exe&lt;br /&gt;
C:ProgrammerScanSoftPaperPortpptd40nt.exe&lt;br /&gt;
C:NormanNpmBinZLH.EXE&lt;br /&gt;
C:ProgrammerGenericUSB Card Reader Driver v1.9e3Disk_Monitor.exe&lt;br /&gt;
C:WINDOWSsystem32ctfmon.exe&lt;br /&gt;
C:ProgrammerGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe&lt;br /&gt;
C:NormanNvcBinNip.exe&lt;br /&gt;
C:NormanNvcBincclaw.exe&lt;br /&gt;
C:WINDOWSexplorer.exe&lt;br /&gt;
C:WINDOWSsystem32notepad.exe&lt;br /&gt;
C:ProgrammerInternet Exploreriexplore.exe&lt;br /&gt;
C:Documents and Settingsniels peterSkrivebordSpywarefriHijackThis.exe&lt;br /&gt;
C:WINDOWSSystem32wbemwmiprvse.exe&lt;/p&gt;

&lt;p&gt;R0 &#45; HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Ftv2.dk%2F&quot;&gt;http://tv2.dk/&lt;/a&gt;&lt;br /&gt;
R1 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;
R1 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;
R1 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;
R0 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;
O2 &#45; BHO: Adobe PDF Reader Link Helper &#45; &#123;06849E9F&#45;C8D7&#45;4D59&#45;B87D&#45;784B7D6BE0B3&#125; &#45; C:ProgrammerAdobeAcrobat 7.0ActiveXAcroIEHelper.dll&lt;br /&gt;
O2 &#45; BHO: Google Toolbar Helper &#45; &#123;AA58ED58&#45;01DD&#45;4d91&#45;8333&#45;CF10577473F7&#125; &#45; c:programmergooglegoogletoolbar1.dll&lt;br /&gt;
O2 &#45; BHO: Google Toolbar Notifier BHO &#45; &#123;AF69DE43&#45;7D58&#45;4638&#45;B6FA&#45;CE66B5AD205D&#125; &#45; C:ProgrammerGoogleGoogleToolbarNotifier2.0.301.7164swg.dll&lt;br /&gt;
O3 &#45; Toolbar: &amp;Google; &#45; &#123;2318C2B1&#45;4965&#45;11d4&#45;9B18&#45;009027A5CD4F&#125; &#45; c:programmergooglegoogletoolbar1.dll&lt;br /&gt;
O4 &#45; HKLM..Run: [SoundMan] SOUNDMAN.EXE&lt;br /&gt;
O4 &#45; HKLM..Run: [SunJavaUpdateSched] C:ProgrammerJavaj2re1.4.2_01binjusched.exe&lt;br /&gt;
O4 &#45; HKLM..Run: [PrinTray] C:WINDOWSSystem32spoolDRIVERSW32X863printray.exe&lt;br /&gt;
O4 &#45; HKLM..Run: [hcenter] &#8220;C:ProgrammerSupport.combintgcmd.exe&#8221; /server /startmonitor&lt;br /&gt;
O4 &#45; HKLM..Run: [PaperPort PTD] C:ProgrammerScanSoftPaperPortpptd40nt.exe&lt;br /&gt;
O4 &#45; HKLM..Run: [Norman ZANDA] &#8220;C:NormanNpmBinZLH.EXE&#8221; /LOAD /SPLASH&lt;br /&gt;
O4 &#45; HKLM..Run: [Disk Monitor] C:ProgrammerGenericUSB Card Reader Driver v1.9e3Disk_Monitor.exe&lt;br /&gt;
O4 &#45; HKLM..Run: [IndexSearch] C:ProgrammerScanSoftPaperPortIndexSearch.exe&lt;br /&gt;
O4 &#45; HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe&lt;br /&gt;
O4 &#45; HKCU..Run: [swg] C:ProgrammerGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe&lt;br /&gt;
O4 &#45; HKCU..Run: [updateMgr] &#8220;C:ProgrammerAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe&#8221; AcRdB7_0_9 &#45;reboot 1&lt;br /&gt;
O4 &#45; HKUSS&#45;1&#45;5&#45;19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User &#8216;LOKAL TJENESTE&#8217;)&lt;br /&gt;
O4 &#45; HKUSS&#45;1&#45;5&#45;19..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NVMCTRAY.DLL,NvTaskbarInit (User &#8216;LOKAL TJENESTE&#8217;)&lt;br /&gt;
O4 &#45; HKUSS&#45;1&#45;5&#45;20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User &#8216;NETVÆRKSTJENESTE&#8217;)&lt;br /&gt;
O4 &#45; HKUSS&#45;1&#45;5&#45;18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User &#8216;SYSTEM&#8217;)&lt;br /&gt;
O4 &#45; HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User &#8216;Default user&#8217;)&lt;br /&gt;
O4 &#45; Global Startup: Adobe Reader Hurtigstart.lnk = C:ProgrammerAdobeAcrobat 7.0Readerreader_sl.exe&lt;br /&gt;
O9 &#45; Extra button: Messenger &#45; &#123;FB5F1910&#45;F110&#45;11d2&#45;BB9E&#45;00C04F795683&#125; &#45; C:ProgrammerMessengermsmsgs.exe&lt;br /&gt;
O9 &#45; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#45; &#123;FB5F1910&#45;F110&#45;11d2&#45;BB9E&#45;00C04F795683&#125; &#45; C:ProgrammerMessengermsmsgs.exe&lt;br /&gt;
O14 &#45; IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/&lt;br /&gt;
O16 &#45; DPF: &#123;07D09E9E&#45;C667&#45;45DD&#45;B035&#45;217BC2A61A3B&#125; (ActiveX sikkerhedssoftware Control) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=https%3A%2F%2Fwww.himmerland.dk%2Fpackage%2Fsdc%2Fexternal%2Factivex%2FActiveXSikkerhedssoftware&#45;prod&#45;1.20.cab&quot;&gt;https://www.himmerland.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware&#45;prod&#45;1.20.cab&lt;/a&gt;&lt;br /&gt;
O16 &#45; DPF: &#123;6414512B&#45;B978&#45;451D&#45;A0D8&#45;FCFDF33E833C&#125; (WUWebControl Class) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fv5.windowsupdate.microsoft.com%2Fv5consumer%2FV5Controls%2Fen%2Fx86%2Fclient%2Fwuweb_site.cab%3F1109694989109&quot;&gt;http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109694989109&lt;/a&gt;&lt;br /&gt;
O16 &#45; DPF: &#123;6E32070A&#45;766D&#45;4EE6&#45;879C&#45;DC1FA91D2FC3&#125; (MUWebControl Class) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fwww.update.microsoft.com%2Fmicrosoftupdate%2Fv6%2FV5Controls%2Fen%2Fx86%2Fclient%2Fmuweb_site.cab%3F1209663121343&quot;&gt;http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1209663121343&lt;/a&gt;&lt;br /&gt;
O16 &#45; DPF: &#123;D27CDB6E&#45;AE6D&#45;11CF&#45;96B8&#45;444553540000&#125; (Shockwave Flash Object) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Ffpdownload2.macromedia.com%2Fget%2Fshockwave%2Fcabs%2Fflash%2Fswflash.cab&quot;&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/a&gt;&lt;br /&gt;
O16 &#45; DPF: &#123;D821DC4A&#45;0814&#45;435E&#45;9820&#45;661C543A4679&#125; (CRLDownloadWrapper Class) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fdrmlicense.one.microsoft.com%2Fcrlupdate%2Fen%2Fcrlocx.ocx&quot;&gt;http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx&lt;/a&gt;&lt;br /&gt;
O20 &#45; Winlogon Notify: SASWinLogon &#45; C:ProgrammerSUPERAntiSpywareSASWINLO.dll&lt;br /&gt;
O23 &#45; Service: BrSplService (Brother XP spl Service) &#45; brother Industries Ltd &#45; C:WINDOWSsystem32brsvc01a.exe&lt;br /&gt;
O23 &#45; Service: Norman eLogger service 6 (eLoggerSvc6) &#45; Norman ASA &#45; C:NormanNpmbinELOGSVC.EXE&lt;br /&gt;
O23 &#45; Service: ewido security suite control &#45; ewido networks &#45; C:Programmerewidosecurity suiteewidoctrl.exe&lt;br /&gt;
O23 &#45; Service: Google Updater Service (gusvc) &#45; Google &#45; C:ProgrammerGoogleCommonGoogle UpdaterGoogleUpdaterService.exe&lt;br /&gt;
O23 &#45; Service: LexBce Server (LexBceS) &#45; Lexmark International, Inc. &#45; C:WINDOWSsystem32LEXBCES.EXE&lt;br /&gt;
O23 &#45; Service: Netropa NHK Server (nhksrv) &#45; Unknown owner &#45; C:ProgrammerOffice keyboard utility1.1nhksrv.exe&lt;br /&gt;
O23 &#45; Service: Norman NJeeves &#45; Norman ASA &#45; C:NormanNpmbinNJEEVES.EXE&lt;br /&gt;
O23 &#45; Service: Norman ZANDA &#45; Norman ASA &#45; C:NormanNpmBinZanda.exe&lt;br /&gt;
O23 &#45; Service: Norman Virus Control on&#45;access component (nvcoas) &#45; Norman ASA &#45; C:NormanNvcbinnvcoas.exe&lt;br /&gt;
O23 &#45; Service: Norman Virus Control Scheduler (NVCScheduler) &#45; Norman ASA &#45; C:NormanNpmbinNVCSCHED.EXE&lt;br /&gt;
O23 &#45; Service: Norman&#8217;s Very Own supplY of resources (NVOY) &#45; Norman ASA &#45; C:Normannpmbinnvoy.exe&lt;/p&gt;

&lt;p&gt;&#8212;&lt;br /&gt;
End of file &#45; 6584 bytes&lt;/p&gt;



&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <dc:date>2008-09-17T21:16:40+01:00</dc:date>
    </item>

    <item>
      <title>Rootkit i win 32 drivers</title>
      <link>http://www.spywarefri.dk/forum/viewthread/51056/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/51056/#When:14:19:39Z</guid>
      <description>&lt;p&gt;Jeg havde på fornemmelsen der var noget der ikke rigtig stemte,så jeg tog en online scanning med Kaspersky,og den fandt et rootkit i system 32 drivers.&lt;br /&gt;
Jeg har prøvet at fjerne det manuelt,og online scanneren siger nu den er i recycler?&lt;br /&gt;
Men jeg er ikke sluppet af med det vel?&lt;br /&gt;
her er diagnosen:&lt;br /&gt;
C:RECYCLERS&#45;1&#45;5&#45;21&#45;527237240&#45;1409082233&#45;1801674531&#45;1003Dc32.sys Infected: Rootkit.Win32.Agent.dml&lt;/p&gt;

&lt;p&gt;
&lt;/p&gt;</description>
      <dc:date>2008-09-13T14:19:39+01:00</dc:date>
    </item>

    <item>
      <title>Infected with W32/Rootkit.gen7</title>
      <link>http://www.spywarefri.dk/forum/viewthread/50625/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/50625/#When:14:28:29Z</guid>
      <description>&lt;p&gt;Hej Team Spywarefri&lt;/p&gt;

&lt;p&gt;Jeg kører NIS 2008 i en fuld opdateret vers, og denne sagde pludselig: Warning rootkit/trojan, for derefter at lukke ned.&lt;br /&gt;
Det var ikke muligt at genstarte NIS eller geninstallere.&lt;br /&gt;
CCleaner vil heller ikke starte op. Jeg havde så hørt om jeres forum,&lt;br /&gt;
og kom til at tænke på om i kunne hjælpe mig.&lt;/p&gt;

&lt;p&gt;På jeres side fandt jeg Norman virus skanner, og her er dens rapport:&lt;br /&gt;
 &lt;br /&gt;
Norman Malware Cleaner&lt;br /&gt;
Copyright © 1990 &#45; 2008, Norman ASA. Built 2008/08/27 13:08:08&lt;/p&gt;

&lt;p&gt;Norman Scanner Engine Version: 5.93.01&lt;br /&gt;
Nvcbin.def Version: 5.93.00, Date: 2008/08/27 13:08:08, Variants: 2049413&lt;/p&gt;

&lt;p&gt;Running pre&#45;scan cleanup routine:&lt;br /&gt;
Operating System: Microsoft Windows XP Home 5.1.2600 Service Pack 3&lt;br /&gt;
Logged on user: KONTORjj&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Scan started: 28/08/2008 12:53:44&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Scanning running processes and process memory&#8230;&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;br /&gt;
Too many infections/an unexpected error (Please contact support)&lt;/p&gt;

&lt;p&gt;Number of processes/threads found: 2054&lt;br /&gt;
Number of processes/threads scanned: 2054&lt;br /&gt;
Number of processes/threads not scanned: 0&lt;br /&gt;
Number of infected processes/threads terminated: 0&lt;br /&gt;
Total scanning time: 2m 21s&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Scanning file system&#8230;&lt;/p&gt;

&lt;p&gt;Scanning: C:*.*&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjApplication Datamflec006.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjLokale indstillingerTemporary Internet FilesContent.IE5 5QVQBGXb64_1[1].jpg (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjLokale indstillingerTemporary Internet FilesContent.IE5CBP7QI7Db64_1[1].jpg (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjLokale indstillingerTemporary Internet FilesContent.IE5CZFBMW55b64[1].jpg (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjLokale indstillingerTemporary Internet FilesContent.IE5CZFBMW55b64_1[1].jpg (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjLokale indstillingerTemporary Internet FilesContent.IE5FJLRFDWWb64_1[1].jpg (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjLokale indstillingerTemporary Internet FilesContent.IE5WVZ3AWLXb64[1].jpg (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:Documents and SettingsjjLokale indstillingerTemporary Internet FilesContent.IE5YXB4TG7Qb64_1[1].jpg (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:ProgrammerEA GAMESThe Sims 2 Glamour Life Xtra PakkeTSBinKeygen.exe (Infected with Suspicious_F.gen)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:ProgrammerNeroNero8Nero BackItUpBackItUp_ImageToolroot.img/unknown0 (Error whilst scanning file: I/O Error (0x0022000A))&lt;br /&gt;
C:ProgrammerNeroNero8Nero BackItUpBackItUp_ImageToolroot.img (Possible archive bomb)&lt;/p&gt;

&lt;p&gt;C:ProgrammerWindows Media Playerwmpnscfg.exe (Infected with W32/Malware.DNDS)&lt;br /&gt;
Removed registry value: HKCUSoftwareMicrosoftWindowsCurrentVersionRun &#45;&amp;gt; WMPNSCFG = &#8220;C:ProgrammerWindows Media PlayerWMPNSCFG.exe&#8221;&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWS$hf_mig$KB890859SP2QFEntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWS$hf_mig$KB929338SP2QFEntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWS$hf_mig$KB931784SP2QFEntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWS$NtServicePackUninstall$ntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWS$NtUninstallKB826939$ntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWS$NtUninstallKB890859$ntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWS$NtUninstallKB929338$ntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWS$NtUninstallKB931784$ntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWSServicePackFilesi386ntoskrnl.exe (Error opening file: Not found)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32mdelk.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32mdelk.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32mdelk.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32mdelk.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32mdelk.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;br /&gt;
Too many infections/an unexpected error (Please contact support)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32wintems.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32drivershldrrr.exe (Infected with W32/Malware.DNDS)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversmdelk.exe (Infected with W32/Malware.DNDS)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversmdelk.exe (Infected with W32/Malware.DNDS)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversmdelk.exe (Infected with W32/Malware.DNDS)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversmdelk.exe (Infected with W32/Malware.DNDS)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversmdelk.exe (Infected with W32/Malware.DNDS)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;br /&gt;
Too many infections/an unexpected error (Please contact support)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driverssrosa.sys (Infected with W32/Rootkit.gen7)&lt;br /&gt;
File marked for defered cleaning (reboot required)&lt;br /&gt;
Too many infections/an unexpected error (Please contact support)&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld1343453.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld1392015.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld1394625.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld155781.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld156531.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld15960625.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld15961859.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld169953.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld172953.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld185812.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld186656.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld195125.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld207125.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld23045250.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld23076609.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld23078062.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld37627656.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld37657000.exe (Infected with W32/Bagle.BCZ)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld52162687.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld52175828.exe (Infected with W32/Bagle.BCY)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld52178031.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld66674890.exe (Infected with W32/Spybot.CYZP)&lt;br /&gt;
Deleted file&lt;/p&gt;

&lt;p&gt;C:WINDOWSsystem32driversdownld66687156.exe (Infected with W32/Bagle.BCO)&lt;br /&gt;
Deleted file&lt;/p&gt;



&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Scanning: c:System Volume Information*.*&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Running post&#45;scan cleanup routine:&lt;/p&gt;

&lt;p&gt;Number of files found: 1213625&lt;br /&gt;
Number of archives unpacked: 8273&lt;br /&gt;
Number of files scanned: 1213554&lt;br /&gt;
Number of files not scanned: 71&lt;br /&gt;
Number of files skipped due to exclude list: 0&lt;br /&gt;
Number of infected files found: 41&lt;br /&gt;
Number of infected files repaired/deleted: 34&lt;br /&gt;
Number of infections removed: 34&lt;br /&gt;
Total scanning time: 9h 40m 3s&lt;/p&gt;

&lt;p&gt;Det hjalp ikke rigtigt, for hvis den køres igen efter en restart&lt;br /&gt;
kommer nøjagtigt det samme resultat, også de filer den siger den har slettet. Hvad gør en klog (måske mindre klog) nu.&lt;/p&gt;

&lt;p&gt;Jan
&lt;/p&gt;</description>
      <dc:date>2008-08-29T14:28:29+01:00</dc:date>
    </item>

    <item>
      <title>SVCHOST</title>
      <link>http://www.spywarefri.dk/forum/viewthread/49210/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/49210/#When:22:38:23Z</guid>
      <description>&lt;p&gt;Kære Spywarefri Forum&lt;/p&gt;

&lt;p&gt;Mit problem er, at min computer næsten går i stå, når jeg connecter til internettet. Skærmen fryser i 10&#45;15 sekunder ad gangen og musemarkøren flytter sig i hak hvert 10&#45;15 sekund. &lt;/p&gt;

&lt;p&gt;Jeg kan se i joblisten, at SVCHOST&#45;programmer beslaglægger min CPU med 97 &#45; 100%. Maskinen kører fint indtil jeg connecter til internettet. Mens den connecter går den i stå. Efter 15 &#45; 20 minutter bliver det muligt at bruge maskinen, men det foregår i hak.&lt;/p&gt;

&lt;p&gt;Jeg har søgt på Google, og har fundet flere hints om at årsagen kan være en spyware &#45; måske en rootkit.&lt;/p&gt;

&lt;p&gt;I dag installerede jeg derfor Spyware Doc Doctor fra PCTOOLS. Jeg har scannet og sat i karantæne, men det har kun gjort problemet være. Nu bliver den ved med at være låst, og forbindelsen til internettet falder ud af sig selv. (Jeg skriver derfor fra min kones PC).&lt;/p&gt;

&lt;p&gt;Mine primære scannere er Bullguard og Webroot spy sweeper. De finder intet. Derudover har jeg scannet med Search &amp;amp; Destroy, Adaware og Superspyware. De har hver i sær findet noget, som er slettet eller sat i karantæne.&lt;/p&gt;

&lt;p&gt;Håber I kan hjælpe mig. &lt;/p&gt;

&lt;p&gt;
&lt;/p&gt;</description>
      <dc:date>2008-07-16T22:38:23+01:00</dc:date>
    </item>

    <item>
      <title>Monster hastighedsnedsættelse</title>
      <link>http://www.spywarefri.dk/forum/viewthread/48218/</link>
      <guid>http://www.spywarefri.dk/forum/viewthread/48218/#When:05:10:47Z</guid>
      <description>&lt;p&gt;Har fra dd haft et seriøst problem hvor det har taget op til 2 min for min puter atreagere på hvad jeg beder den om, det er særligt udpræget når jeg starter IE op og har en anelse om at det måske også hænger sammen med Bullguard da denne ikke kommer med sin sædvanlige &#8220;update&#45;box&#8221; nede i hjørnet efter de ca 2 min det normalt tager.&lt;/p&gt;

&lt;p&gt;Har kørt AVG i fejlsikret tilstand&lt;br /&gt;
Kunne ikke køre Combofix da den siger det kun virker til 2000 og XP&lt;br /&gt;
Har kørt Hijackthis som admin på Vista&lt;/p&gt;

&lt;p&gt;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#45;&lt;br /&gt;
AVG Anti&#45;Spyware &#45; Scan Report&lt;br /&gt;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#45;&lt;/p&gt;

&lt;p&gt; + Created at: 02:55:31 04&#45;06&#45;2008&lt;/p&gt;

&lt;p&gt; + Scan result: &lt;/p&gt;



&lt;p&gt;Nothing found.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
::Report end&lt;/p&gt;

&lt;p&gt;Hijackthis log&#8230;...............:&lt;/p&gt;

&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;
Scan saved at 03:02:50, on 04&#45;06&#45;2008&lt;br /&gt;
Platform: Windows Vista  (WinNT 6.00.1904)&lt;br /&gt;
MSIE: Internet Explorer v7.00 (7.00.6000.16643)&lt;br /&gt;
Boot mode: Normal&lt;/p&gt;

&lt;p&gt;Running processes:&lt;br /&gt;
C:Program Files (x86)Analog DevicesCoresmax4pnp.exe&lt;br /&gt;
C:Program Files (x86)Javajre1.6.0_05binjusched.exe&lt;br /&gt;
C:Program Files (x86)AdobeReader 8.0Readerreader_sl.exe&lt;br /&gt;
C:Program Files (x86)GrisoftAVG Anti&#45;Spyware 7.5avgas.exe&lt;br /&gt;
C:Program Files (x86)OpenOffice.org 2.2programsoffice.exe&lt;br /&gt;
C:Program Files (x86)OpenOffice.org 2.2programsoffice.BIN&lt;br /&gt;
C:WindowsSysWOW64conime.exe&lt;br /&gt;
C:Program Files (x86)Internet Exploreriexplore.exe&lt;br /&gt;
C:Program Files (x86)Internet ExplorerIEUser.exe&lt;br /&gt;
C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWLLoginProxy.exe&lt;br /&gt;
C:UsersEjerDesktopSpywarefriHijackThis.exe&lt;/p&gt;

&lt;p&gt;R1 &#45; HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;
R0 &#45; HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fwww.qnull.net%2Fforum%2Findex_def.html&quot;&gt;http://www.qnull.net/forum/index_def.html&lt;/a&gt;&lt;br /&gt;
R1 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;
R1 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;
R1 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D54896&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;
R0 &#45; HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3FLinkId%3D69157&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;
R0 &#45; HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = &lt;br /&gt;
R0 &#45; HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = &lt;br /&gt;
R0 &#45; HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = &lt;br /&gt;
F2 &#45; REG:system.ini: UserInit=userinit.exe&lt;br /&gt;
O1 &#45; Hosts: ::1 localhost&lt;br /&gt;
O2 &#45; BHO: Adobe PDF Reader Link Helper &#45; &#123;06849E9F&#45;C8D7&#45;4D59&#45;B87D&#45;784B7D6BE0B3&#125; &#45; C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelper.dll&lt;br /&gt;
O2 &#45; BHO: SSVHelper Class &#45; &#123;761497BB&#45;D6F0&#45;462C&#45;B6EB&#45;D4DAF1D92D43&#125; &#45; C:Program Files (x86)Javajre1.6.0_05binssv.dll&lt;br /&gt;
O2 &#45; BHO: (no name) &#45; &#123;7E853D72&#45;626A&#45;48EC&#45;A868&#45;BA8D5E23E045&#125; &#45; (no file)&lt;br /&gt;
O2 &#45; BHO: Windows Live Sign&#45;in Helper &#45; &#123;9030D464&#45;4C02&#45;4ABF&#45;8ECC&#45;5164760863C6&#125; &#45; C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll&lt;br /&gt;
O4 &#45; HKLM..Run: [SoundMAXPnP] C:Program Files (x86)Analog DevicesCoresmax4pnp.exe&lt;br /&gt;
O4 &#45; HKLM..Run: [SunJavaUpdateSched] &#8220;C:Program Files (x86)Javajre1.6.0_05binjusched.exe&#8221;&lt;br /&gt;
O4 &#45; HKLM..Run: [QuickTime Task] &#8220;C:Program Files (x86)QuickTimeQTTask.exe&#8221; &#45;atboottime&lt;br /&gt;
O4 &#45; HKLM..Run: [Adobe Reader Speed Launcher] &#8220;C:Program Files (x86)AdobeReader 8.0ReaderReader_sl.exe&#8221;&lt;br /&gt;
O4 &#45; HKLM..Run: [!AVG Anti&#45;Spyware] &#8220;C:Program Files (x86)GrisoftAVG Anti&#45;Spyware 7.5avgas.exe&#8221; /minimized&lt;br /&gt;
O4 &#45; HKCU..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter&lt;br /&gt;
O4 &#45; HKCU..Run: [MsnMsgr] &#8220;C:Program Files (x86)MSN MessengerMsnMsgr.Exe&#8221; /background&lt;br /&gt;
O4 &#45; HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe&lt;br /&gt;
O4 &#45; HKCU..Run: [BullGuard] &#8220;C:Program FilesBullGuard LtdBullGuardbullguard.exe&#8221;&lt;br /&gt;
O4 &#45; HKUSS&#45;1&#45;5&#45;19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User &#8216;LOKAL TJENESTE&#8217;)&lt;br /&gt;
O4 &#45; HKUSS&#45;1&#45;5&#45;19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User &#8216;LOKAL TJENESTE&#8217;)&lt;br /&gt;
O4 &#45; HKUSS&#45;1&#45;5&#45;20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User &#8216;NETVÆRKSTJENESTE&#8217;)&lt;br /&gt;
O4 &#45; Startup: OpenOffice.org 2.2.lnk = C:Program Files (x86)OpenOffice.org 2.2programquickstart.exe&lt;br /&gt;
O8 &#45; Extra context menu item: E&amp;ksporter; til Microsoft Excel &#45; res://C:PROGRA~2MICROS~1Office12EXCEL.EXE/3000&lt;br /&gt;
O9 &#45; Extra button: (no name) &#45; &#123;08B0E5C0&#45;4FCB&#45;11CF&#45;AAA5&#45;00401C608501&#125; &#45; C:Program Files (x86)Javajre1.6.0_05binssv.dll&lt;br /&gt;
O9 &#45; Extra &#8216;Tools&#8217; menuitem: Sun Java Console &#45; &#123;08B0E5C0&#45;4FCB&#45;11CF&#45;AAA5&#45;00401C608501&#125; &#45; C:Program Files (x86)Javajre1.6.0_05binssv.dll&lt;br /&gt;
O13 &#45; Gopher Prefix: &lt;br /&gt;
O16 &#45; DPF: &#123;0B79F48A&#45;E8D6&#45;11DB&#45;9283&#45;E25056D89593&#125; (F&#45;Secure Online Scanner 3.1) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fsupport.f&#45;secure.com%2Fols%2Ffscax.cab&quot;&gt;http://support.f&#45;secure.com/ols/fscax.cab&lt;/a&gt;&lt;br /&gt;
O16 &#45; DPF: &#123;39B0684F&#45;D7BF&#45;4743&#45;B050&#45;FDC3F48F7E3B&#125; &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fwww.fileplanet.com%2Ffpdlmgr%2Fcabs%2FFPDC_2.3.6.108.cab&quot;&gt;http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab&lt;/a&gt;&lt;br /&gt;
O16 &#45; DPF: &#123;CF40ACC5&#45;E1BB&#45;4AFF&#45;AC72&#45;04C2F616BCA7&#125; (get_atlcom Class) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=http%3A%2F%2Fwww.adobe.com%2Fproducts%2Facrobat%2Fnos%2Fgp.cab&quot;&gt;http://www.adobe.com/products/acrobat/nos/gp.cab&lt;/a&gt;&lt;br /&gt;
O16 &#45; DPF: &#123;D27CDB6E&#45;AE6D&#45;11CF&#45;96B8&#45;444553540000&#125; (Shockwave Flash Object) &#45; &lt;a href=&quot;http://www.spywarefri.dk/?URL=https%3A%2F%2Ffpdownload.macromedia.com%2Fget%2Fshockwave%2Fcabs%2Fflash%2Fswflash.cab&quot;&gt;https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/a&gt;&lt;br /&gt;
O23 &#45; Service: @%SystemRoot%system32Alg.exe,&#45;112 (ALG) &#45; Unknown owner &#45; C:WindowsSystem32alg.exe (file missing)&lt;br /&gt;
O23 &#45; Service: AVG Anti&#45;Spyware Guard &#45; GRISOFT s.r.o. &#45; C:Program Files (x86)GrisoftAVG Anti&#45;Spyware 7.5guard.exe&lt;br /&gt;
O23 &#45; Service: BullGuard LiveUpdate (BgLiveSvc) &#45; BullGuard Software &#45; C:Program FilesBullGuard LtdBullGuardBullGuardUpdate.exe&lt;br /&gt;
O23 &#45; Service: @dfsrres.dll,&#45;101 (DFSR) &#45; Unknown owner &#45; C:Windowssystem32DFSR.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @keyiso.dll,&#45;100 (KeyIso) &#45; Unknown owner &#45; C:Windowssystem32lsass.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @comres.dll,&#45;2797 (MSDTC) &#45; Unknown owner &#45; C:WindowsSystem32msdtc.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%SystemRoot%System32netlogon.dll,&#45;102 (Netlogon) &#45; Unknown owner &#45; C:Windowssystem32lsass.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%systemroot%system32psbase.dll,&#45;300 (ProtectedStorage) &#45; Unknown owner &#45; C:Windowssystem32lsass.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%systemroot%system32Locator.exe,&#45;2 (RpcLocator) &#45; Unknown owner &#45; C:Windowssystem32locator.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%SystemRoot%system32samsrv.dll,&#45;1 (SamSs) &#45; Unknown owner &#45; C:Windowssystem32lsass.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%SystemRoot%system32SLsvc.exe,&#45;101 (slsvc) &#45; Unknown owner &#45; C:Windowssystem32SLsvc.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%SystemRoot%system32snmptrap.exe,&#45;3 (SNMPTRAP) &#45; Unknown owner &#45; C:WindowsSystem32snmptrap.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%systemroot%system32spoolsv.exe,&#45;1 (Spooler) &#45; Unknown owner &#45; C:WindowsSystem32spoolsv.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%SystemRoot%system32ui0detect.exe,&#45;101 (UI0Detect) &#45; Unknown owner &#45; C:Windowssystem32UI0Detect.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%SystemRoot%system32vds.exe,&#45;100 (vds) &#45; Unknown owner &#45; C:WindowsSystem32vds.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%systemroot%system32vssvc.exe,&#45;102 (VSS) &#45; Unknown owner &#45; C:Windowssystem32vssvc.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%Systemroot%system32wbemwmiapsrv.exe,&#45;110 (wmiApSrv) &#45; Unknown owner &#45; C:Windowssystem32wbemWmiApSrv.exe (file missing)&lt;br /&gt;
O23 &#45; Service: @%ProgramFiles%Windows Media Playerwmpnetwk.exe,&#45;101 (WMPNetworkSvc) &#45; Unknown owner &#45; C:Program Files (x86)Windows Media Playerwmpnetwk.exe (file missing)&lt;/p&gt;

&lt;p&gt;&#8212;&lt;br /&gt;
End of file &#45; 6879 bytes&lt;/p&gt;

&lt;p&gt;Håber det giver mening, blev nødt til at hente &#8220;pakken&#8221; i fejlsikret tilstand med netværk, og kørte AVG på samme opstart, har genstartet normalt nu efterfølgende og prøvet at køre Combofix samt kørt Hijackthis.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <dc:date>2008-06-04T05:10:47+01:00</dc:date>
    </item>

    
    </channel>
</rss>