KaffeKlavs
New member
Dear Sirs,
Thank you very much for a nice forum.
My computer suddenly got infected after clicking on one of my friend's videos in Facebook. Now I cannot remove the trojans again. Internet Explorer is blocked for downloading malwareremoval programs and pup-ups is randomly starting. e.g:
http:61.235.11.83/redirctsodt/popup
Firefox is not working, I cannot download Spybot S&D and most tool is blocked for Download. The browser Safari is the only one I can use.
My Avast antivirus programme has detected/deleted/revomed following virus/trojans:
27-08-2009 18:00:50 SYSTEM 1628 Sign of "Win32:LdPinch-CYW [Trj]" has been found in "C:\Windows\srpira1251388849.eXE" file.
27-08-2009 18:17:03 SYSTEM 1628 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\ticedu_info[1].htm" file.
27-08-2009 18:17:09 SYSTEM 1628 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LVIYM277\script_en[1].js" file.
27-08-2009 18:17:16 SYSTEM 1628 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LVIYM277\script_en[1].js" file.
27-08-2009 18:17:20 SYSTEM 1628 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HRX6FIG5\26[1].htm" file.
27-08-2009 18:17:26 SYSTEM 1628 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\text_constants_en[1].js" file.
27-08-2009 18:17:26 SYSTEM 1628 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LVIYM277\destrub[1].js" file.
27-08-2009 18:17:32 SYSTEM 1628 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MEO2HXOJ\unic_scripts[1].js" file.
27-08-2009 18:31:23 Ditte 5392 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\ticedu_info[1].htm" file.
27-08-2009 18:36:56 SYSTEM 1584 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\ticedu_info[1].htm" file.
27-08-2009 18:37:16 SYSTEM 1584 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\script_en[1].js" file.
27-08-2009 18:37:19 SYSTEM 1584 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\script_en[1].js" file.
27-08-2009 18:37:24 SYSTEM 1584 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LNMR7I01\26[1].htm" file.
27-08-2009 18:37:43 SYSTEM 1584 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\text_constants_en[1].js" file.
27-08-2009 18:37:43 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\destrub[1].js" file.
27-08-2009 18:38:07 SYSTEM 1584 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LNMR7I01\unic_scripts[1].js" file.
27-08-2009 18:39:42 SYSTEM 1584 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\330N50ID\26[1].htm" file.
27-08-2009 18:39:42 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\destrub[1].js" file.
27-08-2009 18:40:00 SYSTEM 1584 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\TPI6T4NL\text_constants_en[1].js" file.
27-08-2009 18:40:00 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\TPI6T4NL\destrub[1].js" file.
27-08-2009 18:44:02 SYSTEM 1584 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\DYDKZAIY\unic_scripts[1].js" file.
27-08-2009 18:45:59 SYSTEM 1584 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LWS2J3KI\26[1].htm" file.
27-08-2009 18:46:00 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\L8EULX2U\destrub[1].js" file.
27-08-2009 18:46:09 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\destrub[1].js" file.
27-08-2009 18:46:09 SYSTEM 1584 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\text_constants_en[1].js" file.
27-08-2009 18:46:15 SYSTEM 1584 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LWS2J3KI\unic_scripts[1].js" file.
27-08-2009 18:51:35 SYSTEM 1584 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\L8EULX2U\index[1].htm" file.
27-08-2009 18:52:11 SYSTEM 1584 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7EB8GL42\index[1].htm" file.
27-08-2009 19:09:51 Ditte 4432 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7EB8GL42\index[1].htm" file.
27-08-2009 19:16:03 SYSTEM 1608 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6YTDTP4P\ticedu_info[1].htm" file.
27-08-2009 19:16:17 SYSTEM 1608 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\script_en[1].js" file.
27-08-2009 19:16:21 SYSTEM 1608 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\script_en[1].js" file.
27-08-2009 19:16:26 SYSTEM 1608 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XEG63NS7\26[1].htm" file.
27-08-2009 19:16:30 SYSTEM 1608 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6YTDTP4P\text_constants_en[1].js" file.
27-08-2009 19:16:31 SYSTEM 1608 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6YTDTP4P\destrub[1].js" file.
27-08-2009 19:30:50 SYSTEM 1608 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VPPF76FQ\index[1].htm" file.
27-08-2009 19:32:21 SYSTEM 1608 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\index[1].htm" file.
27-08-2009 19:47:17 Ditte 752 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\index[1].htm" file.
30-08-2009 13:29:57 Ditte 480 Function setifaceUpdatePackages() has failed. Return code is 0x2000000A, dwRes is 2000000A.
30-08-2009 13:30:20 Ditte 2980 Function setifaceUpdatePackages() has failed. Return code is 0x2000000A, dwRes is 2000000A.
30-08-2009 13:31:15 Ditte 4248 Function setifaceUpdatePackages() has failed. Return code is 0x2000000A, dwRes is 2000000A.
30-08-2009 13:44:11 SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\99JGY5CT\hownet_info[1].htm" file.
30-08-2009 13:44:55 SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJ24P0CR\script_en[1].js" file.
30-08-2009 13:45:07 SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJ24P0CR\script_en[1].js" file.
30-08-2009 13:45:15 SYSTEM 1636 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\26[1].htm" file.
30-08-2009 13:45:23 SYSTEM 1636 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\99JGY5CT\text_constants_en[1].js" file.
30-08-2009 13:45:24 SYSTEM 1636 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DH6QMX5E\destrub[1].js" file.
30-08-2009 13:45:38 SYSTEM 1636 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\unic_scripts[1].js" file.
30-08-2009 13:46:16 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\DDnsFilter.dll" file.
30-08-2009 13:48:54 SYSTEM 1636 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJ24P0CR\26[1].htm" file.
30-08-2009 13:49:10 SYSTEM 1636 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\text_constants_en[1].js" file.
30-08-2009 13:49:10 SYSTEM 1636 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\destrub[1].js" file.
30-08-2009 13:49:11 SYSTEM 1636 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\unic_scripts[1].js" file.
30-08-2009 13:56:07 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\DDnsFilter.dll" file.
30-08-2009 13:58:37 SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DH6QMX5E\index[1].htm" file.
30-08-2009 14:03:04 SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\99JGY5CT\index[1].htm" file.
30-08-2009 14:04:36 SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DH6QMX5E\index[1].htm" file.
30-08-2009 14:07:01 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\trzD28A.tmp" file.
30-08-2009 14:24:01 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\prx90[1].exe\[Embedded_I#0b110]" file.
30-08-2009 14:24:41 Ditte 4248 Sign of "JS:ScriptIP-inf [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\popup[1].htm" file.
30-08-2009 14:25:19 Ditte 4248 Sign of "JS:ScriptIP-inf [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\popup[1].htm" file.
30-08-2009 14:25:28 Ditte 4248 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\text_constants_en[1].js" file.
30-08-2009 14:49:31 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\trzEC24.tmp" file.
30-08-2009 15:36:49 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\trzEC24.tmp" file.
HERE IS MY HIJACK LOG:
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:55:25, on 30-08-2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\pp11.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\windows sidebar\gadgets\LGSmartI.Gadget\plugins\LGSmartI.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Users\Ditte\AppData\Local\Temp\9b1lanxj.tmp\HiJackThis.exe
C:\Users\Ditte\AppData\Local\Temp\rfn58kvz.tmp\spybotsd162.exe
C:\Users\Ditte\AppData\Local\Temp\is-JE75S.tmp\spybotsd162.tmp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.psy.ku.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lge.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
O4 - HKLM\..\Run: [KeybdUtility] C:\Program Files\LG Software\On Screen Display\HotKey.exe
O4 - HKLM\..\Run: [BatteryMiser 5] C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\giljabistart.exe" Gilautouc
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [sysldtray] c:\windows\ld14.exe
O4 - HKLM\..\Run: [pp] c:\windows\pp11.exe
O4 - HKLM\..\Run: [ParetoLogic Anti-Virus PLUS] "C:\Program Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" -NM -hidesplash
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: websrvx - Unknown owner - C:\Program Files\websrvx\websrvx.exe
O23 - Service: plasservice (ZeppelinService) - ParetoLogic Inc. - C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe
--
End of file - 8802 bytes
Please help.
Kind regards,
Klavs
Thank you very much for a nice forum.
My computer suddenly got infected after clicking on one of my friend's videos in Facebook. Now I cannot remove the trojans again. Internet Explorer is blocked for downloading malwareremoval programs and pup-ups is randomly starting. e.g:
http:61.235.11.83/redirctsodt/popup
Firefox is not working, I cannot download Spybot S&D and most tool is blocked for Download. The browser Safari is the only one I can use.
My Avast antivirus programme has detected/deleted/revomed following virus/trojans:
27-08-2009 18:00:50 SYSTEM 1628 Sign of "Win32:LdPinch-CYW [Trj]" has been found in "C:\Windows\srpira1251388849.eXE" file.
27-08-2009 18:17:03 SYSTEM 1628 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\ticedu_info[1].htm" file.
27-08-2009 18:17:09 SYSTEM 1628 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LVIYM277\script_en[1].js" file.
27-08-2009 18:17:16 SYSTEM 1628 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LVIYM277\script_en[1].js" file.
27-08-2009 18:17:20 SYSTEM 1628 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HRX6FIG5\26[1].htm" file.
27-08-2009 18:17:26 SYSTEM 1628 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\text_constants_en[1].js" file.
27-08-2009 18:17:26 SYSTEM 1628 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LVIYM277\destrub[1].js" file.
27-08-2009 18:17:32 SYSTEM 1628 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MEO2HXOJ\unic_scripts[1].js" file.
27-08-2009 18:31:23 Ditte 5392 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\ticedu_info[1].htm" file.
27-08-2009 18:36:56 SYSTEM 1584 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\ticedu_info[1].htm" file.
27-08-2009 18:37:16 SYSTEM 1584 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\script_en[1].js" file.
27-08-2009 18:37:19 SYSTEM 1584 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\script_en[1].js" file.
27-08-2009 18:37:24 SYSTEM 1584 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LNMR7I01\26[1].htm" file.
27-08-2009 18:37:43 SYSTEM 1584 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\text_constants_en[1].js" file.
27-08-2009 18:37:43 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BRBCV8DE\destrub[1].js" file.
27-08-2009 18:38:07 SYSTEM 1584 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LNMR7I01\unic_scripts[1].js" file.
27-08-2009 18:39:42 SYSTEM 1584 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\330N50ID\26[1].htm" file.
27-08-2009 18:39:42 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\destrub[1].js" file.
27-08-2009 18:40:00 SYSTEM 1584 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\TPI6T4NL\text_constants_en[1].js" file.
27-08-2009 18:40:00 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\TPI6T4NL\destrub[1].js" file.
27-08-2009 18:44:02 SYSTEM 1584 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\DYDKZAIY\unic_scripts[1].js" file.
27-08-2009 18:45:59 SYSTEM 1584 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LWS2J3KI\26[1].htm" file.
27-08-2009 18:46:00 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\L8EULX2U\destrub[1].js" file.
27-08-2009 18:46:09 SYSTEM 1584 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\destrub[1].js" file.
27-08-2009 18:46:09 SYSTEM 1584 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\text_constants_en[1].js" file.
27-08-2009 18:46:15 SYSTEM 1584 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LWS2J3KI\unic_scripts[1].js" file.
27-08-2009 18:51:35 SYSTEM 1584 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\L8EULX2U\index[1].htm" file.
27-08-2009 18:52:11 SYSTEM 1584 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7EB8GL42\index[1].htm" file.
27-08-2009 19:09:51 Ditte 4432 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7EB8GL42\index[1].htm" file.
27-08-2009 19:16:03 SYSTEM 1608 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6YTDTP4P\ticedu_info[1].htm" file.
27-08-2009 19:16:17 SYSTEM 1608 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\script_en[1].js" file.
27-08-2009 19:16:21 SYSTEM 1608 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\script_en[1].js" file.
27-08-2009 19:16:26 SYSTEM 1608 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XEG63NS7\26[1].htm" file.
27-08-2009 19:16:30 SYSTEM 1608 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6YTDTP4P\text_constants_en[1].js" file.
27-08-2009 19:16:31 SYSTEM 1608 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6YTDTP4P\destrub[1].js" file.
27-08-2009 19:30:50 SYSTEM 1608 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VPPF76FQ\index[1].htm" file.
27-08-2009 19:32:21 SYSTEM 1608 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\index[1].htm" file.
27-08-2009 19:47:17 Ditte 752 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\index[1].htm" file.
30-08-2009 13:29:57 Ditte 480 Function setifaceUpdatePackages() has failed. Return code is 0x2000000A, dwRes is 2000000A.
30-08-2009 13:30:20 Ditte 2980 Function setifaceUpdatePackages() has failed. Return code is 0x2000000A, dwRes is 2000000A.
30-08-2009 13:31:15 Ditte 4248 Function setifaceUpdatePackages() has failed. Return code is 0x2000000A, dwRes is 2000000A.
30-08-2009 13:44:11 SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\99JGY5CT\hownet_info[1].htm" file.
30-08-2009 13:44:55 SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJ24P0CR\script_en[1].js" file.
30-08-2009 13:45:07 SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJ24P0CR\script_en[1].js" file.
30-08-2009 13:45:15 SYSTEM 1636 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\26[1].htm" file.
30-08-2009 13:45:23 SYSTEM 1636 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\99JGY5CT\text_constants_en[1].js" file.
30-08-2009 13:45:24 SYSTEM 1636 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DH6QMX5E\destrub[1].js" file.
30-08-2009 13:45:38 SYSTEM 1636 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\unic_scripts[1].js" file.
30-08-2009 13:46:16 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\DDnsFilter.dll" file.
30-08-2009 13:48:54 SYSTEM 1636 Sign of "JS:FakeAV-X [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJ24P0CR\26[1].htm" file.
30-08-2009 13:49:10 SYSTEM 1636 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\text_constants_en[1].js" file.
30-08-2009 13:49:10 SYSTEM 1636 Sign of "JS:FakeAV-Z [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\destrub[1].js" file.
30-08-2009 13:49:11 SYSTEM 1636 Sign of "JS:FakeAV-Y [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\unic_scripts[1].js" file.
30-08-2009 13:56:07 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\DDnsFilter.dll" file.
30-08-2009 13:58:37 SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DH6QMX5E\index[1].htm" file.
30-08-2009 14:03:04 SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\99JGY5CT\index[1].htm" file.
30-08-2009 14:04:36 SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DH6QMX5E\index[1].htm" file.
30-08-2009 14:07:01 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\trzD28A.tmp" file.
30-08-2009 14:24:01 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WY10EAER\prx90[1].exe\[Embedded_I#0b110]" file.
30-08-2009 14:24:41 Ditte 4248 Sign of "JS:ScriptIP-inf [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4BL247CM\popup[1].htm" file.
30-08-2009 14:25:19 Ditte 4248 Sign of "JS:ScriptIP-inf [Trj]" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LIRX3AU7\popup[1].htm" file.
30-08-2009 14:25:28 Ditte 4248 Sign of "VBS:Malware-gen" has been found in "C:\Users\Ditte\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1POVD47\text_constants_en[1].js" file.
30-08-2009 14:49:31 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\trzEC24.tmp" file.
30-08-2009 15:36:49 Ditte 4248 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\DDnsFilter\trzEC24.tmp" file.
HERE IS MY HIJACK LOG:
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:55:25, on 30-08-2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\pp11.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\windows sidebar\gadgets\LGSmartI.Gadget\plugins\LGSmartI.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Users\Ditte\AppData\Local\Temp\9b1lanxj.tmp\HiJackThis.exe
C:\Users\Ditte\AppData\Local\Temp\rfn58kvz.tmp\spybotsd162.exe
C:\Users\Ditte\AppData\Local\Temp\is-JE75S.tmp\spybotsd162.tmp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.psy.ku.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lge.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
O4 - HKLM\..\Run: [KeybdUtility] C:\Program Files\LG Software\On Screen Display\HotKey.exe
O4 - HKLM\..\Run: [BatteryMiser 5] C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\giljabistart.exe" Gilautouc
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [sysldtray] c:\windows\ld14.exe
O4 - HKLM\..\Run: [pp] c:\windows\pp11.exe
O4 - HKLM\..\Run: [ParetoLogic Anti-Virus PLUS] "C:\Program Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" -NM -hidesplash
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: websrvx - Unknown owner - C:\Program Files\websrvx\websrvx.exe
O23 - Service: plasservice (ZeppelinService) - ParetoLogic Inc. - C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe
--
End of file - 8802 bytes
Please help.
Kind regards,
Klavs