Her er reporten og log'en
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 06:56:30, 14-06-2005
+ Report-Checksum: F1A18C25
+ Date of database: 13-06-2005
+ Version of scan engine: v3.0
+ Duration: 16 min
+ Scanned Files: 18608
+ Speed: 19.36 Files/Second
+ Infected files: 20
+ Removed files: 20
+ Files put in quarantine: 20
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Documents and Settings\Jonas\Cookies\jonas@advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jonas\Cookies\jonas@cgi-bin[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jonas\Cookies\jonas@mediaplex[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jonas\Cookies\jonas@servedby.advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jonas\Lokale indstillinger\Temp\se.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\loader.exe -> TrojanDownloader.Small.aod -> Cleaned with backup
C:\WINDOWS\pumba2.dll -> Spyware.Azesearch -> Cleaned with backup
C:\WINDOWS\system\svchost.dll -> Backdoor.Agent.iw -> Cleaned with backup
C:\WINDOWS\system\svchosthook.dll -> Backdoor.Agent.iw -> Cleaned with backup
C:\WINDOWS\system32\iasada.dll -> Spyware.Azesearch.b -> Cleaned with backup
C:\WINDOWS\system32\init32m.exe -> TrojanDownloader.Agent.ho -> Cleaned with backup
C:\WINDOWS\system32\vxgame2.exe -> Backdoor.Agent.iw -> Cleaned with backup
C:\WINDOWS\system32\vxgame3.exe -> TrojanDownloader.Agent.ho -> Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq1.exe -> TrojanDropper.Small.wp -> Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq2.exe -> Not-A-Virus.Hoax.Renos.a -> Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq8.exe -> TrojanDropper.Small.wp -> Cleaned with backup
C:\WINDOWS\system32\web.exe -> TrojanDownloader.Small.agq -> Cleaned with backup
C:\WINDOWS\system32\wirl.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\system32\wldr.dll -> TrojanProxy.Small.bo -> Cleaned with backup
C:\WINDOWS\uninstIU.exe -> Trojan.Agent.eo -> Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 06:51:46, on 14-06-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ewido\security suite\SecuritySuite.exe
C:\WINDOWS\system32\spider.exe
C:\Programmer\Downloads\hjt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\DOCUME~1\ADMINI~1\LOKALE~1\Temp\se.dll/spage.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\DOCUME~1\Mogens\LOKALE~1\Temp\se.dll/spage.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: auto.search.msn.com 127.0.0.1
O2 - BHO: (no name) - {F29F91F3-4707-416B-B5D5-D733C951A8E9} - C:\WINDOWS\System32\hfon.dll (file missing)
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [PSGuard] C:\Programmer\PSGuard\PSGuard.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
O18 - Filter: text/html - {C6CD1BC3-0A7F-494B-8A10-C174AEC04A00} - C:\WINDOWS\System32\hfon.dll
O18 - Filter: text/plain - {C6CD1BC3-0A7F-494B-8A10-C174AEC04A00} - C:\WINDOWS\System32\hfon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmer\Sygate\SPF\smc.exe