Mit internet har været nede, derfor dette sene svar
Her er de 2 nye logs:
Logfile of HijackThis v1.99.1
Scan saved at 09:26:53, on 7/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\GENIUS~1\mouseElf.exe
C:\Documents and Settings\Administrator\Desktop\popup killer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\iewf.exe
C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Administrator\My Documents\IT problem og løsning\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINDOWS\system32\wbjtf.dll/sp.html#37049R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINDOWS\system32\wbjtf.dll/sp.html#37049R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
res://C:\WINDOWS\system32\wbjtf.dll/sp.html#37049R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINDOWS\system32\wbjtf.dll/sp.html#37049R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINDOWS\system32\wbjtf.dll/sp.html#37049R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://C:\WINDOWS\system32\wbjtf.dll/sp.html#37049R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://C:\WINDOWS\system32\wbjtf.dll/sp.html#37049R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {F9AE87A0-844A-04E0-82FC-ABA9A8BCBB07} - C:\WINDOWS\winsn32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\GENIUS~1\mouseElf.exe
O4 - HKLM\..\Run: [aiepk] C:\Documents and Settings\Administrator\Desktop\popup killer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [iewf.exe] C:\WINDOWS\iewf.exe
O4 - HKLM\..\RunOnce: [appbg32.exe] C:\WINDOWS\system32\appbg32.exe
O4 - HKCU\..\Run: [IE Privacy Keeper] "C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" -stcleanup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cabO16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) -
https://netbank.danskebank.dk/html/activex/DB/Menu.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
http://www.installengine.com/engine/isetup.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cabO16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) -
http://www.ravantivirus.com/scan/ravonline.cabO16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) -
https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabO16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) -
https://netbank.danskebank.dk/html/activex/danskesikker/DB/DanskeSikker.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = lystrupit.dk
O17 - HKLM\Software\..\Telephony: DomainName = lystrupit.dk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = lystrupit.dk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = lystrupit.dk
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\ieyg.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 13:48:43, 7/5/2005
+ Report-Checksum: 2FD68906
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{1228458E-6B19-48F4-5449-A00AEE93F0FC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2BFAB072-A3F3-0A97-6990-3673392B7DFC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{46C8C875-7053-566F-B7DF-A8735884B10E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{830D569A-6507-2B7A-ABB2-4C0D6CA51F32} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8A50C2FE-C00E-0C19-DC1A-BCABABE155C3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F6ED913D-FAB1-F1A5-C359-4E2B2AC7B284} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F7DFCD4F-46CD-BDA8-264C-0A68205F4979} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{031B6D43-CBC4-46A5-8E46-CF8B407C1A33} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0899151F-E69F-1686-3512-49E8D49B547E} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E1230F8-EA50-42A9-983C-D22ABC2EED3B} -> Spyware.ASSbar : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -> Spyware.WinFavorites : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{386A771C-E96A-421F-8BA7-32F1B706892F} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{79849612-A98F-45B8-95E9-4D13C7B6B35C} -> Spyware.Crazywinnings : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{830D569A-6507-2B7A-ABB2-4C0D6CA51F32} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9E98E84C-79E1-49C3-82EB-798FCD552EFB} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-839522115-1326574676-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6ED913D-FAB1-F1A5-C359-4E2B2AC7B284} -> Spyware.CoolWebSearch : Cleaned with backup
C:\Documents and Settings\NetworkService\Cookies\administrator@paycounter[2].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\RECYCLER\NPROTECT\00003159.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003160.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003162.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003164.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003166.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003168.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003170.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003171.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003172.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003174.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003176.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003178.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003179.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003181.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003182.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003183.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003184.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003186.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003189.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003190.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003191.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003192.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003193.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003194.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\NPROTECT\00003196.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addgm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addhy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addjo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addmq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addpl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiao32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiju32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiun.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiwr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiwu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apizr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appad32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appgr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apphn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apphp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appii32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appiq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlbw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlca32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlox32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlxh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlxl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\coolcust.ini:ztlii -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\croc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cruw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crxj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ux32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\disney.ini:ethuwn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hpqEmlSz.INI:rzngbc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\hpudrv.ini:jsbwjz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iecl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieiz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieqf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipac32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipei32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipkt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipxa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javacz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javamj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javane32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javanj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaty.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javazp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcbz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcgz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfclq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msbp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msbu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msgk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msry32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msts32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netes32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netfv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netkg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netmn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netmv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netpo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntdf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntdw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntfi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntkr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntnt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\phlziv.reg:fdbzyq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\phlziv.reg:kvdtqc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkta32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SIGVERIF.TXT:vzdvyv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysoo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addek.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addif.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addql.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addtw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apihr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiqi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apisg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiwx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appnj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlai.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlei32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlib.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atljo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlot.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlov.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlps.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlue.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlva.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crgh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crgn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crju.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crop.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crte32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crwg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ic.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3jx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ka.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ly32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3sa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ta32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3te.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iehz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ietf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipbl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipbv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipgw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipna32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipny.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ippr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipqv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iptw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaby.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaed32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javagm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaje.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javajw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javakc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javatb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javawq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfchs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcqh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcqu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcvn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcwv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msbk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msdl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msfp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msie32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mskt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msns.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msuf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netnw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netss32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netvm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntcn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntfe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nthf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntqe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntzl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkan32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkay32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkcr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkkw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkln.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkop.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkre.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkrr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkur.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkvz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkyp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syscq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysyl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syszl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winge.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winid.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winmy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winxl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winxv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syszb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\tempf.txt:mpuxp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\TSC.ini:hkcek -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\UPGRADE.TXT:kexhd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vbaddin.ini:svfpvw -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winmw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winsn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winws32.exe -> Trojan.Agent.bi : Cleaned with backup
D:\Documents and Settings\Michael Sørensen\Lokale indstillinger\Temporary Internet Files\Content.IE5\CJEBUBO7\MediaTicketsInstaller[1].cab/MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
D:\Documents and Settings\Michael Rex Sørensen\Lokale indstillinger\Temporary Internet Files\Content.IE5\CJEBUBO7\crazywinningsgame[1].exe -> Spyware.WinShow : Cleaned with backup
D:\Documents and Settings\Michael Rex Sørensen\Lokale indstillinger\Temporary Internet Files\Content.IE5\WBYVQPOR\ucmoreiex[1].exe/UCMTSAIE.DLL -> Spyware.UCmore : Cleaned with backup
D:\Documents and Settings\Michael Rex Sørensen\Lokale indstillinger\Temporary Internet Files\Content.IE5\WBYVQPOR\ucmoreiex[1].exe/IUCMORE.DLL -> Spyware.UCmore : Cleaned with backup
D:\Documents and Settings\Michael Rex Sørensen\Dokumenter\backup-20050319-143826-824.dll -> Spyware.MediaTickets : Cleaned with backup
D:\Documents and Settings\Michael Rex Sørensen\Application Data\orec.exe -> Spyware.PurityScan : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP32\A0017787.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP32\A0017788.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP33\A0017889.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP33\A0017890.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP33\A0017893.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP33\A0017902.exe -> Adware.SAHA : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP33\A0017958.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP33\A0017962.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018009.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018013.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018275.exe/UCMTSAIE.DLL -> Spyware.UCmore : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018275.exe/IUCMORE.DLL -> Spyware.UCmore : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018276.dll -> Spyware.SBSoft : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018277.dll -> Spyware.Puper : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018278.exe -> Adware.SAHA : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018281.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018282.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018289.exe -> Adware.SAHA : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018291.dll -> Adware.SAHA : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018292.vxd/D:/WINDOWS/System32/exdl.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018292.vxd/D:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018292.vxd/D:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018292.vxd/D:/WINDOWS/System32/bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018292.vxd/D:/WINDOWS/System32/msexreg.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018292.vxd/D:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018308.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018378.dll -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018379.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018380.exe -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018381.dll -> Spyware.BargainBuddy : Cleaned with backup
D:\System Volume Information\_restore{226B5EF7-B290-4FA2-B1AC-1E78C6CA28E6}\RP35\A0018382.dll -> Spyware.180Solutions : Cleaned with backup
::Report End
Får hele tiden alarmer fra Ewido-programmet om virus, selvom programmet har renset op.
Kunne ikke gøre dette, som var dit forslag:Se om du kan finde én af disse services:
Workstation NetLogon Service
Network Security Service
Remote Procedure Call (RPC) Helper
Remote Access Service
...på listen. Hvis du finder én af dem - Højreklik på den og vælg Egenskaber - klik på "Stop" og vælg Starttype "Deaktiveret" - klik Anvend og OK. Luk service vinduet.
"Stopfeltet" kunne ikke aktiveres.