Log fra ewido:
HKLM\SOFTWARE\Classes\CLSID\{7C559105-9ECF-42b8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{AA4939C3-DECA-4A48-A454-97CD587C0EF5} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EEE4A2E5-9F56-432F-A6ED-F6F625B551E0} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\ISTx.Installer -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\ISTx.Installer\CLSID -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy -> Spyware.SearchRelevancy : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy\Update -> Spyware.SearchRelevancy : Cleaned with backup
HKU\S-1-5-21-436374069-1450960922-682003330-1003\Software\Premium Web Service -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-436374069-1450960922-682003330-1003\Software\Premium Web Service\Content Browser -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-436374069-1450960922-682003330-1003\Software\Premium Web Service\Content Browser\Settings -> Dialer.Generic : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Ejer\Application Data\Mozilla\Firefox\Profiles\uyp2rlma.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Ejer\Application Data\Mozilla\Firefox\Profiles\uyp2rlma.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Ejer\Application Data\Mozilla\Firefox\Profiles\uyp2rlma.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Ejer\Application Data\Mozilla\Firefox\Profiles\uyp2rlma.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Ejer\Application Data\Mozilla\Firefox\Profiles\uyp2rlma.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Ejer\Application Data\Mozilla\Firefox\Profiles\uyp2rlma.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Ejer\Application Data\Mozilla\Profiles\default\3klkd7ur.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Ejer\Application Data\Mozilla\Profiles\default\3klkd7ur.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Ejer\Application Data\Mozilla\Profiles\default\3klkd7ur.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Ejer\Application Data\Mozilla\Profiles\default\3klkd7ur.slt\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Ejer\Cookies\ejer@adtech[1].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\Ejer\Cookies\ejer@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\bpkun.exe -> TrojanSpy.Perfectkeylogger : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\drp219.tmp\thnall1s.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\fWWY1vQ.exe -> TrojanDownloader.IstBar.jn : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\i4aWlK.exe -> TrojanDownloader.IstBar.ka : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\iqEL8Q.exe -> TrojanDownloader.IstBar.ka : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\jfgudk.exe -> TrojanDownloader.IstBar.jn : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\optimize.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\RarSFX0\rinst.exe -> TrojanSpy.Perflogger.az : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\saveinstwm.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\sidefind.exe -> TrojanDownloader.IstBar.jm : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\temp.frD425\update\sidefind.exe -> TrojanDownloader.IstBar.jm : Cleaned with backup
C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\VVSNInst.exe/VVSN.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Ejer\Skrivebord\Programmer\Wpeproalpha\WPE PRO.exe -> Not-A-Virus.Sniffer.WpePro.b : Cleaned with backup
C:\My Downloads\Microsoft Visual Basic 6.0 Professional\IE4\icw95.cab/ICWCONN1.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\My Downloads\Microsoft Visual Basic 6.0 Professional\IE4\icwnt.cab/ICWCONN1.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\My Downloads\Microsoft Visual Basic 6.0 Professional.zip/IE4/icw95.cab/ICWCONN1.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\My Downloads\Microsoft Visual Basic 6.0 Professional.zip/IE4/icwnt.cab/ICWCONN1.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Programmer\BearShare\Installer\saveinstwm.exe -> Adware.SaveNow : Cleaned with backup
C:\Programmer\INSTAFINK\instafink.dll -> Spyware.404Search : Cleaned with backup
C:\Programmer\LeapFTP\LeapFTP.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Programmer\themexp\Themexp.org File\NNEZTA388.exe -> Spyware.NewDotNet : Cleaned with backup
C:\Programmer\themexp\Themexp.org File\TBEZA127Q.exe -> Spyware.Quick : Cleaned with backup
C:\temp\sahagent.exe -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\iGator\Trickler3103_PIC_fs_DMPT.exe -> Adware.Gator : Cleaned with backup
C:\WINDOWS\iLookup\WebDevAZ10.exe -> Adware.eZula : Cleaned with backup
C:\WINDOWS\iTopRebates\WebRebates_Auto.exe -> Spyware.WebRebates.g : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\SYSTEM32\keylog.exe -> TrojanSpy.Perflogger.az : Cleaned with backup
C:\WINDOWS\SYSTEM32\keylogr.exe -> TrojanSpy.Perflogger.az : Cleaned with backup
C:\WINDOWS\SYSTEM32\raddrv.dll -> Not-A-Virus.RiskWare.RemoteAdmin.RAdmin.20 : Cleaned with backup
C:\WINDOWS\SYSTEM32\rebates.exe/rebates.exe -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\SYSTEM32\rebates.exe/toolbar.exe -> Trojan.Crypt.e : Cleaned with backup
C:\WINDOWS\SYSTEM32\r_server.exe -> Not-A-Virus.RiskWare.RemoteAdmin.RAdmin.22 : Cleaned with backup
----------------------------------------------------------------------------------
log fra hijackthis:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "
http://www.google.com/"); (C:\Documents and Settings\Ejer\Application Data\Mozilla\Profiles\default\3klkd7ur.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_1.dll
O2 - BHO: SS SS Plugin - {1D1B2879-99FF-11E3-8D96-D7ACAC95952A} - C:\WINDOWS\system32\keylogwb.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_1.dll
O4 - HKLM\..\Run: [BearShare] "C:\Programmer\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ordbogen.com] C:\Programmer\CoolSystems\ordbogen.com\ordbogen.exe
O4 - HKLM\..\Run: [keylog] C:\WINDOWS\system32\keylog.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MessengerDiscovery] C:\Programmer\MessengerDiscovery\msgdiscoveryx.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
O15 - Trusted Zone: *.moove.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cabO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: R_dddtyermper - Realtek Semiconductor Corporation - (no file)