Okay, så har jeg fulgt anvisningerne, og her kommer Ewido-loggen:
ewido security suite - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 15:07:21, 11-12-2005
+ Rapport-Checksum: 9D550742
+ Scanningsresultat:
HKLM\SOFTWARE\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{86227D9C-0EFE-4f8a-AA55-30386A3F5686} -> Spyware.YourSiteBar : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} -> Spyware.SideFind : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Renset med backup
HKLM\SOFTWARE\Classes\Interface\{339D8AFF-0B42-4260-AD82-78CE605A9543} -> Spyware.SideFind : Renset med backup
HKLM\SOFTWARE\Classes\Interface\{A36A5936-CFD9-4B41-86BD-319A1931887F} -> Spyware.SideFind : Renset med backup
HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Renset med backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer -> Spyware.WinAd : Renset med backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer\CLSID -> Spyware.WinAd : Renset med backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer\CurVer -> Spyware.WinAd : Renset med backup
HKLM\SOFTWARE\Classes\TypeLib\{58634367-D62B-4C2C-86BE-5AAC45CDB671} -> Spyware.SideFind : Renset med backup
HKLM\SOFTWARE\Classes\TypeLib\{D0288A41-9855-4A9B-8316-BABE243648DA} -> Spyware.SideFind : Renset med backup
HKLM\SOFTWARE\Classes\WUSN.1 -> Spyware.SaveNow : Renset med backup
HKLM\SOFTWARE\ClickSpring -> Spyware.PurityScan : Renset med backup
HKLM\SOFTWARE\ISTsvc -> Spyware.ISTBar : Renset med backup
HKLM\SOFTWARE\ISTsvc\history -> Spyware.ISTBar : Renset med backup
HKLM\SOFTWARE\Microsoft\SideFind -> Spyware.SideFind : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/istactivex.dll -> Spyware.ISTBar : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Spyware.MoneyTree : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhenUSaveMsg -> Spyware.SaveNow : Renset med backup
HKLM\SOFTWARE\Policies\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKLM\SOFTWARE\PowerScan -> Spyware.PowerScan : Renset med backup
HKLM\SOFTWARE\sais -> Spyware.180Solutions : Renset med backup
HKLM\SOFTWARE\WhenUSave -> Spyware.SaveNow : Renset med backup
HKLM\SOFTWARE\WhenUSave\Partners -> Spyware.SaveNow : Renset med backup
HKLM\SOFTWARE\WhenUSave\Partners\EEPE -> Spyware.SaveNow : Renset med backup
HKU\.DEFAULT\Software\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} -> Spyware.SideFind : Renset med backup
HKU\S-1-5-21-839522115-842925246-1202660629-1003\Software\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKU\S-1-5-21-839522115-842925246-1202660629-1003\Software\IST -> Spyware.ISTBar : Renset med backup
HKU\S-1-5-21-839522115-842925246-1202660629-1003\Software\Microsoft\Internet Explorer\Explorer Bars\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} -> Spyware.SideFind : Renset med backup
HKU\S-1-5-21-839522115-842925246-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Spyware.InternetOptimizer : Renset med backup
HKU\S-1-5-21-839522115-842925246-1202660629-1003\Software\Policies\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKU\S-1-5-21-839522115-842925246-1202660629-1003\Software\PowerScan -> Spyware.PowerScan : Renset med backup
HKU\S-1-5-21-839522115-842925246-1202660629-1003\Software\sais -> Spyware.180Solutions : Renset med backup
HKU\S-1-5-18\Software\Avenue Media -> Spyware.InternetOptimizer : Renset med backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Explorer Bars\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} -> Spyware.SideFind : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@2o7[1].txt -> Spyware.Cookie.2o7 : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@adopt.euroclick[1].txt -> Spyware.Cookie.Euroclick : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@advertising[2].txt -> Spyware.Cookie.Advertising : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@as-us.falkag[1].txt -> Spyware.Cookie.Falkag : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@atdmt[2].txt -> Spyware.Cookie.Atdmt : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@bfast[2].txt -> Spyware.Cookie.Bfast : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@burstnet[1].txt -> Spyware.Cookie.Burstnet : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@clickagents[1].txt -> Spyware.Cookie.Clickagents : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@com[2].txt -> Spyware.Cookie.Com : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@counter1.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@counter14.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@counter16.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@counter3.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@counter4.sextracker[2].txt -> Spyware.Cookie.Sextracker : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@counter5.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz11.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz3.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz4.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz5.clickzs[1].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz6.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz7.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz8.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@cz9.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@fastclick[2].txt -> Spyware.Cookie.Fastclick : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@hg1.hitbox[1].txt -> Spyware.Cookie.Hitbox : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@media.fastclick[2].txt -> Spyware.Cookie.Fastclick : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@paycounter[1].txt -> Spyware.Cookie.Paycounter : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@paypopup[2].txt -> Spyware.Cookie.Paypopup : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@perf.overture[1].txt -> Spyware.Cookie.Overture : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@revenue[1].txt -> Spyware.Cookie.Revenue : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@sexlist[2].txt -> Spyware.Cookie.Sexlist : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@sextracker[2].txt -> Spyware.Cookie.Sextracker : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@spylog[1].txt -> Spyware.Cookie.Spylog : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@stat.onestat[2].txt -> Spyware.Cookie.Onestat : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@statcounter[1].txt -> Spyware.Cookie.Statcounter : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@statse.webtrendslive[2].txt -> Spyware.Cookie.Webtrendslive : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@targetnet[2].txt -> Spyware.Cookie.Targetnet : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@trafic[1].txt -> Spyware.Cookie.Trafic : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@valueclick[2].txt -> Spyware.Cookie.Valueclick : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@vip.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@vip2.clickzs[1].txt -> Spyware.Cookie.Clickzs : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@www.burstbeacon[2].txt -> Spyware.Cookie.Burstbeacon : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@www.sidefind[2].txt -> Spyware.Cookie.Sidefind : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@xxxcounter[1].txt -> Spyware.Cookie.Xxxcounter : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@xxxtoolbar[2].txt -> Spyware.Cookie.Xxxtoolbar : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Renset med backup
C:\Documents and Settings\Morten\Cookies\morten@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Renset med backup
C:\Documents and Settings\Morten\Menuen Start\Programmer\Power Scan -> Spyware.PowerScan : Renset med backup
C:\Documents and Settings\Morten\Menuen Start\Programmer\Power Scan\Power Scan.lnk -> Spyware.PowerScan : Renset med backup
C:\Documents and Settings\Morten\Menuen Start\Programmer\WhenU -> Spyware.SaveNow : Renset med backup
C:\Documents and Settings\Morten\Menuen Start\Programmer\WhenU\Learn More About Save!.url -> Spyware.SaveNow : Renset med backup
C:\Documents and Settings\Morten\Menuen Start\Programmer\WhenU\Learn More About SaveNow.url -> Spyware.SaveNow : Renset med backup
C:\Documents and Settings\Morten\Menuen Start\Programmer\WhenU\WhenU.com Website.url -> Spyware.SaveNow : Renset med backup
C:\Documents and Settings\Morten\Skrivebord\Hijackthis\backups\backup-20051210-173518-124.dll -> Spyware.WinAD : Renset med backup
C:\Documents and Settings\Morten\Skrivebord\Hijackthis\backups\backup-20051210-173519-171.dll -> Downloader.IstBar : Renset med backup
C:\Documents and Settings\Morten\Skrivebord\Hijackthis\backups\backup-20051210-173520-411.dll -> Downloader.IstBar : Renset med backup
C:\Documents and Settings\Morten\Skrivebord\Hijackthis\backups\backup-20051210-173522-628.dll -> Spyware.MediaTickets : Renset med backup
C:\Documents and Settings\Morten\Skrivebord\Hijackthis\backups\backup-20051210-173523-855.dll -> Spyware.AdPowerZone : Renset med backup
C:\Program Files\Media Access\MediaAccC.dll -> Spyware.WinAD : Renset med backup
C:\Program Files\Media Access\MediaAccK.exe -> Spyware.WinAD : Renset med backup
C:\Programmer\BearShare\Installer\saveinstwm.exe -> Adware.SaveNow : Renset med backup
C:\Programmer\Power Scan -> Spyware.PowerScan : Renset med backup
C:\Programmer\Power Scan\powerscan.exe -> Spyware.PowerScan : Renset med backup
C:\WINDOWS\Downloaded Program Files\int_ver32b.ocx -> Dialer.Generic : Renset med backup
C:\WINDOWS\system32\nvscv32.exe.mwt -> Backdoor.Rbot : Renset med backup
::Rapport slut
Og Hijackthis-loggen:
Logfile of HijackThis v1.99.1
Scan saved at 17:47:32, on 11-12-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Morten\Skrivebord\Hijackthis\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabO23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
Hvordan ser det ud?