---------------------------------------------------------
ewido security suite - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 15:18:08, 11-12-2005
+ Rapport-Checksum: 670D6FDB
+ Scanningsresultat:
HKLM\SOFTWARE\Classes\CLSID\{31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} -> Dialer.Generic : Renset med backup
HKLM\SOFTWARE\Classes\CLSID\{EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} -> Dialer.Generic : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Spyware.BargainBuddy : Renset med backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Spyware.HotBar : Renset med backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Renset med backup
HKU\S-1-5-21-2781504589-1943663836-840360825-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} -> Dialer.Generic : Renset med backup
HKU\S-1-5-21-2781504589-1943663836-840360825-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -> Spyware.MoneyTree : Renset med backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Renset med backup
C:\dialler.exe111 -> Heuristic.Win32.Dialer : Renset med backup
C:\Documents and Settings\Alan Bay\Cookies\alan bay@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
C:\Documents and Settings\Alan Bay\Cookies\alan bay@advertising[2].txt -> Spyware.Cookie.Advertising : Renset med backup
C:\Documents and Settings\Alan Bay\Cookies\alan bay@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
C:\Documents and Settings\Alan Bay\Cookies\alan bay@atdmt[2].txt -> Spyware.Cookie.Atdmt : Renset med backup
C:\Documents and Settings\Alan Bay\Cookies\alan bay@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Renset med backup
C:\Documents and Settings\Alan Bay\Cookies\alan bay@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
C:\Documents and Settings\Alan Bay\Cookies\alan bay@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Renset med backup
C:\Documents and Settings\Jytte Bay\Cookies\jytte bay@banner.newyorkcasino[1].txt -> Spyware.Cookie.Newyorkcasino : Renset med backup
C:\Documents and Settings\Jytte Bay\Cookies\jytte bay@goldenpalace[1].txt -> Spyware.Cookie.Goldenpalace : Renset med backup
C:\Documents and Settings\Jytte Bay\Cookies\jytte bay@grandonline[1].txt -> Spyware.Cookie.Grandonline : Renset med backup
C:\Documents and Settings\Jytte Bay\Cookies\jytte bay@newyorkcasino[1].txt -> Spyware.Cookie.Newyorkcasino : Renset med backup
C:\Documents and Settings\Jytte Bay\Cookies\jytte bay@www.grandonline[1].txt -> Spyware.Cookie.Grandonline : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP100\A0020561.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP100\A0020586.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP101\A0020599.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP102\A0020622.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP102\A0020632.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP102\A0020655.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP102\A0020676.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP102\A0020705.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP102\A0020721.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP103\A0020751.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP103\A0020786.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP103\A0020794.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP103\A0020822.exe -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP104\A0020839.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP105\A0020869.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP105\A0020888.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP106\A0020901.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP108\A0020923.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP108\A0020930.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP108\A0020953.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP109\A0020992.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP111\A0021043.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP112\A0022060.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP112\A0022068.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP112\A0022081.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP112\A0022090.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP113\A0022111.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP113\A0022116.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP113\A0022130.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP113\A0022160.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP113\A0022163.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP113\A0022169.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP114\A0022184.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP114\A0022200.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP115\A0022209.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP115\A0022217.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP115\A0022244.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP116\A0022257.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP116\A0022290.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP116\A0022299.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP117\A0022343.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP118\A0022366.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP118\A0022374.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP118\A0022388.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP118\A0022426.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP119\A0022454.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP120\A0022510.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP120\A0022528.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP121\A0022536.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP121\A0022549.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP121\A0022564.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP121\A0022582.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP122\A0023583.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP122\A0023585.tlb -> Trojan.Puper.bp : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP122\A0023596.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP122\A0023598.tlb -> Trojan.Puper.bp : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP122\A0023621.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP122\A0023625.tlb -> Trojan.Puper.bp : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP123\A0023651.tlb -> Trojan.Puper.bp : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP123\A0023653.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP123\A0023659.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP123\A0023662.tlb -> Trojan.Puper.bp : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023696.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023698.tlb -> Trojan.Puper.bp : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023710.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023713.tlb -> Trojan.Puper.bp : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023724.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023727.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023737.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023738.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023739.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023740.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP124\A0023741.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023759.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023761.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023765.exe -> Adware.Spyaxe : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023766.exe -> Downloader.Zlob.cb : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023773.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023776.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023782.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023786.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023792.exe -> Trojan.Puper.bq : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023799.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023802.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023832.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023833.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023839.exe -> Adware.Spyaxe : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023857.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023858.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023866.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP125\A0023868.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP128\A0023952.exe -> Adware.Spyaxe : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP129\A0023964.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP131\A0023980.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP132\A0023989.exe -> Adware.Spyaxe : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024256.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024264.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024275.exe -> Adware.Spyaxe : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024282.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024303.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024335.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024350.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024351.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024360.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP134\A0024361.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP135\A0024381.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP135\A0024382.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP135\A0024409.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP135\A0024417.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP135\A0024429.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP136\A0024441.dll -> Spyware.NaviPromo : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP136\A0024462.dll -> Not-A-Virus.Downloader.Win32.Spax.a : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP136\A0024465.tlb -> Downloader.Zlob.cf : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP136\A0024467.exe -> Hijacker.SpyAxe : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP76\A0018243.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP77\A0018270.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP77\A0018297.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP77\A0018310.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP78\A0018337.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP80\A0018373.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP80\A0018394.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018439.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018447.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018457.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018483.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018528.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018539.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018555.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP81\A0018565.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP82\A0018569.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP82\A0018579.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP82\A0018617.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP83\A0018661.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP83\A0018691.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP84\A0018711.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP84\A0018730.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP85\A0018750.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP87\A0018799.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP87\A0018818.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP88\A0018835.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP88\A0018869.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP89\A0018901.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP90\A0018936.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP90\A0018946.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP90\A0018949.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP90\A0018973.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP90\A0019008.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP91\A0019029.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP91\A0019045.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP92\A0019067.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP93\A0019088.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP94\A0019141.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP94\A0019156.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP94\A0019178.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP94\A0019201.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP95\A0019299.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP95\A0019313.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP95\A0020321.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP96\A0020345.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP96\A0020366.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP97\A0020381.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP97\A0020393.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP98\A0020408.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP98\A0020488.dll -> Dialer.Generic : Renset med backup
C:\System Volume Information\_restore{1A5BB231-CCF8-48FF-8AD3-21401F791F13}\RP99\A0020499.dll -> Dialer.Generic : Renset med backup
C:\WINDOWS\p2esocks_1042.dll -> Trojan.Wintrim : Renset med backup
C:\WINDOWS\system32\eg_auth_srv_1042.dll -> Trojan.Wintrim : Renset med backup
C:\WINDOWS\system32\msclock32.dll -> Spyware.NaviPromo : Renset med backup
C:\WINDOWS\system32\msplock32.dll -> Spyware.NaviPromo : Renset med backup
C:\WINDOWS\system32\sysinetsvc32.dll -> Dialer.Generic : Renset med backup
C:\WINDOWS\system32\sysnetsvc32.dll -> Dialer.Generic : Renset med backup
::Rapport slut
------------------------------------------------------------------------------------
smitRem © log file
version 2.8
by noahdfear
Microsoft Windows XP [version 5.1.2600]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SpyAxeFix © by noahdfear
spyaxe directory present
spyaxe uninstaller present
Starting spyaxe uninstaller
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
svchosts.dll
1024 dir
msvol.tlb
ncompat.tlb
nvctrl.exe
hp***.tmp
~~~ Icons in System32 ~~~
ts.ico
ot.ico
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 728 'explorer.exe'
Starting registry repairs
Deleting files
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN! :)
-------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 15:51:50, on 11-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\ATI Technologies\ATI Kontrolpanel\atiptaxx.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Lexmark X1100 Series\lxbkbmgr.exe
C:\Programmer\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\Fælles filer\soft602\pdfSaver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PDF\pdfSaver\pdfSaver3.exe
C:\programmer\mailskinner\mailskinner.exe
C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\RDSHOST.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\Documents and Settings\Alan Bay\Skrivebord\zx\11-12-2005\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.google.dk/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer leveret af Opasia
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmer\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [602PC SUITE PDF Saver] "C:\Programmer\Fælles filer\soft602\pdfSaver.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGDACCESS_1071.dll,InstantAccess
O4 - HKCU\..\Run: [pdfSaver3] "c:\Program Files\PDF\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [MailSkinner] c:\programmer\mailskinner\mailskinner.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: &Translate English Word -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmwordtrans.htmlO8 - Extra context menu item: Backward Links -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: Similar Pages -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate Page into English -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone:
http://*.tv2.dkO16 - DPF: {04CCFF26-7D52-4E42-BF6A-F8ECE0896EB7} -
http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1071_XP.cabO16 - DPF: {0D1011B3-89C8-4F8E-8693-BB970E2E81E0} -
http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1069_ASPIV4_XP.cabO16 - DPF: {11F1D260-129E-4EB7-B37E-57E3D97A3DF1} -
http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1044_EN_XP.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {3616F4B5-F6AD-4E67-966A-C218673648A0} -
http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1070_ASPIV4_XP.cabO16 - DPF: {3DAD912E-D2B9-4323-B7C9-7F2C5CC0C57B} -
http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1070_XP.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} -
http://scripts.downloadv3.com/binaries/IA/sysinetsvc32_EN_XP.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cabO16 - DPF: {BA749BC1-143E-430D-B1DA-1D2AF67A3658} -
http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1069_XP.cabO16 - DPF: {BD3653E4-884B-43C4-970B-670802501B7F} -
http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1043_EN_XP.cabO16 - DPF: {BE5A7132-329F-4319-B781-2A83BFE51534} -
http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1045_EN_XP.cabO16 - DPF: {D8B94E9A-A34B-4253-BF48-C7CB7F2CFDB0} -
http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1046_EN_XP.cabO16 - DPF: {E114CD5B-17CE-4807-890E-7B1EDF9F2E5E} -
http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1066_XP.cabO16 - DPF: {E7AE1661-EBEB-492B-AE0D-860DF24174C6} -
http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1064_ASPIV4_XP.cabO16 - DPF: {FA83E942-B796-46DE-9155-1632ECC5473B} -
http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1061_XP.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
-------------------------------------------------------------------------------------
Det er så alle 3 logfiler