sådan - 3 logfiler:
SmitFraudFix v2.81
Scan done at 12:49:28,73, 29-08-2006
Run from C:\Documents and Settings\Martin Moth-Lund\Skrivebord\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 13:45:40, 29-08-2006
+ Rapport-Checksum: 7F9CFAEF
+ Scanningsresultat:
C:\Documents and Settings\Ann Iversen\Cookies\ann iversen@doubleclick[2].txt -> TrackingCookie.Doubleclick : Renset med backup
C:\Documents and Settings\Ann Iversen\Cookies\ann iversen@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset med backup
C:\Documents and Settings\Ann Iversen\Cookies\ann iversen@overture[2].txt -> TrackingCookie.Overture : Renset med backup
C:\Documents and Settings\Ann Iversen\Cookies\ann iversen@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@122.2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@2o7[2].txt -> TrackingCookie.2o7 : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@adtech[2].txt -> TrackingCookie.Adtech : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@advertising[1].txt -> TrackingCookie.Advertising : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@atdmt[2].txt -> TrackingCookie.Atdmt : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@bfast[1].txt -> TrackingCookie.Bfast : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@burstnet[2].txt -> TrackingCookie.Burstnet : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@casalemedia[2].txt -> TrackingCookie.Casalemedia : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@com[1].txt -> TrackingCookie.Com : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter1.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter10.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter12.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter16.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter4.sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter5.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter7.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter8.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@cz2.clickzs[2].txt -> TrackingCookie.Clickzs : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@doubleclick[1].txt -> TrackingCookie.Doubleclick : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@ehg-gamespot.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@ehg-ipswitchinc.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@ehg-nokiafin.hitbox[1].txt -> TrackingCookie.Hitbox : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@fastclick[1].txt -> TrackingCookie.Fastclick : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@hitbox[2].txt -> TrackingCookie.Hitbox : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@image.masterstats[1].txt -> TrackingCookie.Masterstats : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@ivwbox[1].txt -> TrackingCookie.Ivwbox : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@komtrack[2].txt -> TrackingCookie.Komtrack : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@mediaplex[1].txt -> TrackingCookie.Mediaplex : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@paycounter[2].txt -> TrackingCookie.Paycounter : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@sexlist[1].txt -> TrackingCookie.Sexlist : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@sextracker[2].txt -> TrackingCookie.Sextracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@statcounter[1].txt -> TrackingCookie.Statcounter : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@targetnet[1].txt -> TrackingCookie.Targetnet : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@trafficcenter[1].txt -> TrackingCookie.Trafficcenter : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@valueclick[2].txt -> TrackingCookie.Valueclick : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@vip.clickzs[1].txt -> TrackingCookie.Clickzs : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@vip2.clickzs[1].txt -> TrackingCookie.Clickzs : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@www.burstnet[1].txt -> TrackingCookie.Burstnet : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@www.etracker[1].txt -> TrackingCookie.Etracker : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Renset med backup
C:\Documents and Settings\Martin Moth-Lund\Cookies\martin moth-lund@yadro[2].txt -> TrackingCookie.Yadro : Renset med backup
C:\Documents and Settings\Mille\Cookies\mille@atdmt[2].txt -> TrackingCookie.Atdmt : Renset med backup
C:\Documents and Settings\Mille\Cookies\mille@serving-sys[2].txt -> TrackingCookie.Serving-sys : Renset med backup
::Rapport slut
Logfile of HijackThis v1.99.1
Scan saved at 17:31:45, on 29-08-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\VM_STI.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Messenger\MSMSGS.EXE
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\ACD Systems\ImageFox\ImageFox.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Martin Moth-Lund\Skrivebord\hjt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Programmer\PCODEC\isaddon.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O3 - Toolbar: Protection Bar - {860c2f6b-ca82-4282-9187-beccbb66f0af} - C:\Programmer\PCODEC\iesplugin.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Amitech Web Camera
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ImageFox.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) -
http://downol.dr.dk/download/netradio/Rawflow.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127763298859O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1127766045000O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IP-Uploader Control) -
http://asp01.photoprintit.de/microsite/10021/defaults/activex/ImageUploader3.cabO16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) -
http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocxO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe