Check af HijackThis, DrWeb, SuperAntiSpyware
Jeg vil gerne have, hvis nogen vil checke loggen fra disse 3 programmers logfiler:DrWeb- cureit
SuperAntiSpyware
HijackThis
Logfilerne kommer i nævnt rækkefølge her:
geeby.dll;c:\windows\system32;Trojan.Virtumod;Will be cured after reboot.;
grlyiwpy.dll;c:\windows\system32;Trojan.Virtumod;Deleted.;
xxywtst.dll;c:\windows\system32;Trojan.Virtumod;Will be cured after reboot.;
drsmartload.exe;C:\;Adware.DollarRevenue;Renamed.;
drsmartload45a45q.exe;C:\;Adware.DollarRevenue;Renamed.;
drsmartload45a45u.exe;C:\;Adware.DollarRevenue;Renamed.;
drsmartload45a45v.exe;C:\;Adware.DollarRevenue;Renamed.;
kybrdfg_7.exe;C:\;Trojan.DownLoader.11549;Deleted.;
mc44a34.exe;C:\;Adware.DollarRevenue;Renamed.;
mc44a38.exe;C:\;Adware.DollarRevenue;Renamed.;
mc44a39.exe;C:\;Adware.DollarRevenue;Renamed.;
nwnmff_e34.exe;C:\;Adware.DollarRevenue;Renamed.;
nwnmff_e38.exe;C:\;Adware.DollarRevenue;Renamed.;
UERSK_0001_N91M2407NetInstaller.exe;C:\Documents and Settings\Dennis\Lokale indstillinger\Temp\ICD1.tmp;Trojan.DownLoader.10963;Deleted.;
drsmartload44a[1].exe;C:\Documents and Settings\Dennis\Lokale indstillinger\Temporary Internet Files\Content.IE5\0DGHYVCT;Adware.DollarRevenue;Renamed.;
loader[1].exe;C:\Documents and Settings\Dennis\Lokale indstillinger\Temporary Internet Files\Content.IE5\9MGJ7DWP;Adware.DollarRevenue;Renamed.;
aw2.exe;C:\Documents and Settings\Helle;Trojan.Virtumod;Deleted.;
!update.exe;C:\Documents and Settings\Helle\Lokale indstillinger\Temp;Trojan.DownLoader.12196;Deleted.;
!update-4295[1].0000;C:\Documents and Settings\Helle\Lokale indstillinger\Temporary Internet Files\Content.IE5\815BVSHT;Trojan.DownLoader.12196;Deleted.;
aw2.exe;C:\Documents and Settings\Kinn;Trojan.Virtumod;Deleted.;
bb;C:\Documents and Settings\Kinn;Adware.DollarRevenue;Renamed.;
dotdr.exe;C:\Documents and Settings\Kinn;Adware.DollarRevenue;Renamed.;
drfix.exe;C:\Documents and Settings\Kinn;Adware.DollarRevenue;Renamed.;
drsmart.exe;C:\Documents and Settings\Kinn;Adware.DollarRevenue;Renamed.;
eeee.exe;C:\Documents and Settings\Kinn;Adware.DollarRevenue;Renamed.;
kthnx.exe;C:\Documents and Settings\Kinn;Adware.DollarRevenue;Renamed.;
skzeysnj.dll;C:\Documents and Settings\Kinn\Lokale indstillinger\Temp;Win32.HLLW.Toret;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\Documents and Settings\Kinn\Lokale indstillinger\Temp\ICD1.tmp;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\Documents and Settings\Kinn\Lokale indstillinger\Temp\ICD2.tmp;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\Documents and Settings\Kinn\Lokale indstillinger\Temp\ICD3.tmp;Trojan.DownLoader.10963;Deleted.;
UWA6PK_0001_N91M2107NetInstaller.exe;C:\Documents and Settings\Kinn\Lokale indstillinger\Temp\ICD4.tmp;Trojan.DownLoader.10963;Deleted.;
jeg kender en ho 32.wma;C:\Documents and Settings\Kinn\Shared;Trojan.Isbar.389;Deleted.;
printhook030.dll;C:\Programmer\PrintView;Adware.PrintView;Renamed.;
pvmodule.exe;C:\Programmer\PrintView;Adware.PrintView;Renamed.;
A0146761.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP36;BackDoor.HackDef.227;Deleted.;
A0148782.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP36;BackDoor.HackDef.227;Deleted.;
A0148985.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP36;BackDoor.HackDef.227;Deleted.;
A0150007.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP36;Adware.DollarRevenue;Renamed.;
A0152034.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP36;BackDoor.HackDef.227;Deleted.;
A0153714.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP37;BackDoor.HackDef.227;Deleted.;
A0153760.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP37;Adware.ClickSpring;Renamed.;
A0154887.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP38;BackDoor.HackDef.227;Deleted.;
A0154902.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP38;BackDoor.HackDef.227;Deleted.;
A0156732.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Trojan.DownLoader.6550;Deleted.;
A0158469.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0158497.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.DollarRevenue;Renamed.;
A0159142.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0159149.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.DollarRevenue;Renamed.;
A0159271.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0159295.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Trojan.DownLoader.10918;Deleted.;
A0160341.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.AddUrl;Renamed.;
A0160343.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160344.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160345.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160350.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160351.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160352.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160354.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160355.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;BackDoor.HackDef.227;Deleted.;
A0160380.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Trojan.Flood.22016;Deleted.;
A0160381.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Program.PsExec.131;Renamed.;
A0160386.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160387.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160388.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160389.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160390.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160391.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160392.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160393.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160394.dLL;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160395.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160396.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160397.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160398.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160399.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160400.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160401.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160402.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160403.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.ClickSpring;Renamed.;
A0160404.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160405.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160406.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160407.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.ClickSpring;Renamed.;
A0160408.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160409.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160410.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160411.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Trojan.Flood.22016;Deleted.;
A0160412.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160413.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160414.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160415.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160416.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160417.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160418.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160419.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160420.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160421.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160422.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160423.sys;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Tool.KnlKillp;Renamed.;
A0160424.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160425.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160426.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160428.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160429.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160430.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160431.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160432.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160433.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160434.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160435.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160436.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160437.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160438.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160439.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160440.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160441.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160442.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160443.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160444.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160445.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160446.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Tool.PassView;Renamed.;
A0160447.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160448.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;IRC.Flood;Deleted.;
A0160449.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160451.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160452.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.ClickSpring;Renamed.;
A0160453.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160454.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160455.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160456.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160457.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0160458.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0161270.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0161271.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Adware.Look2me;Renamed.;
A0162258.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Program.PrcView.3725;Renamed.;
A0162259.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP40;Tool.Dasniff;Renamed.;
A0174754.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP52;BackDoor.Wrag;Deleted.;
A0181828.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP57;Win32.HLLW.Toret;Deleted.;
A0183900.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP59;Trojan.Virtumod;Deleted.;
A0184934.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP60;BackDoor.IRC.Akbot;Deleted.;
A0184941.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP60;BackDoor.IRC.Akbot;Deleted.;
A0184942.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP60;Win32.HLLW.Toret;Deleted.;
A0187100.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP61;Adware.SearchColours;Renamed.;
A0202454.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Adware.DollarRevenue;Renamed.;
A0203543.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Adware.SearchColours;Renamed.;
A0204604.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Adware.DollarRevenue;Renamed.;
A0205768.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.MulDrop.3949;Deleted.;
A0205769.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Adware.DollarRevenue;Renamed.;
A0205771.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;BackDoor.IRC.Akbot;Deleted.;
A0205776.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;BackDoor.IRC.Akbot;Deleted.;
A0205778.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;BackDoor.Wrag;Deleted.;
A0205779.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205780.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205781.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205782.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205784.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205785.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205786.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205787.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.Spambot;Deleted.;
A0205846.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Program.mIRC.603;Renamed.;
A0205862.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.DownLoader.14336;Deleted.;
A0205864.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.DownLoader.5013;Deleted.;
A0205867.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.DownLoader.14123;Deleted.;
A0205871.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Adware.DollarRevenue;Renamed.;
A0205872.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Adware.DollarRevenue;Renamed.;
A0205873.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Trojan.DownLoader.14286;Deleted.;
A0205874.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP69;Adware.Look2me;Renamed.;
A0205950.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205951.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205952.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Trojan.Click.1452;Deleted.;
A0205953.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205954.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Trojan.Click.1474;Deleted.;
A0205955.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205956.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205957.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205958.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205959.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205961.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205962.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205963.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205964.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205965.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205966.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;BackDoor.IRC.Sdbot;Deleted.;
A0205968.exe\data001;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70\A0205968.exe;Program.PrcView.3725;;
A0205968.exe\data002;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70\A0205968.exe;Program.mIRC.603;;
A0205968.exe\data003;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70\A0205968.exe;Trojan.Flood.22016;;
A0205968.exe\data004;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70\A0205968.exe;Tool.KnlKillp;;
A0205968.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Archive contains infected objects;Moved.;
A0205969.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Trojan.Click.1336;Deleted.;
A0205970.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Trojan.StartPage.1565;Deleted.;
A0205971.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205973.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Trojan.DownLoader.12784;Deleted.;
A0205975.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205976.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205977.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205978.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205979.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205980.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205981.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205983.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205984.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205985.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205986.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205987.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205988.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205989.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205990.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205991.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.Softomate;Renamed.;
A0205992.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0205993.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP70;Adware.DollarRevenue;Renamed.;
A0206011.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Trojan.Virtumod;Deleted.;
A0206012.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206013.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206014.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206015.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206016.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Trojan.DownLoader.11549;Deleted.;
A0206017.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206018.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206019.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206020.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206021.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206022.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Trojan.Virtumod;Deleted.;
A0206023.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Trojan.Virtumod;Deleted.;
A0206024.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206025.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206026.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206027.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206028.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.DollarRevenue;Renamed.;
A0206029.dll;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.PrintView;Renamed.;
A0206030.exe;C:\System Volume Information\_restore{17A76738-C63A-449F-8E17-EC776A501A14}\RP71;Adware.PrintView;Renamed.;
A0039660.exe;C:\System Volume Information\_restore{D621A834-34B1-4ED4-944B-4B50C117242C}\RP154;Trojan.DownLoader.10918;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files;Trojan.DownLoader.10963;Deleted.;
UWA6PK_0001_N91M2107NetInstaller.exe;C:\WINDOWS\Downloaded Program Files;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.1;Trojan.DownLoader.10963;Deleted.;
UWA6PK_0001_N91M2107NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.1;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.2;Trojan.DownLoader.10963;Deleted.;
UWA6PK_0001_N91M2107NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.2;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.3;Trojan.DownLoader.10963;Deleted.;
UWA6PK_0001_N91M2107NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.3;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.4;Trojan.DownLoader.10963;Deleted.;
UWA6PK_0001_N91M2107NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.4;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.5;Trojan.DownLoader.10963;Deleted.;
UWA6PK_0001_N91M2107NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.5;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.6;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.7;Trojan.DownLoader.10963;Deleted.;
UERSK_0001_N91M2407NetInstaller.exe;C:\WINDOWS\Downloaded Program Files\CONFLICT.8;Trojan.DownLoader.10963;Deleted.;
abluuqjb.dll;C:\WINDOWS\system32;Trojan.Virtumod;Deleted.;
cbxvwtt.dll;C:\WINDOWS\system32;Trojan.Virtumod;Deleted.;
fskdrv.dll;C:\WINDOWS\system32;Win32.HLLW.Toret;Deleted.;
gebbayy.dll;C:\WINDOWS\system32;Trojan.Virtumod;Deleted.;
geeby.dll;C:\WINDOWS\system32;Trojan.Virtumod;Will be cured after reboot.;
jfovjssi.exe;C:\WINDOWS\system32;Adware.SearchColours;Renamed.;
mmjkpfvu.exe;C:\WINDOWS\system32;Adware.SearchColours;Renamed.;
mmuocmui.exe;C:\WINDOWS\system32;Adware.SearchColours;Renamed.;
ndklgyqa.dll;C:\WINDOWS\system32;Adware.Duncan;Renamed.;
nkpshlhw.exe;C:\WINDOWS\system32;Adware.SearchColours;Renamed.;
ssmobcjn.exe;C:\WINDOWS\system32;Adware.SearchColours;Renamed.;
ssqqqqn.dll;C:\WINDOWS\system32;Trojan.Virtumod;Deleted.;
vdwmgnpi.exe;C:\WINDOWS\system32;Trojan.DownLoader.12309;Deleted.;
wvuvvut.dll;C:\WINDOWS\system32;Trojan.Virtumod;Deleted.;
xxywtst.dll;C:\WINDOWS\system32;Trojan.Virtumod;Will be cured after reboot.;
drsmartload44a[1]_exe.vir;C:\WINDOWS\Temp\ASHeuristic;Adware.DollarRevenue;Renamed.;
fskdrv_dll.vir;C:\WINDOWS\Temp\ASHeuristic;Win32.HLLW.Toret;Deleted.;
geeby_dll.vir;C:\WINDOWS\Temp\ASHeuristic;Trojan.Virtumod;Deleted.;
isecur_dll.vir;C:\WINDOWS\Temp\ASHeuristic;Trojan.DownLoader.14370;;
mc44a38_exe.vir;C:\WINDOWS\Temp\ASHeuristic;Adware.DollarRevenue;Renamed.;
mc44a39_exe.vir;C:\WINDOWS\Temp\ASHeuristic;Adware.DollarRevenue;Renamed.;
___________________________________________________-
___________________________________________________
SUPERAntiSpyware Scan Log
Generated 10/27/2006 at 02:55 PM
Application Version : 3.3.1020
Core Rules Database Version : 3114
Trace Rules Database Version: 1139
Scan type : Complete Scan
Total Scan Time : 00:12:42
Memory items scanned : 193
Memory threats detected : 2
Registry items scanned : 3899
Registry threats detected : 102
File items scanned : 22758
File threats detected : 85
Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\GEEBY.DLL
C:\WINDOWS\SYSTEM32\GEEBY.DLL
HKLM\Software\Classes\CLSID\{7319CBF9-25BC-4C21-BAB6-8BDE892E1D0C}
HKCR\CLSID\{7319CBF9-25BC-4C21-BAB6-8BDE892E1D0C}
HKCR\CLSID\{7319CBF9-25BC-4C21-BAB6-8BDE892E1D0C}\InprocServer32
HKCR\CLSID\{7319CBF9-25BC-4C21-BAB6-8BDE892E1D0C}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7319CBF9-25BC-4C21-BAB6-8BDE892E1D0C}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\geeby
Trojan.Downloader-LargeInterest
C:\WINDOWS\SYSTEM32\XXYWTST.DLL
C:\WINDOWS\SYSTEM32\XXYWTST.DLL
HKLM\Software\Classes\CLSID\{8E6C490C-AAA7-4410-A1C7-FA769A4F305E}
HKCR\CLSID\{8E6C490C-AAA7-4410-A1C7-FA769A4F305E}
HKCR\CLSID\{8E6C490C-AAA7-4410-A1C7-FA769A4F305E}\InprocServer32
HKCR\CLSID\{8E6C490C-AAA7-4410-A1C7-FA769A4F305E}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E6C490C-AAA7-4410-A1C7-FA769A4F305E}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{8E6C490C-AAA7-4410-A1C7-FA769A4F305E}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\xxywtst
Trojan.WinSysBan
[keyboard] C:\\KYBRDFF_E39.EXE
C:\\KYBRDFF_E39.EXE
C:\DOCUMENTS AND SETTINGS\DENNIS\LOKALE INDSTILLINGER\TEMPORARY INTERNET FILES\CONTENT.IE5\A18ZQHE5\KYBRDFF_E[2].EXE
C:\KYBRDFF_E39.EXE
C:\KYBRDFG_8.EXE
Adware.Tracking Cookie
C:\Documents and Settings\Helle\Cookies\helle@partygaming.122.2o7[1].txt
C:\Documents and Settings\Helle\Cookies\helle@mediaplex[1].txt
C:\Documents and Settings\Helle\Cookies\helle@ad.yieldmanager[3].txt
C:\Documents and Settings\Helle\Cookies\helle@doubleclick[1].txt
C:\Documents and Settings\Helle\Cookies\helle@as-eu.falkag[2].txt
C:\Documents and Settings\Helle\Cookies\helle@tradedoubler[1].txt
C:\Documents and Settings\Helle\Cookies\helle@partypoker[2].txt
C:\Documents and Settings\Helle\Cookies\helle@www.globaladvertisingservices[1].txt
C:\Documents and Settings\Helle\Cookies\helle@adtech[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@ad.yieldmanager[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@admarketplace[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@ads.adnet-plus[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@ads.arto[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@bookspan.122.2o7[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@c.enhance[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@cassava[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@clicktorrent[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@cpvfeed[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@dk.winantivirus[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@http.edge.vru4[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@indexstats[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@interclick[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@kmpads[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@mysexy15x28-moms[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@partygaming.122.2o7[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@partypoker[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@secure.winantivirus[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@smileycentral[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@stats1.reliablestats[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@track.adform[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@winantivirus[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.admedian[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.adnet-plus[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.bannersandpopups[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.sexaben[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.sexgallerier[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.sexstreams[1].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.winantivirus[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@www.xctrk[2].txt
C:\Documents and Settings\Dennis\Cookies\dennis@yieldmanager[2].txt
C:\Documents and Settings\Helle\Cookies\helle@ad.yieldmanager[2].txt
Unclassified.Unknown Origin
HKCR\CLSID\{1DAEFCB9-06C8-47C6-8F20-3FB54B244DAA}
HKCR\CLSID\{1DAEFCB9-06C8-47C6-8F20-3FB54B244DAA}\InprocServer32
HKCR\CLSID\{1DAEFCB9-06C8-47C6-8F20-3FB54B244DAA}\InprocServer32#ThreadingModel
HKCR\CLSID\{849B9523-785F-4014-9CAF-079FB4A74C61}
HKCR\CLSID\{849B9523-785F-4014-9CAF-079FB4A74C61}\InprocServer32
HKCR\CLSID\{849B9523-785F-4014-9CAF-079FB4A74C61}\InprocServer32#ThreadingModel
HKCR\CLSID\{B7672BAF-E9A3-49B6-86B2-C81719A18A4C}
HKCR\CLSID\{B7672BAF-E9A3-49B6-86B2-C81719A18A4C}\InprocServer32
HKCR\CLSID\{B7672BAF-E9A3-49B6-86B2-C81719A18A4C}\InprocServer32#ThreadingModel
Trojan.WinAntiSpyware/WinAntiVirus 2006
HKCR\AppId\WinPGI.DLL
HKCR\AppId\WinPGI.DLL#AppID
C:\WINDOWS\system32\stera.job
Adware.SurfSideKick
C:\Documents and Settings\Helle\Application Data\Sskdmns.dll
C:\Documents and Settings\Helle\Application Data\Sskknwrd.dll
HKU\S-1-5-21-1482476501-583907252-682003330-1004\Software\Microsoft\Internet Explorer\URLSearchHooks#{02EE5B04-F144-47BB-83FB-A60BD91B74A9}
C:\DOCUMENTS AND SETTINGS\DENNIS\APPLICATION DATA\SSKKNWRD.DLL
Trojan.NetMon/DNSChange
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#Type
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#Start
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor#ObjectName
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Security
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\Network Monitor\Enum#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#DeviceDesc
Trojan.cmdService
HKLM\SYSTEM\CurrentControlSet\Services\cmdService
HKLM\SYSTEM\CurrentControlSet\Services\cmdService#Type
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#DeviceDesc
Adware.Avenue Media/Internet Optimizer
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
HKU\S-1-5-21-1482476501-583907252-682003330-1004\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
Adware.Toolbar888
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib
HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version
HKCR\MyToolBar.MyToolBarObj.1
HKCR\MyToolBar.MyToolBarObj.1\CLSID
HKLM\Software\Classes\MyToolBar.MyToolBarObj.1
HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID
Browser Hijacker.Internet Explorer Settings Hijack
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Search\SearchAssistant Explorer\Main#Default_Search_URL [ http://searchbar.findthewebsiteyouneed.com ]
HKU\S-1-5-21-1482476501-583907252-682003330-1004\Software\Microsoft\Internet Explorer\Search\SearchAssistant Explorer\Main#Default_Search_URL [ http://searchbar.findthewebsiteyouneed.com ]
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Search\SearchAssistant Explorer\Main#Default_Search_URL [ http://searchbar.findthewebsiteyouneed.com ]
Adware.ClickSpring/Yazzle
HKLM\Software\Snowball Wars
Adware.IPWins
HKU\S-1-5-21-1482476501-583907252-682003330-1004\Software\IpWins
Trojan.DollarRevenue
C:\WINDOWS\newname.dat
C:\WINDOWS\keyboard1.dat
Trojan.IRC/AIM Spread
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPOOLSVC212\0000#DeviceDesc
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212#Type
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212#Start
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212#ObjectName
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212\Security
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212\Enum
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\SpoolSvc212\Enum#NextInstance
Adware.VSToolbar
C:\Programmer\VSToolbar
C:\Documents and Settings\Helle\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Helle\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\Helle\Application Data\SearchToolbarCorp\Toolbar Vision
C:\Documents and Settings\Helle\Application Data\SearchToolbarCorp
Trojan.Defender1
C:\DFNDRFF_E39.EXE
C:\DOCUMENTS AND SETTINGS\DENNIS\LOKALE INDSTILLINGER\TEMPORARY INTERNET FILES\CONTENT.IE5\0B7JY8P5\DFNDRFF_E[1].EXE
C:\WINDOWS\PREFETCH\DFNDRFF_E24.EXE-2F2BEEA6.PF
C:\WINDOWS\PREFETCH\DFNDRFF_E28.EXE-04C54FC2.PF
C:\WINDOWS\PREFETCH\DFNDRFF_E29.EXE-0E9EC3E9.PF
C:\WINDOWS\PREFETCH\DFNDRFF_E31.EXE-251E3C79.PF
C:\WINDOWS\PREFETCH\DFNDRFF_E32.EXE-14AD51C7.PF
C:\WINDOWS\PREFETCH\DFNDRFF_E34.EXE-3B14CC5C.PF
TargetSaver, Inc. Process
C:\DOCUMENTS AND SETTINGS\DENNIS\LOKALE INDSTILLINGER\TEMP\GLFDGLFD.EXE
C:\WINDOWS\SYSTEM32\TSUNINST.EXE
Browser Hijacker.Deskbar
C:\DOCUMENTS AND SETTINGS\DENNIS\LOKALE INDSTILLINGER\TEMPORARY INTERNET FILES\CONTENT.IE5\0B7JY8P5\DESKBAR_E[1].EXE
Trojan.GimmySmilies
C:\DOCUMENTS AND SETTINGS\DENNIS\LOKALE INDSTILLINGER\TEMPORARY INTERNET FILES\CONTENT.IE5\0B7JY8P5\NWNMFF_E[1].EXE
C:\NWNMFF_E39.EXE
Adware.ClickSpring
C:\PROGRAMMER\COMMON FILES\PPPATC~1\SCANREGW.EXE
C:\Programmer\Common Files\MANTEC~1\OOLSV~1.EXE
C:\WINDOWS\system32\config\systemprofile\Application Data\DOBE~1\SCHOST~1.EXE
C:\WINDOWS\SYSTEM32\THKD.DLL
C:\WINDOWS\PPPATC~1\ARPA.EXE
Trojan.Unknown Origin
C:\PROGRAMMER\FæLLES FILER\{3889659E-0738-1030-0820-04110503002D}\SERVICES.DLL
C:\WINDOWS\UNINSTALL_NMON.VBS
Trojan.Downloader-DoWork
C:\WINDOWS\SYSTEM32\DEOKHTST.DLL
C:\WINDOWS\SYSTEM32\IFPHYMNA.DLL
C:\WINDOWS\SYSTEM32\QEUGVMME.DLL
Trojan.Downloader-VSToolbar
C:\WINDOWS\SYSTEM32\MMJKPFVU.#XE
C:\WINDOWS\SYSTEM32\NKPSHLHW.#XE
Adware.ClickSpring/PuritySCAN
C:\WINDOWS\SYSTEM32\WNSAPISV.EXE
Adware.ClickSpring/Resident
C:\WINDOWS\STEM~1\2CC.TMP
_________________________________________________________-
_________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 15:08:06, on 27-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Helle\Skrivebord\Rune\HijackThis\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ad.firstadsolution.com/rw?iframe3%3FBRUAALj6AABmZwEA04oAAAAAAAAAAP8AAAAGFAACAALaBAEAFdIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA%2DuEvIbe39z8AAAAAAAAAAEVYa4Xw8ABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA1w5BED21AAG2%2DOpbkfMYm%2Dg%2DLUwV4F0SG3xPQwAAAAA%3D%2C
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {6EEB5619-9D81-912D-868F-C56935FA8697} - C:\WINDOWS\system32\thkd.dll (file missing)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - (no file)
O2 - BHO: (no name) - {6EEB5619-9D81-912D-868F-C56935FA8697} - C:\WINDOWS\system32\thkd.dll (file missing)
O2 - BHO: (no name) - {7319CBF9-25BC-4C21-BAB6-8BDE892E1D0C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {8E6C490C-AAA7-4410-A1C7-FA769A4F305E} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152898032061
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152898828593
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: mljjgfd - mljjgfd.dll (file missing)
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\hrj2051oe.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Time Service (Time) - Unknown owner - C:\WINDOWS\System32\cjnr4r4ljbt.exe (file missing)
På forhånd tak.
