OK, Mitor ingen virus fundet på dit swenlink
Fromsej, HAR kørt spybot, efter opdatering, genstartet og kørt hijack, her er loggen:
Logfile of HijackThis v1.97.2
Scan saved at 00:08:14, on 20-09-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Fælles filer\CMEII\CMESys.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\ISTsvc\istsvc.exe
C:\Programmer\PManager\PManager.exe
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Documents and Settings\Ralph\Application Data\aeoo.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Date Manager\DateManager.exe
C:\Programmer\Fælles filer\GMT\GMT.exe
C:\lotus\organize\easyclip6.exe
C:\Programmer\PrecisionTime\PrecisionTime.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\ByteGems.com\Sobig Virus Stopper\SobigStopper.exe
C:\Programmer\Bargain Buddy\bin\bargains.exe
C:\Documents and Settings\Ralph\Skrivebord\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.wflu.com/searchbar.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.wflu.com/searchbar.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dr.dk/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.wflu.com/searchbar.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://thko.com/passthrough/index.html?http://www.dr.dkR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.wflu.com/searchbar.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.wflu.com/searchbar.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://search.searchenhancement.com/nph-enhanced.cgi?affid=sesm&sstring=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.wflu.com/searchbar.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://search.searchenhancement.com/nph-enhanced.cgi?affid=sesm&sstring=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.dr.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
O1 - Hosts: 216.177.73.139 auto.search.msn.com
O1 - Hosts: 216.177.73.139 search.netscape.com
O1 - Hosts: 216.177.73.139 ieautosearch
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Programmer\Panicware\Pop-Up Stopper Pro\CCHelper.dll
O2 - BHO: Support Software - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Programmer\Support Software\SS2.DLL
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem214.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O2 - BHO: Url Catcher - {CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1} - C:\PROGRA~1\BARGAI~1\bin\apuc.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem213.dll
O2 - BHO: (no name) - {fbd1b244-25e0-4502-b84b-013a1fcdff99} - C:\DOCUME~1\Ralph\APPLIC~1\crhoovzwc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Programmer\Panicware\Pop-Up Stopper Pro\popuppro.dll
O3 - Toolbar: qeanvquiems - {b810419a-a392-4d88-bc92-57147e73a47c} - C:\DOCUME~1\Ralph\APPLIC~1\crhoovzwc.dll
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [CMESys] "C:\Programmer\Fælles filer\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [My Search Bar Eq] "C:\Program Files\MySearch\bar\s4bareq.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [winactive] C:\Programmer\Window Active\winactive.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Programmer\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKExe] c:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [IST Service] C:\Programmer\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Password Manager] "C:\Programmer\PManager\PManager.exe" /start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Crti] C:\Documents and Settings\Ralph\Application Data\aeoo.exe
O4 - HKCU\..\Run: [IDMan] C:\Programmer\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [KaZaA Download Accelerator] C:\Programmer\KaZaA Download Accelerator\kda.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: SobigVirusStopper.lnk = C:\Programmer\ByteGems.com\Sobig Virus Stopper\SobigStopper.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Date Manager.lnk = C:\Programmer\Date Manager\DateManager.exe
O4 - Global Startup: GStartup.lnk = ?
O4 - Global Startup: Lotus Organizer EasyClip.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PrecisionTime.lnk = C:\Programmer\PrecisionTime\PrecisionTime.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Download with IDM - C:\PROGRA~1\INTERN~2\IEExt.htm
O8 - Extra context menu item: Generate Password By Password Manager - C:\Programmer\PManager\PMGen.htm
O8 - Extra context menu item: Get Password From Password Manager - C:\Programmer\PManager\PMGet.htm
O8 - Extra context menu item: Save Password To Password Manager - C:\Programmer\PManager\PMSave.htm
O9 - Extra button: Web Entry (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cabO16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) -
http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cabO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) -
https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/vet_install_popup.pl?1&04.00.07.02&http://www.gameboyadvance.com/sp/vp/content.htmlO16 - DPF: {0D4312E2-5E4D-4A27-A9D8-043E43904277} -
http://www.warezoracle.com/xdownloader.exeO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/037c91d2f5cf42f79519/netzip/RdxIE601.cabO16 - DPF: {58F0B492-A42E-435A-BCBF-C6B2608077BA} -
http://imgfarm.com/images/nocache/mysearch/s4initialsetup1.0.0.3.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cabO16 - DPF: {92F02779-6D88-4958-8AD3-83C12D86ADC7} -
http://www.ursearch.com/toolbar/ursearch.cabO16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} -
http://www.warezhits.com/download.exeO16 - DPF: {AB1E62EB-3DE3-428F-A417-64AB3C9B6CF0} (eConn Class) -
http://econnect.libereco.net/econnect.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} (MoneyTree Dialer) -
http://xbs.climaxbucks.com/internet-optimizer/080703/UniDistIOcrack.CABO16 - DPF: {FC87A650-207D-4392-A6A1-82ADBC56FA64} (MultiDist) -
http://xbs.climaxbucks.com/internet-optimizer/080703/MultiDist.CABO16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} -
http://stat.trafficadvance.net/dialer/304438.exe