Gider du lige at kigge på denne Spy Swweper log (begge scanninger er med)
10:27 : |··· Start of Session, 27. december 2004 ···|
10:27 : Spy Sweeper 3.5.0 (Build 189) started
10:27 : Updating spyware definitions
10:27 : There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
10:28 : Sweep initiated using definitions version 421
10:28 : Sweeping memory for threats.
10:28 : Memory sweep has completed. Elapsed time 00:00:18
10:28 : Registry sweep initiated.
10:28 : Found: 5 Altnet registry traces.
10:28 : Found: 4 CWS_NS3 registry traces.
10:28 : Found: 1 Web--search Hijacker registry traces.
10:28 : Found: 84 Cydoor registry traces.
10:28 : Found: 20 IstBar registry traces.
10:28 : Found: 1 PowerScan registry traces.
10:28 : Found: 4 Roings Search Enhancment registry traces.
10:28 : Registry sweep completed. Elapsed time 00:00:31
10:28 : Full sweep on all local drives initiated.
10:28 : Now sweeping drive C:
10:29 : Found Cookie: Mircx Cookie, version 1, c:\documents and settings\manderss\cookies\manderss@pop.mircx[1].txt
10:31 : Found: IwantSearch, version Version
10:31 : Found: Gator (GAIN), version 4.054
10:33 : Found Adware: Altnet, version 1, c:\documents and settings\michael andersson.ma\menuen start\programs\altnet\peer points manager.lnk
10:46 : Found Adware: CoolWebSearch (CWS), version 1, c:\windows\downloaded program files\webdlg32.inf
10:51 : Found Adware: Bullguard Popup Ad, version 3.3, c:\windows\temp\bullguard\bulldownload.exe
10:51 : Found: 30 file traces.
10:51 : Full Sweep has completed. Elapsed time 00:23:48
96.089 files swept
89 item traces located
10:52 : Removal process initiated
10:52 : Quarantining: Altnet
10:52 : Registry: HKEY_CLASSES_ROOT\clsid\{3646c2bd-3554-49ca-8125-44deefb881de}
10:52 : Registry: HKEY_CLASSES_ROOT\clsid\{3f4d4f88-0198-4921-b630-957f3eb814e0}
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run||altnetpointsmanager
10:52 : Registry: HKEY_CLASSES_ROOT\clsid\{3f4d4f88-0198-4921-b630-957f3eb814e0}||(-default-)
10:52 : Registry: HKEY_CLASSES_ROOT\clsid\{3646c2bd-3554-49ca-8125-44deefb881de}||(-default-)
10:52 : File: c:\documents and settings\michael andersson.ma\menuen start\programs\altnet\peer points manager.lnk
10:52 : Quarantining: Bullguard Popup Ad
10:52 : File: c:\windows\temp\bullguard\bulldownload.exe
10:52 : Quarantining: CoolWebSearch (CWS)
10:52 : File: c:\windows\downloaded program files\webdlg32.inf
10:52 : Quarantining: CWS_NS3
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/webdlg32.dll
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls||c:\windows\downloaded program files\webdlg32.dll
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/webdlg32.dll||.owner
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/webdlg32.dll||{0e1230f8-ea50-42a9-983c-d22abc2eed3b}
10:52 : Quarantining: Web--search Hijacker
10:52 : Registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\main||start page
10:52 : Quarantining: Cydoor
10:52 : Registry: HKEY_CURRENT_USER\software\cydoor
10:52 : Registry: HKEY_CURRENT_USER\software\cydoor services
10:52 : Registry: HKEY_USERS\WRSS_Profile_Default User\software\cydoor services
10:52 : Registry: HKEY_USERS\WRSS_Profile_Default User.WINDOWS\software\cydoor services
10:52 : Registry: HKEY_USERS\WRSS_Profile_LocalService\software\cydoor services
10:52 : Registry: HKEY_USERS\WRSS_Profile_man\software\cydoor services
10:52 : Registry: HKEY_USERS\WRSS_Profile_manderss\software\cydoor services
10:52 : Registry: HKEY_USERS\WRSS_Profile_NetworkService\software\cydoor services
10:52 : Registry: HKEY_USERS\WRSS_Profile_Default User\software\cydoor
10:52 : Registry: HKEY_USERS\WRSS_Profile_Default User.WINDOWS\software\cydoor
10:52 : Registry: HKEY_USERS\WRSS_Profile_LocalService\software\cydoor
10:52 : Registry: HKEY_USERS\WRSS_Profile_man\software\cydoor
10:52 : Registry: HKEY_USERS\WRSS_Profile_manderss\software\cydoor
10:52 : Registry: HKEY_USERS\WRSS_Profile_NetworkService\software\cydoor
10:52 : Quarantining: Gator (GAIN)
10:52 : Folder: c:\documents and settings\michael andersson.ma\lokale indstillinger\temp\fsg_tmp\accum
10:52 : Folder: c:\documents and settings\michael andersson.ma\lokale indstillinger\temp\fsg_tmp\accum\trickler
10:52 : Folder: c:\documents and settings\michael andersson.ma\lokale indstillinger\temp\fsg_tmp
10:52 : Quarantining: IstBar
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\flags
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\helpdir
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0\win32
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1||(-default-)
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\flags||(-default-)
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\helpdir||(-default-)
10:52 : Registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0\win32||(-default-)
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\flags
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\helpdir
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0\win32
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1||(-default-)
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\flags||(-default-)
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\helpdir||(-default-)
10:52 : Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0\win32||(-default-)
10:52 : Quarantining: IwantSearch
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\barlinks.ini
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\dating.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\dating1.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\desk.ini
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\finance.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\gambling.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\home.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\hot.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\kliksrch.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\links.ini
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\mortgages.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\pharmaci.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\pharmacy.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\poker.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\privacy1.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\realest.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\search.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\sport.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\spyware.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\switch.ico
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\toolbar.ini
10:52 : File: c:\documents and settings\michael andersson.ma\application data\sbsoft\travel1.ico
10:52 : Folder: c:\documents and settings\michael andersson.ma\application data\sbsoft
10:52 : Quarantining: Mircx Cookie
10:52 : Cookie: c:\documents and settings\manderss\cookies\manderss@pop.mircx[1].txt
10:52 : Quarantining: PowerScan
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main||bandrest
10:52 : Quarantining: Roings Search Enhancment
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mm21.ocx
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls||c:\windows\downloaded program files\mm21.ocx
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mm21.ocx||.owner
10:52 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mm21.ocx||{e0ce16cb-741c-4b24-8d04-a817856e07f4}
10:52 : Cleaning Traces
10:52 : Blasting registry: HKEY_USERS\WRSS_Profile_manderss\software\cydoor services
10:52 : Blasting registry: HKEY_USERS\WRSS_Profile_manderss\software\cydoor
10:52 : Removing registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\helpdir
10:52 : Removing registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\flags
10:52 : Removing registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0\win32
10:52 : Removing registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0
10:52 : Removing registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1
10:52 : Removing registry: HKEY_CLASSES_ROOT\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}
10:52 : Removing registry: HKEY_CLASSES_ROOT\clsid\{3f4d4f88-0198-4921-b630-957f3eb814e0}
10:52 : Removing registry: HKEY_CLASSES_ROOT\clsid\{3646c2bd-3554-49ca-8125-44deefb881de}
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls|| (c:\windows\downloaded program files\webdlg32.dll)
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls|| (c:\windows\downloaded program files\mm21.ocx)
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run|| (altnetpointsmanager)
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/webdlg32.dll
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/webdlg32.dll|| ({0e1230f8-ea50-42a9-983c-d22abc2eed3b})
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/webdlg32.dll|| (.owner)
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mm21.ocx
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mm21.ocx|| ({e0ce16cb-741c-4b24-8d04-a817856e07f4})
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mm21.ocx|| (.owner)
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main|| (bandrest)
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\helpdir
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\flags
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0\win32
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1\0
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}\1.1
10:52 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}
10:52 : Replacing registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\main|| (start page) || (
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
10:52 : Removing file: c:\documents and settings\manderss\cookies\manderss@pop.mircx[1].txt
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\travel1.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\toolbar.ini
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\switch.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\spyware.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\sport.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\search.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\realest.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\privacy1.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\poker.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\pharmacy.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\pharmaci.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\mortgages.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\links.ini
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\kliksrch.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\hot.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\home.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\gambling.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\finance.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\desk.ini
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\dating1.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\dating.ico
10:52 : Removing file: c:\documents and settings\michael andersson.ma\application data\sbsoft\barlinks.ini
10:52 : Removing file: c:\windows\downloaded program files\webdlg32.inf
10:52 : Removing file: c:\windows\temp\bullguard\bulldownload.exe
10:52 : Removing file: c:\documents and settings\michael andersson.ma\menuen start\programs\altnet\peer points manager.lnk
10:52 : Folder: c:\documents and settings\michael andersson.ma\lokale indstillinger\temp\fsg_tmp\accum\trickler
10:52 : Folder: c:\documents and settings\michael andersson.ma\lokale indstillinger\temp\fsg_tmp\accum
10:52 : Folder: c:\documents and settings\michael andersson.ma\lokale indstillinger\temp\fsg_tmp
10:52 : Folder: c:\documents and settings\michael andersson.ma\application data\sbsoft
10:53 : Removal process completed. Elapsed time 00:00:38
12 items (79 traces) quarantined.
10:57 : Internet Explorer Home Page has been re11:02 : |··· Start of Session, 27. december 2004 ···|
11:02 : Spy Sweeper 3.5.0 (Build 189) started
11:07 : Sweep initiated using definitions version 421
11:07 : Sweeping memory for threats.
11:07 : Memory sweep has completed. Elapsed time 00:00:08
11:07 : Registry sweep initiated.
11:08 : Found: 1 Altnet registry traces.
11:08 : Found: 1 Web--search Hijacker registry traces.
11:08 : Registry sweep completed. Elapsed time 00:00:20
11:08 : Full sweep on all local drives initiated.
11:08 : Now sweeping drive C:
11:23 : Found: 0 file traces.
11:23 : Full Sweep has completed. Elapsed time 00:15:23
95.824 files swept
2 item traces located
11:23 : Removal process initiated
11:23 : Quarantining: Altnet
11:23 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run||altnetpointsmanager
11:23 : Quarantining: Web--search Hijacker
11:23 : Registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\main||start page
11:23 : Cleaning Traces
11:23 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run|| (altnetpointsmanager)
11:23 : Replacing registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\main|| (start page) || (
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
11:23 : Removal process completed. Elapsed time 00:00:01
2 items (2 traces) quarantined.