Så har jeg været igang.
Programmet
http://www.spywareinfo.dk/download/mwav.exe har jeg ikke kunnet få til at virke, det siger at min systemtid ikke er rigtig.:(
Ellers har jeg kørt ewido igennem og slettet det der nu var muligt og her er de forskellige logs:
Logfile of HijackThis v1.99.1
Scan saved at 10:03:36, on 23-07-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmer\VeriSign\NAVI\naviagent.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\ASUS\WLAN Card Utilities\Center.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Flemming\Skrivebord\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Control Center] C:\Programmer\ASUS\WLAN Card Utilities\Center.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English -
res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: i-Nav Hjælp - {CE000992-A58C-4441-8938-744CD72AB27F} -
http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: i-Nav Hjælp - {CE000992-A58C-4441-8938-744CD72AB27F} -
http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O9 - Extra 'Tools' menuitem: i-Nav Indstillinger - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) -
http://www.skylinesoft.com/interactive/TerraExplorer/Install/TEInstallPlugIn.cabO16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) -
http://www.geograf.com/viewer/mgaxctrl.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cabO20 - AppInit_DLLs: MsgPlusLoader.dll
O21 - SSODL: System - {A4D51B95-58D6-48EE-B7B7-D4F7E72F0EC0} - vr_sys.dll (file missing)
O21 - SSODL: FTP Voyager_is1 - {FF0DCF7A-C3D4-C992-536B-4EE7B28A794E} - c:\programmer\rhinosoft.com\ftp voyager\winhyzfk32.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: svchost.exe (moto) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: VeriSign Updater (navi) - VeriSign, Inc. - C:\Programmer\VeriSign\NAVI\naviagent.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 09:59:08, 23-07-2005
+ Report-Checksum: 15A67669
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{39DA2444-065F-47CB-B27C-CCB1A39C06B7} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DC341F1B-EC77-47BE-8F58-96E83861CC5A} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6DEEE498-08CC-43F0-BCA0-DBB5A25C9501} -> Spyware.SimpleBar : Cleaned with backup
HKLM\SOFTWARE\ClickSpring -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKU\S-1-5-21-515967899-492894223-1060284298-1003\Software\Classes\CLSID\{0656A137-B161-CADD-9777-E37A75727E78} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-515967899-492894223-1060284298-1003_Classes\CLSID\{0656A137-B161-CADD-9777-E37A75727E78} -> Dialer.Generic : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Flemming\Application Data\Mozilla\Firefox\Profiles\a11vgxpz.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Flemming\Cookies\flemming@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Flemming\Cookies\flemming@adtech[1].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\Flemming\Cookies\flemming@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\Flemming\Cookies\flemming@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Flemming\Cookies\flemming@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Flemming\Cookies\flemming@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\A1DQRMLO\backups\backup-20050723-085421-425.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\A1DQRMLO\MediaTicketsInstaller[1].cab/MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\GPIF670H\latest[1].exe -> Trojan.Crypt.c : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\GZIZAD6D\abc[1].exe -> TrojanSpy.LdPinch.os : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\LGKFPT4P\win32[1].exe -> TrojanDownloader.Small.agq : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\ONLVA2V9\MediaTicketsInstaller[1].cab/MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\ONLVA2V9\open[1].exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\Documents and Settings\Flemming\Lokale indstillinger\Temporary Internet Files\Content.IE5\SV2HWZ45\latest[1].exe -> Trojan.Crypt.c : Cleaned with backup
C:\Documents and Settings\Flemming\Skrivebord\Blandet\Adobe_Photoshop_CS_and_ImageReady_CS_Activation\aer.exe -> TrojanDownloader.INService.i : Cleaned with backup
C:\Documents and Settings\Flemming\Skrivebord\Blandet\Adobe_Photoshop_CS_and_ImageReady_CS_Activation.zip/aer.exe -> TrojanDownloader.INService.i : Cleaned with backup
C:\Documents and Settings\LocalService.NT AUTHORITY\Lokale indstillinger\Temporary Internet Files\Content.IE5\0JBC4WXP\loadppc[1].exe -> TrojanDropper.Small.abx : Cleaned with backup
C:\Documents and Settings\LocalService.NT AUTHORITY\Lokale indstillinger\Temporary Internet Files\Content.IE5\7WAZ1KO0\load02[1].exe -> TrojanDropper.Small.aad : Cleaned with backup
C:\Documents and Settings\Mette & Flemming\Cookies\mette & flemming@adtech[1].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\Mette & Flemming\Cookies\mette & flemming@counter1.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Mette & Flemming\Cookies\mette & flemming@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Mette & Flemming\Cookies\mette & flemming@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Mette & Flemming\Cookies\mette & flemming@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Mette & Flemming\Cookies\mette & flemming@sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Mette & Flemming\Cookies\mette & flemming@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Programmer\RhinoSoft.com\FTP Voyager\winhyzfk32.dll -> TrojanDownloader.Murlo.ar : Cleaned with backup
C:\RECYCLER\S-1-5-21-515967899-492894223-1060284298-1003\Dc1.exe -> Trojan.Crypt.c : Cleaned with backup
C:\RECYCLER\S-1-5-21-515967899-492894223-1060284298-1003\Dc2.exe -> TrojanDownloader.Small.agq : Cleaned with backup
C:\RECYCLER\S-1-5-21-515967899-492894223-1060284298-1003\Dc3.exe -> TrojanDownloader.PurityScan.w : Cleaned with backup
C:\RECYCLER\S-1-5-21-515967899-492894223-1060284298-1003\Dc5\optimize.exe -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\WINDOWS\svchost.exe -> TrojanDownloader.Agent.qx : Cleaned with backup
C:\WINDOWS\sys2816.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys2817.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys2818.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys287.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys288.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys289.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys5510.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys5511.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\sys5514.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\system32\3414990.exe -> TrojanDropper.Small.aad : Cleaned with backup
C:\WINDOWS\system32\abc.exe -> TrojanSpy.LdPinch.os : Cleaned with backup
C:\WINDOWS\system32\abirvalg32.dll -> TrojanProxy.Small.cn : Cleaned with backup
C:\WINDOWS\system32\cssrs.exe -> TrojanSpy.PdPinch : Cleaned with backup
C:\WINDOWS\system32\init32m.exe -> TrojanDownloader.Agent.ho : Cleaned with backup
C:\WINDOWS\system32\latest.exe -> Trojan.Crypt.c : Cleaned with backup
C:\WINDOWS\system32\maxd1.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\vxgame1.exe -> TrojanDropper.Small.acg : Cleaned with backup
C:\WINDOWS\system32\vxgame2.exe -> TrojanDownloader.Small.avt : Cleaned with backup
C:\WINDOWS\system32\vxgame3.exe -> TrojanDownloader.Agent.ho : Cleaned with backup
C:\WINDOWS\system32\vxgame4.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\vxgamet1.exe -> TrojanDropper.Small.aad : Cleaned with backup
C:\WINDOWS\system32\vxgamet2.exe -> Trojan.LowZones.y : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq1.exe -> TrojanDownloader.Agent.qx : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq5.exe -> TrojanDownloader.Small.awa : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq6.exe -> TrojanDownloader.Small.aux : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq7.exe -> TrojanDownloader.Small.atl : Cleaned with backup
C:\WINDOWS\system32\vxh8jkdq8.exe -> TrojanDownloader.Agent.qx : Cleaned with backup
C:\WINDOWS\system32\web.exe -> TrojanDownloader.Small.agq : Cleaned with backup
C:\WINDOWS\system32\~update.exe -> Trojan.Crypt.c : Cleaned with backup
C:\WINDOWS\vr_sys.dll -> TrojanSpy.LdPinch.os : Cleaned with backup
C:\WINDOWS\wsem303.dll -> TrojanDownloader.Dyfuca.dt : Cleaned with backup
::Report End