Ny logfil og loggen fra Ewido:
Logfile of HijackThis v1.99.1
Scan saved at 00:15:52, on 02-01-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Programmer\ewido\security suite\ewidoctrl.exe
H:\Programmer\ewido\security suite\ewidoguard.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\ZoneLabs\vsmon.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\SOUNDMAN.EXE
H:\Programmer\Real\RealPlayer\RealPlay.exe
H:\Programmer\QuickTime\qttask.exe
H:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
H:\Programmer\iTunes\iTunesHelper.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Programmer\Yahoo!\Messenger\ypager.exe
H:\Programmer\Skype\Phone\Skype.exe
H:\Programmer\iPod\bin\iPodService.exe
H:\WINDOWS\system32\wscntfy.exe
H:\Programmer\Internet Explorer\iexplore.exe
H:\Programmer\Internet Explorer\iexplore.exe
H:\Documents and Settings\christian\Skrivebord\hijackthis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.google.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RealTray] H:\Programmer\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "H:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "H:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] H:\Programmer\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] H:\Programmer\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [NBJ] "H:\Programmer\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Skype] "H:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Registration-Studio 8.lnk = H:\Programmer\Pinnacle\Studio 8\Register\RegTool.exe
O9 - Extra button: Adgangforalle.dk fjernbetjening - {0AD5A451-967F-46BD-9F5E-39247D7FC77F} - c:\AdgangForAlle\adgangforalle.exe (file missing)
O9 - Extra 'Tools' menuitem: Adgangforalle.dk fjernbetjening - {0AD5A451-967F-46BD-9F5E-39247D7FC77F} - c:\AdgangForAlle\adgangforalle.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: H:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/controls/msnchat45.cabO23 - Service: ewido security suite control - ewido networks - H:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - H:\Programmer\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - H:\WINDOWS\system32\ZoneLabs\vsmon.exe
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 00:02:30, 02-01-2006
+ Report-Checksum: 3384837
+ Scan result:
HKU\S-1-5-21-1757981266-1500820517-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8A0DCBDA-6E20-489C-9041-C1E8A0352E75} -> Spyware.NetNucleus : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@ads27.bpath[1].txt -> Spyware.Cookie.Bpath : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@adtech[1].txt -> Spyware.Cookie.Adtech : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter1.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter10.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter11.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter12.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter15.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter16.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter2.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter3.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter4.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter6.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter7.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter8.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@counter9.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@fuck-access[1].txt -> Spyware.Cookie.Fuck-access : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@hestia.sextrail.trakkerd[2].txt -> Spyware.Cookie.Trakkerd : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@hotlog[2].txt -> Spyware.Cookie.Hotlog : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@paycounter[1].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@sexlist[1].txt -> Spyware.Cookie.Sexlist : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@spylog[1].txt -> Spyware.Cookie.Spylog : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@stats3.porntrack[2].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@vip.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@xxxcounter[2].txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup
H:\Documents and Settings\christian\Cookies\christian@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
::Report End