Her er Ewido loggen:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:29:52 31-08-2006
+ Scan result:
C:\SWSetup\SYMNSC\02\LUREGWMI.EXE -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\16\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\37\LUREGWMI.EXE -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\AR\LUREGWMI.EXE -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\BR\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\CH\LUREGWMI.EXE -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\CS\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\DK\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\FI\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\FR\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\GK\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\GR\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\HU\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\IL\LUREGWMI.EXE -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\IT\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\JP\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\KR\LUREGWMI.EXE -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\NL\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\NO\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\PL\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\PT\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\RU\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\SE\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\SP\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\TR\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\TW\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\TZ\LURegWMI.exe -> Adware.Dm : No action taken.
C:\SWSetup\SYMNSC\US\LUREGWMI.EXE -> Adware.Dm : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@cz4.clickzs[1].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@cz7.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@cz8.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@tracking.g3x[1].txt -> TrackingCookie.G3x : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@komtrack[2].txt -> TrackingCookie.Komtrack : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@image.masterstats[1].txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@ads.planetactive[2].txt -> TrackingCookie.Planetactive : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@webstat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@free.wegcash[2].txt -> TrackingCookie.Wegcash : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@programs.wegcash[1].txt -> TrackingCookie.Wegcash : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@yadro[1].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Fona\Cookies\fona@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
::Report end
Og her er hijack loggen:
Logfile of HijackThis v1.99.1
Scan saved at 20:58:31, on 31-08-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Documents and Settings\Fona\Skrivebord\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q305&bd=pavilion&pf=laptopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.jubii.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.hp.comR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.hp.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ISUSScheduler] "c:\programmer\fælles filer\installshield\updateservice\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\FLLESF~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [!ewido] "C:\Programmer\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Send til &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmer\ewido anti-spyware 4.0\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programmer\HPQ\SHARED\HPQWMI.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe