Så kom jeg lidt længere.....
Det viser sig at maskinen faktisk er på nettet HVER DAG, men kun på sygehusets
Den ryger så åbenbart med hjem og kommer på der også - selvom det er forbudt....
Nå videre...
FxSasser fandt INTET
En dybdescan med AVS fandt
Scan My Computer
----------------
Scanned: 105164
Detected: 19
Untreated: 0
Start time: 12-08-2007 09:09:21
Duration: 00:41:38
Finish time: 12-08-2007 09:50:59
Detected
--------
Status Object
------ ------
deleted: riskware not-a-virus:PSWTool.Win32.PassView.162 File: C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\RMV7ULDV\dfe8c48c35[1].jpeg
deleted: riskware not-a-virus:Client-IRC.Win32.mIRC.603 File: C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\RMV7ULDV\dfe8c48c35[1].jpeg/l4m3r.exe
deleted: riskware not-a-virus:NetTool.Win32.Sniffer.c File: C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\RMV7ULDV\dfe8c48c35[1].jpeg/lam2.exe
deleted: riskware not-a-virus:RiskTool.Win32.HideWindows File: C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\RMV7ULDV\dfe8c48c35[1].jpeg/lam3.exe/PE_Patch.PECompact/PecBundle/PECompact
deleted: riskware not-a-virus:RiskTool.Win32.HideWindows File: C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\RMV7ULDV\dfe8c48c35[1].jpeg/lam4.exe/UPX
deleted: riskware not-a-virus:PSWTool.Win32.PassView.162 File: C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\RMV7ULDV\dfe8c48c35[1].jpeg/lam5.exe/UPX
deleted: Trojan program Trojan.Win32.StartPage.aoi File: C:\Documents and Settings\Regina Eichhorst\Lokale indstillinger\Temporary Internet Files\Content.IE5\0DXLL321\hp[1].exe/PE_Patch
deleted: virus Net-Worm.Win32.Agent.f File: C:\WINDOWS\system32\a.exe
deleted: riskware not-a-virus:Client-IRC.Win32.mIRC.603 File: C:\WINDOWS\system32\fffssf.exe/l4m3r.exe
deleted: riskware not-a-virus:NetTool.Win32.Sniffer.c File: C:\WINDOWS\system32\fffssf.exe/lam2.exe
deleted: riskware not-a-virus:RiskTool.Win32.HideWindows File: C:\WINDOWS\system32\fffssf.exe/lam3.exe/PE_Patch.PECompact/PecBundle/PECompact
deleted: riskware not-a-virus:RiskTool.Win32.HideWindows File: C:\WINDOWS\system32\fffssf.exe/lam4.exe/UPX
deleted: riskware not-a-virus:PSWTool.Win32.PassView.162 File: C:\WINDOWS\system32\fffssf.exe/lam5.exe/UPX
deleted: virus Net-Worm.Win32.Agent.f File: C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Temporary Internet Files\Content.IE5\0DXLL321\edcv[1].jpeg
deleted: virus Net-Worm.Win32.Agent.f File: C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Temporary Internet Files\Content.IE5\0DXLL321\edcv[4].jpeg
deleted: virus Net-Worm.Win32.Agent.f File: C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Temporary Internet Files\Content.IE5\0DXLL321\edcv[5].jpeg
deleted: virus Net-Worm.Win32.Agent.f File: C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Temporary Internet Files\Content.IE5\0DXLL321\edcv[6].jpeg
deleted: Trojan program Trojan.Win32.StartPage.aoi File: C:\WINDOWS\system32\config\systemprofile\Lokale indstillinger\Temporary Internet Files\Content.IE5\SNNLX8WF\hp[1].exe/PE_Patch
deleted: riskware not-a-virus:PSWTool.Win32.PassView.162 File: C:\WINDOWS\system32\fffssf.exe
Events
------
Time Name Status Reason
---- ---- ------ ------
12-08-2007 09:09:21 Running module: smss.exe\smss.exe ok iChecker
12-08-2007 09:09:21 File: C:\WINDOWS\System32\smss.exe ok iSwift
12-08-2007 09:09:21 Running module: smss.exe\ntdll.dll ok iChecker
12-08-2007 09:09:21 File: C:\WINDOWS\System32\ntdll.dll ok iSwift
12-08-2007 09:09:21 Running module: csrss.exe\csrss.exe ok iChecker
12-08-2007 09:09:21 File: C:\WINDOWS\system32\csrss.exe ok iSwift
12-08-2007 09:09:21 Running module: csrss.exe\ntdll.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\ntdll.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\CSRSRV.dll ok scanned
12-08-2007 09:09:22 File: C:\WINDOWS\system32\CSRSRV.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\basesrv.dll ok scanned
12-08-2007 09:09:22 File: C:\WINDOWS\system32\basesrv.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\winsrv.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\winsrv.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\USER32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\USER32.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\KERNEL32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\KERNEL32.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\GDI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\GDI32.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\ADVAPI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\ADVAPI32.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\RPCRT4.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\RPCRT4.dll ok iSwift
12-08-2007 09:09:22 Running module: csrss.exe\sxs.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\sxs.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\winlogon.exe ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\winlogon.exe ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\ntdll.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\ntdll.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\kernel32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\kernel32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msvcrt.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\msvcrt.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\ADVAPI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\ADVAPI32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\RPCRT4.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\RPCRT4.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\GDI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\GDI32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\USER32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\USER32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\USERENV.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\USERENV.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\NDdeApi.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\NDdeApi.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\CRYPT32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\CRYPT32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\MSASN1.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\MSASN1.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\Secur32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\Secur32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WINSTA.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WINSTA.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\PROFMAP.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\PROFMAP.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\NETAPI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\NETAPI32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\REGAPI.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\REGAPI.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WS2_32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WS2_32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WS2HELP.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WS2HELP.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\AUTHZ.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\AUTHZ.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\PSAPI.DLL ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\PSAPI.DLL ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\VERSION.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\VERSION.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\SETUPAPI.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\SETUPAPI.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\MSGINA.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\MSGINA.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\SHELL32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\SHELL32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\SHLWAPI.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\SHLWAPI.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\COMCTL32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\COMCTL32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\ODBC32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\ODBC32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\comdlg32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\comdlg32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\comctl32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\odbcint.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\odbcint.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\SHSVCS.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\SHSVCS.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\sfc.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\sfc.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\sfc_os.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\sfc_os.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WINTRUST.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\WINTRUST.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\ole32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\ole32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\IMAGEHLP.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\IMAGEHLP.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WINSCARD.DLL ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\WINSCARD.DLL ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WTSAPI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\WTSAPI32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\sxs.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\sxs.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\uxtheme.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\uxtheme.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WINMM.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\WINMM.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\serwvdrv.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\serwvdrv.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\umdmxfrm.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\umdmxfrm.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\cscdll.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\cscdll.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\klogon.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\klogon.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\OLEAUT32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\OLEAUT32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WlNotify.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WlNotify.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WINSPOOL.DRV ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\WINSPOOL.DRV ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\MPR.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\MPR.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\rsaenh.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\rsaenh.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\asycfilt.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\asycfilt.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\SAMLIB.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\SAMLIB.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\cscui.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\cscui.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\NTMARTA.DLL ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\NTMARTA.DLL ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\WLDAP32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WLDAP32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msv1_0.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\msv1_0.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\wdmaud.drv ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\wdmaud.drv ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msacm32.drv ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\msacm32.drv ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\MSACM32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\MSACM32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\midimap.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\midimap.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\imaadp32.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\imaadp32.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msadp32.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\msadp32.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msg711.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\msg711.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msgsm32.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\msgsm32.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\tssoft32.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\tssoft32.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\tsd32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\tsd32.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msg723.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\msg723.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\msaud32.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\msaud32.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\sl_anet.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\sl_anet.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\l3codeca.acm ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\l3codeca.acm ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\COMRes.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\COMRes.dll ok iSwift
12-08-2007 09:09:22 Running module: winlogon.exe\CLBCATQ.DLL ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\CLBCATQ.DLL ok iSwift
12-08-2007 09:09:22 Running module: services.exe\services.exe ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\services.exe ok iSwift
12-08-2007 09:09:22 Running module: services.exe\ntdll.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\ntdll.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\kernel32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\kernel32.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\msvcrt.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\msvcrt.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\ADVAPI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\ADVAPI32.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\RPCRT4.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\RPCRT4.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\USER32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\USER32.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\GDI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\GDI32.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\USERENV.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\USERENV.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\SCESRV.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\SCESRV.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\AUTHZ.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\AUTHZ.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\umpnpmgr.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\umpnpmgr.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\WINSTA.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WINSTA.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\NCObjAPI.DLL ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\NCObjAPI.DLL ok iSwift
12-08-2007 09:09:22 Running module: services.exe\secur32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\secur32.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\eventlog.dll ok scanned
12-08-2007 09:09:22 File: C:\WINDOWS\system32\eventlog.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\WS2_32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WS2_32.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\WS2HELP.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\WS2HELP.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\PSAPI.DLL ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\PSAPI.DLL ok iSwift
12-08-2007 09:09:22 Running module: services.exe\wtsapi32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\wtsapi32.dll ok iSwift
12-08-2007 09:09:22 Running module: services.exe\netapi32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\netapi32.dll ok iSwift
12-08-2007 09:09:22 Running module: lsass.exe\lsass.exe ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\lsass.exe ok iSwift
12-08-2007 09:09:22 Running module: lsass.exe\ntdll.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\System32\ntdll.dll ok iSwift
12-08-2007 09:09:22 Running module: lsass.exe\kernel32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\kernel32.dll ok iSwift
12-08-2007 09:09:22 Running module: lsass.exe\ADVAPI32.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\ADVAPI32.dll ok iSwift
12-08-2007 09:09:22 Running module: lsass.exe\RPCRT4.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\RPCRT4.dll ok iSwift
12-08-2007 09:09:22 Running module: lsass.exe\LSASRV.dll ok iChecker
12-08-2007 09:09:22 File: C:\WINDOWS\system32\LSASRV.dll ok iSwift
12-08-2007 09:09:23 Running module: lsass.exe\msvcrt.dll ok iChecker
12-08-2007 09:09:23 File: C:\WINDOWS\system32\msvcrt.dll ok iSwift
12-08-2007 09:09:23 Running module: lsass.exe\Secur32.dll ok iChecker
12-08-2007 09:09:23 File: C:\WINDOWS\system32\Secur32.dll ok iSwift
Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archived Compressed Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ---------- ------------------ ---------
Total 105164 17 17 0 0 2355 497 0 7
System Memory 2130 0 0 0 0 0 0 0 0
Startup Objects 1830 0 0 0 0 0 0 0 0
System Restore 1 0 0 0 0 0 0 0 0
Mailboxes 425 0 0 0 0 181 0 0 0
All Hard Drives 100778 17 17 0 0 2174 497 0 7
All Removable Drives 0 0 0 0 0 0 0 0 0
Settings
--------
Name Value
---- -----
Security Level Recommended
Action Prompt for action when the scan is complete
File types All
Scan new and changed files only No
Scan archives All
Scan embedded OLE objects All
Skip if object is greater than No
Skip if scan takes longer than No
Parse e-mail formats No
Scan password-protected archives No
Enable iChecker technology Yes
Enable iSwift technology Yes
Show detected threats on "Detected" tab Yes
En ny efter sletning fandt INTET
Her en hjacklog
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:59:23, on 12-08-2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\tools\Active Virus Shield\avp.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programmer\Ahead\InCD\InCD.exe
C:\Programmer\QuickTime\qttask.exe
C:\tools\Active Virus Shield\avp.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Cordless USB Phone\Cordless DUALphone Suite.exe
C:\Programmer\Microsoft Office\Office\OUTLOOK.EXE
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\dllcache\winsony.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Skype\Plugin Manager\skypePM.exe
C:\Programmer\HJTrenamed.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.tvinfo.de/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [VOBID] C:\Programmer\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [IW ControlCenter] C:\Programmer\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Programmer\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Wind0ws Ser7ice Agent] colwindos.exe
O4 - HKLM\..\Run: [aol] "C:\tools\Active Virus Shield\avp.exe"
O4 - HKLM\..\RunServices: [Wind0ws Ser7ice Agent] colwindos.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Wind0ws Ser7ice Agent] colwindos.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cordless DUALphone opstart.lnk = C:\Programmer\Cordless USB Phone\Cordless DUALphone Suite.exe
O4 - Global Startup: Kalender.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O23 - Service: Active Virus Shield (AVP) - AOL - C:\tools\Active Virus Shield\avp.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony Network Analysis Tool - Unknown owner - C:\WINDOWS\System32\dllcache\winsony.exe
--
End of file - 5151 bytes
Tør jeg håbe den er REN