This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I need help! Removed spyware--> slow pc

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi folks - I really need your help.

At first I found that I had got some spyware on my pc. TrendMicro ATV found something everytime I acced the internet - and pop-ups started coming up. I read a lot of your very helpfull instructions and I think I have removed it all now with the help of AntiVir XP (antivirus and spyware) and AdAware SE. TrendMicro never found anything!
- but the process deleted a lot of Windows files, as they couldent be cleaned.

I succesfully removed it all from booting in secure mode and running both AntiVir and Adaware 2 times.
BUT - my system takes now 15-20 seconds everytime I do something new. Opening a mail takes 18 sec. and just opening a filefolder takes 15 sec. Nothing is running and taking up power… and still I have a 15sec total break with nothing happening. Nothing at all!
Pls. help… What do I need to do or what might be missing on my system?

Hijack found:
Logfile of HijackThis v1.99.1
Scan saved at 00:39:53, on 28-07-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\AVPersonal\AVGUARD.EXE
C:\Programmer\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\basfipm.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\JW2BF.EXE
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\PROGRA~1\FÆLLES~1\PCSuite\Services\SERVIC~1.EXE
C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\PROGRA~1\FÆLLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\stidos\LOKALE~1\Temp\Midlertidig mappe 1 for hijackthis.zip\HijackThis.exe
C:\Programmer\Outlook Express\msimn.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://My.Gunnebo.NET
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://My.Gunnebo.NET
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Gunnebo.NET
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://segboprx01.gunnebo.net:8080;https=http://segboprx01.gunnebo.net:8080;ftp=http://segboprx01.gunnebo.net:8080;gopher=http://segboprx01.gunnebo.net:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.gunnebo.net;128.5.84.160;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [HPWJTOOLBOX] C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe "-i"
O4 - HKLM\..\Run: [mfcmr.exe] C:\WINDOWS\system32\mfcmr.exe
O4 - HKLM\..\Run: [sysym32.exe] C:\WINDOWS\system32\sysym32.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Programmer\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Programmer\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://My.Gunnebo.NET
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122499746406
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gunnebo.net
O17 - HKLM\Software\..\Telephony: DomainName = gunnebo.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gunnebo.net
O20 - Winlogon Notify: IntelWireless - C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programmer\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programmer\AVPersonal\AVWUPSRV.EXE
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe

Hope that someone out there will find the time to offer me some assistance.

Regards, Stig Døssing
Hi and welcome to the forum. :D

Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/downloadget.php?…7fd6b3ff02edc90

REBOOT

Step #2

Please download and run Spybot 1.4 & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Then do a virus scan here >>> Trend Micro

Reboot and post a new HiJackThis log.
Dear Siggyx. Thanks a lot so far… :P
I have followed your instructions exactly and the results where:
CWShredder: Found nothing
Spybot: Found "DoubleClick" and "MediaPlex". Both removed
AdAware: Found 3 cookies - removed
Virusscan: Found nothing

My pc is still very-very slow. :scratch: It seems like everytime I do something on it, like opening a filefolder, browser, new mail, excel sheet or anything - or start a new function within a program like excel, - all stops for 10-15 seconds.
This also means that the startup takes like 5 minutes, as it will hold for 10-15 seconds before starting any new process.
(It's by the way a new DELL Latitude D810 with 512MB ram)

:oops: I really don't know what to do and would appriciate any help :oops:

Regards Stig
Hijackthis found:
Logfile of HijackThis v1.99.1
Scan saved at 14:51:17, on 28-07-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\AVPersonal\AVGUARD.EXE
C:\Programmer\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\basfipm.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\RO51E8.EXE
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\AVPersonal\AVGNT.EXE
C:\PROGRA~1\FÆLLES~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\FÆLLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Programmer\Microsoft Office\Office10\OUTLOOK.EXE
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Microsoft Office\Office10\WINWORD.EXE
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Install\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://My.Gunnebo.NET
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://My.Gunnebo.NET
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Gunnebo.NET
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://segboprx01.gunnebo.net:8080;https=http://segboprx01.gunnebo.net:8080;ftp=http://segboprx01.gunnebo.net:8080;gopher=http://segboprx01.gunnebo.net:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.gunnebo.net;128.5.84.160;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [HPWJTOOLBOX] C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe "-i"
O4 - HKLM\..\Run: [mfcmr.exe] C:\WINDOWS\system32\mfcmr.exe
O4 - HKLM\..\Run: [sysym32.exe] C:\WINDOWS\system32\sysym32.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Programmer\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://My.Gunnebo.NET
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122499746406
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gunnebo.net
O17 - HKLM\Software\..\Telephony: DomainName = gunnebo.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gunnebo.net
O20 - Winlogon Notify: IntelWireless - C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programmer\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programmer\AVPersonal\AVWUPSRV.EXE
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
Waiting for someone to reply to my cry for help, I was reading some other threads in this forum. One of them has as a final conclusion that one should always remember to have an active antivirus program - and updated…
Hmm - yes I know!

- but it also stated that you ONLY should have ONE ATV program running… - and suddenly it stroke me that I during all the panic for removing virus and stuff, I downloaded and installed several anti virus- and spyware programs. - and and…

Now I have uninstalled the ekstra antivirus program - AND YPPIEEEE :P
- it seems like I have been getting speed back on my pc.

Anyway - I would still appriciate someone to take a look on the above Hijack log - just to make sure that it all looks as it should.

So - thanks a lot for your help.
/Stig B)
Scan with hijackthis and put a check beside these lines and choose FIX R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) O4 - HKLM\..\Run: [mfcmr.exe] C:\WINDOWS\system32\mfcmr.exe O4 - HKLM\..\Run: [sysym32.exe] C:\WINDOWS\system32\sysym32.exe Then reboot and post a new log please.
Hi Siggyx.

Really appriciate your help!

Here are my HJT log.

Regards, Stig
Denmark
————————–
Logfile of HijackThis v1.99.1
Scan saved at 09:20:21, on 29-07-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\basfipm.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\OS29FC.EXE
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe
C:\Programmer\Apoint\Apntex.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\FÆLLES~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\FÆLLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Install\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.computerworld.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://My.Gunnebo.NET
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Gunnebo.NET
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://segboprx01.gunnebo.net:8080;https=http://segboprx01.gunnebo.net:8080;ftp=http://segboprx01.gunnebo.net:8080;gopher=http://segboprx01.gunnebo.net:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.gunnebo.net;128.5.84.160;
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [HPWJTOOLBOX] C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe "-i"
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://My.Gunnebo.NET
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122499746406
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gunnebo.net
O17 - HKLM\Software\..\Telephony: DomainName = gunnebo.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gunnebo.net
O20 - Winlogon Notify: IntelWireless - C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
I just recieved a message from Microsoft Antispyware (recident) that CWS was trying to install it self again. It was removed - and I run a scan with the same program.
After that I have started a scan with Ad-Aware SE - and it found new 7 critical objects…
Log here:
Ad-Aware SE Build 1.06r1
Logfile Created on:29. juli 2005 14:49:08
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R58 28.07.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie(TAC index:3):7 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R57 26.07.2005
Internal build : 67
File location : C:\Programmer\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 503962 Bytes
Total size : 1519153 Bytes
Signature data size : 1486585 Bytes
Reference data size : 32056 Bytes
Signatures total : 42350
CSI Fingerprints total : 982
CSI data size : 34567 Bytes
Target categories : 15
Target families : 720

29-07-2005 14:41:48 Performing WebUpdate…

Installing Update…
Definitions File Loaded:
Reference Number : SE1R58 28.07.2005
Internal build : 68
File location : C:\Programmer\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 504264 Bytes
Total size : 1520233 Bytes
Signature data size : 1487665 Bytes
Reference data size : 32056 Bytes
Signatures total : 42386
CSI Fingerprints total : 982
CSI data size : 34567 Bytes
Target categories : 15
Target families : 720


29-07-2005 14:42:19 Success
Update successfully downloaded and installed.


Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Non Intel
Memory available:42 %
Total physical memory:523664 kb
Available physical memory:216196 kb
Total page file size:1276496 kb
Available on page file:900376 kb
Total virtual memory:2097024 kb
Available virtual memory:2023764 kb
OS:Microsoft Windows XP Professional Service Pack 2 (Build 2600)

Ad-Aware SE Settings
===========================
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Don't log streams smaller than 0 Bytes
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


29-07-2005 14:49:08 - Scan started. (Full System Scan)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 1148
ThreadCreationTime : 29-07-2005 07:16:03
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 1244
ThreadCreationTime : 29-07-2005 07:16:05
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 1268
ThreadCreationTime : 29-07-2005 07:16:07
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1312
ThreadCreationTime : 29-07-2005 07:16:07
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Tjenester og controllerprogrammer
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1324
ThreadCreationTime : 29-07-2005 07:16:07
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1528
ThreadCreationTime : 29-07-2005 07:16:08
BasePriority : Normal
FileVersion : 6.14.10.4107
ProductVersion : 6.14.10.4107.05
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1540
ThreadCreationTime : 29-07-2005 07:16:08
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1612
ThreadCreationTime : 29-07-2005 07:16:08
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1752
ThreadCreationTime : 29-07-2005 07:16:08
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [evteng.exe]
FilePath : C:\Programmer\Intel\Wireless\Bin\
ProcessID : 1788
ThreadCreationTime : 29-07-2005 07:16:08
BasePriority : Normal
FileVersion : 9, 0, 1, 12
ProductVersion : 9, 0, 0, 0
ProductName : EvtEng Module
CompanyName : Intel Corporation
FileDescription : EvtEng Module
InternalName : EvtEng
LegalCopyright : Copyright © Intel Corporation 1999-2004
OriginalFilename : EvtEng.EXE

#:11 [s24evmon.exe]
FilePath : C:\Programmer\Intel\Wireless\Bin\
ProcessID : 1872
ThreadCreationTime : 29-07-2005 07:16:08
BasePriority : Normal
FileVersion : 9, 0, 1, 41
ProductVersion : 9, 0, 0, 0
ProductName : Mobile Unit Support Service
CompanyName : Intel Corporation
FileDescription : Event Monitor - Supports driver extensions to NIC Driver for wireless adapters.
InternalName : S24EvMon
LegalCopyright : Copyright © Intel Corporation 1999-2004
OriginalFilename : S24EvMon.exe

#:12 [wlkeeper.exe]
FilePath : C:\Programmer\Intel\Wireless\Bin\
ProcessID : 1900
ThreadCreationTime : 29-07-2005 07:16:08
BasePriority : Normal
FileVersion : 9, 0, 1, 14
ProductVersion : 1, 0, 0, 1
ProductName : SSOFSet Service
CompanyName : Intel® Corporation
FileDescription : WLKEEPER
InternalName : WLKEEPER
LegalCopyright : Copyright © 2004
OriginalFilename : WLKEEPER.exe

#:13 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1956
ThreadCreationTime : 29-07-2005 07:16:09
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:14 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 296
ThreadCreationTime : 29-07-2005 07:16:09
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:15 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 740
ThreadCreationTime : 29-07-2005 07:16:09
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:16 [scardsvr.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 776
ThreadCreationTime : 29-07-2005 07:16:09
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Server til styring af chipkortets ressourcer
InternalName : SCardSvr.exe
LegalCopyright : © Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : SCardSvr.exe

#:17 [basfipm.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 476
ThreadCreationTime : 29-07-2005 07:16:16
BasePriority : Normal
FileVersion : 6.0.4
ProductVersion : 6.0.4
ProductName : Broadcom ASF IP monitoring service
CompanyName : Broadcom Corp.
FileDescription : Broadcom ASF IP monitoring service
InternalName : BAsfIpM
LegalCopyright : Copyright © 2004 Broadcom Corporation, All Rights Reserved
OriginalFilename : BAsfIpM.EXE

#:18 [mdm.exe]
FilePath : C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\
ProcessID : 556
ThreadCreationTime : 29-07-2005 07:16:16
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright © Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe

#:19 [nicconfigsvc.exe]
FilePath : C:\Programmer\Dell\NICCONFIGSVC\
ProcessID : 588
ThreadCreationTime : 29-07-2005 07:16:16
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : NicConfigSvc
CompanyName : Dell Inc.
FileDescription : Internal Network Card Power Management Service
InternalName : TestMFCAppWiz
LegalCopyright : Copyright © 2004 Dell Inc.
OriginalFilename : NicConfigSvc.EXE

#:20 [ntrtscan.exe]
FilePath : C:\Programmer\Trend Micro\OfficeScan Client\
ProcessID : 676
ThreadCreationTime : 29-07-2005 07:16:16
BasePriority : Normal
FileVersion : 7.0.0.1040
ProductVersion : 7.0
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
FileDescription : Ntrtscan.exe
LegalCopyright : Copyright © 1999-2005 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.

#:21 [regsrvc.exe]
FilePath : C:\Programmer\Intel\Wireless\Bin\
ProcessID : 1056
ThreadCreationTime : 29-07-2005 07:16:16
BasePriority : Normal
FileVersion : 9, 0, 1, 10
ProductVersion : 9, 0, 0, 0
ProductName : RegSrvc Module
CompanyName : Intel Corporation
FileDescription : RegSrvc Module
InternalName : RegSrvc
LegalCopyright : Copyright © Intel Corporation 1999-2004
OriginalFilename : RegSrvc.EXE
Comments : Registry Interface for Intel Wireless Products

#:22 [tmlisten.exe]
FilePath : C:\Programmer\Trend Micro\OfficeScan Client\
ProcessID : 1100
ThreadCreationTime : 29-07-2005 07:16:16
BasePriority : Normal
FileVersion : 7.0.0.1040
ProductVersion : 7.0
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
LegalCopyright : Copyright © 1999-2005 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.

#:23 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1228
ThreadCreationTime : 29-07-2005 07:16:17
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:24 [ofcpfwsvc.exe]
FilePath : C:\Programmer\Trend Micro\OfficeScan Client\
ProcessID : 1848
ThreadCreationTime : 29-07-2005 07:16:17
BasePriority : Normal
FileVersion : 7.0.0.1040
ProductVersion : 7.0
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
FileDescription : OfcPfwSvc
InternalName : OfcPfwSvc
LegalCopyright : Copyright © 1999-2005 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.
OriginalFilename : OfcPfwSvc.exe
Comments : OFC PFW Service

#:25 [wmiprvse.exe]
FilePath : C:\WINDOWS\system32\wbem\
ProcessID : 468
ThreadCreationTime : 29-07-2005 07:16:17
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : WMI
InternalName : Wmiprvse.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : Wmiprvse.exe

#:26 [os29fc.exe]
FilePath : C:\WINDOWS\TEMP\
ProcessID : 2068
ThreadCreationTime : 29-07-2005 07:16:23
BasePriority : Normal


#:27 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2196
ThreadCreationTime : 29-07-2005 07:16:23
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:28 [zcfgsvc.exe]
FilePath : C:\Programmer\Intel\Wireless\Bin\
ProcessID : 2416
ThreadCreationTime : 29-07-2005 07:16:25
BasePriority : Normal
FileVersion : 9, 0, 1, 45
ProductVersion : 1, 0, 0, 2
ProductName : ZeroCfgSvc Application
CompanyName : Intel Corporation
FileDescription : ZeroCfgSvc MFC Application
InternalName : ZeroCfgSvc
LegalCopyright : Copyright © Intel Corporation 1999-2004
OriginalFilename : ZeroCfgSvc.EXE

#:29 [1xconfig.exe]
FilePath : C:\PROGRA~1\Intel\Wireless\Bin\
ProcessID : 2752
ThreadCreationTime : 29-07-2005 07:16:27
BasePriority : Normal
FileVersion : 9, 0, 1, 33
ProductVersion : 9, 0, 0, 0
ProductName : 8021XConfig Module
CompanyName : Intel
FileDescription : 8021XConfig Module
InternalName : 8021XConfig
LegalCopyright : Copyright © Intel Corporation 1999-2004
OriginalFilename : 1XConfig.EXE
Comments : Wrapper for MH. (Service COM)

#:30 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3308
ThreadCreationTime : 29-07-2005 07:16:29
BasePriority : Normal
FileVersion : 6.14.10.4107
ProductVersion : 6.14.10.4107.05
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE

#:31 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 3828
ThreadCreationTime : 29-07-2005 07:16:32
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Windows Stifinder
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : EXPLORER.EXE

#:32 [apoint.exe]
FilePath : C:\Programmer\Apoint\
ProcessID : 1928
ThreadCreationTime : 29-07-2005 07:16:34
BasePriority : Normal
FileVersion : 5.5.101.141
ProductVersion : 5.5.101.141
ProductName : Alps Pointing-device Driver
CompanyName : Alps Electric Co., Ltd.
FileDescription : Alps Pointing-device Driver
InternalName : Alps Pointing-device Driver
LegalCopyright : Copyright © 1999-2004 Alps Electric Co., Ltd.
OriginalFilename : Apoint.exe

#:33 [atiptaxx.exe]
FilePath : C:\Programmer\ATI Technologies\ATI Control Panel\
ProcessID : 1068
ThreadCreationTime : 29-07-2005 07:16:35
BasePriority : Normal
FileVersion : 6.14.10.5125
ProductVersion : 6.14.10.5125
ProductName : ATI Desktop Component
CompanyName : ATI Technologies, Inc.
FileDescription : ATI Desktop Control Panel
InternalName : Atiptaxx.exe
LegalCopyright : Copyright © 1998-2004 ATI Technologies Inc.
OriginalFilename : Atiptaxx.exe

#:34 [ifrmewrk.exe]
FilePath : C:\Programmer\Intel\Wireless\Bin\
ProcessID : 2008
ThreadCreationTime : 29-07-2005 07:16:35
BasePriority : Normal
FileVersion : 9, 0, 1, 19
ProductVersion : 9, 0, 0, 0
ProductName : Intel PROSet/Wireless
CompanyName : Intel Corporation
FileDescription : Intel Framework MFC Application
InternalName : Framework
LegalCopyright : Copyright © Intel Corporation 1999-2004
OriginalFilename : iFramewrk.exe

#:35 [quickset.exe]
FilePath : C:\Programmer\Dell\QuickSet\
ProcessID : 1992
ThreadCreationTime : 29-07-2005 07:16:37
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : QuickSet Application
FileDescription : QuickSet MFC Application
InternalName : direct
LegalCopyright : Copyright © 2001
OriginalFilename : direct.EXE

#:36 [dvdlauncher.exe]
FilePath : C:\Programmer\r\CyberLink\PowerDVD\
ProcessID : 1980
ThreadCreationTime : 29-07-2005 07:16:38
BasePriority : Normal
FileVersion : 3.00.0000
ProductVersion : 3.00.0000
ProductName : Cyberlink PowerCinema 3.0
CompanyName : CyberLink Corp.
FileDescription : CyberLink PowerCinema Resident Program
InternalName : CyberLink PowerCinema Resident Program
LegalCopyright : Copyright © 2003 CyberLink Corp.
OriginalFilename : DVDLauncher.EXE

#:37 [apntex.exe]
FilePath : C:\Programmer\Apoint\
ProcessID : 2120
ThreadCreationTime : 29-07-2005 07:16:39
BasePriority : Normal
FileVersion : 5.5.1.19
ProductVersion : 5.5.1.19
ProductName : Alps Pointing-device Driver for Windows NT/2000/XP
CompanyName : Alps Electric Co., Ltd.
FileDescription : Alps Pointing-device Driver for Windows NT/2000/XP
InternalName : Alps Pointing-device Driver for Windows NT/2000/XP
LegalCopyright : Copyright © 1998-2004 Alps Electric Co., Ltd.
OriginalFilename : ApntEx.exe

#:38 [tfswctrl.exe]
FilePath : C:\WINDOWS\system32\dla\
ProcessID : 2132
ThreadCreationTime : 29-07-2005 07:16:39
BasePriority : Normal
FileVersion : 1.04.08a
CompanyName : Sonic Solutions
FileDescription : Drive Letter Access Component
LegalCopyright : Copyright © 2004 Sonic Solutions

#:39 [pccntmon.exe]
FilePath : C:\Programmer\Trend Micro\OfficeScan Client\
ProcessID : 2156
ThreadCreationTime : 29-07-2005 07:16:39
BasePriority : Normal
FileVersion : 7.0.0.1040
ProductVersion : 7.0
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
FileDescription : I/O Monitor
InternalName : PCCNTMON
LegalCopyright : Copyright © 1999-2005 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.
OriginalFilename : PCCNTMON.EXE

#:40 [launchapplication.exe]
FilePath : C:\Programmer\Nokia\Nokia PC Suite 6\
ProcessID : 2368
ThreadCreationTime : 29-07-2005 07:16:41
BasePriority : Normal


#:41 [datalayer.exe]
FilePath : C:\Programmer\Fælles filer\PCSuite\DataLayer\
ProcessID : 2568
ThreadCreationTime : 29-07-2005 07:16:43
BasePriority : Normal
FileVersion : 6, 50, 101, 3
ProductVersion : 6, 0
ProductName : Nokia PC Suite
CompanyName : Nokia Mobile Phones Ltd.
FileDescription : DataLayer 2.0 Module
InternalName : DataLayer 2.0
LegalCopyright : Copyright © 2005. Nokia. All rights reserved.
OriginalFilename : DataLayer.exe

#:42 [hpwjtbx.exe]
FilePath : C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\
ProcessID : 2912
ThreadCreationTime : 29-07-2005 07:16:44
BasePriority : Normal
FileVersion : 2003.0912.0.0
ProductVersion : 1.0
ProductName : HP Printing System for Windows
CompanyName : Hewlett-Packard Company
FileDescription : Toolbox for HP Printing System for Windows
InternalName : HPWJTBX
LegalCopyright : Copyright © Hewlett-Packard Co., 1990-2000
Copyright © Microsoft Corp. 1991
OriginalFilename : HPWJTBX

#:43 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3648
ThreadCreationTime : 29-07-2005 07:16:46
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:44 [wcescomm.exe]
FilePath : C:\Programmer\Microsoft ActiveSync\
ProcessID : 3796
ThreadCreationTime : 29-07-2005 07:16:50
BasePriority : Normal
FileVersion : 3.7.1.4034
ProductVersion : 3.7.4034
ProductName : Microsoft ActiveSync
CompanyName : Microsoft Corporation
FileDescription : ActiveSync Connection Manager
InternalName : wcescomm
LegalCopyright : Copyright © 1995-2004 Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation.
OriginalFilename : WCESCOMM.EXE

#:45 [pcsync2.exe]
FilePath : C:\Programmer\Nokia\Nokia PC Suite 6\
ProcessID : 4040
ThreadCreationTime : 29-07-2005 07:16:53
BasePriority : Normal
FileVersion : 2.00 (423)
ProductVersion : 2.00
ProductName : PC Sync
CompanyName : Time Information Services Ltd.
FileDescription : PC Sync
InternalName : PcSync2
LegalCopyright : Copyright © Time I.S. Ltd. 2002 - 2005
OriginalFilename : PcSync2.EXE

#:46 [gcasdtserv.exe]
FilePath : C:\Programmer\Microsoft AntiSpyware\
ProcessID : 4056
ThreadCreationTime : 29-07-2005 07:16:53
BasePriority : Normal
FileVersion : 1.00.0615
ProductVersion : 1.00.0615
ProductName : Microsoft AntiSpyware (Beta 1)
CompanyName : Microsoft Corporation
FileDescription : Microsoft AntiSpyware Data Service
InternalName : gcasDtServ
LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet™ is a trademark of Microsoft Corporation.
OriginalFilename : gcasDtServ.exe

#:47 [servic~1.exe]
FilePath : C:\PROGRA~1\FÆLLES~1\PCSuite\Services\
ProcessID : 4060
ThreadCreationTime : 29-07-2005 07:16:53
BasePriority : Normal
FileVersion : 6, 50, 28, 2
ProductVersion : 6.0
ProductName : Nokia Connectivity Library
CompanyName : Nokia.
FileDescription : ServiceLayer Module
InternalName : ServiceLayer
LegalCopyright : Copyright © 2002-2005 Nokia. All Rights Reserved.
OriginalFilename : ServiceLayer.exe

#:48 [mpapi3s.exe]
FilePath : C:\PROGRA~1\FÆLLES~1\Nokia\MPAPI\
ProcessID : 2884
ThreadCreationTime : 29-07-2005 07:16:59
BasePriority : Normal
FileVersion : 6.50.156.3
ProductVersion : 6.0
ProductName : Nokia Connectivity Library
CompanyName : Nokia Corporation
FileDescription : Mobile Phone API
InternalName : MPAPI
LegalCopyright : Copyright © 1999-2004 Nokia. All Rights Reserved
OriginalFilename : MPAPI.EXE

#:49 [dlg.exe]
FilePath : C:\Programmer\Digital Line Detect\
ProcessID : 4008
ThreadCreationTime : 29-07-2005 07:17:03
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : BVRP Software TestLine
CompanyName : BVRP Software
FileDescription : Digital Line Detection
InternalName : TestLine
LegalCopyright : Copyright © 2003
OriginalFilename : TestLine.exe

#:50 [isatray.exe]
FilePath : C:\Programmer\Microsoft Firewall Client\
ProcessID : 4080
ThreadCreationTime : 29-07-2005 07:17:04
BasePriority : Normal
FileVersion : 3.0
ProductVersion : 3.0
ProductName : Microsoft® Internet Security and Acceleration Server 2000
CompanyName : Microsoft Corporation
FileDescription : Microsoft Firewall Client taskbar application
InternalName : isatray
LegalCopyright : Copyright © Microsoft Corp. 1995 - 2000
OriginalFilename : isatray.exe

#:51 [tosbtmng.exe]
FilePath : C:\Programmer\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 4092
ThreadCreationTime : 29-07-2005 07:17:05
BasePriority : Normal


#:52 [tosa2dp.exe]
FilePath : C:\Programmer\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 136
ThreadCreationTime : 29-07-2005 07:17:08
BasePriority : Normal


#:53 [tosbthsp.exe]
FilePath : C:\Programmer\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 2820
ThreadCreationTime : 29-07-2005 07:17:09
BasePriority : Normal


#:54 [tosobex.exe]
FilePath : C:\Programmer\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 3028
ThreadCreationTime : 29-07-2005 07:17:10
BasePriority : Normal
FileVersion : 1, 0, 0, 2
ProductVersion : 1, 0, 0, 2
ProductName : tosOBEX
CompanyName : TOSHIBA CORPORATION.
FileDescription : tosOBEX
InternalName : tosOBEX
LegalCopyright : Copyright © 2002-2004 TOSHIBA CORPORATION. All rights reserved.
OriginalFilename : tosOBEX.EXE

#:55 [tosbtproc.exe]
FilePath : C:\Programmer\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 2536
ThreadCreationTime : 29-07-2005 07:17:13
BasePriority : Normal
FileVersion : 1.01.08.DA
ProductVersion : 1.01.08.0
ProductName : TOSHIBA CORPORATION
CompanyName : TOSHIBA CORPORATION.
FileDescription : TosBtProc
InternalName : TosBtProc
LegalCopyright : Copyright 2002-2004 TOSHIBA CORPORATION. Alle rettigheder er forbeholdt
OriginalFilename : TosBtProc.exe

#:56 [msimn.exe]
FilePath : C:\Programmer\Outlook Express\
ProcessID : 3144
ThreadCreationTime : 29-07-2005 07:20:36
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Outlook Express
InternalName : MSIMN
LegalCopyright : © 2004 Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : MSIMN.EXE

#:57 [msmsgs.exe]
FilePath : C:\Programmer\Messenger\
ProcessID : 3804
ThreadCreationTime : 29-07-2005 07:20:38
BasePriority : Normal
FileVersion : 4.7.3001
ProductVersion : Version 4.7.3001
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe

#:58 [outlook.exe]
FilePath : C:\Programmer\Microsoft Office\Office10\
ProcessID : 2624
ThreadCreationTime : 29-07-2005 07:20:38
BasePriority : Normal


#:59 [winword.exe]
FilePath : C:\Programmer\Microsoft Office\Office10\
ProcessID : 2532
ThreadCreationTime : 29-07-2005 07:20:52
BasePriority : Normal


#:60 [gcasserv.exe]
FilePath : C:\Programmer\Microsoft AntiSpyware\
ProcessID : 3920
ThreadCreationTime : 29-07-2005 12:33:32
BasePriority : Idle
FileVersion : 1.00.0615
ProductVersion : 1.00.0615
ProductName : Microsoft AntiSpyware (Beta 1)
CompanyName : Microsoft Corporation
FileDescription : Microsoft AntiSpyware Service
InternalName : gcasServ
LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet™ is a trademark of Microsoft Corporation.
OriginalFilename : gcasServ.exe

#:61 [ad-aware.exe]
FilePath : C:\Programmer\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3936
ThreadCreationTime : 29-07-2005 12:40:55
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : stidos@instadia[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Expires : 04-07-2029 02:00:00
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : stidos@cgi-bin[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:[removed]/cgi-bin
Expires : 19-01-2009 01:00:00
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : stidos@doubleclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:8
Value : Cookie:[removed]/
Expires : 27-07-2008 16:23:28
LastSync : Hits:8
UseCount : 0
Hits : 8

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : stidos@advertising[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:[removed]/
Expires : 28-07-2010 13:44:38
LastSync : Hits:4
UseCount : 0
Hits : 4

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:[removed]/
Expires : 28-08-2005 13:45:26
LastSync : Hits:6
UseCount : 0
Hits : 6

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : stidos@adtech[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:[removed]/
Expires : 26-07-2015 16:22:34
LastSync : Hits:6
UseCount : 0
Hits : 6

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : stidos@mediaplex[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Expires : 22-06-2009 02:00:00
LastSync : Hits:3
UseCount : 0
Hits : 3

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 7
Objects found so far: 7



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7


Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7

14:55:48 Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:06:40.34
Objects scanned:99714
Objects identified:7
Objects ignored:0
New critical objects:7

———————————————————————-
I have removed them all.
New HJT:
Logfile of HijackThis v1.99.1
Scan saved at 14:59:06, on 29-07-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\basfipm.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\OS29FC.EXE
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programmer\Apoint\Apntex.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\FÆLLES~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\FÆLLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Programmer\Outlook Express\msimn.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Microsoft Office\Office10\OUTLOOK.EXE
C:\Programmer\Microsoft Office\Office10\WINWORD.EXE
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Install\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.computerworld.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://My.Gunnebo.NET
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Gunnebo.NET
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://segboprx01.gunnebo.net:8080;https=http://segboprx01.gunnebo.net:8080;ftp=http://segboprx01.gunnebo.net:8080;gopher=http://segboprx01.gunnebo.net:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.gunnebo.net;128.5.84.160;
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [HPWJTOOLBOX] C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe "-i"
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://My.Gunnebo.NET
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122499746406
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gunnebo.net
O17 - HKLM\Software\..\Telephony: DomainName = gunnebo.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gunnebo.net
O20 - Winlogon Notify: IntelWireless - C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe

Regards, Stig
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Install it, and update the definitions to the newest files.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Dear Siggyx… I'm deeply shocked! :o The scan in secure mode found 198 infections - and I really belived that it was clean.

Here are the HJT log as well as the scan report.

Regards, Stig
(Don't know what I should have done without you guys - a donation is a must - but not until I can use my creditcard on the internet again without havi'n spyware :ph34r: looking over my shulder)

———————————–
Logfile of HijackThis v1.99.1
Scan saved at 13:55:44, on 30-07-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\basfipm.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\TEMP\NV6426.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sessmgr.exe
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
C:\PROGRA~1\FÆLLES~1\PCSuite\Services\SERVIC~1.EXE
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\FÆLLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Install\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.computerworld.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://My.Gunnebo.NET
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Gunnebo.NET
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://segboprx01.gunnebo.net:8080;https=http://segboprx01.gunnebo.net:8080;ftp=http://segboprx01.gunnebo.net:8080;gopher=http://segboprx01.gunnebo.net:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.gunnebo.net;128.5.84.160;
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [HPWJTOOLBOX] C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe "-i"
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://My.Gunnebo.NET
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122499746406
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gunnebo.net
O17 - HKLM\Software\..\Telephony: DomainName = gunnebo.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gunnebo.net
O20 - Winlogon Notify: IntelWireless - C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe

********************************************************************
———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 13:49:44, 30-07-2005
+ Report-Checksum: 13C351F2

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{011710E1-B483-710E-97E0-2570CF3083B8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B5A2313-AE67-454E-9A8B-F74070E57F1B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4C96C433-2EDC-3926-B873-410DB1199685} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5F574346-A206-D78A-7149-4C709D5204A4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{65D75D06-7395-6352-09CD-E13B9059EFE9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8327E127-2658-4B06-86B0-8D575DE1575B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A66A7703-9E5D-D32F-B86A-2B0EE436B436} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C42CF26E-2B02-05DE-7D7B-A16C5C2095BB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FD53AF3D-B5A4-3DEC-C009-E2E6791F3EE9} -> Spyware.CoolWebSearch : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@ivwbox[2].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\[removed][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\stidos\Cookies\stidos@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Install\Everest Poker.exe -> Spyware.Casino : Cleaned with backup
C:\WINDOWS\apifq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apiho.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlan32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atleu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlfy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlso32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\aucfg.ini:lvtyy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Common.ini:cclah -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control.ini:qhevp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crbb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crkt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\delvh.txt:awiwab -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\desktop.ini:cxwhog -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\gfopr.txt:xuwmd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\hpbj2300.ini:sfyjj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieka.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ievz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iewl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcbk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcbv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcfv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ModemLog_Standardmodem, 33600 bps.txt:kvpch -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msdfmap.ini:psztz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mshu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msro.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msrr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netjo.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netkb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netnw32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\NokiaContentCopier.INI:bjkzv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\NokiaContentCopier.INI:tpsjf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntbb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntbtlog.txt:fdpbia -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntdd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntnl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:tvyfk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qlopx.txt:slizti -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\rwflx.txt:stuhqk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:ekzyxr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkbf.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdknm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkyp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setuplog.txt:ncfye -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setuplog.txt:qcmqq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Setupwizard.ini:eawxeh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\smscfg.ini:afufl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\smscfg.ini:dffeo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\smscfg.ini:fkhuh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sysig32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32:chaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\addfz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\addmg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\addzn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\apijf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\atldo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\atlov32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\atlqf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\creh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crkd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crrb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crwg32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\d3eu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\d3so.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iehs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ieiq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ielv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iest32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ieub.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iexi32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ipka32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\javaem32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\javayk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcbc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfchh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcul.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcuq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcvi32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfczl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\msgh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mstx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntbt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntkd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntzr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdkdp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdklk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdkxu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdkyc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdkze.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\syskk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\winuu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\tmupdate.ini:hyoef -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\tosOBEX.INI:xiwqt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vbaddin.ini:emfcds -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wininit.ini:matmy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winmw32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winpd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winqf.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winty.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ahmci -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:aosww -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:arvphj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:azrxz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:btfjh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:cnjny -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:dayya -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:duqrx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ejirz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ffiag -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:fhgpdx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ftsds -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:fuwnhm -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:fvwlxa -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:fwalq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:gdhew -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:gjvyx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:grsagr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:grvso -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:gsetk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:hlvfk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:hpzck -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:iaxqk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:idhqj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:inzqu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:jophzq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:jpvedx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:juqaeq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:jyazg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:jzedg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:kvhiq -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:lhdbd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:lrasc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ltmmkn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:lzskd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:maivc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:mawxx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:mdtnj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:mrulu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:mzzad -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:nfyie -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:nidlc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:nsqur -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ntyxy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:nzuoi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:odlgf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:owqzn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:pbwhe -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:pknwf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:plrlwe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:pnhla -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:pnijm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:pqswlx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:qenqfk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:qhtgd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:qlmkxs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:qlwgn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:qtpjt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:qtuun -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:rgvcbk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:rtpmz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:rtyuc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:rxlxk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:rzrut -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:sbfhb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:snyxg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:stuhqk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:suodo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:tltgy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:tmzrj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ubzhb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:uefhk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:uerndj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:uzdkc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:vamxls -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:vikga -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:vykzr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:weeru -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:xmwyy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:xpzrq -> TrojanDownloader.Agent.bq : Cleaned with backup

::Report End

*************************
By the way - I can see that the installation .exe file from Everst Poker was infected with a spyware. Will my creditcard information then be at risk? :(
/Stig
I would change any passwords you have.

Lets look a bit deeper.

Download MicroWorld virus scan here >>> Micro World http://www.mwti.net/antivirus/free_utilities.asp

To run the virus scan make sure you click the following

memory, registry, startup folders, system folders, services, drive (all drives will be added) then click on scan clean. When the scan is complete hilight all the files in the LOWER box. Then ctrl + c and paste them into the thread ctrl + v.

I warn you the scan will take a long time to run and will not fix anything just identifies bad files.
The requestet log: Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\MSXML3A.DLL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\DIMM.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{08484541-BCCD-C18F-32D6-EB815B6DEC10}" refers to invalid object "C:\WINDOWS\system32\nthe.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2404EFC9-478B-558B-A3F4-CA1604130A5C}" refers to invalid object "C:\WINDOWS\system32\apitd.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{3EAF3A17-CC8D-5DC9-285D-C38B83233D28}" refers to invalid object "C:\WINDOWS\ieqs32.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{41600CBD-0A19-11D2-B54A-080009D023F9}" refers to invalid object "C:\PROGRA~1\ACAD2000\shapes.arx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5B791DC9-4315-DB99-ED8F-D81BA733A257}" refers to invalid object "C:\WINDOWS\system32\wingy32.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{713AF1A3-FF45-D249-8F51-854010144B4A}" refers to invalid object "C:\WINDOWS\system32\mfcvi32.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9EFBF860-5685-11D3-AA3D-00C04F4C5275}" refers to invalid object "cdooff.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BA6A7285-A488-F292-5E38-FED53B83902B}" refers to invalid object "C:\WINDOWS\winnt.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D6D61CAE-CB82-9B91-F7B6-9E1F3F604EE2}" refers to invalid object "C:\WINDOWS\sysie32.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{daa873d4-958c-453c-81ca-3fe6f3676a87}" refers to invalid object "C:\WINDOWS\system32:chaa.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F6D567AD-A699-840D-2FA3-690BC237682F}" refers to invalid object "C:\WINDOWS\system32\netzk.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F8241258-7425-E5B8-2794-A607FBD21C67}" refers to invalid object "C:\WINDOWS\syscl.dll". Action Taken: No Action Taken. Entry "HKCR\AcroIEHelper.AcroIEHlprObj" refers to invalid object "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}". Action Taken: No Action Taken. Entry "HKCR\AcroIEHelper.AcroIEHlprObj.1" refers to invalid object "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken. File C:\ms32.tmp infected by "Trojan-Downloader.Win32.Small.bel" Virus! Action Taken: No Action Taken. File C:\Programmer\Everest Poker\CStart.exe tagged as "not-a-virus:AdWare.Casino.l". Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000017.exe tagged as "not-a-virus:AdWare.Casino.d". Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000018.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000019.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000020.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000021.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000022.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000023.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000027.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000028.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000031.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000032.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000033.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000034.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000035.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000036.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000038.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000039.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000040.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000041.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000042.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000043.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000045.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000046.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000047.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000049.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000050.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000051.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000054.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000055.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000056.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000057.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000058.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000059.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000060.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000061.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000062.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000063.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000064.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000065.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000066.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000067.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000068.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000069.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000070.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000071.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000072.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000073.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000074.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000075.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000076.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000077.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000078.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000079.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000080.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000081.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000082.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000083.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000084.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000085.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000086.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000087.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000088.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000089.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000090.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000091.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000092.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000093.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000094.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000099.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000100.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000101.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{26FBF7D6-90BD-4B6B-9B40-27D3A07CC125}\RP2\A0000102.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. (There are still lots of stuff….) /Stig
ownload FxAgentB.exe from HERE and save it to your desktop. After downloading, double-click the FxAgentB file to run it and the program will scan your entire hard drive - this may take a while. When it is done, it will generate a log file called FxAgentB.log - save that information as you will need to paste it here later. Reboot when done.

Next click HERE to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. If you already have CWShredder, click 'Check for update' and make sure you are running version 2.12. Reboot when done.

Then click HERE to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Click "Start", select "Perform Full System scan" and "Next" to start the scan. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done, rescan with HijackThis and post a new log here, together with the FxAgentB log.
Here it is…


Logfile of HijackThis v1.99.1
Scan saved at 18:50:12, on 31-07-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\basfipm.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\GC193E.EXE
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe
C:\PROGRA~1\FÆLLES~1\PCSuite\Services\SERVIC~1.EXE
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\FÆLLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Programmer\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Install\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.computerworld.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://My.Gunnebo.NET
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Gunnebo.NET
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://segboprx01.gunnebo.net:8080;https=http://segboprx01.gunnebo.net:8080;ftp=http://segboprx01.gunnebo.net:8080;gopher=http://segboprx01.gunnebo.net:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.gunnebo.net;128.5.84.160;
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmer\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [HPWJTOOLBOX] C:\Programmer\Hewlett-Packard\hp business inkjet 2300 series\Toolbox\HPWJTBX.exe "-i"
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Programmer\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://My.Gunnebo.NET
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122499746406
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gunnebo.net
O17 - HKLM\Software\..\Telephony: DomainName = gunnebo.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gunnebo.net
O20 - Winlogon Notify: IntelWireless - C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programmer\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe

**********************************************************
And….
Symantec Backdoor.Agent.B Removal Tool 1.0.1.2


C:\System Volume Information: (not scanned)
Backdoor.Agent.B has not been found on your computer.

**********************************************************
The CWShredder found nothing
Download About Buster

1. Please download About:Buster from here: http://www.malwarebytes.biz/AboutBuster5.zip.

2. Once it is downloaded extract it to c:\aboutbuster.

3. Check to make sure it is up-to-date.

[*]Navigate to the c:\aboutbuster directory

[*]double-click on aboutbuster.exe

[*]When the tool opens press the OK button, then Start button, then the OK button

[*]then finally the Yes button. It will start scanning your computer for files.

[*]If it asks if you would like to do a second pass, allow it to do so.

[*]Post the log file in your next reply

The logfile…: AboutBuster 5.0 reference file 31 Scan started on [01-08-2005] at [17:39:53] ———————————————— Removed Stream! C:\WINDOWS\bhkiw.dat:fjjfus Removed Stream! C:\WINDOWS\DELL.BMP:fqtfoo Removed Stream! C:\WINDOWS\fsbza.log:frsffd Removed Stream! C:\WINDOWS\fytbu.txt:pjkzxc Removed Stream! C:\WINDOWS\gvcasinos.ini:bspdfl Removed Stream! C:\WINDOWS\hpbj2300.ini:qtvxby Removed Stream! C:\WINDOWS\mtstack.INI:hlikdt Removed Stream! C:\WINDOWS\ODBC.INI:seluzg Removed Stream! C:\WINDOWS\smscfg.ini:yciujp Removed Stream! C:\WINDOWS\sycxs.dat:evmwzr Removed Stream! C:\WINDOWS\T30DebugLogFile.txt:bvlfgc Removed Stream! C:\WINDOWS\Thumbs.db:encryptable Removed Stream! C:\WINDOWS\tmupdate.ini:pwphve Removed Stream! C:\WINDOWS\tosOBEX.INI:gpxin Removed Stream! C:\WINDOWS\_default.pif:dnatmg Removed Stream! C:\WINDOWS\_default.pif:ejkdi ———————————————— Removed File! : C:\Windows\bhkiw.dat Removed File! : C:\Windows\jpved.dat Removed File! : C:\Windows\lzmuf.dat Removed File! : C:\Windows\nudhf.dat Removed File! : C:\Windows\sycxs.dat Removed File! : C:\Windows\zixwq.dat Removed File! : C:\Windows\System32\aekjl.dat Removed File! : C:\Windows\System32\cdwzn.dat Removed File! : C:\Windows\System32\gzjjk.dat Removed File! : C:\Windows\System32\nsoht.dat Removed File! : C:\Windows\System32\rzklc.dat Removed File! : C:\Windows\System32\xkegm.dat ———————————————— Scan was COMPLETED SUCCESSFULLY at 17:40:49

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI