Jag gjorde som du skrev Malou.
1:
SmitFraudFix v2.102
Scan done at 12:03:54,42, 2006-10-01
Run from C:\anti\SmitFraud\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\httge.dll Deleted
C:\WINDOWS\system32\ishost.exe Deleted
C:\WINDOWS\system32\ismini.exe Deleted
C:\WINDOWS\system32\isnotify.exe Deleted
C:\WINDOWS\system32\issearch.exe Deleted
C:\WINDOWS\system32\ixt?.dll Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\ts.ico Deleted
C:\DOCUME~1\ALLUSE~1\START-~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\START-~1\Security Troubleshooting.url Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
2:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 13:12:42 2006-10-01
+ Scan result:
HKLM\SYSTEM\ControlSet003\Services\lanmanserver\Shares\\Allt! -> Adware.CometCursor : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program\Analog Devices\SoundMAX\SMTray.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program\D-Tools\daemon.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program\Java\jre1.5.0_06\bin\jusched.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program\Steam\Steam.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\NeroCheck.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
:mozilla.169:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.170:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.364:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.203:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.204:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.374:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.376:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.377:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.77:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.183:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.219:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.220:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.262:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
:mozilla.265:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
:mozilla.266:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
:mozilla.267:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
:mozilla.320:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup (quarantined).
:mozilla.123:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.294:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.295:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.167:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.168:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.350:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.387:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.388:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.135:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.137:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.138:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.139:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.201:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.205:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.375:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.251:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.115:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.353:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.354:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.367:C:\Documents and Settings\Gäst\Application Data\Mozilla\Firefox\Profiles\wmf9vl4h.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
::Report end
3:
Logfile of HijackThis v1.99.1
Scan saved at 13:52:51, on 2006-10-01
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Program\TechSmith\SnagIt 8\SnagIt32.exe
C:\Program\VIA\RAID\raid_tool.exe
C:\Program\TechSmith\SnagIt 8\TSCHelp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Winamp\winamp.exe
C:\Program\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\System32\ixt0.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [Smapp] C:\Program\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!ewido] "C:\Program\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program\Steam\Steam.exe" -silent
O4 - Startup: Deer Hunter 2005 Registration.lnk = C:\Program\Atari\Deer Hunter 2005\ATR1.EXE
O4 - Global Startup: SnagIt 8.lnk = C:\Program\TechSmith\SnagIt 8\SnagIt32.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program\VIA\RAID\raid_tool.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O16 - DPF: {7DFDB8FD-B498-4958-B930-38021B94351D} (imlUCID Class) - http://imlive.com/chatsource/ImlCID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{13CD3C49-986A-4B4C-9E30-A998DA55D43E}: NameServer = 80.88.100.13,194.165.224.165
O17 - HKLM\System\CS1\Services\Tcpip\..\{13CD3C49-986A-4B4C-9E30-A998DA55D43E}: NameServer = 80.88.100.13,194.165.224.165
O17 - HKLM\System\CS2\Services\Tcpip\..\{13CD3C49-986A-4B4C-9E30-A998DA55D43E}: NameServer = 80.88.100.13,194.165.224.165
O17 - HKLM\System\CS3\Services\Tcpip\..\{13CD3C49-986A-4B4C-9E30-A998DA55D43E}: NameServer = 80.88.100.13,194.165.224.165
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs:
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program\Analog Devices\SoundMAX\SMAgent.exe
4:
Datorn mår hittils bra och det verkar fungerat fint!
Stort tack för all hjälp! :):):)
EDIT: Kan man avinstallera ewido, ccleaner och det nu?