FROM SPYSWEEPER.
********
16:20: | Start of Session, den 29 mars 2006 |
16:20: Spy Sweeper started
16:20: Sweep initiated using definitions version 643
16:20: Found Adware: security2k hijacker
16:20: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || nvctrl.exe (ID = 1052559)
16:20: nvctrl.exe (ID = 1052559)
16:20: Found Trojan Horse: trojan-downloader-zlob
16:20: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || kernel32.dll (ID = 1052560)
16:20: mssearchnet.exe (ID = 1052560)
16:20: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || wininet.dll (ID = 1052561)
16:20: dfrgsrv.exe (ID = 1052561)
16:20: Starting Memory Sweep
16:20: Found Adware: popuper
16:20: HKCR\clsid\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22}\inprocserver32\ (2 subtraces) (ID = 1150213)
16:20: hpCC0A.tmp (ID = 1150213)
16:21: Found Adware: purityscan
16:21: Detected running threat: C:\Documents and Settings\Andreas Hallikainen\Application Data\?racle\dvdplay.exe (ID = 230)
16:23: Memory Sweep Complete, Elapsed Time: 00:02:23
16:23: Starting Registry Sweep
16:23: HKCR\clsid\{9eb320ce-be1d-4304-a081-4b4665414bef}\ (21 subtraces) (ID = 137128)
16:23: HKCR\clsid\{39da2444-065f-47cb-b27c-ccb1a39c06b7}\ (3 subtraces) (ID = 137170)
16:23: HKCR\interface\{3517fb25-305d-4012-b531-186e3851e7ed}\ (8 subtraces) (ID = 137348)
16:23: HKCR\interface\{4781daa6-4de5-47a1-b02a-945f0d017a9e}\ (8 subtraces) (ID = 137349)
16:23: HKCR\mediaticketsinstaller.mediaticketsinstallerctrl.1\ (3 subtraces) (ID = 137352)
16:23: HKLM\software\classes\clsid\{9eb320ce-be1d-4304-a081-4b4665414bef}\ (21 subtraces) (ID = 137470)
16:23: HKLM\software\classes\clsid\{39da2444-065f-47cb-b27c-ccb1a39c06b7}\ (3 subtraces) (ID = 137505)
16:23: HKLM\software\classes\interface\{3517fb25-305d-4012-b531-186e3851e7ed}\ (8 subtraces) (ID = 137678)
16:23: HKLM\software\classes\interface\{4781daa6-4de5-47a1-b02a-945f0d017a9e}\ (8 subtraces) (ID = 137679)
16:23: HKLM\software\classes\interface\{4781daa6-4de5-47a1-b02a-945f0d017a9e}\typelib\ (2 subtraces) (ID = 137680)
16:23: HKLM\software\classes\mediaticketsinstaller.mediaticketsinstallerctrl.1\ (3 subtraces) (ID = 137683)
16:23: HKLM\software\classes\typelib\{5530d356-0063-41b9-b20d-e9d799e8d907}\ (9 subtraces) (ID = 137687)
16:23: HKLM\software\microsoft\code store database\distribution units\{9eb320ce-be1d-4304-a081-4b4665414bef}\ (14 subtraces) (ID = 137704)
16:23: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaticketsinstaller.ocx\ (2 subtraces) (ID = 137986)
16:23: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaticketsinstaller.ocx (ID = 139077)
16:23: HKLM\software\microsoft\windows\currentversion\uninstall\mediatickets\ (12 subtraces) (ID = 139080)
16:23: HKCR\typelib\{5530d356-0063-41b9-b20d-e9d799e8d907}\ (9 subtraces) (ID = 139091)
16:23: Found Adware: webhancer
16:23: HKLM\software\webhancer\ (5 subtraces) (ID = 146278)
16:23: Found Adware: winad
16:23: HKCR\clsid\{1e5f0d38-214b-4085-ad2a-d2290e6a2d2c}\ (14 subtraces) (ID = 147153)
16:23: HKLM\software\classes\clsid\{1e5f0d38-214b-4085-ad2a-d2290e6a2d2c}\ (14 subtraces) (ID = 147167)
16:23: HKCR\mediagateway.installer\ (5 subtraces) (ID = 359542)
16:23: HKLM\software\classes\mediagateway.installer\ (5 subtraces) (ID = 359544)
16:23: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objecta\ (2 subtraces) (ID = 735573)
16:23: Found Adware: 180search assistant/zango
16:23: HKCR\clsid\{d676f999-4608-4dc5-a135-4f51f4212739}\ (1 subtraces) (ID = 792270)
16:23: HKLM\software\classes\clsid\{d676f999-4608-4dc5-a135-4f51f4212739}\ (1 subtraces) (ID = 792320)
16:23: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || kernel32.dll (ID = 796421)
16:23: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || wininet.dll (ID = 797671)
16:23: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || nvctrl.exe (ID = 797753)
16:23: Found Trojan Horse: trojan agent winlogonhook
16:23: HKLM\software\microsoft\mssmgr\ (12 subtraces) (ID = 937101)
16:23: HKCR\mediagateway.installer.1\ (3 subtraces) (ID = 1026542)
16:23: HKCR\mediagateway.licenseinstaller\ (5 subtraces) (ID = 1026546)
16:23: HKCR\mediagateway.licenseinstaller.1\ (3 subtraces) (ID = 1026552)
16:23: HKCR\clsid\{144b9c7e-235a-4316-9eb3-5e393714c77a}\ (14 subtraces) (ID = 1026556)
16:23: HKCR\typelib\{91e523db-2a1c-4231-bb06-9be27c28739a}\ (9 subtraces) (ID = 1026571)
16:23: HKLM\software\classes\mediagateway.licenseinstaller\ (5 subtraces) (ID = 1026584)
16:23: HKLM\software\classes\mediagateway.licenseinstaller.1\ (3 subtraces) (ID = 1026590)
16:23: HKLM\software\classes\clsid\{144b9c7e-235a-4316-9eb3-5e393714c77a}\ (14 subtraces) (ID = 1026594)
16:23: HKLM\software\classes\typelib\{91e523db-2a1c-4231-bb06-9be27c28739a}\ (9 subtraces) (ID = 1026609)
16:23: HKLM\software\mediagateway\ (4 subtraces) (ID = 1026619)
16:23: HKLM\software\classes\mediagateway.installer.1\ (3 subtraces) (ID = 1026624)
16:23: HKLM\software\microsoft\windows\currentversion\uninstall\mediagateway\ (2 subtraces) (ID = 1026626)
16:23: HKCR\interface\{610e0e95-8f2f-4b71-966e-f91701d4dc2c}\ (8 subtraces) (ID = 1027782)
16:23: HKCR\interface\{67a89831-6bc7-4cc0-a2c3-560f9a581e64}\ (8 subtraces) (ID = 1027791)
16:23: HKLM\software\classes\interface\{67a89831-6bc7-4cc0-a2c3-560f9a581e64}\ (8 subtraces) (ID = 1027841)
16:23: HKCR\clsid\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22}\ (4 subtraces) (ID = 1150210)
16:23: HKLM\software\classes\clsid\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22}\ (4 subtraces) (ID = 1150211)
16:23: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22}\ (1 subtraces) (ID = 1150212)
16:23: Found Adware: spyware quake
16:23: HKCR\clsid\{5b55c4e3-c179-ba0b-b4fd-f2db862d6202}\ (35 subtraces) (ID = 1218826)
16:23: HKCR\typelib\{661173ee-fa31-4769-97d4-b556b5d09bda}\ (9 subtraces) (ID = 1218844)
16:23: HKLM\software\spywarequake\ (1 subtraces) (ID = 1218854)
16:23: HKLM\software\classes\clsid\{5b55c4e3-c179-ba0b-b4fd-f2db862d6202}\ (35 subtraces) (ID = 1218857)
16:23: HKLM\software\microsoft\windows\currentversion\run\ || spywarequake (ID = 1218858)
16:23: HKLM\software\microsoft\windows\currentversion\uninstall\spywarequake\ (7 subtraces) (ID = 1218859)
16:23: HKLM\software\classes\typelib\{661173ee-fa31-4769-97d4-b556b5d09bda}\ (9 subtraces) (ID = 1218883)
16:23: HKLM\software\microsoft\windows\currentversion\app paths\spywarequake.exe\ (1 subtraces) (ID = 1218894)
16:23: Found Adware: spyware quake fakealert
16:23: HKLM\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler\ || {e2ca7cd1-1ad9-f1c4-3d2a-dc1a33e7af9d} (ID = 1219030)
16:23: HKU\S-1-5-21-448539723-688789844-839522115-1003\software\classes\clsid\{e2ca7cd1-1ad9-f1c4-3d2a-dc1a33e7af9d}\ (3 subtraces) (ID = 1219032)
16:23: Registry Sweep Complete, Elapsed Time:00:00:05
16:23: Starting Cookie Sweep
16:23: Found Spy Cookie: yieldmanager cookie
16:23: andreas hallikainen@ad.yieldmanager[1].txt (ID = 3751)
16:23: Found Spy Cookie: atlas dmt cookie
16:23: andreas hallikainen@atdmt[2].txt (ID = 2253)
16:23: Found Spy Cookie: malwarewipe cookie
16:23: andreas hallikainen@malwarewipe[2].txt (ID = 6467)
16:23: Found Spy Cookie: partypoker cookie
16:23: andreas hallikainen@partypoker[2].txt (ID = 3111)
16:23: Found Spy Cookie: pesttrap cookie
16:23: andreas hallikainen@www.pesttrap[1].txt (ID = 6462)
16:23: Found Spy Cookie: xiti cookie
16:23: andreas hallikainen@xiti[1].txt (ID = 3717)
16:23: Cookie Sweep Complete, Elapsed Time: 00:00:03
16:23: Starting File Sweep
16:23: c:\program\whinstall (2 subtraces) (ID = -2147480064)
16:23: c:\program\spywarequake (13 subtraces) (ID = -2147453334)
16:23: c:\program\mediagateway (ID = -2147463340)
16:23: c:\documents and settings\andreas hallikainen\start-meny\program\spywarequake (3 subtraces) (ID = -2147453332)
16:23: adse0000 (ID = 267748)
16:23: adservice.dll (ID = 267748)
16:23: whinstaller.ini (ID = 83847)
16:24: Found Trojan Horse: trojan-downloader-aux
16:24: win2c.tmp.exe (ID = 267746)
16:24: spywarequake.exe (ID = 271989)
16:24: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || SpywareQuake (ID = 0)
16:24: whagent.inf (ID = 83820)
16:27: whagent.exe (ID = 83818)
16:28: wh.exe (ID = 156803)
16:28: winzp32[1].exe (ID = 267747)
16:28: srvlbin5[1].exe (ID = 267746)
16:28: 180c4.mht (ID = 147169)
16:29: win36b.tmp.exe (ID = 267746)
16:41: spywarequake 2.0.lnk (ID = 271989)
16:41: spywarequake.lnk (ID = 271989)
16:41: spywarequake 2.0.lnk (ID = 271989)
16:41: spywarequake 2.0.lnk (ID = 271989)
16:41: File Sweep Complete, Elapsed Time: 00:17:46
16:41: Full Sweep has completed. Elapsed time 00:20:19
16:41: Traces Found: 513
17:07: Removal process initiated
17:07: Quarantining All Traces: 180search assistant/zango
17:07: Quarantining All Traces: popuper
17:07: popuper is in use. It will be removed on reboot.
17:07: hpCC0A.tmp is in use. It will be removed on reboot.
17:07: Quarantining All Traces: purityscan
17:07: purityscan is in use. It will be removed on reboot.
17:07: C:\Documents and Settings\Andreas Hallikainen\Application Data\?racle\dvdplay.exe is in use. It will be removed on reboot.
17:07: Quarantining All Traces: security2k hijacker
17:07: Quarantining All Traces: trojan-downloader-zlob
17:07: trojan-downloader-zlob is in use. It will be removed on reboot.
17:07: mssearchnet.exe is in use. It will be removed on reboot.
17:07: Quarantining All Traces: trojan agent winlogonhook
17:07: Quarantining All Traces: trojan-downloader-aux
17:07: Quarantining All Traces: winad
17:07: Quarantining All Traces: spyware quake fakealert
17:07: Quarantining All Traces: spyware quake
17:07: Quarantining All Traces: webhancer
17:07: Quarantining All Traces: atlas dmt cookie
17:07: Quarantining All Traces: malwarewipe cookie
17:07: Quarantining All Traces: partypoker cookie
17:07: Quarantining All Traces: pesttrap cookie
17:07: Quarantining All Traces: xiti cookie
17:07: Quarantining All Traces: yieldmanager cookie
17:07: Removal process completed. Elapsed time 00:00:42
********
16:19: | Start of Session, den 29 mars 2006 |
16:19: Spy Sweeper started
16:20: Your spyware definitions have been updated.
16:20: | End of Session, den 29 mars 2006
-----------------------
FROM EWIDO
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 17:58:35, 2006-03-29
+ Report-Checksum: 1C078D9A
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Cleaned with backup
[620] C:\WINDOWS\system32\winghy32.dll -> Downloader.Small.cml : Error during cleaning
:mozilla.11:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.211:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.212:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.258:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.269:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.279:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.307:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.435:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.511:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.514:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.519:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.527:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.559:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.561:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.562:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.563:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.564:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.565:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.592:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.597:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.598:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.601:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.602:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.664:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup
:mozilla.700:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned with backup
:mozilla.713:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup
:mozilla.714:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Estat : Cleaned with backup
:mozilla.716:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.717:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.737:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.746:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.747:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.753:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Adition : Cleaned with backup
:mozilla.754:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Adition : Cleaned with backup
:mozilla.756:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.757:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.758:C:\Documents and Settings\Andreas Hallikainen\Application Data\Mozilla\Firefox\Profiles\hkwa19l8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Application Data\Οracle\__delete_on_reboot__dvdplay.exe -> Downloader.PurityScan.cb : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Cookies\andreas hallikainen@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Lokala inställningar\Temp\!update.exe -> Downloader.PurityScan.cb : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Lokala inställningar\Temporary Internet Files\Content.IE5\0B37E09H\mulbin1[1].exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Lokala inställningar\Temporary Internet Files\Content.IE5\2LFO58VM\rdgSE2427[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Lokala inställningar\Temporary Internet Files\Content.IE5\HZRB1DGE\!update-3615[1].0000 -> Downloader.PurityScan.cb : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Lokala inställningar\Temporary Internet Files\Content.IE5\KZ5VYMV5\MediaTicketsInstaller[1].cab/MediaTicketsInstaller.ocx -> Adware.MediaTickets : Cleaned with backup
C:\Documents and Settings\Andreas Hallikainen\Lokala inställningar\Temporary Internet Files\Content.IE5\S9EBSD2B\!update-3595[1].0000 -> Downloader.PurityScan.bw : Cleaned with backup
C:\Program\Security Stronghold\True Sword\Infected\MediaGateway.exe -> Adware.WinAD : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup
C:\WINDOWS\mtuninst.exe -> Adware.MediaTickets : Cleaned with backup
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup
C:\WINDOWS\system32\1024\ld7EA5.tmp -> Dropper.Agent.alo : Cleaned with backup
C:\WINDOWS\system32\dfrgsrv.exe -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\hpCDFE.tmp -> Downloader.Zlob.jp : Cleaned with backup
C:\WINDOWS\system32\interf.tlb -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\ld1E5F4A -> Downloader.Zlob.jm : Cleaned with backup
C:\WINDOWS\system32\ldCB5E.tmp -> Downloader.Zlob.jm : Cleaned with backup
C:\WINDOWS\system32\nvctrl.exe -> Hijacker.SpyAxe : Cleaned with backup
C:\WINDOWS\system32\oins.exe -> Downloader.PurityScan.bt : Cleaned with backup
C:\WINDOWS\system32\stickrep.dll -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__winghy32.dll -> Downloader.Small.cml : Cleaned with backup
C:\WINDOWS\Temp\hniicpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINDOWS\Temp\obagbcod.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINDOWS\Temp\win2F.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\Temp\win36D.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\YAXUninst.exe -> Adware.MediaTickets : Cleaned with backup
::Report End
-----------
NEW HIJACKTHIS
Logfile of HijackThis v1.99.1
Scan saved at 19:05:43, on 2006-03-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program\ewido\security suite\ewidoctrl.exe
C:\Program\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program\Java\jre1.5.0_06\bin\jusched.exe
C:\Program\ATI Technologies\ATI.ACE\cli.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\Program\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Program\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Andreas Hallikainen\Mina dokument\?dobe\w?nspool.exe
C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program\ATI Technologies\ATI.ACE\cli.exe
C:\Program\ATI Technologies\ATI.ACE\cli.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Windows NT\Tillbehör\WORDPAD.EXE
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O4 - HKLM\..\Run: [ATIPTA] C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\Program\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Mblewze] C:\Documents and Settings\Andreas Hallikainen\Mina dokument\?dobe\w?nspool.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) -
http://yax-download.yazzle.net/Yazzl...cab?refid=1123
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary...n.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: winghy32 - winghy32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program\Webroot\Spy Sweeper\WRSSSDK.exe
----------------------
Thx for the help

. Is it clean now ?