Gå til innhold

Trenger analyse av HJT-logg [LØST]


Anbefalte innlegg

Skrevet (endret)

SAS-LOGG

Klikk for å se/fjerne innholdet nedenfor
SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 04/30/2007 at 01:36 AM

 

Application Version : 3.7.1018

 

Core Rules Database Version : 3227Trace Rules Database Version: 1238

 

Scan type : Complete Scan

Total Scan Time : 00:33:33

 

Memory items scanned : 197

Memory threats detected : 0

Registry items scanned : 5474

Registry threats detected : 230

File items scanned : 30714

File threats detected : 14

 

Trojan.Smitfraud Variant

HKLM\Software\Classes\CLSID\{b23dc537-3e13-44c7-bf67-d8405eb377f7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\RCOHTY.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{b23dc537-3e13-44c7-bf67-d8405eb377f7}

 

Adware.ToolBar888

HKLM\Software\Classes\CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32#ThreadingModel

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\ProgID

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\Programmable

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\TypeLib

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\VersionIndependentProgID

C:\PROGRAMFILER\TOOLBAR888\MYTOOLBAR.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKLM\Software\Microsoft\Internet Explorer\Toolbar#{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\MyToolBar.MyToolBarObj.1

HKCR\MyToolBar.MyToolBarObj.1\CLSID

HKCR\MyToolBar.MyToolBarObj

HKCR\MyToolBar.MyToolBarObj\CLSID

HKCR\MyToolBar.MyToolBarObj\CurVer

HKCR\TypeLib\{CD2A09D7-EE7E-4c25-993C-C2678ECFAD01}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version

HKLM\Software\Classes\MyToolBar.MyToolBarObj

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CLSID

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CurVer

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID

HKU\S-1-5-21-1645522239-484061587-839522115-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

 

Trojan.Media-Codec/V2

HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\BPVOL.DLL

HKLM\Software\Classes\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories\{00021493-0000-0000-C000-000000000046}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\SPLUG.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString

 

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007

HKCR\WAP6.PCheck

HKCR\WAP6.PCheck\CLSID

HKCR\WAP6.PCheck\CurVer

HKCR\WAP6.PCheck.1

HKCR\WAP6.PCheck.1\CLSID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version

 

Trojan.Unknown Origin

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#SystemComponent

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#Installer

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation#CODEBASE

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion#LastModified

 

Trojan.ZQuest

C:\WINDOWS\dh.ini

 

Trojan.DollarRevenue

C:\WINDOWS\newname.dat

C:\WINDOWS\keyboard1.dat

 

Trojan.ErrorSafe

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32#ThreadingModel

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\ProgID

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Programmable

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\TypeLib

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\VersionIndependentProgID

 

Browser Hijacker.Deskbar

HKCR\DBTB00001.DBTB00001

HKCR\DBTB00001.DBTB00001\CLSID

HKCR\DBTB00001.DBTB00001\CurVer

HKCR\DBTB00001.DBTB00001.1

HKCR\DBTB00001.DBTB00001.1\CLSID

HKCR\DBTB00001.DeskBar

HKCR\DBTB00001.DeskBar\CLSID

HKCR\DBTB00001.DeskBar\CurVer

HKCR\DBTB00001.DeskBar.1

HKCR\DBTB00001.DeskBar.1\CLSID

HKCR\DBTB00001.deskbarBHO

HKCR\DBTB00001.deskbarBHO\CLSID

HKCR\DBTB00001.deskbarBHO\CurVer

HKCR\DBTB00001.deskbarBHO.1

HKCR\DBTB00001.deskbarBHO.1\CLSID

HKCR\DBTB00001.DeskbarEnabler

HKCR\DBTB00001.DeskbarEnabler\CLSID

HKCR\DBTB00001.DeskbarEnabler.1

HKCR\DBTB00001.DeskbarEnabler.1\CLSID

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid32

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib#Version

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid32

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib#Version

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid32

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib#Version

 

Trojan.Media-Codec

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#user32.dll [ C:\Programfiler\Video AX Object\bpmon.exe ]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#rare [ C:\Programfiler\Video AX Object\smmain.exe ]

 

Malware.SpyLocked

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32#ThreadingModel

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\OtiLglrhUikvj

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\podtlbEyd

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\pysFxsmg

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\rxirdocusi

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\TypeLib

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\uCniqDrba

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\wnFySqsxcxws

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0\win32

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\FLAGS

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\HELPDIR

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid32

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib#Version

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid32

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib#Version

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid32

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib#Version

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid32

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib#Version

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid32

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib#Version

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid32

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib#Version

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid32

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib#Version

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid32

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib#Version

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid32

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib#Version

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid32

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib#Version

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid32

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib#Version

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid32

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib#Version

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid32

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib#Version

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid32

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib#Version

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid32

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib#Version

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid32

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib#Version

 

Worm.Alcra Variant

C:\WINDOWS\SYSTEM32\CMD.COM

C:\WINDOWS\SYSTEM32\NETSTAT.COM

C:\WINDOWS\SYSTEM32\PING.COM

C:\WINDOWS\SYSTEM32\REGEDIT.COM

C:\WINDOWS\SYSTEM32\TASKKILL.COM

C:\WINDOWS\SYSTEM32\TASKLIST.COM

C:\WINDOWS\SYSTEM32\TRACERT.COM

 

HJT-Logg

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 01:48:14, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\msnlogm.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\msnlogs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\notepad.exe

C:\PROGRA~1\Mozilla Firefox\firefox.exe

C:\Documents and Settings\- Nils\Skrivebord\rootchk.exe

C:\WINDOWS\system32\cmd.exe

C:\DOCUME~1\-NILS~1\LOKALE~1\Temp\Rootchk\catchme.exe

C:\Programfiler\HijackThis\HijackThis.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Programfiler\Start.no Turbo\components\NOWImaging.dll (file missing)

O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing)

O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing)

O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing)

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe

O4 - HKLM\..\Run: [defender] C:\\dfndrff_e37.exe

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [newname] C:\\nwnmff_e37.exe

O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e37.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: bw+0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: offline-8876480 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

 

Rootchk Logg

Klikk for å se/fjerne innholdet nedenfor
******************************** ROOTCHK-(25-04-07)-LOG, by ejvindh

30.04.07 1:46:49,21

 

Driver nm (visible) is present. Run COMBOFIX by sUBs.

 

********************************* ROOTCHK-LOG-end

 

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 01:46:50

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

msnsyslog = C:\WINDOWS\msnlogm.exe??X?2??|d?2??|p?2??|??8[??H??|8??|??2??|?|?|??%?@?R?B~??%?@?\?B~??@?@?

 

scanning hidden files ...

 

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 102

 

Har jeg noe ufine ting? :thumbdown:

Og hvordan fjerner jeg hvis jeg har? :dontgetit:

Endret av trysilgutt
Videoannonse
Annonse
Skrevet

WOW.... :dribble: Der var det endel og ta tak i ser jeg...Midt beste forslag akkurat er og gå på denne siden og følge guiden som er satt opp der....Når det er gjort så legger du ut en ny logg....

Skrevet (endret)
WOW.... :dribble: Der var det endel og ta tak i ser jeg...Midt beste forslag akkurat er og gå på denne siden og følge guiden som er satt opp der....Når det er gjort så legger du ut en ny logg....

8499132[/snapback]

 

Legge til en SAS-Logg?

 

Edit: Nå skjønte jeg :)

Endret av trysilgutt
Skrevet (endret)

SAS-LOGG

Klikk for å se/fjerne innholdet nedenfor
SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 04/30/2007 at 01:36 AM

 

Application Version : 3.7.1018

 

Core Rules Database Version : 3227Trace Rules Database Version: 1238

 

Scan type : Complete Scan

Total Scan Time : 00:33:33

 

Memory items scanned : 197

Memory threats detected : 0

Registry items scanned : 5474

Registry threats detected : 230

File items scanned : 30714

File threats detected : 14

 

Trojan.Smitfraud Variant

HKLM\Software\Classes\CLSID\{b23dc537-3e13-44c7-bf67-d8405eb377f7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\RCOHTY.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{b23dc537-3e13-44c7-bf67-d8405eb377f7}

 

Adware.ToolBar888

HKLM\Software\Classes\CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32#ThreadingModel

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\ProgID

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\Programmable

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\TypeLib

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\VersionIndependentProgID

C:\PROGRAMFILER\TOOLBAR888\MYTOOLBAR.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKLM\Software\Microsoft\Internet Explorer\Toolbar#{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\MyToolBar.MyToolBarObj.1

HKCR\MyToolBar.MyToolBarObj.1\CLSID

HKCR\MyToolBar.MyToolBarObj

HKCR\MyToolBar.MyToolBarObj\CLSID

HKCR\MyToolBar.MyToolBarObj\CurVer

HKCR\TypeLib\{CD2A09D7-EE7E-4c25-993C-C2678ECFAD01}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version

HKLM\Software\Classes\MyToolBar.MyToolBarObj

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CLSID

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CurVer

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID

HKU\S-1-5-21-1645522239-484061587-839522115-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

 

Trojan.Media-Codec/V2

HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\BPVOL.DLL

HKLM\Software\Classes\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories\{00021493-0000-0000-C000-000000000046}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\SPLUG.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString

 

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007

HKCR\WAP6.PCheck

HKCR\WAP6.PCheck\CLSID

HKCR\WAP6.PCheck\CurVer

HKCR\WAP6.PCheck.1

HKCR\WAP6.PCheck.1\CLSID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version

 

Trojan.Unknown Origin

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#SystemComponent

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#Installer

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation#CODEBASE

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion#LastModified

 

Trojan.ZQuest

C:\WINDOWS\dh.ini

 

Trojan.DollarRevenue

C:\WINDOWS\newname.dat

C:\WINDOWS\keyboard1.dat

 

Trojan.ErrorSafe

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32#ThreadingModel

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\ProgID

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Programmable

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\TypeLib

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\VersionIndependentProgID

 

Browser Hijacker.Deskbar

HKCR\DBTB00001.DBTB00001

HKCR\DBTB00001.DBTB00001\CLSID

HKCR\DBTB00001.DBTB00001\CurVer

HKCR\DBTB00001.DBTB00001.1

HKCR\DBTB00001.DBTB00001.1\CLSID

HKCR\DBTB00001.DeskBar

HKCR\DBTB00001.DeskBar\CLSID

HKCR\DBTB00001.DeskBar\CurVer

HKCR\DBTB00001.DeskBar.1

HKCR\DBTB00001.DeskBar.1\CLSID

HKCR\DBTB00001.deskbarBHO

HKCR\DBTB00001.deskbarBHO\CLSID

HKCR\DBTB00001.deskbarBHO\CurVer

HKCR\DBTB00001.deskbarBHO.1

HKCR\DBTB00001.deskbarBHO.1\CLSID

HKCR\DBTB00001.DeskbarEnabler

HKCR\DBTB00001.DeskbarEnabler\CLSID

HKCR\DBTB00001.DeskbarEnabler.1

HKCR\DBTB00001.DeskbarEnabler.1\CLSID

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid32

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib#Version

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid32

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib#Version

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid32

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib#Version

 

Trojan.Media-Codec

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#user32.dll [ C:\Programfiler\Video AX Object\bpmon.exe ]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#rare [ C:\Programfiler\Video AX Object\smmain.exe ]

 

Malware.SpyLocked

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32#ThreadingModel

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\OtiLglrhUikvj

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\podtlbEyd

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\pysFxsmg

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\rxirdocusi

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\TypeLib

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\uCniqDrba

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\wnFySqsxcxws

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0\win32

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\FLAGS

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\HELPDIR

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid32

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib#Version

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid32

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib#Version

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid32

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib#Version

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid32

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib#Version

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid32

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib#Version

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid32

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib#Version

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid32

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib#Version

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid32

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib#Version

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid32

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib#Version

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid32

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib#Version

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid32

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib#Version

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid32

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib#Version

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid32

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib#Version

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid32

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib#Version

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid32

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib#Version

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid32

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib#Version

 

Worm.Alcra Variant

C:\WINDOWS\SYSTEM32\CMD.COM

C:\WINDOWS\SYSTEM32\NETSTAT.COM

C:\WINDOWS\SYSTEM32\PING.COM

C:\WINDOWS\SYSTEM32\REGEDIT.COM

C:\WINDOWS\SYSTEM32\TASKKILL.COM

C:\WINDOWS\SYSTEM32\TASKLIST.COM

C:\WINDOWS\SYSTEM32\TRACERT.COM

 

HJT-Logg

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 01:48:14, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\msnlogm.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\msnlogs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\notepad.exe

C:\PROGRA~1\Mozilla Firefox\firefox.exe

C:\Documents and Settings\- Nils\Skrivebord\rootchk.exe

C:\WINDOWS\system32\cmd.exe

C:\DOCUME~1\-NILS~1\LOKALE~1\Temp\Rootchk\catchme.exe

C:\Programfiler\HijackThis\HijackThis.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Programfiler\Start.no Turbo\components\NOWImaging.dll (file missing)

O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing)

O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing)

O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing)

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe

O4 - HKLM\..\Run: [defender] C:\\dfndrff_e37.exe

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [newname] C:\\nwnmff_e37.exe

O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e37.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: bw+0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: offline-8876480 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

 

Rootchk Logg

Klikk for å se/fjerne innholdet nedenfor
******************************** ROOTCHK-(25-04-07)-LOG, by ejvindh

30.04.07 1:46:49,21

 

Driver nm (visible) is present. Run COMBOFIX by sUBs.

 

********************************* ROOTCHK-LOG-end

 

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 01:46:50

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

msnsyslog = C:\WINDOWS\msnlogm.exe??X?2??|d?2??|p?2??|??8[??H??|8??|??2??|?|?|????%?@???R?B~??%?@?\?B~??????@?@?

 

scanning hidden files ...

 

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 102

Endret av trysilgutt
Skrevet (endret)

Avinstaller om mulig, fra legg til/fjern programmer:

Logitech desktop messenger

MSN Content Plus

 

Kjør HJT, sett merke framfor følgende linjer og klikk 'Fix checked':

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing)

O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing)

O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing)

O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe

O4 - HKLM..Run: [defender] C:\dfndrff_e37.exe

O4 - HKLM..Run: [newname] C:\nwnmff_e37.exe

O4 - HKLM..Run: [keyboard] C:\kybrdff_e37.exe

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab

 

 

Hent Combofix og legg det på skrivebordet. Lukk alle andre programmer. Kjør programmet. Ikke klikk på noe annet.

 

Når programmet er ferdig åpnes en loggfil: combofix.txt

Den loggfilen poster du senere.

 

Sørg for at du kan se skjulte filer og mapper:

Kontrollpanel->mappealt.->vis->"vis skjulte filer og mapper"

 

Restart i sikker modus (tapp F8 under oppstart)

 

Bruk utforsker til å finne og slette (i fet):

C:\WINDOWS\msnlogm.exe

C:\WINDOWS\msnlogs.exe

 

Restart i normal tilstand

 

Post en ny HJT-logg + loggen fra combofix.

Endret av norbat
Skrevet

HJT LOGG

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 13:50:46, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\VTTimer.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\HijackThis\HijackThis.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

 

COMBO-FIX LOG

Klikk for å se/fjerne innholdet nedenfor
"- Nils" - 07-04-30 13:04:28 Service Pack 2

ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\"

 

 

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\qoobox\purity\C\Programfiler\MCROSO~1.NET

C:\qoobox\purity\C\WINDOWS\PPATCH~1

C:\qoobox\purity\C\WINDOWS\system32\FNTS~1

 

 

((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\nm

-------\LEGACY_NM

-------\LEGACY_NPF

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 ))))))))))))))))))))))))))))))))))

 

 

2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-04-30 03:17 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste

2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner

2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca

2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp

2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts

2007-04-29 23:23 1,048,576 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask

2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord

2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT

2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata

2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter

2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp

2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts

2007-04-29 15:16 1,310,720 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT

2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask

2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord

2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr

2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir

2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft

2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet

2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared

2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour

2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software

2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes

2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain

2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes

2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no

2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic

2007-03-31 17:32 <DIR> d-------- C:\Programfiler\Duplicate File Finder

2007-03-30 15:38 118,784 --------- C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe

2007-03-30 15:37 13,440 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS

2007-03-30 15:36 68,864 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys

2007-03-30 15:36 55,040 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys

2007-03-30 15:36 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe

2007-03-30 15:36 26,112 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys

2007-03-30 15:36 258,352 --a------ C:\WINDOWS\system32\unicows.dll

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Logitech

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech

2007-03-28 21:19 <DIR> d-------- C:\Programfiler\Windows Media Connect 2

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson

2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared

2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp

2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7

2007-04-23 19:06 -------- d-------- C:\Programfiler\opera

2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod

2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime

2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2

2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire

2007-03-30 15:38 -------- d--h----- C:\Programfiler\installshield installation information

2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat

2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat

2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll

2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp

2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture

2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger

2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys

2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll

2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll

2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll

2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys

2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus

2007-03-06 18:36 -------- d-------- C:\Programfiler\utorrent

2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent

2007-02-28 21:25 -------- d-------- C:\Programfiler\msn messenger

2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe

2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat

2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini

2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

{784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"VTTimer"="VTTimer.exe"

"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"

"!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages REG_MULTI_SZ msv1_0\0\0

Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages REG_MULTI_SZ scecli\0\0

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma Loader"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start"

"item"="Logitech Desktop Messenger"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe "

"item"="Logitech SetPoint"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk"

"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"

"item"="Microsoft Office"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk"

"backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE "

"item"="MagicDisc"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk"

"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"

"location"="Startup"

"command"="C:\\Programfiler\\Xfire\\xfire.exe "

"item"="Xfire"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="avgas"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ashDisp"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="bittorrent"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="daemon"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="UDC2006"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\DriveCleaner 2006 Free\\UDC2006.exe\" /min"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="InCD"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iTunesHelper"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="dumprep 0 -k"

"hkey"="HKLM"

"command"="%systemroot%\\system32\\dumprep 0 -k"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LogitechDesktopMessenger"

"hkey"="HKCU"

"command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="lxczbmgr"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NCLAUNCH"

"hkey"="HKCU"

"command"="C:\\WINDOWS\\NCLAUNCH.EXe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NeroCheck"

"hkey"="HKLM"

"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LAUNCH~1"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="PCTAV"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="pvmodule"

"hkey"="HKLM"

"command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="qttask"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Skype"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Application Launcher"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SOUNDMAN"

"hkey"="HKLM"

"command"="SOUNDMAN.EXE"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="jusched"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SUPERAntiSpyware"

"hkey"="HKCU"

"command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="VCDDaemon"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="CAMTHINS"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="winampa"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Winamp\\winampa.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="xfiremusic"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="MultiIM"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"PCTAVSvc"=dword:00000002

"usnjsvc"=dword:00000003

"UserAccess7"=dword:00000002

"rpcapd"=dword:00000003

"LexBceS"=dword:00000002

"iPod Service"=dword:00000003

"InCDsrv"=dword:00000002

"IDriverT"=dword:00000003

"Adobe LM Service"=dword:00000003

"NVCScheduler"=dword:00000003

"Norman ZANDA"=dword:00000002

"Norman NJeeves"=dword:00000003

"NipSvc"=dword:00000003

"nvcoas"=dword:00000003

"Bonjour Service"=dword:00000002

"avast! Web Scanner"=dword:00000003

"avast! Mail Scanner"=dword:00000003

"avast! Antivirus"=dword:00000002

"aswUpdSv"=dword:00000002

"FLEXnet Licensing Service"=dword:00000003

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter REG_MULTI_SZ HTTPFilter\0\0

LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService REG_MULTI_SZ DnsCache\0\0

DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

rpcss REG_MULTI_SZ RpcSs\0\0

imgsvc REG_MULTI_SZ StiSvc\0\0

termsvcs REG_MULTI_SZ TermService\0\0

WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

 

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 13:08:51

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 07-04-30 13:09:21

C:\ComboFix-quarantined-files.txt ... 07-04-30 13:09

C:\ComboFix2.txt ... 07-04-30 13:01

Gjest medlem-105082
Skrevet

Var litt av en liste fra SAS det der :)

Skrevet
Var litt av en liste fra SAS det der :)

8504279[/snapback]

 

Shit happen when you download porn! :p

 

Men forresten, takk for all hjelp =)

Gjest medlem-105082
Skrevet

Haha, ja sånn går det :)

 

Men norbat fikser og ser gjennom de loggene, så skal du se at alt blir fjernet.

Skrevet (endret)

Åpne Notisblokk og kopier og lim inn det som står under (i fet):

 

REGEDIT4

 

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]

 

(PS. sørg for at det ikke er noe luft over REGEDIT4 - altså den skal stå aller øverst i notisblokkvinduet)

 

Klikk 'Lagre som', velg 'Alle filer' som filtype. Lagre file med filnavn: fix.reg på skrivebordet.

 

Dobbeltklikk på fila (fix.reg), og si ja til å legge inn/flette inn i registeret.

 

Kjør HJT, sett merke framfor følgende linjer og klikk 'Fix checked':

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.ca

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

 

Hvis du ikke allerede har programmet: Hent CCleaner.

Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......."

Klikk på 'Renser' og deretter 'Kjør CCleaner'.

Kjør også noen runder med 'Saker' til det ikke finner flere feil.

 

Nullstille gjenopprettingsmappa

Kontrollpanel->system->systemgjenoppretting .

Sett merke framfor "Slå av .....",

restart pc,

fjern merket igjen for å aktivere funksjonen.

 

Kjør på ny en scan med Combofix

 

Post deretter combofix-loggen samt en ny HJT-logg (Før du kjører HJT, forandrer du programnavnet, hijackthis, til noe annet, feks. test )

 

Fortell også hvordan pc'n kjører.

 

I mens noen sjekker de siste loggene, kjører du på ny en complete scan med SAS. Fortell gjerne om den finner noe :)

Endret av norbat
Skrevet (endret)

HJT-LOGG

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 18:17:15, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\VTTimer.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\Mozilla Firefox\firefox.exe

C:\Programfiler\HijackThis\Test.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

 

COMBOFIX Logg

 

Klikk for å se/fjerne innholdet nedenfor
- Nils" - 07-04-30 18:06:14 Service Pack 2

ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\"

 

 

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\qoobox\purity\C\Programfiler\MCROSO~1.NET

C:\qoobox\purity\C\WINDOWS\PPATCH~1

C:\qoobox\purity\C\WINDOWS\system32\FNTS~1

 

 

((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\nm

-------\LEGACY_NM

-------\LEGACY_NPF

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 ))))))))))))))))))))))))))))))))))

 

 

2007-04-30 17:53 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste

2007-04-30 17:11 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\AdobeUM

2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner

2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca

2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp

2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts

2007-04-29 23:23 1,048,576 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask

2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord

2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT

2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata

2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter

2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp

2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts

2007-04-29 15:16 1,310,720 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT

2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask

2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord

2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr

2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir

2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft

2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet

2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared

2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour

2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software

2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes

2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain

2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes

2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no

2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic

2007-03-31 17:32 <DIR> d-------- C:\Programfiler\Duplicate File Finder

2007-03-30 15:37 13,440 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS

2007-03-30 15:36 68,864 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys

2007-03-30 15:36 55,040 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys

2007-03-30 15:36 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe

2007-03-30 15:36 26,112 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys

2007-03-30 15:36 258,352 --a------ C:\WINDOWS\system32\unicows.dll

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Logitech

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech

2007-03-28 21:19 <DIR> d-------- C:\Programfiler\Windows Media Connect 2

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson

2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared

2007-04-30 00:22 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\teleca

2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp

2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7

2007-04-23 19:06 -------- d-------- C:\Programfiler\opera

2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod

2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime

2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2

2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire

2007-03-30 15:38 -------- d--h----- C:\Programfiler\installshield installation information

2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat

2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat

2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll

2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp

2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture

2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger

2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys

2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll

2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll

2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll

2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys

2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus

2007-03-06 18:36 -------- d-------- C:\Programfiler\utorrent

2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent

2007-02-28 21:25 -------- d-------- C:\Programfiler\msn messenger

2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe

2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat

2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini

2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

{784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"VTTimer"="VTTimer.exe"

"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"

"!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages REG_MULTI_SZ msv1_0\0\0

Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages REG_MULTI_SZ scecli\0\0

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma Loader"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start"

"item"="Logitech Desktop Messenger"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe "

"item"="Logitech SetPoint"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk"

"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"

"item"="Microsoft Office"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk"

"backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE "

"item"="MagicDisc"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk"

"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"

"location"="Startup"

"command"="C:\\Programfiler\\Xfire\\xfire.exe "

"item"="Xfire"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="avgas"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ashDisp"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="bittorrent"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="daemon"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="InCD"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iTunesHelper"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="dumprep 0 -k"

"hkey"="HKLM"

"command"="%systemroot%\\system32\\dumprep 0 -k"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LogitechDesktopMessenger"

"hkey"="HKCU"

"command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="lxczbmgr"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NCLAUNCH"

"hkey"="HKCU"

"command"="C:\\WINDOWS\\NCLAUNCH.EXe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NeroCheck"

"hkey"="HKLM"

"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LAUNCH~1"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="PCTAV"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="pvmodule"

"hkey"="HKLM"

"command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="qttask"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Skype"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Application Launcher"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SOUNDMAN"

"hkey"="HKLM"

"command"="SOUNDMAN.EXE"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="jusched"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SUPERAntiSpyware"

"hkey"="HKCU"

"command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="VCDDaemon"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="CAMTHINS"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="winampa"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Winamp\\winampa.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="xfiremusic"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="MultiIM"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"PCTAVSvc"=dword:00000002

"usnjsvc"=dword:00000003

"UserAccess7"=dword:00000002

"rpcapd"=dword:00000003

"LexBceS"=dword:00000002

"iPod Service"=dword:00000003

"InCDsrv"=dword:00000002

"IDriverT"=dword:00000003

"Adobe LM Service"=dword:00000003

"NVCScheduler"=dword:00000003

"Norman ZANDA"=dword:00000002

"Norman NJeeves"=dword:00000003

"NipSvc"=dword:00000003

"nvcoas"=dword:00000003

"Bonjour Service"=dword:00000002

"avast! Web Scanner"=dword:00000003

"avast! Mail Scanner"=dword:00000003

"avast! Antivirus"=dword:00000002

"aswUpdSv"=dword:00000002

"FLEXnet Licensing Service"=dword:00000003

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter REG_MULTI_SZ HTTPFilter\0\0

LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService REG_MULTI_SZ DnsCache\0\0

DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

rpcss REG_MULTI_SZ RpcSs\0\0

imgsvc REG_MULTI_SZ StiSvc\0\0

termsvcs REG_MULTI_SZ TermService\0\0

WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

 

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 18:11:54

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 07-04-30 18:12:41

C:\ComboFix-quarantined-files.txt ... 07-04-30 18:12

C:\ComboFix2.txt ... 07-04-30 13:09

C:\ComboFix3.txt ... 07-04-30 13:01

 

Takk For all hjelp :thumbup:

 

Datan går raskere, den bootere hvertfall raskere.. Det er vel det eneste jeg har lagt merke til - Hvertfall til nå : )

 

EDIT: SAS fant ingenting :w00t:

 

EDIT2: Spilte noen spill nå, ikke en eneste lagg :w00t: !

Endret av trysilgutt
Skrevet (endret)

ComboFix Logg

 

Klikk for å se/fjerne innholdet nedenfor
"- Nils" - 07-05-01 11:47:17 Service Pack 2

ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\"

 

 

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\qoobox\purity\C\Programfiler\MCROSO~1.NET

C:\qoobox\purity\C\WINDOWS\PPATCH~1

C:\qoobox\purity\C\WINDOWS\system32\FNTS~1

 

 

((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\nm

-------\LEGACY_NM

-------\LEGACY_NPF

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-04-01 to 2007-05-01 ))))))))))))))))))))))))))))))))))

 

 

2007-05-01 11:42 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste

2007-05-01 00:05 <DIR> d-------- C:\Programfiler\LEGO Island

2007-05-01 00:03 <DIR> d-------- C:\Programfiler\DaemonTools_WhenUSave_Installer

2007-05-01 00:01 <DIR> d-------- C:\Programfiler\DAEMON Tools

2007-04-30 19:05 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\uTorrent

2007-04-30 17:11 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\AdobeUM

2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner

2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca

2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp

2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts

2007-04-29 23:23 1,310,720 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask

2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord

2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT

2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata

2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter

2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp

2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts

2007-04-29 15:16 1,572,864 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT

2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask

2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord

2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr

2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir

2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft

2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet

2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared

2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour

2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software

2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes

2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain

2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes

2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no

2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-05-01 11:40 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\utorrent

2007-05-01 01:05 -------- d--h----- C:\Programfiler\installshield installation information

2007-04-30 23:57 682232 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2007-04-30 12:47 -------- d-------- C:\Programfiler\logitech

2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson

2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared

2007-04-30 00:22 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\teleca

2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp

2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7

2007-04-23 19:06 -------- d-------- C:\Programfiler\opera

2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod

2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime

2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2

2007-03-31 17:39 -------- d-------- C:\Programfiler\duplicate file finder

2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire

2007-03-28 21:19 -------- d-------- C:\Programfiler\windows media connect 2

2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat

2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat

2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll

2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp

2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture

2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger

2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys

2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll

2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll

2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll

2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys

2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus

2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent

2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe

2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat

2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini

2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

{784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"VTTimer"="VTTimer.exe"

"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"

"!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

"DAEMON Tools"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages REG_MULTI_SZ msv1_0\0\0

Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages REG_MULTI_SZ scecli\0\0

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma Loader"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start"

"item"="Logitech Desktop Messenger"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe "

"item"="Logitech SetPoint"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk"

"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"

"item"="Microsoft Office"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk"

"backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE "

"item"="MagicDisc"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk"

"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"

"location"="Startup"

"command"="C:\\Programfiler\\Xfire\\xfire.exe "

"item"="Xfire"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="avgas"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ashDisp"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="bittorrent"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="daemon"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="InCD"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iTunesHelper"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="dumprep 0 -k"

"hkey"="HKLM"

"command"="%systemroot%\\system32\\dumprep 0 -k"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LogitechDesktopMessenger"

"hkey"="HKCU"

"command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="lxczbmgr"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NCLAUNCH"

"hkey"="HKCU"

"command"="C:\\WINDOWS\\NCLAUNCH.EXe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NeroCheck"

"hkey"="HKLM"

"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LAUNCH~1"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="PCTAV"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="pvmodule"

"hkey"="HKLM"

"command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="qttask"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Skype"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Application Launcher"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SOUNDMAN"

"hkey"="HKLM"

"command"="SOUNDMAN.EXE"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="jusched"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SUPERAntiSpyware"

"hkey"="HKCU"

"command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="VCDDaemon"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="CAMTHINS"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="winampa"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Winamp\\winampa.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="xfiremusic"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="MultiIM"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"PCTAVSvc"=dword:00000002

"usnjsvc"=dword:00000003

"UserAccess7"=dword:00000002

"rpcapd"=dword:00000003

"LexBceS"=dword:00000002

"iPod Service"=dword:00000003

"InCDsrv"=dword:00000002

"IDriverT"=dword:00000003

"Adobe LM Service"=dword:00000003

"NVCScheduler"=dword:00000003

"Norman ZANDA"=dword:00000002

"Norman NJeeves"=dword:00000003

"NipSvc"=dword:00000003

"nvcoas"=dword:00000003

"Bonjour Service"=dword:00000002

"avast! Web Scanner"=dword:00000003

"avast! Mail Scanner"=dword:00000003

"avast! Antivirus"=dword:00000002

"aswUpdSv"=dword:00000002

"FLEXnet Licensing Service"=dword:00000003

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter REG_MULTI_SZ HTTPFilter\0\0

LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService REG_MULTI_SZ DnsCache\0\0

DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

rpcss REG_MULTI_SZ RpcSs\0\0

imgsvc REG_MULTI_SZ StiSvc\0\0

termsvcs REG_MULTI_SZ TermService\0\0

WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

 

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-01 11:52:20

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 07-05-01 11:52:59

C:\ComboFix-quarantined-files.txt ... 07-05-01 11:52

C:\ComboFix2.txt ... 07-04-30 18:12

C:\ComboFix3.txt ... 07-04-30 13:09

 

Er det noe galt? :dontgetit:

 

 

Åpne Notisblokk og kopier og lim inn det som står under (i fet):

 

REGEDIT4

 

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]

 

(PS. sørg for at det ikke er noe luft over REGEDIT4 - altså den skal stå aller øverst i notisblokkvinduet)

 

Klikk 'Lagre som', velg 'Alle filer' som filtype. Lagre file med filnavn: fix.reg på skrivebordet.

 

Dobbeltklikk på fila (fix.reg), og si ja til å legge inn/flette inn i registeret.

 

Kan jeg slette den fra skriverbordet mitt nå? :)

Endret av trysilgutt
Skrevet

Haha, sorry.

 

Rootchk logg

 

Klikk for å se/fjerne innholdet nedenfor
********************************* ROOTCHK-(30-04-07)-LOG, by ejvindh

01.05.07 22:29:44,64

 

The rootkits that are detected by this tool were not found.

 

********************************* ROOTCHK-LOG-end

 

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-01 22:29:45

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 102

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...