Dan-The-Man Skrevet 1. mai 2008 Forfatter Skrevet 1. mai 2008 Oppdatert router til siste firmware? Har det bestandig vært slik eller kom problemet etter at du installerte Vista x64? Kan jo komme av at Routeren ikke er 100% kompatibel med Vista, og trenger en oppdatering på Firmware. Si navnet på routeren så kan jeg finne de siste oppdateringene for den om du ønsker. har bestandig vært sånn, og jeg har btw vista 32-bit routeren er en speedtouch multimodem-ST 780WLT
Dan-The-Man Skrevet 1. mai 2008 Forfatter Skrevet 1. mai 2008 (endret) Prøvde og gi noen råd i post 10.Kansje gjøre det beklager, trodde jeg hadde gjort det... Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2Scan saved at 15:32, on 2008-05-01 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Windows\sttray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Servi...omeLeftPane.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer levert av Dell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file) O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing) O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [steam] "c:\program files\steam\steam.exe" -silent O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETTVERKSTJENESTE') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: QuickSet.lnk = ? O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing) O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing) O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O13 - Gopher Prefix: O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 10431 bytes Endret 1. mai 2008 av Dan-The-Man
Taxmannen Skrevet 1. mai 2008 Skrevet 1. mai 2008 (endret) Har problemer med dette selv. MSN fungerer ikke. Proxy-innstillinger elle brannmur-innstillinger er feil, visstnok. Utrolig nok kan jeg åpne diskusjon.no, men den bruker omtrent et minutt (eller mer) hver gang den laster en side. Jeg er tilkoblet og alt er fint sånn sett. Men internettet oppfører seg rart. Hva er feil? Den klarer ikke laste Gunners.no eller vg, i alle fall. Jeg skjønner ikke hvorfor diskusjon.no funker. "Problem ved lasting av side", står det. Dessuten når jeg diagnostiserer, står det at den ikke kan kommunisere. Og da kan man tilbakestille nettverkskortet. Men dette hjelper ikke. Fortsatt like ødelagt som før. Noen ganger står det også at TCP (eller noe sånt) ikke er kompatibel med ruter. Jeg kan ingenting om data og skjønner ingenting nå heller. Kan noen hjelpe? Vet dette var rotete forklart. Edit: Det har fikset seg nå. Antakelig bare et forbigående problem. Endret 2. mai 2008 av Faces Down
Kistesnekker Skrevet 3. mai 2008 Skrevet 3. mai 2008 Har problemer med dette selv. MSN fungerer ikke. Proxy-innstillinger elle brannmur-innstillinger er feil, visstnok. Utrolig nok kan jeg åpne diskusjon.no, men den bruker omtrent et minutt (eller mer) hver gang den laster en side. Jeg er tilkoblet og alt er fint sånn sett. Men internettet oppfører seg rart. Hva er feil? Den klarer ikke laste Gunners.no eller vg, i alle fall. Jeg skjønner ikke hvorfor diskusjon.no funker. "Problem ved lasting av side", står det. Dessuten når jeg diagnostiserer, står det at den ikke kan kommunisere. Og da kan man tilbakestille nettverkskortet. Men dette hjelper ikke. Fortsatt like ødelagt som før. Noen ganger står det også at TCP (eller noe sånt) ikke er kompatibel med ruter. Jeg kan ingenting om data og skjønner ingenting nå heller. Kan noen hjelpe? Vet dette var rotete forklart. Edit: Det har fikset seg nå. Antakelig bare et forbigående problem. Har du tuklet med nettverkskortet? Har du antivirus? <-Kjekt å ha! Står ip-adressen på nettverkskortet ditt på automatisk?? (Hvis det ikke funker prøv å restart ruteren)
errgo Skrevet 3. mai 2008 Skrevet 3. mai 2008 Jeg hadde også det problemet at internettleseren ofte gikk tregt og stoppet opp mens alt annet fungerte, særlig hvis jeg lastet ned i uTorrent. Løsningen var å laste ned denne tcp/ip patchen http://www.lvllord.de/?lang=en&url=downloads Måtte i kjøre den i fra kommandolinjen (Start - Run.../Kjør... - cmd) for å få lagt inn patchen. Enkelte antivirus kan gi advarsel om "hack tool" eller lignende, men det er bare å ignorere. Filen er trygg. Etter at jeg la inn denne tcp/ip patchen, forsvant problemet.
snippsat Skrevet 3. mai 2008 Skrevet 3. mai 2008 (endret) Du har noe grums ja,dette må fjernes. Disable antivirus-brannvegg når du kjører combofix. Last Combofix ned ,legg på skrivebordet. Ikke klikk på vindu mens programet kjører. post logg C:\combofix.txt tcp/ip patchen, forsvant problemet Tcp/ip patch kan hjelpe ja Endret 3. mai 2008 av SNIPPSAT
Dan-The-Man Skrevet 3. mai 2008 Forfatter Skrevet 3. mai 2008 Du har noe grums ja,dette må fjernes. Disable antivirus-brannvegg når du kjører combofix. Last Combofix ned ,legg på skrivebordet. Ikke klikk på vindu mens programet kjører. post logg C:\combofix.txt tcp/ip patchen, forsvant problemet Tcp/ip patch kan hjelpe ja will do! Klikk for å se/fjerne innholdet nedenfor ComboFix 08-04-27.3 - Daniel 2008-05-03 14:48:40.1 - NTFSx86Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1044.18.1068 [GMT 2:00] Running from: C:\Users\Daniel\Desktop\ComboFix1.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Program Files\FunWebProducts C:\Program Files\MyWebSearch C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat C:\Windows\system32\x64 . ((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-03 12:45 1,422 ----a-w C:\Users\Daniel\AppData\Roaming\wklnhst.dat 2008-05-02 11:17 --------- d-----w C:\Users\Daniel\AppData\Roaming\LimeWire 2008-05-02 08:18 --------- d-----w C:\Program Files\Steam 2008-05-01 21:55 --------- d-----w C:\ProgramData\Messenger Plus! 2008-05-01 21:54 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-05-01 12:18 --------- d-----w C:\Program Files\IDT 2008-05-01 11:28 1,552 ----a-w C:\Windows\system32\drivers\stwrte.log 2008-04-28 20:31 --------- d-----w C:\Program Files\Counter-Strike 1.6 2008-04-28 19:40 --------- d-----w C:\Program Files\Windows Mail 2008-04-28 19:37 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-04-28 19:31 --------- d---a-w C:\ProgramData\TEMP 2008-04-28 19:31 --------- d-----w C:\Program Files\WinSpyKiller 2008-04-28 18:19 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys 2008-04-28 18:19 67,080 ----a-w C:\Windows\system32\drivers\avgwfpx.sys 2008-04-28 18:19 10,520 ----a-w C:\Windows\System32\avgrsstx.dll 2008-04-28 18:19 --------- d-----w C:\ProgramData\avg8 2008-04-28 18:19 --------- d-----w C:\Program Files\AVG 2008-04-22 15:44 --------- d-----w C:\Program Files\Trend Micro 2008-04-22 14:17 --------- d-----w C:\Program Files\Apple Software Update 2008-04-22 13:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-04-20 16:46 --------- d-----w C:\ProgramData\Symantec 2008-04-19 19:19 --------- d-----w C:\Program Files\The Seal Hunter 2008-04-12 18:56 --------- d-----w C:\Users\Daniel\AppData\Roaming\Apple Computer 2008-04-10 20:38 --------- d-----w C:\Program Files\Wfwin 2008-04-10 17:38 --------- d-----w C:\Program Files\Google 2008-04-08 17:25 --------- d-----w C:\Program Files\SwiftSwitch 2008-04-06 16:14 --------- d-----w C:\ProgramData\Roxio 2008-04-04 12:43 --------- d-----w C:\Program Files\Common Files\Steam 2008-04-04 09:48 --------- d-----w C:\Program Files\iTunes 2008-04-04 09:47 --------- d-----w C:\Program Files\iPod 2008-04-04 09:44 --------- d-----w C:\Program Files\QuickTime 2008-03-30 13:16 --------- d-----w C:\Program Files\SystemRequirementsLab 2008-03-30 11:07 --------- d-----w C:\Program Files\Dell 2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys 2008-03-27 18:06 --------- d-----w C:\Users\Daniel\AppData\Roaming\Talkback 2008-03-14 15:39 --------- d-----w C:\Users\Daniel\AppData\Roaming\Leadertech 2008-03-14 15:37 --------- d-----w C:\Program Files\Common Files\Adobe 2008-03-13 16:36 --------- d-----w C:\ProgramData\Documents 2008-03-13 16:16 --------- d-----w C:\Users\Daniel\AppData\Roaming\AdobeUM 2008-03-13 07:13 --------- d-----w C:\ProgramData\Skype 2008-03-05 14:42 --------- d-----w C:\Users\Daniel\AppData\Roaming\Azureus 2008-03-05 14:39 --------- d-----w C:\Program Files\BitLord2 2008-03-05 14:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll 2008-03-05 14:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll 2008-03-05 14:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll 2008-03-05 13:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll 2008-03-05 13:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll 2008-03-04 16:00 --------- d-----w C:\Program Files\Common Files\PX Storage Engine 2008-03-03 15:25 --------- d-----w C:\Program Files\Windows Live Toolbar 2008-03-03 15:23 --------- d-----w C:\Program Files\Windows Live 2008-03-03 15:22 --------- d-----w C:\Users\Daniel\AppData\Roaming\Windows Live Writer 2008-03-03 15:13 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-03-03 15:10 --------- d-----w C:\ProgramData\Telenor 2008-03-03 15:10 --------- d-----w C:\Program Files\Telenor 2008-03-03 15:06 --------- d-----w C:\ProgramData\McAfee 2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll 2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll 2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll 2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe 2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe 2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll 2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll 2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys 2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll 2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll 2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll 2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll 2008-02-16 10:40 736,220,974 ----a-w C:\Program Files\Image_080216_1134.gi 2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe 2008-02-14 22:19 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-02-14 22:14 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-02-14 22:14 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-02-14 22:14 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll 2008-02-05 21:07 462,864 ----a-w C:\Windows\System32\d3dx10_37.dll 2007-09-12 14:58 174 --sha-w C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}] 2008-04-28 20:19 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-28 20:19 2050816] [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}] [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-28 20:19 2050816] [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}] [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-06 11:14 1006264] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-15 20:08 98304] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-15 20:07 106496] "Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-15 20:07 81920] "SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-09-06 03:35 77824] "Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2006-11-28 01:15 1540096] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 12:50 17920] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-06 03:51 1862144] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184] "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [ ] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [ ] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 20:19 1177368] "SigmatelSysTrayApp"="sttray.exe" [2007-02-08 07:11 303104 C:\Windows\sttray.exe] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1820041221-4144176497-4136927534-1000] "EnableNotificationsRef"=dword:00000008 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{F215BAA5-362F-4388-AFB1-7046BFAA6723}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{7A802F48-2B53-4130-946E-02F1E58FC4DB}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{F82B975B-F725-429E-9F1F-B96A0E72F07F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{604116BB-2FC4-49B9-971D-5AF2FCA8893F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{0A101FA8-F434-4164-9A2F-09CA54E12BFB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "{6901F69B-90E8-4B5A-BEF3-25FA0CB3EDDA}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{426750E8-61D5-4375-AD6B-12F92C50E891}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{6016AB2B-A412-4B89-B75A-E7679AE54BA4}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{79E3EFAF-AA4E-4CBF-8F10-C9AA9AD53C3E}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{EE8173FC-0612-4E04-A899-EC46867489AD}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8 "{0C59E7F3-DEB7-4D42-A491-CE892D781337}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8 "{1425428C-4109-4316-8F5E-C55A965B6671}"= %ProgramFiles%\Telenor\Online Start\Telenor.exe:Online Start "TCP Query User{435687BA-EDE5-489F-937C-56B8E42D22DE}C:\\program files\\counter-strike 1.6\\hl.exe"= UDP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher "UDP Query User{10A1F102-F7AF-4CFE-8F31-54DEA12950FD}C:\\program files\\counter-strike 1.6\\hl.exe"= TCP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher "{4E43A063-F692-44EF-AF4D-614ED8352E85}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{43610C69-9580-454F-B469-448C47967CFD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype "TCP Query User{0D93150B-5E89-48DC-A0AA-D0DBF0DD603E}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe: "UDP Query User{9C2AF00F-6378-4D6D-917F-EF374325494C}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe: "{90CE36F8-B55F-4115-BE2F-28DE89586BEC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "TCP Query User{C70CD4EE-896E-4332-A182-5A070CC2B29B}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus "UDP Query User{D739FDEF-97B6-4D09-AE23-BD61FB5E216B}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus "TCP Query User{9FF94F28-2E16-40B6-AFC3-EDB605E3EF10}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2 "UDP Query User{FA364296-73CD-4E26-9B77-227818D98B6E}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2 "TCP Query User{D63ED578-202D-4FD7-9CDC-60E0057031A8}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{7F36C02B-708B-49C9-B79F-7A2258B1C906}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "TCP Query User{AC1F5B1C-5B2C-43EF-9B59-72298EDA889D}C:\\program files\\counter-strike 1.6\\hlds.exe"= UDP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher "UDP Query User{514EAB2F-2F8A-4173-9AF5-B4C54E6EA3E4}C:\\program files\\counter-strike 1.6\\hlds.exe"= TCP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher "{59217433-9C36-4E8F-A684-A5CE4C6C28AF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{C4FC3841-7F9F-4554-ACD4-0C96FCE38D2F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "TCP Query User{33B6A06F-FF30-42A0-8576-0A7157E826D9}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{44A96FEE-281B-4F98-B638-3EAA2297B82C}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{48610643-8143-49B8-80DF-509C116C4D88}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "UDP Query User{04048DEA-4972-4E82-8634-F115A6B4A415}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "TCP Query User{4CB1FA52-F0C9-4624-B90A-3332E795044B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{B9F1CE36-C5DA-4234-92AE-D3CFEC19B393}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{126EAD4D-4057-4D2E-AB75-0188ECF38681}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "UDP Query User{7C7C2B68-71CB-4EE3-90D5-FB30E130BE3E}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "TCP Query User{F6EF78ED-59E0-429D-ABF9-B5448CD0DA16}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "UDP Query User{B3572E3D-8B04-4AB8-9BBB-84E860226E6B}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "TCP Query User{2E3E6A16-3C6C-49A5-AA82-3277BE5F904B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{ED08CB23-ACC6-460F-AC59-808C062BF4A6}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{5CCD2E63-6938-42B1-AE61-34E03E95B6A6}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{291AD43A-928A-467D-9F2E-319DED1A549A}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{50BA01F5-42B1-46AF-9217-4DB75EB4C1C5}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "UDP Query User{FEC47B1E-1D48-4887-8474-C94617225337}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "TCP Query User{7C99411B-0217-4247-B1C8-E67D63922DB9}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "UDP Query User{23B15472-4D99-4C2E-9791-6E86847771F4}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "TCP Query User{78342C9B-D30E-4589-AA3A-FA6020242A68}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "UDP Query User{3EC04C63-AA9D-4F3D-AC4C-8C5F61599EFE}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "TCP Query User{89D336AE-6FCA-4813-A749-4FCC0960A961}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher "UDP Query User{46FDF6C9-1276-4E3B-A62B-6266B4766F47}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher "{BEF8CCC8-B25D-481D-8FEA-5090BAF2907F}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe "{9CF5C224-7223-472F-B9D0-7DB821D592BB}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 20:19] R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32] R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 20:19] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 20:19] R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 20:19] R3 btwaudio;Bluetooth-lydenhet;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 03:37] R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 01:13] R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 01:13] R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-15 20:07] S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36] S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-04-04 14:43] S3 stusb2ir;USB 2.0 IrDA Bridge;C:\Windows\system32\DRIVERS\stusb2ir.sys [2006-11-02 09:30] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc bthsvcs REG_MULTI_SZ BthServ [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f73e66e-8eef-11dc-928a-001c26f02b6b}] \shell\AutoRun\command - F:\usdeiect.com \shell\explore\Command - F:\usdeiect.com \shell\open\Command - F:\usdeiect.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bb41413-62dc-11dc-9a64-001c26f02b6b}] \shell\AutoRun\command - F:\ntde1ect.com \shell\explore\Command - F:\ntde1ect.com \shell\open\Command - F:\ntde1ect.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6230faca-ce3d-11dc-90fa-001c26f02b6b}] \shell\AutoRun\command - b.com \shell\explore\Command - b.com \shell\open\Command - b.com *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-03 14:51:23 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-05-03 14:52:37 ComboFix-quarantined-files.txt 2008-05-03 12:52:20 Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application. Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application. 245 --- E O F --- 2008-05-03 12:35:34 takk for at du tar deg tid til det her
snippsat Skrevet 3. mai 2008 Skrevet 3. mai 2008 (endret) Slett mapper. C:\Program Files\Common Files\Symantec Shared C:\ProgramData\Symantec Kopiere fet tekst under bildet->åpne notisblokk og lim inn. Lagre på skrivebordet som CFScript.txt Gjør som på bildet combofix vil starte,Post logg c:\combofix.txt Folder:: C:\Program Files\WinSpyKiller Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "My Web Search Bar Search Scope Monitor"=- [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f73e66e-8eef-11dc-928a-001c26f02b6b}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bb41413-62dc-11dc-9a64-001c26f02b6b}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6230faca-ce3d-11dc-90fa-001c26f02b6b}] Last ned kjør CCleaner 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t. Kjør register-renser og"svar ja til og reparere" --- Last ned oppdatere og kjør full scan SAS free Post loggen fra SAS (preferences->statistics/logs) --- Restart og en ny HijackThis logg. Endret 3. mai 2008 av SNIPPSAT
Dan-The-Man Skrevet 3. mai 2008 Forfatter Skrevet 3. mai 2008 her kommer logg for combofix.txt Klikk for å se/fjerne innholdet nedenfor ComboFix 08-04-27.3 - Daniel 2008-05-03 17:29:28.2 - NTFSx86Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1044.18.862 [GMT 2:00] Running from: C:\Users\Daniel\Desktop\ComboFix1.exe Command switches used :: C:\Users\Daniel\Desktop\CFScript.txt..lnk * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-03 14:55 --------- d-----w C:\Users\Daniel\AppData\Roaming\LimeWire 2008-05-03 14:18 --------- d-----w C:\Users\Daniel\AppData\Roaming\dvdcss 2008-05-03 12:45 1,422 ----a-w C:\Users\Daniel\AppData\Roaming\wklnhst.dat 2008-05-02 08:18 --------- d-----w C:\Program Files\Steam 2008-05-01 21:55 --------- d-----w C:\ProgramData\Messenger Plus! 2008-05-01 21:54 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-05-01 12:18 --------- d-----w C:\Program Files\IDT 2008-05-01 11:28 1,552 ----a-w C:\Windows\system32\drivers\stwrte.log 2008-04-28 20:31 --------- d-----w C:\Program Files\Counter-Strike 1.6 2008-04-28 19:40 --------- d-----w C:\Program Files\Windows Mail 2008-04-28 19:37 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-04-28 19:31 --------- d---a-w C:\ProgramData\TEMP 2008-04-28 19:31 --------- d-----w C:\Program Files\WinSpyKiller 2008-04-28 18:19 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys 2008-04-28 18:19 67,080 ----a-w C:\Windows\system32\drivers\avgwfpx.sys 2008-04-28 18:19 10,520 ----a-w C:\Windows\System32\avgrsstx.dll 2008-04-28 18:19 --------- d-----w C:\ProgramData\avg8 2008-04-28 18:19 --------- d-----w C:\Program Files\AVG 2008-04-22 15:44 --------- d-----w C:\Program Files\Trend Micro 2008-04-22 14:17 --------- d-----w C:\Program Files\Apple Software Update 2008-04-19 19:19 --------- d-----w C:\Program Files\The Seal Hunter 2008-04-12 18:56 --------- d-----w C:\Users\Daniel\AppData\Roaming\Apple Computer 2008-04-10 20:38 --------- d-----w C:\Program Files\Wfwin 2008-04-10 17:38 --------- d-----w C:\Program Files\Google 2008-04-08 17:25 --------- d-----w C:\Program Files\SwiftSwitch 2008-04-06 16:14 --------- d-----w C:\ProgramData\Roxio 2008-04-04 12:43 --------- d-----w C:\Program Files\Common Files\Steam 2008-04-04 09:48 --------- d-----w C:\Program Files\iTunes 2008-04-04 09:47 --------- d-----w C:\Program Files\iPod 2008-04-04 09:44 --------- d-----w C:\Program Files\QuickTime 2008-03-30 13:16 --------- d-----w C:\Program Files\SystemRequirementsLab 2008-03-30 11:07 --------- d-----w C:\Program Files\Dell 2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys 2008-03-27 18:06 --------- d-----w C:\Users\Daniel\AppData\Roaming\Talkback 2008-03-14 15:39 --------- d-----w C:\Users\Daniel\AppData\Roaming\Leadertech 2008-03-14 15:37 --------- d-----w C:\Program Files\Common Files\Adobe 2008-03-13 16:36 --------- d-----w C:\ProgramData\Documents 2008-03-13 16:16 --------- d-----w C:\Users\Daniel\AppData\Roaming\AdobeUM 2008-03-13 07:13 --------- d-----w C:\ProgramData\Skype 2008-03-05 14:42 --------- d-----w C:\Users\Daniel\AppData\Roaming\Azureus 2008-03-05 14:39 --------- d-----w C:\Program Files\BitLord2 2008-03-05 14:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll 2008-03-05 14:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll 2008-03-05 14:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll 2008-03-05 13:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll 2008-03-05 13:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll 2008-03-04 16:00 --------- d-----w C:\Program Files\Common Files\PX Storage Engine 2008-03-03 15:25 --------- d-----w C:\Program Files\Windows Live Toolbar 2008-03-03 15:23 --------- d-----w C:\Program Files\Windows Live 2008-03-03 15:22 --------- d-----w C:\Users\Daniel\AppData\Roaming\Windows Live Writer 2008-03-03 15:13 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-03-03 15:10 --------- d-----w C:\ProgramData\Telenor 2008-03-03 15:10 --------- d-----w C:\Program Files\Telenor 2008-03-03 15:06 --------- d-----w C:\ProgramData\McAfee 2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll 2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll 2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll 2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe 2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe 2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll 2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll 2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys 2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll 2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll 2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll 2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll 2008-02-16 10:40 736,220,974 ----a-w C:\Program Files\Image_080216_1134.gi 2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe 2008-02-14 22:19 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-02-14 22:14 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-02-14 22:14 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-02-14 22:14 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll 2008-02-05 21:07 462,864 ----a-w C:\Windows\System32\d3dx10_37.dll 2007-09-12 14:58 174 --sha-w C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((( snapshot@2008-05-03_14.52.05.97 ))))))))))))))))))))))))))))))))))))))))) . - 2008-05-03 12:32:14 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-05-03 14:31:48 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat - 2008-05-03 12:48:49 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-05-03 15:28:52 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}] 2008-04-28 20:19 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-28 20:19 2050816] [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}] [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-28 20:19 2050816] [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}] [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-06 11:14 1006264] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-15 20:08 98304] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-15 20:07 106496] "Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-15 20:07 81920] "SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-09-06 03:35 77824] "Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2006-11-28 01:15 1540096] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 12:50 17920] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-06 03:51 1862144] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184] "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [ ] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [ ] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 20:19 1177368] "SigmatelSysTrayApp"="sttray.exe" [2007-02-08 07:11 303104 C:\Windows\sttray.exe] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1820041221-4144176497-4136927534-1000] "EnableNotificationsRef"=dword:00000008 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{F215BAA5-362F-4388-AFB1-7046BFAA6723}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{7A802F48-2B53-4130-946E-02F1E58FC4DB}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{F82B975B-F725-429E-9F1F-B96A0E72F07F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{604116BB-2FC4-49B9-971D-5AF2FCA8893F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{0A101FA8-F434-4164-9A2F-09CA54E12BFB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "{6901F69B-90E8-4B5A-BEF3-25FA0CB3EDDA}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{426750E8-61D5-4375-AD6B-12F92C50E891}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{6016AB2B-A412-4B89-B75A-E7679AE54BA4}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{79E3EFAF-AA4E-4CBF-8F10-C9AA9AD53C3E}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{EE8173FC-0612-4E04-A899-EC46867489AD}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8 "{0C59E7F3-DEB7-4D42-A491-CE892D781337}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8 "{1425428C-4109-4316-8F5E-C55A965B6671}"= %ProgramFiles%\Telenor\Online Start\Telenor.exe:Online Start "TCP Query User{435687BA-EDE5-489F-937C-56B8E42D22DE}C:\\program files\\counter-strike 1.6\\hl.exe"= UDP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher "UDP Query User{10A1F102-F7AF-4CFE-8F31-54DEA12950FD}C:\\program files\\counter-strike 1.6\\hl.exe"= TCP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher "{4E43A063-F692-44EF-AF4D-614ED8352E85}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{43610C69-9580-454F-B469-448C47967CFD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype "TCP Query User{0D93150B-5E89-48DC-A0AA-D0DBF0DD603E}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe: "UDP Query User{9C2AF00F-6378-4D6D-917F-EF374325494C}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe: "{90CE36F8-B55F-4115-BE2F-28DE89586BEC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "TCP Query User{C70CD4EE-896E-4332-A182-5A070CC2B29B}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus "UDP Query User{D739FDEF-97B6-4D09-AE23-BD61FB5E216B}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus "TCP Query User{9FF94F28-2E16-40B6-AFC3-EDB605E3EF10}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2 "UDP Query User{FA364296-73CD-4E26-9B77-227818D98B6E}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2 "TCP Query User{D63ED578-202D-4FD7-9CDC-60E0057031A8}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{7F36C02B-708B-49C9-B79F-7A2258B1C906}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "TCP Query User{AC1F5B1C-5B2C-43EF-9B59-72298EDA889D}C:\\program files\\counter-strike 1.6\\hlds.exe"= UDP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher "UDP Query User{514EAB2F-2F8A-4173-9AF5-B4C54E6EA3E4}C:\\program files\\counter-strike 1.6\\hlds.exe"= TCP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher "{59217433-9C36-4E8F-A684-A5CE4C6C28AF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{C4FC3841-7F9F-4554-ACD4-0C96FCE38D2F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "TCP Query User{33B6A06F-FF30-42A0-8576-0A7157E826D9}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{44A96FEE-281B-4F98-B638-3EAA2297B82C}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{48610643-8143-49B8-80DF-509C116C4D88}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "UDP Query User{04048DEA-4972-4E82-8634-F115A6B4A415}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "TCP Query User{4CB1FA52-F0C9-4624-B90A-3332E795044B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{B9F1CE36-C5DA-4234-92AE-D3CFEC19B393}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{126EAD4D-4057-4D2E-AB75-0188ECF38681}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "UDP Query User{7C7C2B68-71CB-4EE3-90D5-FB30E130BE3E}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "TCP Query User{F6EF78ED-59E0-429D-ABF9-B5448CD0DA16}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "UDP Query User{B3572E3D-8B04-4AB8-9BBB-84E860226E6B}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "TCP Query User{2E3E6A16-3C6C-49A5-AA82-3277BE5F904B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{ED08CB23-ACC6-460F-AC59-808C062BF4A6}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{5CCD2E63-6938-42B1-AE61-34E03E95B6A6}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{291AD43A-928A-467D-9F2E-319DED1A549A}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{50BA01F5-42B1-46AF-9217-4DB75EB4C1C5}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "UDP Query User{FEC47B1E-1D48-4887-8474-C94617225337}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "TCP Query User{7C99411B-0217-4247-B1C8-E67D63922DB9}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "UDP Query User{23B15472-4D99-4C2E-9791-6E86847771F4}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "TCP Query User{78342C9B-D30E-4589-AA3A-FA6020242A68}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "UDP Query User{3EC04C63-AA9D-4F3D-AC4C-8C5F61599EFE}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "TCP Query User{89D336AE-6FCA-4813-A749-4FCC0960A961}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher "UDP Query User{46FDF6C9-1276-4E3B-A62B-6266B4766F47}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher "{BEF8CCC8-B25D-481D-8FEA-5090BAF2907F}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe "{9CF5C224-7223-472F-B9D0-7DB821D592BB}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 20:19] R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32] R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 20:19] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 20:19] R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 20:19] R3 btwaudio;Bluetooth-lydenhet;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 03:37] R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 01:13] R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 01:13] R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-15 20:07] S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36] S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-04-04 14:43] S3 stusb2ir;USB 2.0 IrDA Bridge;C:\Windows\system32\DRIVERS\stusb2ir.sys [2006-11-02 09:30] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc bthsvcs REG_MULTI_SZ BthServ [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f73e66e-8eef-11dc-928a-001c26f02b6b}] \shell\AutoRun\command - F:\usdeiect.com \shell\explore\Command - F:\usdeiect.com \shell\open\Command - F:\usdeiect.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bb41413-62dc-11dc-9a64-001c26f02b6b}] \shell\AutoRun\command - F:\ntde1ect.com \shell\explore\Command - F:\ntde1ect.com \shell\open\Command - F:\ntde1ect.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6230faca-ce3d-11dc-90fa-001c26f02b6b}] \shell\AutoRun\command - b.com \shell\explore\Command - b.com \shell\open\Command - b.com *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-03 17:31:30 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-05-03 17:32:56 ComboFix-quarantined-files.txt 2008-05-03 15:32:39 ComboFix2.txt 2008-05-03 12:52:37 Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application. Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application. 245 --- E O F --- 2008-05-03 12:35:34
snippsat Skrevet 3. mai 2008 Skrevet 3. mai 2008 (endret) Nei det ble feil. "CFScript.txt..lnk" Skal kun hete "CFScript.txt" Kjør igjen tro jeg hadde et . for mye. Endret 3. mai 2008 av SNIPPSAT
Dan-The-Man Skrevet 3. mai 2008 Forfatter Skrevet 3. mai 2008 Og her har du scan loggen. Klikk for å se/fjerne innholdet nedenfor SUPERAntiSpyware Scan Loghttp://www.superantispyware.com Generated 05/03/2008 at 06:20 PM Application Version : 4.0.1154 Core Rules Database Version : 3452 Trace Rules Database Version: 1444 Scan type : Complete Scan Total Scan Time : 00:26:52 Memory items scanned : 790 Memory threats detected : 0 Registry items scanned : 6177 Registry threats detected : 13 File items scanned : 20857 File threats detected : 52 Adware.Tracking Cookie C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@atwola[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@doubleclick[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@adrevolver[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@superstats[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@atdmt[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@burstnet[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@insightexpressai[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@tribalfusion[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@clicktorrent[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@specificclick[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@casalemedia[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@2o7[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@revsci[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@zedo[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@statcounter[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@fastclick[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@advertising[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@serving-sys[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@clicksor[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@tradedoubler[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@imrworldwide[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@adtech[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@hitbox[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@realmedia[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@questionmarket[2].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@tacoda[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@apmebf[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@indextools[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@mediaplex[1].txt C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@xiti[1].txt Trojan.Media-Codec/V4 HKCR\multimediaControls.chl HKCR\multimediaControls.chl\CLSID Rogue.WinSpyKiller C:\Program Files\WinSpyKiller\WinSpyKiller.lic C:\Program Files\WinSpyKiller Rogue.MalwareCore HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781} HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\cJmgtsdL HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\cwnouQq HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\InProcServer32 HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\InProcServer32#ThreadingModel HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\lbukzrL HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\mzni HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\uiybasvhdT HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\Vihpkghw HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\WfHmyGtcd HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\wkyeofa åheidu...
Dan-The-Man Skrevet 3. mai 2008 Forfatter Skrevet 3. mai 2008 Nei det ble feil."CFScript.txt..lnk" Skal kun hete "CFScript.txt" Kjør igjen tro jeg hadde et . for mye. Oisann.. nå leste ikke jeg det her før virus scanen var posta men... skal jeg bare sjekke den med combofix en gang til da? og btw, autolagrer den til "CFScript.txt."?
Dan-The-Man Skrevet 3. mai 2008 Forfatter Skrevet 3. mai 2008 Nei det ble feil."CFScript.txt..lnk" Skal kun hete "CFScript.txt" Kjør igjen tro jeg hadde et . for mye. Oisann.. nå leste ikke jeg det her før virus scanen var posta men... skal jeg bare sjekke den med combofix en gang til da? og btw, autolagrer den til "CFScript.txt."? det var nok jeg som satte inn det ekstra punktumet:blush: Men har det noe å si for scriptet?
snippsat Skrevet 3. mai 2008 Skrevet 3. mai 2008 Ja du må kjøre på nytt virker ikke med et . for mye.
Dan-The-Man Skrevet 3. mai 2008 Forfatter Skrevet 3. mai 2008 Ja du må kjøre på nytt virker ikke med et . for mye. Alright..kommer her Klikk for å se/fjerne innholdet nedenfor ComboFix 08-04-27.3 - Daniel 2008-05-03 20:27:52.3 - NTFSx86Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1044.18.1052 [GMT 2:00] Running from: C:\Users\Daniel\Desktop\ComboFix.exe Command switches used :: C:\Users\Daniel\Desktop\CFScript.txt * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-03 15:51 --------- d-----w C:\Users\Daniel\AppData\Roaming\SUPERAntiSpyware.com 2008-05-03 15:51 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com 2008-05-03 15:51 --------- d-----w C:\Program Files\SUPERAntiSpyware 2008-05-03 15:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-05-03 15:48 --------- d-----w C:\ProgramData\Yahoo! Companion 2008-05-03 15:42 --------- d-----w C:\Program Files\Yahoo! 2008-05-03 15:42 --------- d-----w C:\Program Files\CCleaner 2008-05-03 14:55 --------- d-----w C:\Users\Daniel\AppData\Roaming\LimeWire 2008-05-03 14:18 --------- d-----w C:\Users\Daniel\AppData\Roaming\dvdcss 2008-05-03 12:45 1,422 ----a-w C:\Users\Daniel\AppData\Roaming\wklnhst.dat 2008-05-02 08:18 --------- d-----w C:\Program Files\Steam 2008-05-01 21:55 --------- d-----w C:\ProgramData\Messenger Plus! 2008-05-01 21:54 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-05-01 12:18 --------- d-----w C:\Program Files\IDT 2008-05-01 11:28 1,552 ----a-w C:\Windows\system32\drivers\stwrte.log 2008-04-28 20:31 --------- d-----w C:\Program Files\Counter-Strike 1.6 2008-04-28 19:40 --------- d-----w C:\Program Files\Windows Mail 2008-04-28 19:37 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-04-28 19:31 --------- d---a-w C:\ProgramData\TEMP 2008-04-28 18:19 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys 2008-04-28 18:19 67,080 ----a-w C:\Windows\system32\drivers\avgwfpx.sys 2008-04-28 18:19 10,520 ----a-w C:\Windows\System32\avgrsstx.dll 2008-04-28 18:19 --------- d-----w C:\ProgramData\avg8 2008-04-28 18:19 --------- d-----w C:\Program Files\AVG 2008-04-22 15:44 --------- d-----w C:\Program Files\Trend Micro 2008-04-22 14:17 --------- d-----w C:\Program Files\Apple Software Update 2008-04-19 19:19 --------- d-----w C:\Program Files\The Seal Hunter 2008-04-12 18:56 --------- d-----w C:\Users\Daniel\AppData\Roaming\Apple Computer 2008-04-10 20:38 --------- d-----w C:\Program Files\Wfwin 2008-04-10 17:38 --------- d-----w C:\Program Files\Google 2008-04-08 17:25 --------- d-----w C:\Program Files\SwiftSwitch 2008-04-06 16:14 --------- d-----w C:\ProgramData\Roxio 2008-04-04 12:43 --------- d-----w C:\Program Files\Common Files\Steam 2008-04-04 09:48 --------- d-----w C:\Program Files\iTunes 2008-04-04 09:47 --------- d-----w C:\Program Files\iPod 2008-04-04 09:44 --------- d-----w C:\Program Files\QuickTime 2008-03-30 13:16 --------- d-----w C:\Program Files\SystemRequirementsLab 2008-03-30 11:07 --------- d-----w C:\Program Files\Dell 2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys 2008-03-27 18:06 --------- d-----w C:\Users\Daniel\AppData\Roaming\Talkback 2008-03-14 15:39 --------- d-----w C:\Users\Daniel\AppData\Roaming\Leadertech 2008-03-14 15:37 --------- d-----w C:\Program Files\Common Files\Adobe 2008-03-13 16:36 --------- d-----w C:\ProgramData\Documents 2008-03-13 16:16 --------- d-----w C:\Users\Daniel\AppData\Roaming\AdobeUM 2008-03-13 07:13 --------- d-----w C:\ProgramData\Skype 2008-03-05 14:42 --------- d-----w C:\Users\Daniel\AppData\Roaming\Azureus 2008-03-05 14:39 --------- d-----w C:\Program Files\BitLord2 2008-03-05 14:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll 2008-03-05 14:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll 2008-03-05 14:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll 2008-03-05 13:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll 2008-03-05 13:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll 2008-03-04 16:00 --------- d-----w C:\Program Files\Common Files\PX Storage Engine 2008-03-03 15:25 --------- d-----w C:\Program Files\Windows Live Toolbar 2008-03-03 15:23 --------- d-----w C:\Program Files\Windows Live 2008-03-03 15:22 --------- d-----w C:\Users\Daniel\AppData\Roaming\Windows Live Writer 2008-03-03 15:13 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-03-03 15:10 --------- d-----w C:\ProgramData\Telenor 2008-03-03 15:10 --------- d-----w C:\Program Files\Telenor 2008-03-03 15:06 --------- d-----w C:\ProgramData\McAfee 2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll 2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll 2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll 2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe 2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe 2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll 2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll 2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys 2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll 2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll 2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll 2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll 2008-02-16 10:40 736,220,974 ----a-w C:\Program Files\Image_080216_1134.gi 2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe 2008-02-14 22:19 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-02-14 22:14 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-02-14 22:14 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-02-14 22:14 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll 2008-02-05 21:07 462,864 ----a-w C:\Windows\System32\d3dx10_37.dll 2007-09-12 14:58 174 --sha-w C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((( snapshot@2008-05-03_14.52.05.97 ))))))))))))))))))))))))))))))))))))))))) . + 2008-05-03 15:51:12 18,944 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe + 2008-05-03 15:51:12 65,024 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe - 2008-05-03 12:32:14 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-05-03 17:31:56 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat - 2008-05-03 12:48:49 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-05-03 18:27:26 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat - 2008-05-02 08:19:57 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-05-03 15:41:58 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2008-05-02 08:19:57 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-05-03 15:41:58 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-05-02 08:19:57 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-05-03 15:41:58 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}] 2008-04-28 20:19 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-28 20:19 2050816] [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}] [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-28 20:19 2050816] [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}] [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-06 11:14 1006264] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-15 20:08 98304] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-15 20:07 106496] "Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-15 20:07 81920] "SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-09-06 03:35 77824] "Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2006-11-28 01:15 1540096] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 12:50 17920] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-06 03:51 1862144] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 20:19 1177368] "SigmatelSysTrayApp"="sttray.exe" [2007-02-08 07:11 303104 C:\Windows\sttray.exe] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1820041221-4144176497-4136927534-1000] "EnableNotificationsRef"=dword:00000008 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{F215BAA5-362F-4388-AFB1-7046BFAA6723}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{7A802F48-2B53-4130-946E-02F1E58FC4DB}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{F82B975B-F725-429E-9F1F-B96A0E72F07F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{604116BB-2FC4-49B9-971D-5AF2FCA8893F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{0A101FA8-F434-4164-9A2F-09CA54E12BFB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "{6901F69B-90E8-4B5A-BEF3-25FA0CB3EDDA}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{426750E8-61D5-4375-AD6B-12F92C50E891}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{6016AB2B-A412-4B89-B75A-E7679AE54BA4}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{79E3EFAF-AA4E-4CBF-8F10-C9AA9AD53C3E}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{EE8173FC-0612-4E04-A899-EC46867489AD}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8 "{0C59E7F3-DEB7-4D42-A491-CE892D781337}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8 "{1425428C-4109-4316-8F5E-C55A965B6671}"= %ProgramFiles%\Telenor\Online Start\Telenor.exe:Online Start "TCP Query User{435687BA-EDE5-489F-937C-56B8E42D22DE}C:\\program files\\counter-strike 1.6\\hl.exe"= UDP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher "UDP Query User{10A1F102-F7AF-4CFE-8F31-54DEA12950FD}C:\\program files\\counter-strike 1.6\\hl.exe"= TCP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher "{4E43A063-F692-44EF-AF4D-614ED8352E85}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{43610C69-9580-454F-B469-448C47967CFD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype "TCP Query User{0D93150B-5E89-48DC-A0AA-D0DBF0DD603E}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe: "UDP Query User{9C2AF00F-6378-4D6D-917F-EF374325494C}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe: "{90CE36F8-B55F-4115-BE2F-28DE89586BEC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "TCP Query User{C70CD4EE-896E-4332-A182-5A070CC2B29B}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus "UDP Query User{D739FDEF-97B6-4D09-AE23-BD61FB5E216B}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus "TCP Query User{9FF94F28-2E16-40B6-AFC3-EDB605E3EF10}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2 "UDP Query User{FA364296-73CD-4E26-9B77-227818D98B6E}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2 "TCP Query User{D63ED578-202D-4FD7-9CDC-60E0057031A8}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{7F36C02B-708B-49C9-B79F-7A2258B1C906}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "TCP Query User{AC1F5B1C-5B2C-43EF-9B59-72298EDA889D}C:\\program files\\counter-strike 1.6\\hlds.exe"= UDP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher "UDP Query User{514EAB2F-2F8A-4173-9AF5-B4C54E6EA3E4}C:\\program files\\counter-strike 1.6\\hlds.exe"= TCP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher "{59217433-9C36-4E8F-A684-A5CE4C6C28AF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{C4FC3841-7F9F-4554-ACD4-0C96FCE38D2F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "TCP Query User{33B6A06F-FF30-42A0-8576-0A7157E826D9}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{44A96FEE-281B-4F98-B638-3EAA2297B82C}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{48610643-8143-49B8-80DF-509C116C4D88}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "UDP Query User{04048DEA-4972-4E82-8634-F115A6B4A415}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "TCP Query User{4CB1FA52-F0C9-4624-B90A-3332E795044B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{B9F1CE36-C5DA-4234-92AE-D3CFEC19B393}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{126EAD4D-4057-4D2E-AB75-0188ECF38681}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "UDP Query User{7C7C2B68-71CB-4EE3-90D5-FB30E130BE3E}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "TCP Query User{F6EF78ED-59E0-429D-ABF9-B5448CD0DA16}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "UDP Query User{B3572E3D-8B04-4AB8-9BBB-84E860226E6B}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "TCP Query User{2E3E6A16-3C6C-49A5-AA82-3277BE5F904B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{ED08CB23-ACC6-460F-AC59-808C062BF4A6}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{5CCD2E63-6938-42B1-AE61-34E03E95B6A6}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{291AD43A-928A-467D-9F2E-319DED1A549A}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher "TCP Query User{50BA01F5-42B1-46AF-9217-4DB75EB4C1C5}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "UDP Query User{FEC47B1E-1D48-4887-8474-C94617225337}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2 "TCP Query User{7C99411B-0217-4247-B1C8-E67D63922DB9}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "UDP Query User{23B15472-4D99-4C2E-9791-6E86847771F4}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher "TCP Query User{78342C9B-D30E-4589-AA3A-FA6020242A68}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "UDP Query User{3EC04C63-AA9D-4F3D-AC4C-8C5F61599EFE}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2 "TCP Query User{89D336AE-6FCA-4813-A749-4FCC0960A961}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher "UDP Query User{46FDF6C9-1276-4E3B-A62B-6266B4766F47}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher "{BEF8CCC8-B25D-481D-8FEA-5090BAF2907F}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe "{9CF5C224-7223-472F-B9D0-7DB821D592BB}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 20:19] R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32] R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 20:19] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 20:19] R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 20:19] R3 btwaudio;Bluetooth-lydenhet;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 03:37] R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 01:13] R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 01:13] R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-15 20:07] S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36] S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-04-04 14:43] S3 stusb2ir;USB 2.0 IrDA Bridge;C:\Windows\system32\DRIVERS\stusb2ir.sys [2006-11-02 09:30] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc bthsvcs REG_MULTI_SZ BthServ *Newly Created Service* - CATCHME *Newly Created Service* - SASDIFSV *Newly Created Service* - SASENUM *Newly Created Service* - SASKUTIL . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-03 20:29:34 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-05-03 20:31:04 ComboFix-quarantined-files.txt 2008-05-03 18:30:31 ComboFix2.txt 2008-05-03 15:36:28 Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application. Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application. 252 --- E O F --- 2008-05-03 12:35:34 nå da? men det stod et . bak txt denne gangen også
Dan-The-Man Skrevet 3. mai 2008 Forfatter Skrevet 3. mai 2008 Gikk greit nå.Og en ny hijackthis-logg. Her kommer hijackthis-log.. og nok en gang... mange takk for det her! jeg merker at pcen er betydelig raskere når jeg f. eks booter her er log! Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2Scan saved at 22:13:48, on 03.05.2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Windows\sttray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O1 - Hosts: ::1 localhost O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll O2 - BHO: (no name) - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file) O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file) O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETTVERKSTJENESTE') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: QuickSet.lnk = ? O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O13 - Gopher Prefix: O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 9249 bytes
snippsat Skrevet 3. mai 2008 Skrevet 3. mai 2008 (endret) Start HijackThis "scan" finn disse linjene merk dem,så trykk fix checked. O2 - BHO: (no name) - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file) O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file) Da er du ren for grums Bruk pcen kjører den greit kan du gjøre dette. Du kan fjerne combofix ved å skrive combofix /u fra kjør-vinduet. Denne kommandoen gjør at filer i karantene og backups blir slette. Systemgjenopprettingsmappa nullstilt etc. Du får se om dette har hjelpet på problemet. Endret 3. mai 2008 av SNIPPSAT
Dan-The-Man Skrevet 4. mai 2008 Forfatter Skrevet 4. mai 2008 Da er det bare å si tusen takk. har ikke brukt internettet noe serlig enda, men den har ikke skrudd seg av Glemte og si at det hjalp å søke på windows update, da ordna det seg intill neste gang. Men uansett så har jeg fårr renska pcen godt nå all cred to SNIPPSAT
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå