Gå til innhold
Trenger du hjelp med PCen? Still spørsmål her! ×

internett leseren slutter å virke


Anbefalte innlegg

Skrevet
Oppdatert router til siste firmware?

 

Har det bestandig vært slik eller kom problemet etter at du installerte Vista x64?

 

Kan jo komme av at Routeren ikke er 100% kompatibel med Vista, og trenger en oppdatering på Firmware.

 

 

Si navnet på routeren så kan jeg finne de siste oppdateringene for den om du ønsker.

har bestandig vært sånn, og jeg har btw vista 32-bit

routeren er en speedtouch multimodem-ST 780WLT

Videoannonse
Annonse
Skrevet (endret)
Prøvde og gi noen råd i post 10.

Kansje gjøre det ;)

beklager, trodde jeg hadde gjort det...

Klikk for å se/fjerne innholdet nedenfor
Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:32, on 2008-05-01

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Windows\System32\WLTRAY.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Windows\sttray.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe

C:\Program Files\iTunes\iTunes.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Servi...omeLeftPane.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer levert av Dell

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll

O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)

O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll (file missing)

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"

O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [steam] "c:\program files\steam\steam.exe" -silent

O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe

O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETTVERKSTJENESTE')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O4 - Global Startup: QuickSet.lnk = ?

O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)

O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O13 - Gopher Prefix:

O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 10431 bytes

Endret av Dan-The-Man
Skrevet (endret)

Har problemer med dette selv. MSN fungerer ikke. Proxy-innstillinger elle brannmur-innstillinger er feil, visstnok. Utrolig nok kan jeg åpne diskusjon.no, men den bruker omtrent et minutt (eller mer) hver gang den laster en side. Jeg er tilkoblet og alt er fint sånn sett. Men internettet oppfører seg rart. Hva er feil? Den klarer ikke laste Gunners.no eller vg, i alle fall. Jeg skjønner ikke hvorfor diskusjon.no funker. "Problem ved lasting av side", står det.

 

Dessuten når jeg diagnostiserer, står det at den ikke kan kommunisere. Og da kan man tilbakestille nettverkskortet. Men dette hjelper ikke. Fortsatt like ødelagt som før. Noen ganger står det også at TCP (eller noe sånt) ikke er kompatibel med ruter.

 

Jeg kan ingenting om data og skjønner ingenting nå heller. Kan noen hjelpe? Vet dette var rotete forklart.

 

 

Edit: Det har fikset seg nå. Antakelig bare et forbigående problem.

Endret av Faces Down
Skrevet
Har problemer med dette selv. MSN fungerer ikke. Proxy-innstillinger elle brannmur-innstillinger er feil, visstnok. Utrolig nok kan jeg åpne diskusjon.no, men den bruker omtrent et minutt (eller mer) hver gang den laster en side. Jeg er tilkoblet og alt er fint sånn sett. Men internettet oppfører seg rart. Hva er feil? Den klarer ikke laste Gunners.no eller vg, i alle fall. Jeg skjønner ikke hvorfor diskusjon.no funker. "Problem ved lasting av side", står det.

 

Dessuten når jeg diagnostiserer, står det at den ikke kan kommunisere. Og da kan man tilbakestille nettverkskortet. Men dette hjelper ikke. Fortsatt like ødelagt som før. Noen ganger står det også at TCP (eller noe sånt) ikke er kompatibel med ruter.

 

Jeg kan ingenting om data og skjønner ingenting nå heller. Kan noen hjelpe? Vet dette var rotete forklart.

 

 

Edit: Det har fikset seg nå. Antakelig bare et forbigående problem.

 

Har du tuklet med nettverkskortet? :)

Har du antivirus? <-Kjekt å ha!

 

Står ip-adressen på nettverkskortet ditt på automatisk??

(Hvis det ikke funker prøv å restart ruteren) :hmm:

Skrevet

Jeg hadde også det problemet at internettleseren ofte gikk tregt og stoppet opp mens alt annet fungerte, særlig hvis jeg lastet ned i uTorrent. Løsningen var å laste ned denne tcp/ip patchen http://www.lvllord.de/?lang=en&url=downloads

 

Måtte i kjøre den i fra kommandolinjen (Start - Run.../Kjør... - cmd) for å få lagt inn patchen.

 

Enkelte antivirus kan gi advarsel om "hack tool" eller lignende, men det er bare å ignorere. Filen er trygg.

 

Etter at jeg la inn denne tcp/ip patchen, forsvant problemet.

Skrevet (endret)

Du har noe grums ja,dette må fjernes.

 

Disable antivirus-brannvegg når du kjører combofix.

Last Combofix ned ,legg på skrivebordet.

Ikke klikk på vindu mens programet kjører.

post logg C:\combofix.txt

 

tcp/ip patchen, forsvant problemet

Tcp/ip patch kan hjelpe ja

Endret av SNIPPSAT
Skrevet
Du har noe grums ja,dette må fjernes.

 

Disable antivirus-brannvegg når du kjører combofix.

Last Combofix ned ,legg på skrivebordet.

Ikke klikk på vindu mens programet kjører.

post logg C:\combofix.txt

 

tcp/ip patchen, forsvant problemet

Tcp/ip patch kan hjelpe ja

 

will do!

 

Klikk for å se/fjerne innholdet nedenfor
ComboFix 08-04-27.3 - Daniel 2008-05-03 14:48:40.1 - NTFSx86

Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1044.18.1068 [GMT 2:00]

Running from: C:\Users\Daniel\Desktop\ComboFix1.exe

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Program Files\FunWebProducts

C:\Program Files\MyWebSearch

C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat

C:\Windows\system32\x64

 

.

((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))

.

 

No new files created in this timespan

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-03 12:45 1,422 ----a-w C:\Users\Daniel\AppData\Roaming\wklnhst.dat

2008-05-02 11:17 --------- d-----w C:\Users\Daniel\AppData\Roaming\LimeWire

2008-05-02 08:18 --------- d-----w C:\Program Files\Steam

2008-05-01 21:55 --------- d-----w C:\ProgramData\Messenger Plus!

2008-05-01 21:54 --------- d-----w C:\Program Files\Messenger Plus! Live

2008-05-01 12:18 --------- d-----w C:\Program Files\IDT

2008-05-01 11:28 1,552 ----a-w C:\Windows\system32\drivers\stwrte.log

2008-04-28 20:31 --------- d-----w C:\Program Files\Counter-Strike 1.6

2008-04-28 19:40 --------- d-----w C:\Program Files\Windows Mail

2008-04-28 19:37 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-04-28 19:31 --------- d---a-w C:\ProgramData\TEMP

2008-04-28 19:31 --------- d-----w C:\Program Files\WinSpyKiller

2008-04-28 18:19 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys

2008-04-28 18:19 67,080 ----a-w C:\Windows\system32\drivers\avgwfpx.sys

2008-04-28 18:19 10,520 ----a-w C:\Windows\System32\avgrsstx.dll

2008-04-28 18:19 --------- d-----w C:\ProgramData\avg8

2008-04-28 18:19 --------- d-----w C:\Program Files\AVG

2008-04-22 15:44 --------- d-----w C:\Program Files\Trend Micro

2008-04-22 14:17 --------- d-----w C:\Program Files\Apple Software Update

2008-04-22 13:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-04-20 16:46 --------- d-----w C:\ProgramData\Symantec

2008-04-19 19:19 --------- d-----w C:\Program Files\The Seal Hunter

2008-04-12 18:56 --------- d-----w C:\Users\Daniel\AppData\Roaming\Apple Computer

2008-04-10 20:38 --------- d-----w C:\Program Files\Wfwin

2008-04-10 17:38 --------- d-----w C:\Program Files\Google

2008-04-08 17:25 --------- d-----w C:\Program Files\SwiftSwitch

2008-04-06 16:14 --------- d-----w C:\ProgramData\Roxio

2008-04-04 12:43 --------- d-----w C:\Program Files\Common Files\Steam

2008-04-04 09:48 --------- d-----w C:\Program Files\iTunes

2008-04-04 09:47 --------- d-----w C:\Program Files\iPod

2008-04-04 09:44 --------- d-----w C:\Program Files\QuickTime

2008-03-30 13:16 --------- d-----w C:\Program Files\SystemRequirementsLab

2008-03-30 11:07 --------- d-----w C:\Program Files\Dell

2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys

2008-03-27 18:06 --------- d-----w C:\Users\Daniel\AppData\Roaming\Talkback

2008-03-14 15:39 --------- d-----w C:\Users\Daniel\AppData\Roaming\Leadertech

2008-03-14 15:37 --------- d-----w C:\Program Files\Common Files\Adobe

2008-03-13 16:36 --------- d-----w C:\ProgramData\Documents

2008-03-13 16:16 --------- d-----w C:\Users\Daniel\AppData\Roaming\AdobeUM

2008-03-13 07:13 --------- d-----w C:\ProgramData\Skype

2008-03-05 14:42 --------- d-----w C:\Users\Daniel\AppData\Roaming\Azureus

2008-03-05 14:39 --------- d-----w C:\Program Files\BitLord2

2008-03-05 14:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll

2008-03-05 14:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll

2008-03-05 14:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll

2008-03-05 13:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll

2008-03-05 13:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll

2008-03-04 16:00 --------- d-----w C:\Program Files\Common Files\PX Storage Engine

2008-03-03 15:25 --------- d-----w C:\Program Files\Windows Live Toolbar

2008-03-03 15:23 --------- d-----w C:\Program Files\Windows Live

2008-03-03 15:22 --------- d-----w C:\Users\Daniel\AppData\Roaming\Windows Live Writer

2008-03-03 15:13 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-03-03 15:10 --------- d-----w C:\ProgramData\Telenor

2008-03-03 15:10 --------- d-----w C:\Program Files\Telenor

2008-03-03 15:06 --------- d-----w C:\ProgramData\McAfee

2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll

2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll

2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll

2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe

2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe

2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll

2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll

2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys

2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll

2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll

2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll

2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe

2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll

2008-02-16 10:40 736,220,974 ----a-w C:\Program Files\Image_080216_1134.gi

2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe

2008-02-14 22:19 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-02-14 22:14 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-02-14 22:14 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-02-14 22:14 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll

2008-02-05 21:07 462,864 ----a-w C:\Windows\System32\d3dx10_37.dll

2007-09-12 14:58 174 --sha-w C:\Program Files\desktop.ini

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]

2008-04-28 20:19 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-28 20:19 2050816]

 

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]

[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-28 20:19 2050816]

 

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]

[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-06 11:14 1006264]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-15 20:08 98304]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-15 20:07 106496]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-15 20:07 81920]

"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-09-06 03:35 77824]

"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2006-11-28 01:15 1540096]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]

"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 12:50 17920]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-06 03:51 1862144]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]

"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [ ]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]

"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [ ]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 20:19 1177368]

"SigmatelSysTrayApp"="sttray.exe" [2007-02-08 07:11 303104 C:\Windows\sttray.exe]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1820041221-4144176497-4136927534-1000]

"EnableNotificationsRef"=dword:00000008

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{F215BAA5-362F-4388-AFB1-7046BFAA6723}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{7A802F48-2B53-4130-946E-02F1E58FC4DB}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{F82B975B-F725-429E-9F1F-B96A0E72F07F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{604116BB-2FC4-49B9-971D-5AF2FCA8893F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{0A101FA8-F434-4164-9A2F-09CA54E12BFB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{6901F69B-90E8-4B5A-BEF3-25FA0CB3EDDA}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{426750E8-61D5-4375-AD6B-12F92C50E891}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{6016AB2B-A412-4B89-B75A-E7679AE54BA4}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{79E3EFAF-AA4E-4CBF-8F10-C9AA9AD53C3E}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{EE8173FC-0612-4E04-A899-EC46867489AD}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8

"{0C59E7F3-DEB7-4D42-A491-CE892D781337}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8

"{1425428C-4109-4316-8F5E-C55A965B6671}"= %ProgramFiles%\Telenor\Online Start\Telenor.exe:Online Start

"TCP Query User{435687BA-EDE5-489F-937C-56B8E42D22DE}C:\\program files\\counter-strike 1.6\\hl.exe"= UDP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher

"UDP Query User{10A1F102-F7AF-4CFE-8F31-54DEA12950FD}C:\\program files\\counter-strike 1.6\\hl.exe"= TCP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher

"{4E43A063-F692-44EF-AF4D-614ED8352E85}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{43610C69-9580-454F-B469-448C47967CFD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"TCP Query User{0D93150B-5E89-48DC-A0AA-D0DBF0DD603E}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:

"UDP Query User{9C2AF00F-6378-4D6D-917F-EF374325494C}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:

"{90CE36F8-B55F-4115-BE2F-28DE89586BEC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"TCP Query User{C70CD4EE-896E-4332-A182-5A070CC2B29B}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus

"UDP Query User{D739FDEF-97B6-4D09-AE23-BD61FB5E216B}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus

"TCP Query User{9FF94F28-2E16-40B6-AFC3-EDB605E3EF10}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2

"UDP Query User{FA364296-73CD-4E26-9B77-227818D98B6E}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2

"TCP Query User{D63ED578-202D-4FD7-9CDC-60E0057031A8}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

"UDP Query User{7F36C02B-708B-49C9-B79F-7A2258B1C906}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

"TCP Query User{AC1F5B1C-5B2C-43EF-9B59-72298EDA889D}C:\\program files\\counter-strike 1.6\\hlds.exe"= UDP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher

"UDP Query User{514EAB2F-2F8A-4173-9AF5-B4C54E6EA3E4}C:\\program files\\counter-strike 1.6\\hlds.exe"= TCP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher

"{59217433-9C36-4E8F-A684-A5CE4C6C28AF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{C4FC3841-7F9F-4554-ACD4-0C96FCE38D2F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"TCP Query User{33B6A06F-FF30-42A0-8576-0A7157E826D9}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{44A96FEE-281B-4F98-B638-3EAA2297B82C}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{48610643-8143-49B8-80DF-509C116C4D88}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"UDP Query User{04048DEA-4972-4E82-8634-F115A6B4A415}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"TCP Query User{4CB1FA52-F0C9-4624-B90A-3332E795044B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{B9F1CE36-C5DA-4234-92AE-D3CFEC19B393}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{126EAD4D-4057-4D2E-AB75-0188ECF38681}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"UDP Query User{7C7C2B68-71CB-4EE3-90D5-FB30E130BE3E}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"TCP Query User{F6EF78ED-59E0-429D-ABF9-B5448CD0DA16}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"UDP Query User{B3572E3D-8B04-4AB8-9BBB-84E860226E6B}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"TCP Query User{2E3E6A16-3C6C-49A5-AA82-3277BE5F904B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{ED08CB23-ACC6-460F-AC59-808C062BF4A6}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{5CCD2E63-6938-42B1-AE61-34E03E95B6A6}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{291AD43A-928A-467D-9F2E-319DED1A549A}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{50BA01F5-42B1-46AF-9217-4DB75EB4C1C5}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"UDP Query User{FEC47B1E-1D48-4887-8474-C94617225337}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"TCP Query User{7C99411B-0217-4247-B1C8-E67D63922DB9}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"UDP Query User{23B15472-4D99-4C2E-9791-6E86847771F4}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"TCP Query User{78342C9B-D30E-4589-AA3A-FA6020242A68}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"UDP Query User{3EC04C63-AA9D-4F3D-AC4C-8C5F61599EFE}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"TCP Query User{89D336AE-6FCA-4813-A749-4FCC0960A961}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher

"UDP Query User{46FDF6C9-1276-4E3B-A62B-6266B4766F47}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher

"{BEF8CCC8-B25D-481D-8FEA-5090BAF2907F}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe

"{9CF5C224-7223-472F-B9D0-7DB821D592BB}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 20:19]

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]

R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 20:19]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 20:19]

R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 20:19]

R3 btwaudio;Bluetooth-lydenhet;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 03:37]

R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 01:13]

R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 01:13]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-15 20:07]

S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]

S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-04-04 14:43]

S3 stusb2ir;USB 2.0 IrDA Bridge;C:\Windows\system32\DRIVERS\stusb2ir.sys [2006-11-02 09:30]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

bthsvcs REG_MULTI_SZ BthServ

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f73e66e-8eef-11dc-928a-001c26f02b6b}]

\shell\AutoRun\command - F:\usdeiect.com

\shell\explore\Command - F:\usdeiect.com

\shell\open\Command - F:\usdeiect.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bb41413-62dc-11dc-9a64-001c26f02b6b}]

\shell\AutoRun\command - F:\ntde1ect.com

\shell\explore\Command - F:\ntde1ect.com

\shell\open\Command - F:\ntde1ect.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6230faca-ce3d-11dc-90fa-001c26f02b6b}]

\shell\AutoRun\command - b.com

\shell\explore\Command - b.com

\shell\open\Command - b.com

 

*Newly Created Service* - CATCHME

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-03 14:51:23

Windows 6.0.6000 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-05-03 14:52:37

ComboFix-quarantined-files.txt 2008-05-03 12:52:20

 

Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application.

Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application.

 

245 --- E O F --- 2008-05-03 12:35:34

 

takk for at du tar deg tid til det her :p

Skrevet (endret)

Slett mapper.

C:\Program Files\Common Files\Symantec Shared

C:\ProgramData\Symantec

 

Kopiere fet tekst under bildet->åpne notisblokk og lim inn.

Lagre på skrivebordet som CFScript.txt

Gjør som på bildet combofix vil starte,Post logg c:\combofix.txt

cfscriptyt1.gif

 

Folder::

C:\Program Files\WinSpyKiller

 

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"My Web Search Bar Search Scope Monitor"=-

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f73e66e-8eef-11dc-928a-001c26f02b6b}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bb41413-62dc-11dc-9a64-001c26f02b6b}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6230faca-ce3d-11dc-90fa-001c26f02b6b}]

 

Last ned kjør CCleaner

'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t.

Kjør register-renser og"svar ja til og reparere"

---

Last ned oppdatere og kjør full scan SAS free

Post loggen fra SAS (preferences->statistics/logs)

---

Restart og en ny HijackThis logg.

Endret av SNIPPSAT
Skrevet

her kommer logg for combofix.txt

 

Klikk for å se/fjerne innholdet nedenfor
ComboFix 08-04-27.3 - Daniel 2008-05-03 17:29:28.2 - NTFSx86

Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1044.18.862 [GMT 2:00]

Running from: C:\Users\Daniel\Desktop\ComboFix1.exe

Command switches used :: C:\Users\Daniel\Desktop\CFScript.txt..lnk

* Created a new restore point

.

 

((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))

.

 

No new files created in this timespan

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-03 14:55 --------- d-----w C:\Users\Daniel\AppData\Roaming\LimeWire

2008-05-03 14:18 --------- d-----w C:\Users\Daniel\AppData\Roaming\dvdcss

2008-05-03 12:45 1,422 ----a-w C:\Users\Daniel\AppData\Roaming\wklnhst.dat

2008-05-02 08:18 --------- d-----w C:\Program Files\Steam

2008-05-01 21:55 --------- d-----w C:\ProgramData\Messenger Plus!

2008-05-01 21:54 --------- d-----w C:\Program Files\Messenger Plus! Live

2008-05-01 12:18 --------- d-----w C:\Program Files\IDT

2008-05-01 11:28 1,552 ----a-w C:\Windows\system32\drivers\stwrte.log

2008-04-28 20:31 --------- d-----w C:\Program Files\Counter-Strike 1.6

2008-04-28 19:40 --------- d-----w C:\Program Files\Windows Mail

2008-04-28 19:37 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-04-28 19:31 --------- d---a-w C:\ProgramData\TEMP

2008-04-28 19:31 --------- d-----w C:\Program Files\WinSpyKiller

2008-04-28 18:19 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys

2008-04-28 18:19 67,080 ----a-w C:\Windows\system32\drivers\avgwfpx.sys

2008-04-28 18:19 10,520 ----a-w C:\Windows\System32\avgrsstx.dll

2008-04-28 18:19 --------- d-----w C:\ProgramData\avg8

2008-04-28 18:19 --------- d-----w C:\Program Files\AVG

2008-04-22 15:44 --------- d-----w C:\Program Files\Trend Micro

2008-04-22 14:17 --------- d-----w C:\Program Files\Apple Software Update

2008-04-19 19:19 --------- d-----w C:\Program Files\The Seal Hunter

2008-04-12 18:56 --------- d-----w C:\Users\Daniel\AppData\Roaming\Apple Computer

2008-04-10 20:38 --------- d-----w C:\Program Files\Wfwin

2008-04-10 17:38 --------- d-----w C:\Program Files\Google

2008-04-08 17:25 --------- d-----w C:\Program Files\SwiftSwitch

2008-04-06 16:14 --------- d-----w C:\ProgramData\Roxio

2008-04-04 12:43 --------- d-----w C:\Program Files\Common Files\Steam

2008-04-04 09:48 --------- d-----w C:\Program Files\iTunes

2008-04-04 09:47 --------- d-----w C:\Program Files\iPod

2008-04-04 09:44 --------- d-----w C:\Program Files\QuickTime

2008-03-30 13:16 --------- d-----w C:\Program Files\SystemRequirementsLab

2008-03-30 11:07 --------- d-----w C:\Program Files\Dell

2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys

2008-03-27 18:06 --------- d-----w C:\Users\Daniel\AppData\Roaming\Talkback

2008-03-14 15:39 --------- d-----w C:\Users\Daniel\AppData\Roaming\Leadertech

2008-03-14 15:37 --------- d-----w C:\Program Files\Common Files\Adobe

2008-03-13 16:36 --------- d-----w C:\ProgramData\Documents

2008-03-13 16:16 --------- d-----w C:\Users\Daniel\AppData\Roaming\AdobeUM

2008-03-13 07:13 --------- d-----w C:\ProgramData\Skype

2008-03-05 14:42 --------- d-----w C:\Users\Daniel\AppData\Roaming\Azureus

2008-03-05 14:39 --------- d-----w C:\Program Files\BitLord2

2008-03-05 14:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll

2008-03-05 14:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll

2008-03-05 14:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll

2008-03-05 13:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll

2008-03-05 13:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll

2008-03-04 16:00 --------- d-----w C:\Program Files\Common Files\PX Storage Engine

2008-03-03 15:25 --------- d-----w C:\Program Files\Windows Live Toolbar

2008-03-03 15:23 --------- d-----w C:\Program Files\Windows Live

2008-03-03 15:22 --------- d-----w C:\Users\Daniel\AppData\Roaming\Windows Live Writer

2008-03-03 15:13 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-03-03 15:10 --------- d-----w C:\ProgramData\Telenor

2008-03-03 15:10 --------- d-----w C:\Program Files\Telenor

2008-03-03 15:06 --------- d-----w C:\ProgramData\McAfee

2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll

2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll

2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll

2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe

2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe

2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll

2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll

2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys

2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll

2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll

2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll

2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe

2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll

2008-02-16 10:40 736,220,974 ----a-w C:\Program Files\Image_080216_1134.gi

2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe

2008-02-14 22:19 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-02-14 22:14 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-02-14 22:14 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-02-14 22:14 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll

2008-02-05 21:07 462,864 ----a-w C:\Windows\System32\d3dx10_37.dll

2007-09-12 14:58 174 --sha-w C:\Program Files\desktop.ini

.

 

((((((((((((((((((((((((((((( snapshot@2008-05-03_14.52.05.97 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-05-03 12:32:14 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-05-03 14:31:48 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat

- 2008-05-03 12:48:49 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-05-03 15:28:52 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]

2008-04-28 20:19 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-28 20:19 2050816]

 

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]

[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-28 20:19 2050816]

 

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]

[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-06 11:14 1006264]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-15 20:08 98304]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-15 20:07 106496]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-15 20:07 81920]

"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-09-06 03:35 77824]

"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2006-11-28 01:15 1540096]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]

"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 12:50 17920]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-06 03:51 1862144]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]

"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [ ]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]

"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [ ]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 20:19 1177368]

"SigmatelSysTrayApp"="sttray.exe" [2007-02-08 07:11 303104 C:\Windows\sttray.exe]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1820041221-4144176497-4136927534-1000]

"EnableNotificationsRef"=dword:00000008

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{F215BAA5-362F-4388-AFB1-7046BFAA6723}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{7A802F48-2B53-4130-946E-02F1E58FC4DB}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{F82B975B-F725-429E-9F1F-B96A0E72F07F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{604116BB-2FC4-49B9-971D-5AF2FCA8893F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{0A101FA8-F434-4164-9A2F-09CA54E12BFB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{6901F69B-90E8-4B5A-BEF3-25FA0CB3EDDA}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{426750E8-61D5-4375-AD6B-12F92C50E891}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{6016AB2B-A412-4B89-B75A-E7679AE54BA4}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{79E3EFAF-AA4E-4CBF-8F10-C9AA9AD53C3E}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{EE8173FC-0612-4E04-A899-EC46867489AD}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8

"{0C59E7F3-DEB7-4D42-A491-CE892D781337}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8

"{1425428C-4109-4316-8F5E-C55A965B6671}"= %ProgramFiles%\Telenor\Online Start\Telenor.exe:Online Start

"TCP Query User{435687BA-EDE5-489F-937C-56B8E42D22DE}C:\\program files\\counter-strike 1.6\\hl.exe"= UDP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher

"UDP Query User{10A1F102-F7AF-4CFE-8F31-54DEA12950FD}C:\\program files\\counter-strike 1.6\\hl.exe"= TCP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher

"{4E43A063-F692-44EF-AF4D-614ED8352E85}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{43610C69-9580-454F-B469-448C47967CFD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"TCP Query User{0D93150B-5E89-48DC-A0AA-D0DBF0DD603E}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:

"UDP Query User{9C2AF00F-6378-4D6D-917F-EF374325494C}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:

"{90CE36F8-B55F-4115-BE2F-28DE89586BEC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"TCP Query User{C70CD4EE-896E-4332-A182-5A070CC2B29B}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus

"UDP Query User{D739FDEF-97B6-4D09-AE23-BD61FB5E216B}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus

"TCP Query User{9FF94F28-2E16-40B6-AFC3-EDB605E3EF10}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2

"UDP Query User{FA364296-73CD-4E26-9B77-227818D98B6E}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2

"TCP Query User{D63ED578-202D-4FD7-9CDC-60E0057031A8}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

"UDP Query User{7F36C02B-708B-49C9-B79F-7A2258B1C906}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

"TCP Query User{AC1F5B1C-5B2C-43EF-9B59-72298EDA889D}C:\\program files\\counter-strike 1.6\\hlds.exe"= UDP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher

"UDP Query User{514EAB2F-2F8A-4173-9AF5-B4C54E6EA3E4}C:\\program files\\counter-strike 1.6\\hlds.exe"= TCP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher

"{59217433-9C36-4E8F-A684-A5CE4C6C28AF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{C4FC3841-7F9F-4554-ACD4-0C96FCE38D2F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"TCP Query User{33B6A06F-FF30-42A0-8576-0A7157E826D9}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{44A96FEE-281B-4F98-B638-3EAA2297B82C}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{48610643-8143-49B8-80DF-509C116C4D88}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"UDP Query User{04048DEA-4972-4E82-8634-F115A6B4A415}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"TCP Query User{4CB1FA52-F0C9-4624-B90A-3332E795044B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{B9F1CE36-C5DA-4234-92AE-D3CFEC19B393}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{126EAD4D-4057-4D2E-AB75-0188ECF38681}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"UDP Query User{7C7C2B68-71CB-4EE3-90D5-FB30E130BE3E}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"TCP Query User{F6EF78ED-59E0-429D-ABF9-B5448CD0DA16}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"UDP Query User{B3572E3D-8B04-4AB8-9BBB-84E860226E6B}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"TCP Query User{2E3E6A16-3C6C-49A5-AA82-3277BE5F904B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{ED08CB23-ACC6-460F-AC59-808C062BF4A6}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{5CCD2E63-6938-42B1-AE61-34E03E95B6A6}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{291AD43A-928A-467D-9F2E-319DED1A549A}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{50BA01F5-42B1-46AF-9217-4DB75EB4C1C5}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"UDP Query User{FEC47B1E-1D48-4887-8474-C94617225337}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"TCP Query User{7C99411B-0217-4247-B1C8-E67D63922DB9}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"UDP Query User{23B15472-4D99-4C2E-9791-6E86847771F4}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"TCP Query User{78342C9B-D30E-4589-AA3A-FA6020242A68}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"UDP Query User{3EC04C63-AA9D-4F3D-AC4C-8C5F61599EFE}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"TCP Query User{89D336AE-6FCA-4813-A749-4FCC0960A961}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher

"UDP Query User{46FDF6C9-1276-4E3B-A62B-6266B4766F47}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher

"{BEF8CCC8-B25D-481D-8FEA-5090BAF2907F}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe

"{9CF5C224-7223-472F-B9D0-7DB821D592BB}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 20:19]

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]

R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 20:19]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 20:19]

R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 20:19]

R3 btwaudio;Bluetooth-lydenhet;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 03:37]

R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 01:13]

R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 01:13]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-15 20:07]

S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]

S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-04-04 14:43]

S3 stusb2ir;USB 2.0 IrDA Bridge;C:\Windows\system32\DRIVERS\stusb2ir.sys [2006-11-02 09:30]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

bthsvcs REG_MULTI_SZ BthServ

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f73e66e-8eef-11dc-928a-001c26f02b6b}]

\shell\AutoRun\command - F:\usdeiect.com

\shell\explore\Command - F:\usdeiect.com

\shell\open\Command - F:\usdeiect.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bb41413-62dc-11dc-9a64-001c26f02b6b}]

\shell\AutoRun\command - F:\ntde1ect.com

\shell\explore\Command - F:\ntde1ect.com

\shell\open\Command - F:\ntde1ect.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6230faca-ce3d-11dc-90fa-001c26f02b6b}]

\shell\AutoRun\command - b.com

\shell\explore\Command - b.com

\shell\open\Command - b.com

 

*Newly Created Service* - CATCHME

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-03 17:31:30

Windows 6.0.6000 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-05-03 17:32:56

ComboFix-quarantined-files.txt 2008-05-03 15:32:39

ComboFix2.txt 2008-05-03 12:52:37

 

Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application.

Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application.

 

245 --- E O F --- 2008-05-03 12:35:34

Skrevet (endret)

Nei det ble feil.

"CFScript.txt..lnk"

Skal kun hete "CFScript.txt"

 

Kjør igjen tro jeg hadde et . for mye.

Endret av SNIPPSAT
Skrevet

Og her har du scan loggen.

 

Klikk for å se/fjerne innholdet nedenfor
SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 05/03/2008 at 06:20 PM

 

Application Version : 4.0.1154

 

Core Rules Database Version : 3452

Trace Rules Database Version: 1444

 

Scan type : Complete Scan

Total Scan Time : 00:26:52

 

Memory items scanned : 790

Memory threats detected : 0

Registry items scanned : 6177

Registry threats detected : 13

File items scanned : 20857

File threats detected : 52

 

Adware.Tracking Cookie

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@atwola[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@doubleclick[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@adrevolver[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@superstats[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@atdmt[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@burstnet[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@insightexpressai[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@tribalfusion[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@clicktorrent[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@specificclick[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@casalemedia[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@2o7[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@revsci[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@zedo[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@statcounter[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@fastclick[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@advertising[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@serving-sys[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@clicksor[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@tradedoubler[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@imrworldwide[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@adtech[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@hitbox[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@realmedia[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@questionmarket[2].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@tacoda[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@apmebf[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@indextools[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@mediaplex[1].txt

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\daniel@xiti[1].txt

 

Trojan.Media-Codec/V4

HKCR\multimediaControls.chl

HKCR\multimediaControls.chl\CLSID

 

Rogue.WinSpyKiller

C:\Program Files\WinSpyKiller\WinSpyKiller.lic

C:\Program Files\WinSpyKiller

 

Rogue.MalwareCore

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\cJmgtsdL

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\cwnouQq

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\InProcServer32

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\InProcServer32#ThreadingModel

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\lbukzrL

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\mzni

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\uiybasvhdT

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\Vihpkghw

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\WfHmyGtcd

HKCR\CLSID\{5D4348FB-DF43-0334-69B8-DAD6CA156781}\wkyeofa

 

åheidu... :whistle:

Skrevet
Nei det ble feil.

"CFScript.txt..lnk"

Skal kun hete "CFScript.txt"

 

Kjør igjen tro jeg hadde et . for mye.

Oisann.. nå leste ikke jeg det her før virus scanen var posta men...

skal jeg bare sjekke den med combofix en gang til da?

og btw, autolagrer den til "CFScript.txt."?

Skrevet
Nei det ble feil.

"CFScript.txt..lnk"

Skal kun hete "CFScript.txt"

 

Kjør igjen tro jeg hadde et . for mye.

Oisann.. nå leste ikke jeg det her før virus scanen var posta men...

skal jeg bare sjekke den med combofix en gang til da?

og btw, autolagrer den til "CFScript.txt."?

det var nok jeg som satte inn det ekstra punktumet:blush: Men har det noe å si for scriptet?

Skrevet
Ja du må kjøre på nytt virker ikke med et . for mye.

Alright..kommer her :blush:

Klikk for å se/fjerne innholdet nedenfor
ComboFix 08-04-27.3 - Daniel 2008-05-03 20:27:52.3 - NTFSx86

Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1044.18.1052 [GMT 2:00]

Running from: C:\Users\Daniel\Desktop\ComboFix.exe

Command switches used :: C:\Users\Daniel\Desktop\CFScript.txt

* Created a new restore point

.

 

((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))

.

 

No new files created in this timespan

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-03 15:51 --------- d-----w C:\Users\Daniel\AppData\Roaming\SUPERAntiSpyware.com

2008-05-03 15:51 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com

2008-05-03 15:51 --------- d-----w C:\Program Files\SUPERAntiSpyware

2008-05-03 15:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2008-05-03 15:48 --------- d-----w C:\ProgramData\Yahoo! Companion

2008-05-03 15:42 --------- d-----w C:\Program Files\Yahoo!

2008-05-03 15:42 --------- d-----w C:\Program Files\CCleaner

2008-05-03 14:55 --------- d-----w C:\Users\Daniel\AppData\Roaming\LimeWire

2008-05-03 14:18 --------- d-----w C:\Users\Daniel\AppData\Roaming\dvdcss

2008-05-03 12:45 1,422 ----a-w C:\Users\Daniel\AppData\Roaming\wklnhst.dat

2008-05-02 08:18 --------- d-----w C:\Program Files\Steam

2008-05-01 21:55 --------- d-----w C:\ProgramData\Messenger Plus!

2008-05-01 21:54 --------- d-----w C:\Program Files\Messenger Plus! Live

2008-05-01 12:18 --------- d-----w C:\Program Files\IDT

2008-05-01 11:28 1,552 ----a-w C:\Windows\system32\drivers\stwrte.log

2008-04-28 20:31 --------- d-----w C:\Program Files\Counter-Strike 1.6

2008-04-28 19:40 --------- d-----w C:\Program Files\Windows Mail

2008-04-28 19:37 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-04-28 19:31 --------- d---a-w C:\ProgramData\TEMP

2008-04-28 18:19 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys

2008-04-28 18:19 67,080 ----a-w C:\Windows\system32\drivers\avgwfpx.sys

2008-04-28 18:19 10,520 ----a-w C:\Windows\System32\avgrsstx.dll

2008-04-28 18:19 --------- d-----w C:\ProgramData\avg8

2008-04-28 18:19 --------- d-----w C:\Program Files\AVG

2008-04-22 15:44 --------- d-----w C:\Program Files\Trend Micro

2008-04-22 14:17 --------- d-----w C:\Program Files\Apple Software Update

2008-04-19 19:19 --------- d-----w C:\Program Files\The Seal Hunter

2008-04-12 18:56 --------- d-----w C:\Users\Daniel\AppData\Roaming\Apple Computer

2008-04-10 20:38 --------- d-----w C:\Program Files\Wfwin

2008-04-10 17:38 --------- d-----w C:\Program Files\Google

2008-04-08 17:25 --------- d-----w C:\Program Files\SwiftSwitch

2008-04-06 16:14 --------- d-----w C:\ProgramData\Roxio

2008-04-04 12:43 --------- d-----w C:\Program Files\Common Files\Steam

2008-04-04 09:48 --------- d-----w C:\Program Files\iTunes

2008-04-04 09:47 --------- d-----w C:\Program Files\iPod

2008-04-04 09:44 --------- d-----w C:\Program Files\QuickTime

2008-03-30 13:16 --------- d-----w C:\Program Files\SystemRequirementsLab

2008-03-30 11:07 --------- d-----w C:\Program Files\Dell

2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys

2008-03-27 18:06 --------- d-----w C:\Users\Daniel\AppData\Roaming\Talkback

2008-03-14 15:39 --------- d-----w C:\Users\Daniel\AppData\Roaming\Leadertech

2008-03-14 15:37 --------- d-----w C:\Program Files\Common Files\Adobe

2008-03-13 16:36 --------- d-----w C:\ProgramData\Documents

2008-03-13 16:16 --------- d-----w C:\Users\Daniel\AppData\Roaming\AdobeUM

2008-03-13 07:13 --------- d-----w C:\ProgramData\Skype

2008-03-05 14:42 --------- d-----w C:\Users\Daniel\AppData\Roaming\Azureus

2008-03-05 14:39 --------- d-----w C:\Program Files\BitLord2

2008-03-05 14:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll

2008-03-05 14:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll

2008-03-05 14:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll

2008-03-05 13:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll

2008-03-05 13:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll

2008-03-04 16:00 --------- d-----w C:\Program Files\Common Files\PX Storage Engine

2008-03-03 15:25 --------- d-----w C:\Program Files\Windows Live Toolbar

2008-03-03 15:23 --------- d-----w C:\Program Files\Windows Live

2008-03-03 15:22 --------- d-----w C:\Users\Daniel\AppData\Roaming\Windows Live Writer

2008-03-03 15:13 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-03-03 15:10 --------- d-----w C:\ProgramData\Telenor

2008-03-03 15:10 --------- d-----w C:\Program Files\Telenor

2008-03-03 15:06 --------- d-----w C:\ProgramData\McAfee

2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll

2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll

2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll

2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe

2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe

2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll

2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll

2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys

2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll

2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll

2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll

2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe

2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll

2008-02-16 10:40 736,220,974 ----a-w C:\Program Files\Image_080216_1134.gi

2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe

2008-02-14 22:19 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-02-14 22:14 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-02-14 22:14 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-02-14 22:14 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll

2008-02-05 21:07 462,864 ----a-w C:\Windows\System32\d3dx10_37.dll

2007-09-12 14:58 174 --sha-w C:\Program Files\desktop.ini

.

 

((((((((((((((((((((((((((((( snapshot@2008-05-03_14.52.05.97 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-05-03 15:51:12 18,944 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe

+ 2008-05-03 15:51:12 65,024 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe

- 2008-05-03 12:32:14 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-05-03 17:31:56 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat

- 2008-05-03 12:48:49 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-05-03 18:27:26 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat

- 2008-05-02 08:19:57 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-05-03 15:41:58 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-05-02 08:19:57 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-05-03 15:41:58 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-05-02 08:19:57 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-05-03 15:41:58 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]

2008-04-28 20:19 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-28 20:19 2050816]

 

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]

[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-28 20:19 2050816]

 

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]

[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-06 11:14 1006264]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-15 20:08 98304]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-15 20:07 106496]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-15 20:07 81920]

"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-09-06 03:35 77824]

"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2006-11-28 01:15 1540096]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]

"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 12:50 17920]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-06 03:51 1862144]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 20:19 1177368]

"SigmatelSysTrayApp"="sttray.exe" [2007-02-08 07:11 303104 C:\Windows\sttray.exe]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1820041221-4144176497-4136927534-1000]

"EnableNotificationsRef"=dword:00000008

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{F215BAA5-362F-4388-AFB1-7046BFAA6723}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{7A802F48-2B53-4130-946E-02F1E58FC4DB}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{F82B975B-F725-429E-9F1F-B96A0E72F07F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{604116BB-2FC4-49B9-971D-5AF2FCA8893F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{0A101FA8-F434-4164-9A2F-09CA54E12BFB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{6901F69B-90E8-4B5A-BEF3-25FA0CB3EDDA}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{426750E8-61D5-4375-AD6B-12F92C50E891}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{6016AB2B-A412-4B89-B75A-E7679AE54BA4}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{79E3EFAF-AA4E-4CBF-8F10-C9AA9AD53C3E}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{EE8173FC-0612-4E04-A899-EC46867489AD}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8

"{0C59E7F3-DEB7-4D42-A491-CE892D781337}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire 4.14.8

"{1425428C-4109-4316-8F5E-C55A965B6671}"= %ProgramFiles%\Telenor\Online Start\Telenor.exe:Online Start

"TCP Query User{435687BA-EDE5-489F-937C-56B8E42D22DE}C:\\program files\\counter-strike 1.6\\hl.exe"= UDP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher

"UDP Query User{10A1F102-F7AF-4CFE-8F31-54DEA12950FD}C:\\program files\\counter-strike 1.6\\hl.exe"= TCP:C:\program files\counter-strike 1.6\hl.exe:Half-Life Launcher

"{4E43A063-F692-44EF-AF4D-614ED8352E85}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"{43610C69-9580-454F-B469-448C47967CFD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

"TCP Query User{0D93150B-5E89-48DC-A0AA-D0DBF0DD603E}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:

"UDP Query User{9C2AF00F-6378-4D6D-917F-EF374325494C}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:

"{90CE36F8-B55F-4115-BE2F-28DE89586BEC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"TCP Query User{C70CD4EE-896E-4332-A182-5A070CC2B29B}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus

"UDP Query User{D739FDEF-97B6-4D09-AE23-BD61FB5E216B}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus

"TCP Query User{9FF94F28-2E16-40B6-AFC3-EDB605E3EF10}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2

"UDP Query User{FA364296-73CD-4E26-9B77-227818D98B6E}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2

"TCP Query User{D63ED578-202D-4FD7-9CDC-60E0057031A8}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

"UDP Query User{7F36C02B-708B-49C9-B79F-7A2258B1C906}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

"TCP Query User{AC1F5B1C-5B2C-43EF-9B59-72298EDA889D}C:\\program files\\counter-strike 1.6\\hlds.exe"= UDP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher

"UDP Query User{514EAB2F-2F8A-4173-9AF5-B4C54E6EA3E4}C:\\program files\\counter-strike 1.6\\hlds.exe"= TCP:C:\program files\counter-strike 1.6\hlds.exe:HLDS Launcher

"{59217433-9C36-4E8F-A684-A5CE4C6C28AF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{C4FC3841-7F9F-4554-ACD4-0C96FCE38D2F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"TCP Query User{33B6A06F-FF30-42A0-8576-0A7157E826D9}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{44A96FEE-281B-4F98-B638-3EAA2297B82C}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{48610643-8143-49B8-80DF-509C116C4D88}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"UDP Query User{04048DEA-4972-4E82-8634-F115A6B4A415}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"TCP Query User{4CB1FA52-F0C9-4624-B90A-3332E795044B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{B9F1CE36-C5DA-4234-92AE-D3CFEC19B393}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{126EAD4D-4057-4D2E-AB75-0188ECF38681}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"UDP Query User{7C7C2B68-71CB-4EE3-90D5-FB30E130BE3E}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"TCP Query User{F6EF78ED-59E0-429D-ABF9-B5448CD0DA16}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"UDP Query User{B3572E3D-8B04-4AB8-9BBB-84E860226E6B}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"TCP Query User{2E3E6A16-3C6C-49A5-AA82-3277BE5F904B}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{ED08CB23-ACC6-460F-AC59-808C062BF4A6}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{5CCD2E63-6938-42B1-AE61-34E03E95B6A6}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"UDP Query User{291AD43A-928A-467D-9F2E-319DED1A549A}C:\\program files\\steam\\steamapps\\jake543\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike\hl.exe:Half-Life Launcher

"TCP Query User{50BA01F5-42B1-46AF-9217-4DB75EB4C1C5}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"UDP Query User{FEC47B1E-1D48-4887-8474-C94617225337}C:\\program files\\steam\\steamapps\\per_christian\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\per_christian\counter-strike source\hl2.exe:hl2

"TCP Query User{7C99411B-0217-4247-B1C8-E67D63922DB9}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"UDP Query User{23B15472-4D99-4C2E-9791-6E86847771F4}C:\\program files\\steam\\steamapps\\per_christian\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\half-life\hl.exe:Half-Life Launcher

"TCP Query User{78342C9B-D30E-4589-AA3A-FA6020242A68}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"UDP Query User{3EC04C63-AA9D-4F3D-AC4C-8C5F61599EFE}C:\\program files\\steam\\steamapps\\jake543\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\jake543\counter-strike source\hl2.exe:hl2

"TCP Query User{89D336AE-6FCA-4813-A749-4FCC0960A961}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= UDP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher

"UDP Query User{46FDF6C9-1276-4E3B-A62B-6266B4766F47}C:\\program files\\steam\\steamapps\\per_christian\\team fortress classic\\hl.exe"= TCP:C:\program files\steam\steamapps\per_christian\team fortress classic\hl.exe:Half-Life Launcher

"{BEF8CCC8-B25D-481D-8FEA-5090BAF2907F}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe

"{9CF5C224-7223-472F-B9D0-7DB821D592BB}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 20:19]

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]

R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 20:19]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 20:19]

R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 20:19]

R3 btwaudio;Bluetooth-lydenhet;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 03:37]

R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 01:13]

R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 01:13]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-15 20:07]

S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]

S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-04-04 14:43]

S3 stusb2ir;USB 2.0 IrDA Bridge;C:\Windows\system32\DRIVERS\stusb2ir.sys [2006-11-02 09:30]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

bthsvcs REG_MULTI_SZ BthServ

 

*Newly Created Service* - CATCHME

*Newly Created Service* - SASDIFSV

*Newly Created Service* - SASENUM

*Newly Created Service* - SASKUTIL

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-03 20:29:34

Windows 6.0.6000 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-05-03 20:31:04

ComboFix-quarantined-files.txt 2008-05-03 18:30:31

ComboFix2.txt 2008-05-03 15:36:28

 

Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application.

Finner ikke meldingstekst for melding nummer 0x2379 i meldingsfilen for Application.

 

252 --- E O F --- 2008-05-03 12:35:34

 

nå da? men det stod et . bak txt denne gangen også :hmm:

Skrevet
Gikk greit nå.

Og en ny hijackthis-logg.

Her kommer hijackthis-log..

 

og nok en gang... mange takk for det her! jeg merker at pcen er betydelig raskere når jeg f. eks booter :thumbup:

 

her er log!

Klikk for å se/fjerne innholdet nedenfor
Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:13:48, on 03.05.2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Windows\System32\WLTRAY.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Windows\sttray.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O1 - Hosts: ::1 localhost

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll

O2 - BHO: (no name) - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)

O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"

O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETTVERKSTJENESTE')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O4 - Global Startup: QuickSet.lnk = ?

O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O13 - Gopher Prefix:

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 9249 bytes

Skrevet (endret)

Start HijackThis "scan" finn disse linjene merk dem,så trykk fix checked.

O2 - BHO: (no name) - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)

O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)

 

Da er du ren for grums :thumbup:

 

Bruk pcen kjører den greit kan du gjøre dette.

 

Du kan fjerne combofix ved å skrive combofix /u fra kjør-vinduet. Denne kommandoen gjør at filer i karantene og backups blir slette. Systemgjenopprettingsmappa nullstilt etc.

 

Du får se om dette har hjelpet på problemet.

Endret av SNIPPSAT
Skrevet

Da er det bare å si tusen takk.

 

har ikke brukt internettet noe serlig enda, men den har ikke skrudd seg av :p

Glemte og si at det hjalp å søke på windows update, da ordna det seg intill neste gang.

 

Men uansett så har jeg fårr renska pcen godt nå :thumbup: all cred to SNIPPSAT

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...