Gå til innhold

Kan noen sjekke Hijack loggen min :) ?


Anbefalte innlegg

Klikk for å se/fjerne innholdet nedenfor

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:04:09, on 28.11.2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Programfiler\Bonjour\mDNSResponder.exe

C:\Programfiler\Fellesfiler\InterVideo\RegMgr\iviRegMgr.exe

C:\Programfiler\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\TUProgSt.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\WINDOWS\system32\igfxtray.exe

C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\igfxext.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe

C:\Programfiler\InterVideo\Common\Bin\WinCinemaMgr.exe

C:\DOCUME~1\Bruker\LOKALE~1\Temp\RtkBtMnt.exe

C:\Programfiler\Windows Live\Messenger\usnsvc.exe

C:\Programfiler\Opera\opera.exe

C:\Documents and Settings\Bruker\Mine dokumenter\mbam-setup.exe

C:\DOCUME~1\Bruker\LOKALE~1\Temp\is-V0Q7S.tmp\mbam-setup.tmp

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

C:\Programfiler\Malwarebytes' Anti-Malware\mbam.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.rd.yahoo.com/customize/ycomp/def.../search/ie.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://no.intl.acer.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg/startp...0848351F6F32535

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programfiler\AVG\AVG8\avgssie.dll

O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre6\bin\ssv.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programfiler\AVG\AVG8\avgtoolbar.dll

O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programfiler\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programfiler\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programfiler\AVG\AVG8\avgtoolbar.dll

O4 - HKLM\..\Run: [LaunchApp] Alaunch

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [AzMixerSel] C:\Programfiler\Realtek\Audio\InstallShield\AzMixerSel.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt

O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE

O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe /idle

O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Programfiler\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programfiler\InterVideo\Common\Bin\WinCinemaMgr.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: IviRegMgr - InterVideo - C:\Programfiler\Fellesfiler\InterVideo\RegMgr\iviRegMgr.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programfiler\Java\jre6\bin\jqs.exe

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe

O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

 

--

End of file - 8558 bytes

 

Kan noen være snile og se om det er noe rusk i systemet?

Plages med treg pc og hakkende lyd.

 

Mvh Jonas.

Lenke til kommentar
Videoannonse
Annonse

Hijackthis loggen ser grei ut.

Kjøre det submit har postet,så ser vi om du er malware fri.

 

Husk og gi korrekt info om combofix submit.

 

Last Combofix ned ,legg på skrivebordet.

Ikke klikk på vindu mens programmet kjører.

post logg C:\combofix.txt

 

Last ned MBAM til skrivebordet.

Velg Norsk språkdrakt-->kjør hurtig systemskann.

Når MBAM er ferdig åpner den en logg,den poster du.

 

Sånn skal det se ut eller så linker du til veiledningen ;)

Lenke til kommentar

Klikk for å se/fjerne innholdet nedenfor

Malwarebytes' Anti-Malware 1.30

Database versjon: 1433

Windows 5.1.2600 Service Pack 3

 

28.11.2008 19:27:33

mbam-log-2008-11-28 (19-27-33).txt

 

Skanntype: Rask Skann

Objekter skannet: 46653

Tid tilbakelagt: 22 minute(s), 50 second(s)

 

Minneprosesser infisert: 0

Minnemoduler infisert: 0

Registernøkler infisert: 0

Registerverdier infisert: 0

Registerfiler infisert: 0

Mapper infisert: 0

Filer infisert: 0

 

Minneprosesser infisert:

(Ingen mistenkelige filer funnet)

 

Minnemoduler infisert:

(Ingen mistenkelige filer funnet)

 

Registernøkler infisert:

(Ingen mistenkelige filer funnet)

 

Registerverdier infisert:

(Ingen mistenkelige filer funnet)

 

Registerfiler infisert:

(Ingen mistenkelige filer funnet)

 

Mapper infisert:

(Ingen mistenkelige filer funnet)

 

Filer infisert:

(Ingen mistenkelige filer funnet)

Malware logg

Lenke til kommentar

ComboFix logg.

 

Klikk for å se/fjerne innholdet nedenfor

ComboFix 08-11-27.07 - Bruker 2008-11-29 18:49:49.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1044.18.645 [GMT 1:00]

Kjører fra: c:\documents and settings\Bruker\Mine dokumenter\ComboFix.exe

* Opprettet nytt gjenopprettingspunkt

 

ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !!

.

 

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\autorun.ini

 

.

((((((((((((((((((((((((((( Filer Opprettet Fra 2008-10-28 til 2008-11-29 )))))))))))))))))))))))))))))))))

.

 

2008-11-28 21:17 . 2008-11-28 21:17 <DIR> d-------- c:\windows\system32\windows media

2008-11-28 21:16 . 2008-11-28 21:17 <DIR> d--h----- c:\windows\msdownld.tmp

2008-11-28 21:16 . 2008-11-28 21:16 <DIR> d-------- c:\programfiler\Windows Media Components

2008-11-28 19:03 . 2008-11-28 19:03 <DIR> d-------- c:\programfiler\Trend Micro

2008-11-28 19:03 . 2008-11-28 19:03 <DIR> d-------- c:\programfiler\Malwarebytes' Anti-Malware

2008-11-28 19:03 . 2008-11-28 19:03 <DIR> d-------- c:\documents and settings\Bruker\Programdata\Malwarebytes

2008-11-28 19:03 . 2008-11-28 19:03 <DIR> d-------- c:\documents and settings\All Users\Programdata\Malwarebytes

2008-11-28 19:03 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-11-28 19:03 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-11-28 11:11 . 2008-11-29 16:42 2,286,592 --a------ c:\windows\system32\TUKernel.exe

2008-11-27 18:58 . 2008-11-28 11:48 <DIR> d-------- c:\windows\system32\autorun

2008-11-27 17:53 . 2008-11-27 17:53 <DIR> d-------- c:\documents and settings\Bruker\Programdata\TuneUp Software

2008-11-27 17:53 . 2008-11-27 17:53 603,904 --a------ c:\windows\system32\TUProgSt.exe

2008-11-27 17:53 . 2008-11-27 17:53 362,240 --a------ c:\windows\system32\TuneUpDefragService.exe

2008-11-27 17:53 . 2008-11-12 16:44 27,904 --a------ c:\windows\system32\uxtuneup.dll

2008-11-27 17:52 . 2008-11-28 11:40 <DIR> d-------- c:\programfiler\TuneUp Utilities 2009

2008-11-27 17:52 . 2008-11-27 17:52 <DIR> d-------- c:\documents and settings\All Users\Programdata\TuneUp Software

2008-11-27 17:49 . 2008-11-27 17:49 <DIR> d--hs---- c:\documents and settings\All Users\Programdata\{55A29068-F2CE-456C-9148-C869879E2357}

2008-11-26 17:51 . 2008-11-26 17:51 <DIR> d-------- c:\documents and settings\Bruker\Programdata\Template

2008-11-26 17:51 . 2008-11-26 17:51 0 --a------ c:\documents and settings\Bruker\Programdata\wklnhst.dat

2008-11-25 18:51 . 2005-05-03 12:43 69,632 --a------ c:\windows\Alcmtr.exe

2008-11-25 18:50 . 2008-11-25 18:50 319,488 --a------ c:\windows\HideWin.exe

2008-11-24 17:16 . 2008-11-10 15:35 34,816 --a------ c:\windows\system32\RtkCoInstXP.dll

2008-11-24 17:15 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys

2008-11-24 17:15 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys

2008-11-22 20:51 . 2008-11-22 20:51 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys

2008-11-22 20:51 . 2008-11-22 20:51 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys

2008-11-22 20:51 . 2008-11-22 20:51 10,520 --a------ c:\windows\system32\avgrsstx.dll

2008-11-22 20:50 . 2008-11-28 20:48 <DIR> d-------- c:\windows\system32\drivers\Avg

2008-11-22 20:50 . 2008-11-22 20:50 <DIR> d-------- c:\programfiler\AVG

2008-11-22 20:50 . 2008-11-23 00:19 <DIR> d-------- c:\documents and settings\Bruker\Programdata\AVGTOOLBAR

2008-11-22 20:50 . 2008-11-22 20:50 <DIR> d-------- c:\documents and settings\All Users\Programdata\avg8

2008-11-13 21:10 . 2008-11-13 21:10 <DIR> d-------- c:\programfiler\SiteAdvisor

2008-11-12 14:08 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-11-10 20:21 . 2008-11-23 12:13 <DIR> d-------- c:\documents and settings\Bruker\Programdata\LimeWire

2008-11-10 20:21 . 2008-11-10 20:20 410,976 --a------ c:\windows\system32\deploytk.dll

2008-11-10 20:21 . 2008-11-10 20:20 73,728 --a------ c:\windows\system32\javacpl.cpl

2008-11-10 20:20 . 2008-11-10 20:20 <DIR> d-------- c:\programfiler\Java

2008-11-10 20:16 . 2008-11-10 20:17 <DIR> d-------- c:\programfiler\LimeWire

2008-11-09 09:19 . 2008-11-09 09:19 <DIR> d-------- c:\documents and settings\LocalService\Programdata\SACore

2008-11-08 20:11 . 2008-11-08 20:11 <DIR> d-------- c:\programfiler\Vizky

2008-11-08 20:11 . 2008-11-08 20:12 <DIR> d-------- c:\documents and settings\All Users\Programdata\VIZ_MPS

2008-11-08 16:05 . 2008-11-13 16:03 <DIR> d-------- c:\programfiler\Counter-Strike 1.6

2008-11-07 17:17 . 2008-11-07 17:17 <DIR> d-------- c:\programfiler\iTunes

2008-11-07 17:17 . 2008-11-07 17:17 <DIR> d-------- c:\programfiler\iPod

2008-11-07 17:17 . 2008-11-07 17:17 <DIR> d-------- c:\documents and settings\All Users\Programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-11-07 17:15 . 2008-11-07 17:15 <DIR> d-------- c:\programfiler\Bonjour

2008-11-07 17:14 . 2008-11-07 17:15 <DIR> d-------- c:\programfiler\QuickTime

2008-11-07 16:51 . 2008-11-07 16:51 <DIR> d-------- c:\documents and settings\Bruker\Programdata\vlc

2008-11-07 16:35 . 2008-11-07 16:35 54,156 --ah----- c:\windows\QTFont.qfn

2008-11-07 16:35 . 2008-11-07 16:35 1,409 --a------ c:\windows\QTFont.for

2008-11-07 16:34 . 2008-11-07 16:34 <DIR> d-------- c:\documents and settings\Bruker\Programdata\Apple Computer

2008-11-07 16:31 . 2008-11-08 10:54 <DIR> d-------- c:\programfiler\Apple Software Update

2008-11-07 16:31 . 2008-11-07 16:33 <DIR> d-------- c:\documents and settings\All Users\Programdata\Apple Computer

2008-11-07 16:30 . 2008-11-07 16:30 <DIR> d-------- c:\programfiler\Fellesfiler\Apple

2008-11-07 16:29 . 2008-11-07 16:29 <DIR> d-------- c:\documents and settings\All Users\Programdata\Apple

2008-11-07 16:26 . 2008-11-07 16:26 <DIR> d-------- c:\programfiler\VideoLAN

2008-11-07 15:41 . 2001-10-06 13:36 12,160 --a------ c:\windows\system32\drivers\mouhid.sys

2008-11-07 15:41 . 2001-10-06 13:36 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys

2008-11-07 15:40 . 2008-04-16 04:00 10,368 --a------ c:\windows\system32\drivers\hidusb.sys

2008-11-07 15:40 . 2008-04-16 04:00 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys

2008-11-07 15:38 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll

2008-11-07 15:38 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll

2008-11-07 15:38 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui

2008-11-06 21:12 . 2008-10-03 18:31 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll

2008-11-06 21:12 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat

2008-11-06 21:12 . 2007-03-08 06:11 1,007,616 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui

2008-11-06 21:12 . 2008-08-26 09:30 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll

2008-11-06 21:12 . 2008-08-26 09:30 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll

2008-11-06 21:12 . 2008-08-26 09:30 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll

2008-11-06 21:12 . 2008-08-26 09:30 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll

2008-11-06 21:12 . 2008-08-26 09:30 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll

2008-11-06 21:12 . 2008-08-25 09:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe

2008-11-06 19:54 . 2008-08-06 15:27 499,712 --a------ c:\windows\system32\msvcp71.dll

2008-11-06 19:54 . 2008-08-06 15:29 348,160 --a------ c:\windows\system32\msvcr71.dll

2008-11-06 19:53 . 2008-11-06 19:44 <DIR> d-------- c:\windows\system32\Adobe

2008-11-06 19:40 . 2008-11-06 19:40 <DIR> d--hs---- c:\documents and settings\Bruker\UserData

2008-11-06 19:22 . 2008-11-06 19:22 <DIR> d-------- c:\documents and settings\Bruker\Programdata\InterVideo

2008-11-06 19:11 . 2008-11-06 19:11 <DIR> d-------- c:\documents and settings\Bruker\Contacts

2008-11-06 18:53 . 2008-11-06 19:10 <DIR> d-------- c:\programfiler\Windows Live

2008-11-06 18:53 . 2008-11-06 19:10 <DIR> d--hsc--- c:\programfiler\Fellesfiler\WindowsLiveInstaller

2008-11-06 18:53 . 2008-11-06 18:53 <DIR> d-------- c:\documents and settings\All Users\Programdata\WLInstaller

2008-11-06 18:49 . 2008-11-06 18:49 <DIR> d-------- c:\programfiler\Windows Media Connect 2

2008-11-06 18:48 . 2008-06-14 18:36 272,256 --------- c:\windows\system32\drivers\bthport.sys

2008-11-06 18:48 . 2008-06-14 18:36 272,256 -----c--- c:\windows\system32\dllcache\bthport.sys

2008-11-06 18:47 . 2008-08-14 14:27 2,190,976 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2008-11-06 18:47 . 2008-08-14 14:27 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2008-11-06 18:47 . 2008-08-14 14:27 2,067,840 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2008-11-06 18:47 . 2008-08-14 14:27 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2008-11-06 18:45 . 2008-11-06 18:45 <DIR> d-------- c:\windows\system32\LogFiles

2008-11-06 18:45 . 2008-11-06 18:48 <DIR> d-------- c:\windows\system32\drivers\UMDF

2008-11-06 18:44 . 2008-11-06 18:44 <DIR> d-------- c:\programfiler\Opera

2008-11-06 18:39 . 2008-11-13 14:11 <DIR> d--h----- c:\windows\$hf_mig$

2008-11-06 18:39 . 2006-09-25 17:58 23,856 --a------ c:\windows\system32\spupdsvc.exe

2008-11-06 18:37 . 2008-11-06 18:37 <DIR> d-------- c:\documents and settings\Bruker\Programdata\Yahoo!

2008-11-06 18:37 . 2008-11-06 18:37 <DIR> d-------- c:\documents and settings\All Users\Programdata\Yahoo! Companion

2008-11-01 10:46 . 2007-04-13 11:51 321,024 --a------ c:\windows\system32\ERUpdateHidden.EXE

2008-11-01 10:46 . 2006-03-23 12:02 258,048 --a------ c:\windows\system32\Uninstall_eRecovery.exe

2008-11-01 10:46 . 2006-03-30 13:06 258,048 --a------ c:\windows\system32\CheckD2DSystem.exe

2008-11-01 10:46 . 2004-11-03 09:06 159,744 --a------ c:\windows\system32\CloseProcessWindow.dll

2008-11-01 10:46 . 2005-12-09 09:12 16,384 --a------ c:\windows\system32\ClearEvent.exe

2008-11-01 10:46 . 2006-03-23 21:55 730 --a------ c:\windows\system32\setup.iss

2008-11-01 10:45 . 2008-11-01 19:05 <DIR> dr------- c:\documents and settings\Bruker\Start-meny

2008-11-01 10:45 . 2008-07-16 23:30 <DIR> d--h----- c:\documents and settings\Bruker\Skrivere

2008-11-01 10:45 . 2008-11-28 19:03 <DIR> d-------- c:\documents and settings\Bruker\Skrivebord

2008-11-01 10:45 . 2008-11-29 16:41 <DIR> dr-h----- c:\documents and settings\Bruker\Siste

2008-11-01 10:45 . 2008-11-01 19:05 <DIR> d-------- c:\documents and settings\Bruker\Programdata\InstallShield

2008-11-01 10:45 . 2008-11-28 19:03 <DIR> d--h----- c:\documents and settings\Bruker\Programdata

2008-11-01 10:45 . 2008-11-28 23:40 <DIR> dr------- c:\documents and settings\Bruker\Mine dokumenter

2008-11-01 10:45 . 2008-11-01 19:05 <DIR> d--h----- c:\documents and settings\Bruker\Maler

2008-11-01 10:45 . 2008-11-29 18:52 <DIR> d--h----- c:\documents and settings\Bruker\Lokale innstillinger

2008-11-01 10:45 . 2008-11-06 21:17 <DIR> dr------- c:\documents and settings\Bruker\Favoritter

2008-11-01 10:45 . 2008-07-16 23:30 <DIR> d--h----- c:\documents and settings\Bruker\AndrMask

2008-11-01 10:45 . 2008-11-29 16:46 <DIR> d-------- c:\documents and settings\Bruker

2008-11-01 10:20 . 2008-11-01 10:20 <DIR> d-------- c:\windows\JMCR_DIR

2008-11-01 10:20 . 2008-11-01 10:46 <DIR> d-------- C:\Acer

2008-11-01 10:20 . 2008-05-14 11:53 110,080 --a------ c:\windows\system32\JmCrIcon.dll

2008-11-01 10:20 . 2008-07-08 02:16 96,856 --a------ c:\windows\system32\drivers\jmcr.sys

2008-11-01 10:20 . 2008-11-01 10:20 124 --a------ c:\windows\xUninstall.bat

2008-11-01 10:19 . 2008-11-01 10:19 <DIR> d-------- c:\programfiler\Fellesfiler\CrystalEye

2008-11-01 10:19 . 2007-04-20 06:30 222,382 --a------ c:\windows\Acer Crystal Eye webcam.ico

2008-11-01 10:18 . 2008-11-01 10:18 <DIR> d-------- c:\windows\ACER

2008-11-01 10:18 . 2008-11-01 10:18 <DIR> d-------- c:\programfiler\Yahoo!

2008-11-01 10:18 . 2008-11-01 10:18 <DIR> d-------- c:\programfiler\Acer Incorporated

2008-11-01 10:18 . 2007-04-19 13:41 83,554,304 --a------ c:\windows\system32\acer.scr

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-11-28 22:27 --------- d--h--w c:\programfiler\InstallShield Installation Information

2008-11-22 19:45 --------- d-----w c:\documents and settings\All Users\Programdata\McAfee

2008-11-13 13:12 --------- d-----w c:\documents and settings\All Users\Programdata\Microsoft Help

2008-11-08 22:18 --------- d-----w c:\documents and settings\All Users\Programdata\SiteAdvisor

2008-11-06 18:36 --------- d-----w c:\programfiler\Microsoft Works

2008-11-01 18:07 --------- d-----w c:\programfiler\Synaptics

2008-11-01 18:07 --------- d-----w c:\programfiler\Realtek

2008-11-01 18:07 --------- d-----w c:\programfiler\Microsoft.NET

2008-11-01 18:06 --------- d-----w c:\programfiler\microsoft frontpage

2008-11-01 18:06 --------- d-----w c:\programfiler\InterVideo

2008-11-01 18:06 --------- d-----w c:\programfiler\Intel

2008-11-01 18:06 --------- d-----w c:\programfiler\Fellesfiler\Tjenester

2008-11-01 18:06 --------- d-----w c:\programfiler\Fellesfiler\InterVideo

2008-11-01 18:06 --------- d-----w c:\programfiler\Fellesfiler\InstallShield

2008-11-01 18:06 --------- d-----w c:\programfiler\Fellesfiler\Adobe

2008-11-01 18:06 --------- d-----w c:\programfiler\Elektroniske tjenester

2008-11-01 18:06 --------- d-----w c:\programfiler\Atheros

2008-11-01 18:06 --------- d-----w c:\programfiler\Activation Assistant for the 2007 Microsoft Office suites

2008-11-01 18:05 --------- d-----w c:\documents and settings\All Users\Programdata\Atheros

2008-11-01 18:05 --------- d-----w c:\documents and settings\All Users\Programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}

2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-09-15 15:29 1,846,400 ----a-w c:\windows\system32\win32k.sys

2008-09-10 01:16 1,307,648 ----a-w c:\windows\system32\msxml6.dll

2008-09-04 17:17 1,106,944 ----a-w c:\windows\system32\msxml3.dll

2008-08-29 09:18 87,336 ----a-w c:\windows\system32\dns-sd.exe

2008-08-29 08:53 61,440 ----a-w c:\windows\system32\dnssd.dll

.

 

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-16 15360]

"MsnMsgr"="c:\programfiler\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LaunchApp"="Alaunch" [X]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]

"AzMixerSel"="c:\programfiler\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]

"SynTPEnh"="c:\programfiler\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]

"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-16 59392]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-16 455168]

"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]

"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2007-02-20 61440]

"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]

"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-16 208952]

"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 c:\windows\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-16 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"MSMSGS"="c:\programfiler\Messenger\msmsgs.exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"

"iTunesHelper"="c:\programfiler\iTunes\iTunesHelper.exe"

"QuickTime Task"="c:\programfiler\QuickTime\QTTask.exe" -atboottime

"SunJavaUpdateSched"="c:\programfiler\Java\jre6\bin\jusched.exe"

"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Programfiler\\Bonjour\\mDNSResponder.exe"=

"c:\\Programfiler\\iTunes\\iTunes.exe"=

"c:\\Programfiler\\LimeWire\\LimeWire.exe"=

"c:\\Programfiler\\AVG\\AVG8\\avgemc.exe"=

"c:\\Programfiler\\AVG\\AVG8\\avgupd.exe"=

"c:\\Programfiler\\Counter-Strike 1.6\\hl.exe"=

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-22 97928]

R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-11-22 875288]

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-22 231704]

R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-22 76040]

R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2008-11-27 603904]

R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\Drivers\M3000KNT.sys [2008-05-05 254976]

S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-11-01 96856]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

 

*Newly Created Service* - PROCEXP90

.

Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

 

2008-11-29 c:\windows\Tasks\1-Click Maintenance.job

- c:\programfiler\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 16:28]

 

2008-11-07 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\programfiler\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

.

- - - - TOMME PEKERE FJERNET - - - -

 

HKLM-Run-M3000Mnt - M3000Rmv.dll

 

 

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-11-29 18:53:03

Windows 5.1.2600 Service Pack 3 NTFS

 

skanner skjulte prosesser ...

 

skanner skjulte autostart-oppføringer ...

 

skanner skjulte filer ...

 

skanning vellykket

skjulte filer: 0

 

**************************************************************************

.

--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

 

- - - - - - - > 'winlogon.exe'(716)

c:\windows\system32\avgrsstx.dll

 

- - - - - - - > 'lsass.exe'(856)

c:\windows\system32\avgrsstx.dll

.

Tidspunkt ferdig: 2008-11-29 18:54:44

ComboFix-quarantined-files.txt 2008-11-29 17:54:40

 

Pre-Run: 94 026 838 016 byte ledig

Post-Run: 94,570,795,008 byte ledig

 

262 --- E O F --- 2008-11-13 14:40:12

 

Endret av skylinepower
Lenke til kommentar

Loggene ser greie ut.

 

Plages med treg pc og hakkende lyd.

Kom dette plutselig eller har det utviklet seg over tid.

 

Ctrl+alt+del<prosesser>

Se på cpu forbruk om en prosess bruker mye.

 

Defragmering er dette noe du har gjort på en stund.

 

Rydder litt.

Du kan fjerne combofix ved å skrive combofix /u fra kjør-vinduet. Denne kommandoen gjør at filer i karantene og backups blir slette. Systemgjenopprettingsmappa nullstilt etc.

 

Last ned kjør CCleaner

'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t.

Kjør og register-renser"svar ja til og reparere"-->backup svar ja når du blir spørt.

Kjør register-renser et par ganger til alle feil er borte.

 

Auslogics Registry Defrag

http://www.auslogics.com/en/software/registry-defrag

 

Auslogics Disk Defrag

http://www.auslogics.com/en/software/disk-defrag

Endret av SNIPPSAT
Lenke til kommentar

Kom plutselig.

Pc en er en Asus Aspire one A150.

Har kjørt optimalisering med TuneUp (Uten hjelp, inneholder defrag av register og harddisk)

Avg bruker nermere 50-60000Kb og Operaen bruker ofte oppi 200000Kb, noe jeg ikke har merket spesielt til.

Msn kjører oppe i 30-40000Kb noe som er mye siden en kompis har samme pc og kjører på 8000Kb.

Lenke til kommentar

Husker desverre ikke dato.

husker bare at det skjedde rundt tiden jeg la inn avg og slettet det som lå inn ifra før.

Så på den tilbake stillingsloggen, var ingen dato med fet skrift nå.

Sikkert noe med at jeg har hatt de i dvalemodus ganske lenge.

 

På CCleaner er det trygt og Reparere alle merkede feil?

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...