V?rbris Skrevet 4. juni 2009 Del Skrevet 4. juni 2009 Hei Kommer ikke lengre inn i sikkerhetsmodus på min maskin med XP P3 Skulle ha kjørt noen scanner da jeg nylig fjernet noe virus. Trykker på F8 som tidligere, men nå får jeg ei ramme som kommer opp med spørsmål om hvilken stasjon jeg vil boote fra. Jeg trykker selvfølgelig c-disk, men da starter windows opp på ordinær måte selv om jeg trykker F8. Noen med peiling? Lenke til kommentar
V?rbris Skrevet 4. juni 2009 Forfatter Del Skrevet 4. juni 2009 (endret) Har kommet inn i sikkerhetsmodus og scannet. Fant CWS.Msconfig med CWshredder. Søkte på dette med Google, fant ikke noe i Norge men i utlandet ble det linket til hijakers? Legger ved highjackthislogg hvis noen orker å se på den? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:00:04, on 04.06.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programfiler\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\Analog Devices\Core\smax4pnp.exe C:\Programfiler\Analog Devices\SoundMAX\smax4.exe C:\Programfiler\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\RunDLL32.exe D:\Malwarebytes\Malwarebytes' Anti-Malware\mbamgui.exe C:\Programfiler\EXPERTool\TBPanel.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Avira\AntiVir Desktop\avguard.exe C:\Programfiler\Java\jre6\bin\jqs.exe D:\Malwarebytes\Malwarebytes' Anti-Malware\mbamservice.exe D:\CDburnerxp\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Programfiler\Avira\AntiVir Desktop\avmailc.exe C:\Programfiler\Avira\AntiVir Desktop\AVWEBGRD.EXE D:\div antivirus\ANTICOOLWWWSEARCH\CWShredder.exe C:\Programfiler\Internet Explorer\IEXPLORE.EXE C:\Programfiler\Internet Explorer\IEXPLORE.EXE C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Internet Explorer\iexplore.exe D:\div antivirus\Highjackthis\ulfjoh01.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - D:\Canon MP510\Easy-WebPrint\EWPBrowseLoader.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre6\bin\ssv.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programfiler\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programfiler\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - D:\Canon MP510\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot O4 - HKLM\..\Run: [soundMAXPnP] C:\Programfiler\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMax] "C:\Programfiler\Analog Devices\SoundMAX\smax4.exe" /tray O4 - HKLM\..\Run: [avgnt] "C:\Programfiler\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "D:\Malwarebytes\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto O4 - HKCU\..\Run: [GAINWARD] C:\Programfiler\EXPERTool\TBPanel.exe /A O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\DOCUME~1\Eier\MINEDO~1\office\Office12\EXCEL.EXE/3000 O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1226813877171 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1227015707796 O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Programfiler\Avira\AntiVir Desktop\avmailc.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Programfiler\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programfiler\Avira\AntiVir Desktop\avguard.exe O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Programfiler\Avira\AntiVir Desktop\AVWEBGRD.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programfiler\Java\jre6\bin\jqs.exe O23 - Service: MBAMService - Malwarebytes Corporation - D:\Malwarebytes\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: NMSAccessU - Unknown owner - D:\CDburnerxp\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 6548 bytes Her er repport fra CWshredder: **** Run Keys **** RUN: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe RUN: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot RUN: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot RUN: [soundMAXPnP] C:\Programfiler\Analog Devices\Core\smax4pnp.exe RUN: [soundMax] "C:\Programfiler\Analog Devices\SoundMAX\smax4.exe" /tray RUN: [avgnt] "C:\Programfiler\Avira\AntiVir Desktop\avgnt.exe" /min RUN: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit RUN: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup RUN: [Malwarebytes' Anti-Malware] "D:\Malwarebytes\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray RUN: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto RUN: [GAINWARD] C:\Programfiler\EXPERTool\TBPanel.exe /A RUN: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe **** Browser Helper Objects **** BHO: [Adobe PDF Link Helper] C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: [EWPBrowseObject Class] D:\Canon MP510\Easy-WebPrint\EWPBrowseLoader.dll BHO: [Java Plug-In SSV Helper] C:\Programfiler\Java\jre6\bin\ssv.dll BHO: [Java Plug-In 2 SSV Helper] C:\Programfiler\Java\jre6\bin\jp2ssv.dll BHO: [JQSIEStartDetectorImpl Class] C:\Programfiler\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll **** IE Toolbars **** TOOLBAR: [Easy-WebPrint] D:\Canon MP510\Easy-WebPrint\Toolband.dll **** IE Extensions **** IEExt: [send til OneNote] IEExt: [Research] IEExt: [Research] IEExt: [Messenger] C:\Programfiler\Messenger\msmsgs.exe **** Hosts File Entries **** HOSTS: 127.0.0.1 localhost HOSTS: 127.0.0.1 localhost **** IE Settings **** Default Page: http://go.microsoft.com/fwlink/?LinkId=69157 Default Search: http://go.microsoft.com/fwlink/?LinkId=54896 Local Page: C:\WINDOWS\system32\blank.htm Search Page: http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch **** IE Context Menu (Right click) **** IEContext: [E&ksporter til Microsoft Excel] res://C:\DOCUME~1\Eier\MINEDO~1\office\Office12\EXCEL.EXE/3000 **** Layered Service Providers **** LSP: AVSDA over [MSAFD Tcpip [TCP/IP]] LSP: AVSDA over [MSAFD Tcpip [uDP/IP]] LSP: MSAFD Tcpip [TCP/IP] LSP: MSAFD Tcpip [uDP/IP] LSP: RSVP UDP Service Provider LSP: RSVP TCP Service Provider LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6CE31D71-9827-4D3B-B187-AC00D0DA0E17}] SEQPACKET 4 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6CE31D71-9827-4D3B-B187-AC00D0DA0E17}] DATAGRAM 4 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{96884F1C-15D1-4243-BB5C-7AF57A71904F}] SEQPACKET 3 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{96884F1C-15D1-4243-BB5C-7AF57A71904F}] DATAGRAM 3 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B22C4DD9-BCD0-4B77-8D9F-9F73DC8F426E}] SEQPACKET 0 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B22C4DD9-BCD0-4B77-8D9F-9F73DC8F426E}] DATAGRAM 0 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FFDDB692-4C52-4E67-AA4F-6EBDBCBD6150}] SEQPACKET 1 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FFDDB692-4C52-4E67-AA4F-6EBDBCBD6150}] DATAGRAM 1 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{63B316D8-5C85-40F5-B800-A12CCC1B86D5}] SEQPACKET 2 LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{63B316D8-5C85-40F5-B800-A12CCC1B86D5}] DATAGRAM 2 **** Blocked Control Panel Items **** BLOCKED: [ncpa.cpl] No BLOCKED: [odbccp32.cpl] No **** Downloaded Program Files **** {6414512B-B978-451D-A0D8-FCFDF33E833C} [http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226813877171] C:\WINDOWS\system32\wuweb.dll {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227015707796] {8AD9C840-044E-11D1-B3E9-00805F499D93} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab] {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab] {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab] {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab] {D27CDB6E-AE6D-11CF-96B8-444553540000} [http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab] **** Windows Services **** [Alerter] %SystemRoot%\system32\svchost.exe -k LocalService [ALG] %SystemRoot%\System32\alg.exe [AntiVirMailService] "C:\Programfiler\Avira\AntiVir Desktop\avmailc.exe" [AntiVirSchedulerService] "C:\Programfiler\Avira\AntiVir Desktop\sched.exe" [AntiVirService] "C:\Programfiler\Avira\AntiVir Desktop\avguard.exe" [AntiVirWebService] "C:\Programfiler\Avira\AntiVir Desktop\AVWEBGRD.EXE" [AppMgmt] %SystemRoot%\system32\svchost.exe -k netsvcs [aspnet_state] %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [AudioSrv] %SystemRoot%\System32\svchost.exe -k netsvcs [bITS] %SystemRoot%\system32\svchost.exe -k netsvcs [browser] %SystemRoot%\system32\svchost.exe -k netsvcs [CiSvc] %SystemRoot%\system32\cisvc.exe [ClipSrv] %SystemRoot%\system32\clipsrv.exe [clr_optimization_v2.0.50727_32] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [COMSysApp] C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} [CryptSvc] %SystemRoot%\system32\svchost.exe -k netsvcs [DcomLaunch] %SystemRoot%\system32\svchost -k DcomLaunch [Dhcp] %SystemRoot%\system32\svchost.exe -k netsvcs [dmadmin] %SystemRoot%\System32\dmadmin.exe /com [dmserver] %SystemRoot%\System32\svchost.exe -k netsvcs [Dnscache] %SystemRoot%\system32\svchost.exe -k NetworkService [Dot3svc] %SystemRoot%\System32\svchost.exe -k dot3svc [EapHost] %SystemRoot%\System32\svchost.exe -k eapsvcs [ERSvc] %SystemRoot%\System32\svchost.exe -k netsvcs [Eventlog] %SystemRoot%\system32\services.exe [EventSystem] C:\WINDOWS\system32\svchost.exe -k netsvcs [FastUserSwitchingCompatibility] %SystemRoot%\System32\svchost.exe -k netsvcs [FontCache3.0.0.0] c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [helpsvc] %SystemRoot%\System32\svchost.exe -k netsvcs [HidServ] %SystemRoot%\System32\svchost.exe -k netsvcs [hkmsvc] %SystemRoot%\System32\svchost.exe -k netsvcs [HTTPFilter] %SystemRoot%\System32\svchost.exe -k HTTPFilter [iDriverT] "C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [idsvc] "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" [imapiService] %systemroot%\system32\imapi.exe [JavaQuickStarterService] "C:\Programfiler\Java\jre6\bin\jqs.exe" -service -config "C:\Programfiler\Java\jre6\lib\deploy\jqs\jqs.conf" [lanmanserver] %SystemRoot%\system32\svchost.exe -k netsvcs [lanmanworkstation] %SystemRoot%\system32\svchost.exe -k netsvcs [LmHosts] %SystemRoot%\system32\svchost.exe -k LocalService [MBAMService] "D:\Malwarebytes\Malwarebytes' Anti-Malware\mbamservice.exe" [Messenger] %SystemRoot%\system32\svchost.exe -k netsvcs [mnmsrvc] C:\WINDOWS\system32\mnmsrvc.exe [MSDTC] C:\WINDOWS\system32\msdtc.exe [MSIServer] %systemroot%\system32\msiexec.exe /V [napagent] %SystemRoot%\System32\svchost.exe -k netsvcs [NetDDE] %SystemRoot%\system32\netdde.exe [NetDDEdsdm] %SystemRoot%\system32\netdde.exe [Netlogon] %SystemRoot%\system32\lsass.exe [Netman] %SystemRoot%\System32\svchost.exe -k netsvcs [NetTcpPortSharing] "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" [Nla] %SystemRoot%\system32\svchost.exe -k netsvcs [NMSAccessU] D:\CDburnerxp\CDBurnerXP\NMSAccessU.exe [NtLmSsp] %SystemRoot%\system32\lsass.exe [NtmsSvc] %SystemRoot%\system32\svchost.exe -k netsvcs [NVSvc] %SystemRoot%\system32\nvsvc32.exe [odserv] "C:\Programfiler\Fellesfiler\Microsoft Shared\OFFICE12\ODSERV.EXE" [ose] "C:\Programfiler\Fellesfiler\Microsoft Shared\Source Engine\OSE.EXE" [PlugPlay] %SystemRoot%\system32\services.exe [PolicyAgent] %SystemRoot%\system32\lsass.exe [ProtectedStorage] %SystemRoot%\system32\lsass.exe [RasAuto] %SystemRoot%\system32\svchost.exe -k netsvcs [RasMan] %SystemRoot%\system32\svchost.exe -k netsvcs [RDSessMgr] C:\WINDOWS\system32\sessmgr.exe [RemoteAccess] %SystemRoot%\system32\svchost.exe -k netsvcs [RemoteRegistry] %SystemRoot%\system32\svchost.exe -k LocalService [RpcLocator] %SystemRoot%\system32\locator.exe [RpcSs] %SystemRoot%\system32\svchost -k rpcss [RSVP] %SystemRoot%\system32\rsvp.exe [samSs] %SystemRoot%\system32\lsass.exe [sCardSvr] %SystemRoot%\System32\SCardSvr.exe [schedule] %SystemRoot%\System32\svchost.exe -k netsvcs [seclogon] %SystemRoot%\System32\svchost.exe -k netsvcs [sENS] %SystemRoot%\system32\svchost.exe -k netsvcs [sharedAccess] %SystemRoot%\System32\svchost.exe -k netsvcs [shellHWDetection] %SystemRoot%\System32\svchost.exe -k netsvcs [spooler] %SystemRoot%\system32\spoolsv.exe [srservice] %SystemRoot%\system32\svchost.exe -k netsvcs [sSDPSRV] %SystemRoot%\system32\svchost.exe -k LocalService [stisvc] %SystemRoot%\system32\svchost.exe -k imgsvc [swPrv] C:\WINDOWS\system32\dllhost.exe /Processid:{C9DED91F-04AC-43F2-8FF9-28F971971C94} [sysmonLog] %SystemRoot%\system32\smlogsvc.exe [TapiSrv] %SystemRoot%\System32\svchost.exe -k netsvcs [TermService] %SystemRoot%\System32\svchost -k DComLaunch [Themes] %SystemRoot%\System32\svchost.exe -k netsvcs [TlntSvr] C:\WINDOWS\system32\tlntsvr.exe [TrkWks] %SystemRoot%\system32\svchost.exe -k netsvcs [upnphost] %SystemRoot%\system32\svchost.exe -k LocalService [uPS] %SystemRoot%\System32\ups.exe [VSS] %SystemRoot%\System32\vssvc.exe [W32Time] %SystemRoot%\System32\svchost.exe -k netsvcs [WebClient] %SystemRoot%\system32\svchost.exe -k LocalService [winmgmt] %systemroot%\system32\svchost.exe -k netsvcs [WmdmPmSN] %SystemRoot%\System32\svchost.exe -k netsvcs [Wmi] %SystemRoot%\System32\svchost.exe -k netsvcs [WmiApSrv] C:\WINDOWS\system32\wbem\wmiapsrv.exe [WMPNetworkSvc] "C:\Programfiler\Windows Media Player\WMPNetwk.exe" [wscsvc] %SystemRoot%\System32\svchost.exe -k netsvcs [wuauserv] %systemroot%\system32\svchost.exe -k netsvcs [WudfSvc] %SystemRoot%\system32\svchost.exe -k WudfServiceGroup [WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs [xmlprov] %SystemRoot%\System32\svchost.exe -k netsvcs **** Custom IE Search Items **** SEARCH: [searchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm **** Complete IE Options **** IEOPT: [NoUpdateCheck] IEOPT: [NoJITSetup] IEOPT: [Disable Script Debugger] yes IEOPT: [show_ChannelBand] No IEOPT: [Anchor Underline] yes IEOPT: [Cache_Update_Frequency] Once_Per_Session IEOPT: [Display Inline Images] yes IEOPT: [Do404Search] IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm IEOPT: [save_Session_History_On_Exit] no IEOPT: [show_FullURL] no IEOPT: [show_StatusBar] yes IEOPT: [show_ToolBar] yes IEOPT: [show_URLinStatusBar] yes IEOPT: [show_URLToolBar] yes IEOPT: [start Page] http://www.google.no/ IEOPT: [use_DlgBox_Colors] yes IEOPT: [search Page] http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IEOPT: [FullScreen] no IEOPT: [Window_Placement] , IEOPT: [use FormSuggest] yes IEOPT: [AddToFavoritesExpanded] IEOPT: [NotifyDownloadComplete] no IEOPT: [xmlHTTP] IEOPT: [useClearType] yes IEOPT: [AlwaysShowMenus] IEOPT: [Enable Browser Extensions] yes IEOPT: [Play_Background_Sounds] yes IEOPT: [Play_Animations] yes IEOPT: [CompatibilityFlags] IEOPT: [searchMigrated] IEOPT: [AutoHide] yes IEOPT: [Print_Background] no IEOPT: [Enable AutoImageResize] no IEOPT: [show image placeholders] IEOPT: [AutoSearch] IEOPT: [Move System Caret] no IEOPT: [Expand Alt Text] no IEOPT: [Page_Transitions] IEOPT: [useThemes] IEOPT: [smoothScroll] IEOPT: [AllowWindowReuse] IEOPT: [DisableScriptDebuggerIE] yes IEOPT: [EnableSearchPane] IEOPT: [NscSingleExpand] IEOPT: [Force Offscreen Composition] IEOPT: [Friendly http errors] yes IEOPT: [Error Dlg Displayed On Every Error] no IEOPT: [FormSuggest Passwords] yes IEOPT: [FormSuggest PW Ask] yes IEOPT: [iE8RunOnceLastShown] IEOPT: [iE8RunOnceLastShown_TIMESTAMP] IEOPT: [iE8RunOncePerInstallCompleted] IEOPT: [iE8RunOnceCompletionTime] IEOPT: [iE8TourShown] IEOPT: [iE8TourShownTime] IEOPT: [Default_Page_URL] http://go.microsoft.com/fwlink/?LinkId=69157 IEOPT: [Default_Search_URL] http://go.microsoft.com/fwlink/?LinkId=54896 IEOPT: [search Page] http://go.microsoft.com/fwlink/?LinkId=54896 IEOPT: [Enable_Disk_Cache] yes IEOPT: [Cache_Percent_of_Disk] IEOPT: [Delete_Temp_Files_On_Exit] yes IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm IEOPT: [Anchor_Visitation_Horizon] IEOPT: [use_Async_DNS] yes IEOPT: [Placeholder_Width] IEOPT: [Placeholder_Height] IEOPT: [start Page] http://go.microsoft.com/fwlink/?LinkId=69157 IEOPT: [CompanyName] Microsoft Corporation IEOPT: [Custom_Key] MICROSO IEOPT: [Wizard_Version] 6.0.2600.0000 IEOPT: [FullScreen] no IEOPT: [Default_Secondary_Page_URL] IEOPT: [Extensions Off Page] about:NoAdd-ons IEOPT: [security Risk Page] about:SecurityRisk IEOPT: [Check_Associations] yes Må tilføre at jeg finner ingenting med Avira Premium, Dr.Web, Malwarebytes eller Superantispyware som jeg scanner med nå. Endret 4. juni 2009 av ulfjoh01 Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå