Gå til innhold

Noen som orker å se hijackthis loggen min?


Anbefalte innlegg

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:12:46, on 06.08.2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Java\jre6\bin\jusched.exe

C:\Programfiler\Logitech\G-series Software\LGDCore.exe

C:\Programfiler\Logitech\G-series Software\LCDMon.exe

C:\Programfiler\MSI\Live Update 3\LMonitor.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\RunDLL32.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Programfiler\Logitech\G-series Software\Applets\LCDClock.exe

C:\Programfiler\Logitech\G-series Software\Applets\LCDMedia.exe

C:\WINDOWS\system32\ctfmon.exe

D:\Steam\Steam.exe

C:\Programfiler\Creative\Shared Files\CamTray.exe

C:\Programfiler\Windows Live\Messenger\msnmsgr.exe

C:\Programfiler\Skype\Phone\Skype.exe

C:\Programfiler\Messenger\msmsgs.exe

C:\Programfiler\Logitech\SetPoint\SetPoint.exe

C:\Programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.EXE

F:\Hamachi\hamachi.exe

C:\Programfiler\Skype\Plugin Manager\skypePM.exe

C:\WINDOWS\ATKKBService.exe

C:\Programfiler\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Programfiler\Windows Live\Contacts\wlcomm.exe

F:\Mozilla Firefox\firefox.exe

C:\Programfiler\Skype\Toolbars\Shared\SkypeNames.exe

F:\Spotify\spotify.exe

F:\VideoLAN\vlc.exe

F:\uTorrent\uTorrent.exe

C:\Documents and Settings\All Users\Skrivebord\Hijackthis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://tw.msi.com.tw/autobios/VerChk/LSeri...nction=LMonitor

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programfiler\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programfiler\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [GameFace Messenger] C:\Programfiler\GameFace Messenger\GameFace.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Adobe Reader\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programfiler\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE

O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programfiler\Logitech\G-series Software\LCDMon.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [LiveMonitor] C:\Programfiler\MSI\Live Update 3\LMonitor.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [steam] "D:\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [Creative WebCam Tray] C:\Programfiler\Creative\Shared Files\CamTray.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [skype] "C:\Programfiler\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [DAEMON Tools Lite] F:\Daemon Tools\DAEMON Tools Lite\daemon.exe -autorun

O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: hamachi.lnk = F:\Hamachi\hamachi.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Programfiler\Logitech\SetPoint\SetPoint.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL

O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programfiler\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

 

Takk for svar på forhånd

Lenke til kommentar
Videoannonse
Annonse

Jeg har ikke noe med det, men hvorfor har du programmene spredt overalt?

 

- kjenner jeg ikke til GameFace, men slike programmer pleier ofte å være ulumske.

[VF0060 STISvc] RunDLL32.exe kan være infisert, dog antaglivis fra en sikker kilde. Tilhører antaglivis Creative Cam.

 

- Du har også mange programmer som ikke trenger å starte sammen med Windows:

 

¤ nwiz.exe

¤ GameFace.exe

¤ Reader_sl.exe

¤ jusched.exe

¤ LGDCore.exe (?)

¤ LCDMon.exe (?)

¤ KHALMNPR.EXE (?)

¤ LMonitor.exe

¤ NvMcTray.dll

¤ dumprep 0 -k

¤ SOUNDMAN.EXE

¤ ctfmon.exe

¤ Steam.exe

¤ CamTray.exe

¤ msnmsgr.exe

¤ Skype.exe

¤ daemon.exe (?)

¤ SetPoint.exe (?)

 

PS: Prosessor merket med (?) bør du være forsiktig med å deaktivere, les først gjennom og se om du benytter deg av dens funksjoner før du deaktivcerer disse. De andre kan du trygt deaktivere fra oppstart uten noe fare, og er høyst anbefalt fra min side, det vil frigjør en del systemressurser. Du kan bruke CCleaner for å enkelt aktivere/deaktivere disse oppstartsprosessene

 

PPS: Du kan for at vi skal være mer sikkre, kjøre MBAM og poste loggen her i denne tråden.

https://www.diskusjon.no/index.php?showtopic=691246

Lenke til kommentar

Har mange partisjoner, liker å ha det ryddig :p

 

 

MBAM

Klikk for å se/fjerne innholdet nedenfor
Malwarebytes' Anti-Malware 1.40

Databaseversjon: 2571

Windows 5.1.2600 Service Pack 3

 

06.08.2009 21:00:02

mbam-log-2009-08-06 (21-00-02).txt

 

Skanntype: Rask Skann

Objekter skannet: 83699

Tid tilbakelagt: 3 minute(s), 20 second(s)

 

Minneprosesser infisert: 0

Minnemoduler infisert: 0

Registernøkler infisert: 1

Registerverdier infisert: 0

Registerfiler infisert: 0

Mapper infisert: 0

Filer infisert: 1

 

Minneprosesser infisert:

(Ingen mistenkelige filer funnet)

 

Minnemoduler infisert:

(Ingen mistenkelige filer funnet)

 

Registernøkler infisert:

HKEY_CLASSES_ROOT\CLSID\{58101905-d80f-4788-96f6-986a8186178a} (Trojan.Agent) -> Quarantined and deleted successfully.

 

Registerverdier infisert:

(Ingen mistenkelige filer funnet)

 

Registerfiler infisert:

(Ingen mistenkelige filer funnet)

 

Mapper infisert:

(Ingen mistenkelige filer funnet)

 

Filer infisert:

C:\WINDOWS\system32\flashd32.dll (Trojan.Agent) -> Quarantined and deleted successfully.

 

Combofix

Klikk for å se/fjerne innholdet nedenfor
ComboFix 09-08-04.04 - Clinkz 06.08.2009 21:02.1.2 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18.2047.1284 [GMT 2:00]

Kjører fra: c:\documents and settings\Clinkz\Skrivebord\ComboFix.exe

 

ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !!

.

 

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\Drivers\krso.sys

 

.

((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_wprpg

 

 

((((((((((((((((((((((((((( Filer Opprettet Fra 2009-07-06 til 2009-08-06 )))))))))))))))))))))))))))))))))

.

 

2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Malwarebytes

2009-08-06 18:52 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\All Users\Programdata\Malwarebytes

2009-08-06 18:52 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-08-05 19:55 . 2009-08-05 19:55 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_15\lzma.dll

2009-08-03 00:47 . 2009-08-03 00:47 -------- d-----w- c:\documents and settings\All Users\Programdata\Blizzard

2009-08-03 00:46 . 2009-08-03 00:46 -------- d-----w- c:\programfiler\Fellesfiler\Blizzard Entertainment

2009-08-02 18:35 . 2009-08-02 18:35 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Identities

2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\Clinkz\IETldCache

2009-08-02 06:18 . 2009-07-19 16:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll

2009-08-02 06:18 . 2009-07-03 17:01 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2009-08-02 06:18 . 2009-07-03 17:01 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll

2009-08-02 06:18 . 2009-07-03 17:01 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll

2009-08-02 06:18 . 2009-07-03 17:01 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2009-08-02 06:18 . 2009-07-03 17:01 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll

2009-08-02 06:18 . 2009-08-02 06:18 -------- d-----w- c:\windows\ie8updates

2009-08-02 06:18 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll

2009-08-02 06:17 . 2009-08-02 06:18 -------- dc-h--w- c:\windows\ie8

2009-07-20 16:50 . 2009-07-20 16:50 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Ubisoft

2009-07-20 16:46 . 2009-07-20 16:46 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys

2009-07-20 16:46 . 2009-07-20 16:46 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys

2009-07-19 14:48 . 2009-07-19 14:48 -------- d-----w- c:\programfiler\DIFX

2009-07-19 14:46 . 2009-07-19 14:46 -------- d-----w- c:\programfiler\Realtek AC97

2009-07-17 17:47 . 2009-07-17 18:20 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Aspyr

2009-07-17 02:04 . 2009-08-02 07:00 -------- d-----w- c:\windows\system32\nb-no

2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\no

2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\bits

2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\l2schemas

2009-07-17 02:03 . 2009-07-17 02:03 -------- d-----w- c:\windows\ServicePackFiles

2009-07-17 02:01 . 2009-07-17 02:01 -------- d-----w- c:\windows\EHome

2009-07-16 05:50 . 2009-07-16 05:50 60416 ----a-w- c:\windows\ALCFDRTM.EXE

2009-07-15 22:57 . 2009-07-21 00:40 -------- d-----w- c:\documents and settings\All Users\Programdata\TrackMania

2009-07-15 07:50 . 2009-07-15 07:50 -------- d-----w- c:\documents and settings\NetworkService\Lokale innstillinger\Programdata\Apple

2009-07-14 15:41 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll

2009-07-14 15:41 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\DirectX

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\windows\system32\AGEIA

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\AGEIA Technologies

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\Wise Installation Wizard

2009-07-14 04:01 . 2009-07-14 04:01 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Creative

2009-07-14 03:36 . 2009-07-14 03:36 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\CAPCOM

2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\programfiler\Microsoft Games for Windows - LIVE

2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\windows\system32\xlive

2009-07-14 02:45 . 2009-08-02 08:02 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Adobe

2009-07-14 02:45 . 2009-07-14 03:11 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\VirtuaTennis2009

2009-07-14 02:43 . 2009-07-14 02:43 63904 ----a-w- c:\documents and settings\LocalService\Lokale innstillinger\Programdata\FontCache3.0.0.0.dat

2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\MSBuild

2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\windows\system32\XPSViewer

2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\Reference Assemblies

2009-07-14 02:43 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll

2009-07-14 02:41 . 2009-07-14 02:41 -------- d-----w- c:\programfiler\MSXML 6.0

2009-07-14 01:26 . 2009-07-14 01:26 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Apple Computer

2009-07-14 01:25 . 2009-07-14 01:25 -------- d-----w- c:\documents and settings\Clinkz\Programdata\dvdcss

2009-07-14 00:52 . 2009-07-14 00:52 -------- d-----w- c:\windows\Sun

2009-07-14 00:50 . 2009-07-22 09:34 -------- d-----w- c:\documents and settings\Clinkz\Programdata\mIRC

2009-07-13 23:56 . 2009-07-13 23:56 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GHOSTBUSTERS

2009-07-13 23:30 . 2009-07-13 23:30 -------- d-----w- c:\programfiler\Realtek

2009-07-13 23:30 . 2009-06-24 08:43 831488 ----a-w- c:\windows\RtlExUpd.dll

2009-07-13 22:17 . 2009-07-13 22:17 -------- d-----w- c:\windows\Logs

2009-07-13 21:51 . 2009-07-13 21:51 -------- d-----w- c:\programfiler\Atari

2009-07-13 21:31 . 2009-07-15 18:27 8 ----a-w- c:\windows\system32\nvModes.dat

2009-07-13 21:30 . 2009-07-13 21:30 -------- d-----w- c:\documents and settings\All Users\Programdata\nView_Profiles

2009-07-13 21:27 . 2009-02-09 11:18 290816 ----a-w- c:\windows\system32\nvwrsth.dll

2009-07-13 21:27 . 2009-02-09 11:18 253952 ----a-w- c:\windows\system32\nvrsth.dll

2009-07-13 21:27 . 2009-02-09 11:18 401408 ----a-w- c:\windows\system32\nvcuvid.dll

2009-07-13 21:27 . 2006-06-01 15:22 1011712 ----a-w- c:\windows\system32\nvcpluir.dll

2009-07-13 21:25 . 2009-07-13 21:25 -------- d-----w- c:\programfiler\My Company Name

2009-07-13 21:18 . 2009-08-06 10:35 -------- d-----w- c:\documents and settings\Clinkz\Programdata\vlc

2009-07-13 21:14 . 2004-08-03 20:29 63488 ------w- c:\windows\system32\drivers\atinxsxx.sys

2009-07-13 21:08 . 2009-07-13 21:08 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Macromedia

2009-07-13 21:07 . 2009-07-13 21:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-07-13 21:07 . 2009-08-06 14:07 -------- d-----w- c:\documents and settings\Clinkz\Programdata\skypePM

2009-07-13 21:06 . 2009-07-13 21:06 45056 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe

2009-07-13 21:06 . 2009-07-13 21:07 -------- d-----w- c:\programfiler\Fellesfiler\Macromedia

2009-07-13 21:06 . 2009-08-02 06:23 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Spotify

2009-07-13 21:06 . 2009-07-13 21:06 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Spotify

2009-07-13 21:05 . 2009-07-13 21:05 -------- d-----w- c:\windows\Downloaded Installations

2009-07-13 21:00 . 2001-08-17 21:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys

2009-07-13 21:00 . 2009-07-13 21:00 -------- d-----w- c:\windows\system32\Lang

2009-07-13 21:00 . 2008-04-14 16:22 21504 ----a-w- c:\windows\system32\hidserv.dll

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-08-06 19:06 . 2009-07-13 20:06 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Hamachi

2009-08-06 19:04 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Skype

2009-08-06 18:49 . 2009-07-13 20:42 -------- d-----w- c:\documents and settings\Clinkz\Programdata\uTorrent

2009-08-05 20:05 . 2009-07-13 19:52 -------- d--h--w- c:\programfiler\InstallShield Installation Information

2009-07-22 10:08 . 2009-07-13 20:24 13688 ----a-w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT

2009-07-19 15:04 . 2004-08-04 12:00 75854 ----a-w- c:\windows\system32\perfc014.dat

2009-07-19 15:04 . 2004-08-04 12:00 436116 ----a-w- c:\windows\system32\perfh014.dat

2009-07-19 14:56 . 2009-07-13 20:29 -------- d-----w- c:\programfiler\Setup Files

2009-07-17 02:06 . 2009-07-13 19:17 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-07-16 23:46 . 2009-07-13 20:05 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys

2009-07-13 22:20 . 2009-07-13 22:20 -------- d--h--r- c:\documents and settings\Clinkz\Programdata\SecuROM

2009-07-13 21:39 . 2009-07-13 20:45 -------- d-----w- c:\documents and settings\Clinkz\Programdata\DAEMON Tools Lite

2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\documents and settings\All Users\Programdata\DAEMON Tools Lite

2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\programfiler\DAEMON Tools Toolbar

2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----r- c:\programfiler\Skype

2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\programfiler\Fellesfiler\Skype

2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\All Users\Programdata\Skype

2009-07-13 20:48 . 2009-07-13 20:47 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Winamp

2009-07-13 20:45 . 2009-07-13 20:45 721904 ----a-w- c:\windows\system32\drivers\sptd.sys

2009-07-13 20:35 . 2009-07-13 20:35 0 ----a-w- c:\windows\nsreg.dat

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Microsoft

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live SkyDrive

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\MSI

2009-07-13 20:27 . 2009-07-13 20:27 -------- d-----w- c:\programfiler\Fellesfiler\Windows Live

2009-07-13 20:23 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\GameFace Messenger

2009-07-13 20:17 . 2009-07-13 20:15 -------- d-----w- c:\programfiler\Creative

2009-07-13 20:15 . 2009-07-13 19:50 -------- d-----w- c:\programfiler\Fellesfiler\InstallShield

2009-07-13 20:13 . 2009-07-13 20:08 -------- d-----w- c:\programfiler\Logitech

2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Logitech

2009-07-13 20:13 . 2009-07-13 20:13 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe

2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\programfiler\Fellesfiler\LogiShared

2009-07-13 20:11 . 2009-07-13 20:11 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe

2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf

2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\programfiler\Fellesfiler\Logitech

2009-07-13 20:10 . 2009-07-13 20:10 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe

2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\documents and settings\Clinkz\Programdata\InstallShield

2009-07-13 20:09 . 2009-07-13 20:09 -------- d-----w- c:\documents and settings\All Users\Programdata\LogiShrd

2009-07-13 20:08 . 2009-07-13 20:08 -------- d-----w- c:\documents and settings\All Users\Programdata\Logitech

2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple Computer

2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\programfiler\Apple Software Update

2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple

2009-07-13 20:02 . 2009-07-13 20:02 410984 ----a-w- c:\windows\system32\deploytk.dll

2009-07-13 20:02 . 2009-07-13 20:02 -------- d-----w- c:\programfiler\Java

2009-07-13 20:02 . 2009-07-13 20:02 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_13\lzma.dll

2009-07-13 20:01 . 2009-07-13 20:01 -------- d-----w- c:\programfiler\Fellesfiler\Adobe AIR

2009-07-13 20:01 . 2009-07-13 20:00 -------- d-----w- c:\programfiler\Fellesfiler\Adobe

2009-07-13 19:56 . 2009-07-13 19:56 737280 ----a-w- c:\windows\iun6002.exe

2009-07-13 19:56 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\ASUSTeK

2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\Realtek Sound Manager

2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\AvRack

2009-07-13 19:18 . 2009-07-13 19:18 -------- d-----w- c:\programfiler\microsoft frontpage

2009-07-13 19:17 . 2009-07-13 19:17 -------- d-----w- c:\programfiler\Elektroniske tjenester

2009-07-13 19:16 . 2009-07-13 19:16 -------- d-----w- c:\programfiler\Fellesfiler\Tjenester

2009-07-13 19:15 . 2009-07-13 19:15 21704 ----a-w- c:\windows\system32\emptyregdb.dat

2009-07-03 17:01 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll

2009-06-16 14:43 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll

2009-06-16 14:43 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll

2009-06-03 19:11 . 2004-08-04 12:00 1294336 ----a-w- c:\windows\system32\quartz.dll

.

 

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]

"Launch LGDCore"="c:\programfiler\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]

"Launch LCDMon"="c:\programfiler\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]

"LiveMonitor"="c:\programfiler\MSI\Live Update 3\LMonitor.exe" [2009-02-24 498688]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

"VF0060 STISvc"="V0060Pin.dll" - c:\windows\system32\V0060Pin.dll [2004-11-01 36864]

"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\Clinkz\Start-meny\Programmer\Oppstart\

hamachi.lnk - f:\hamachi\hamachi.exe [2009-2-5 625952]

 

c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\

Logitech SetPoint.lnk - c:\programfiler\Logitech\SetPoint\SetPoint.exe [2009-7-13 692224]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

@=""

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"f:\\uTorrent\\uTorrent.exe"=

"f:\\Garena\\Garena.exe"=

"f:\\Spotify\\spotify.exe"=

"d:\\Overlord II\\Overlord2.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Programfiler\\Skype\\Phone\\Skype.exe"=

 

R2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [04.08.2004 14:00 14336]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp --> c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp [?]

S3 V0060VID;Creative WebCam Live! Ultra;c:\windows\system32\drivers\V0060Vid.sys [15.07.2009 00:41 196409]

 

--- Andre tjenester/drivere lastet i minnet ---

 

*NewlyCreated* - WEBNTACCESS

*Deregistered* - WEBNTACCESS

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

wmcmgc

 

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

 

2009-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\programfiler\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

.

.

------- Tilleggsskanning -------

.

uInternet Connection Wizard,ShellNext = hxxp://tw.msi.com.tw/autobios/VerChk/LSeries.asp?MSIOCXVersion=3.76&WorkFunction=LMonitor

FF - ProfilePath - c:\documents and settings\Clinkz\Programdata\Mozilla\Firefox\Profiles\67k6v12c.default\

FF - component: f:\mozilla firefox\components\FFComm.dll

FF - component: f:\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll

FF - plugin: f:\adobe reader\Reader\browser\nppdf32.dll

FF - plugin: f:\mozilla firefox\plugins\npoctoshape.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin2.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin3.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin4.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin5.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin6.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin7.dll

 

---- FIREFOX POLICIES ----

f:\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);

f:\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);

f:\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");

f:\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);

f:\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);

f:\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);

f:\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);

f:\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);

f:\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);

f:\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);

f:\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);

f:\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);

f:\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);

f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");

f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");

f:\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");

f:\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);

f:\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-08-06 21:06

Windows 5.1.2600 Service Pack 3 NTFS

 

skanner skjulte prosesser ...

 

skanner skjulte autostart-oppføringer ...

 

skanner skjulte filer ...

 

skanning vellykket

skjulte filer: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp"

.

--------------------- LÅSTE REGISTERNØKLER ---------------------

 

[HKEY_USERS\S-1-5-21-329068152-1844823847-682003330-1004\Software\SecuROM\License information*]

"datasecu"=hex:25,47,3f,41,60,9a,c2,f0,93,11,89,3a,53,31,e2,19,fd,cc,67,ab,f4,

a2,2d,2b,f7,06,cc,c7,ee,d1,49,67,89,59,d6,6c,1a,41,28,1b,16,a9,42,77,3a,3a,\

"rkeysecu"=hex:8c,c2,22,e8,15,86,f7,44,b3,d5,d3,99,33,14,11,2b

.

--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

 

- - - - - - - > 'explorer.exe'(2540)

c:\programfiler\Logitech\SetPoint\GameHook.dll

c:\programfiler\Logitech\SetPoint\lgscroll.dll

c:\windows\system32\webcheck.dll

.

------------------------ Andre Kjørende Prosesser ------------------------

.

c:\windows\system32\rundll32.exe

c:\windows\system32\rundll32.exe

c:\programfiler\Logitech\G-series Software\Applets\LCDClock.exe

c:\programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.exe

c:\windows\ATKKBService.exe

c:\programfiler\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Tidspunkt ferdig: 2009-08-06 21:08 - maskinen ble startet på nytt

ComboFix-quarantined-files.txt 2009-08-06 19:08

 

Pre-Run: 16 755 998 720 byte ledig

Post-Run: 17 031 151 616 byte ledig

 

315 --- E O F --- 2009-08-02 06:18

Endret av BendItLikeBender
Lenke til kommentar

Ny combofix logg

 

Klikk for å se/fjerne innholdet nedenfor
ComboFix 09-08-06.01 - Clinkz 06.08.2009 23:26.3.2 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18.2047.995 [GMT 2:00]

Kjører fra: c:\documents and settings\Clinkz\Skrivebord\ComboFix.exe

Command switches brukt :: c:\documents and settings\Clinkz\Skrivebord\CFScript.txt.txt

 

ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !!

 

FILE ::

"c:\docume~1\Clinkz\LOKALE~1\Temp\PAFBA.tmp"

.

 

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

((((((((((((((((((((((((((((((((((((((( Drivere/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_GARENAPENGINE

-------\Service_GarenaPEngine

 

 

((((((((((((((((((((((((((( Filer Opprettet Fra 2009-07-06 til 2009-08-06 )))))))))))))))))))))))))))))))))

.

 

2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Malwarebytes

2009-08-06 18:52 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-06 18:52 . 2009-08-06 18:52 -------- d-----w- c:\documents and settings\All Users\Programdata\Malwarebytes

2009-08-06 18:52 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-08-05 19:55 . 2009-08-05 19:55 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_15\lzma.dll

2009-08-03 00:47 . 2009-08-03 00:47 -------- d-----w- c:\documents and settings\All Users\Programdata\Blizzard

2009-08-03 00:46 . 2009-08-03 00:46 -------- d-----w- c:\programfiler\Fellesfiler\Blizzard Entertainment

2009-08-02 18:35 . 2009-08-02 18:35 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Identities

2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2009-08-02 07:01 . 2009-08-02 07:01 -------- d-sh--w- c:\documents and settings\Clinkz\IETldCache

2009-08-02 06:18 . 2009-07-19 16:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll

2009-08-02 06:18 . 2009-07-03 17:01 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2009-08-02 06:18 . 2009-07-03 17:01 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll

2009-08-02 06:18 . 2009-07-03 17:01 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll

2009-08-02 06:18 . 2009-07-03 17:01 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2009-08-02 06:18 . 2009-07-03 17:01 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll

2009-08-02 06:18 . 2009-08-02 06:18 -------- d-----w- c:\windows\ie8updates

2009-08-02 06:18 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll

2009-08-02 06:17 . 2009-08-02 06:18 -------- dc-h--w- c:\windows\ie8

2009-07-20 16:50 . 2009-07-20 16:50 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Ubisoft

2009-07-20 16:46 . 2009-07-20 16:46 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys

2009-07-20 16:46 . 2009-07-20 16:46 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys

2009-07-19 14:48 . 2009-07-19 14:48 -------- d-----w- c:\programfiler\DIFX

2009-07-19 14:46 . 2009-07-19 14:46 -------- d-----w- c:\programfiler\Realtek AC97

2009-07-17 17:47 . 2009-07-17 18:20 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Aspyr

2009-07-17 02:04 . 2009-08-02 07:00 -------- d-----w- c:\windows\system32\nb-no

2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\no

2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\system32\bits

2009-07-17 02:04 . 2009-07-17 02:04 -------- d-----w- c:\windows\l2schemas

2009-07-17 02:03 . 2009-07-17 02:03 -------- d-----w- c:\windows\ServicePackFiles

2009-07-17 02:01 . 2009-07-17 02:01 -------- d-----w- c:\windows\EHome

2009-07-16 05:50 . 2009-07-16 05:50 60416 ----a-w- c:\windows\ALCFDRTM.EXE

2009-07-15 22:57 . 2009-07-21 00:40 -------- d-----w- c:\documents and settings\All Users\Programdata\TrackMania

2009-07-15 07:50 . 2009-07-15 07:50 -------- d-----w- c:\documents and settings\NetworkService\Lokale innstillinger\Programdata\Apple

2009-07-14 15:41 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll

2009-07-14 15:41 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\DirectX

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\windows\system32\AGEIA

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\AGEIA Technologies

2009-07-14 13:35 . 2009-07-14 13:35 -------- d-----w- c:\programfiler\Fellesfiler\Wise Installation Wizard

2009-07-14 04:01 . 2009-07-14 04:01 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Creative

2009-07-14 03:36 . 2009-07-14 03:36 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\CAPCOM

2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\programfiler\Microsoft Games for Windows - LIVE

2009-07-14 03:18 . 2009-07-14 03:18 -------- d-----w- c:\windows\system32\xlive

2009-07-14 02:45 . 2009-08-02 08:02 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Adobe

2009-07-14 02:45 . 2009-07-14 03:11 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\VirtuaTennis2009

2009-07-14 02:43 . 2009-07-14 02:43 63904 ----a-w- c:\documents and settings\LocalService\Lokale innstillinger\Programdata\FontCache3.0.0.0.dat

2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\MSBuild

2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\windows\system32\XPSViewer

2009-07-14 02:43 . 2009-07-14 02:43 -------- d-----w- c:\programfiler\Reference Assemblies

2009-07-14 02:43 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll

2009-07-14 02:41 . 2009-07-14 02:41 -------- d-----w- c:\programfiler\MSXML 6.0

2009-07-14 01:26 . 2009-07-14 01:26 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Apple Computer

2009-07-14 01:25 . 2009-07-14 01:25 -------- d-----w- c:\documents and settings\Clinkz\Programdata\dvdcss

2009-07-14 00:52 . 2009-07-14 00:52 -------- d-----w- c:\windows\Sun

2009-07-14 00:50 . 2009-07-22 09:34 -------- d-----w- c:\documents and settings\Clinkz\Programdata\mIRC

2009-07-13 23:56 . 2009-07-13 23:56 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GHOSTBUSTERS

2009-07-13 23:30 . 2009-07-13 23:30 -------- d-----w- c:\programfiler\Realtek

2009-07-13 23:30 . 2009-06-24 08:43 831488 ----a-w- c:\windows\RtlExUpd.dll

2009-07-13 22:17 . 2009-07-13 22:17 -------- d-----w- c:\windows\Logs

2009-07-13 21:51 . 2009-07-13 21:51 -------- d-----w- c:\programfiler\Atari

2009-07-13 21:31 . 2009-07-15 18:27 8 ----a-w- c:\windows\system32\nvModes.dat

2009-07-13 21:30 . 2009-07-13 21:30 -------- d-----w- c:\documents and settings\All Users\Programdata\nView_Profiles

2009-07-13 21:27 . 2009-02-09 11:18 290816 ----a-w- c:\windows\system32\nvwrsth.dll

2009-07-13 21:27 . 2009-02-09 11:18 253952 ----a-w- c:\windows\system32\nvrsth.dll

2009-07-13 21:27 . 2009-02-09 11:18 401408 ----a-w- c:\windows\system32\nvcuvid.dll

2009-07-13 21:27 . 2006-06-01 15:22 1011712 ----a-w- c:\windows\system32\nvcpluir.dll

2009-07-13 21:25 . 2009-07-13 21:25 -------- d-----w- c:\programfiler\My Company Name

2009-07-13 21:18 . 2009-08-06 10:35 -------- d-----w- c:\documents and settings\Clinkz\Programdata\vlc

2009-07-13 21:14 . 2004-08-03 20:29 63488 ------w- c:\windows\system32\drivers\atinxsxx.sys

2009-07-13 21:08 . 2009-07-13 21:08 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Macromedia

2009-07-13 21:07 . 2009-07-13 21:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-07-13 21:07 . 2009-08-06 14:07 -------- d-----w- c:\documents and settings\Clinkz\Programdata\skypePM

2009-07-13 21:06 . 2009-07-13 21:06 45056 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe

2009-07-13 21:06 . 2009-07-13 21:07 -------- d-----w- c:\programfiler\Fellesfiler\Macromedia

2009-07-13 21:06 . 2009-08-02 06:23 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Spotify

2009-07-13 21:06 . 2009-07-13 21:06 -------- d-----w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\Spotify

2009-07-13 21:05 . 2009-07-13 21:05 -------- d-----w- c:\windows\Downloaded Installations

2009-07-13 21:00 . 2001-08-17 21:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys

2009-07-13 21:00 . 2009-07-13 21:00 -------- d-----w- c:\windows\system32\Lang

2009-07-13 21:00 . 2008-04-14 16:22 21504 ----a-w- c:\windows\system32\hidserv.dll

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-08-06 21:30 . 2009-07-13 20:06 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Hamachi

2009-08-06 19:04 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Skype

2009-08-06 18:49 . 2009-07-13 20:42 -------- d-----w- c:\documents and settings\Clinkz\Programdata\uTorrent

2009-08-05 20:05 . 2009-07-13 19:52 -------- d--h--w- c:\programfiler\InstallShield Installation Information

2009-07-22 10:08 . 2009-07-13 20:24 13688 ----a-w- c:\documents and settings\Clinkz\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT

2009-07-19 15:04 . 2004-08-04 12:00 75854 ----a-w- c:\windows\system32\perfc014.dat

2009-07-19 15:04 . 2004-08-04 12:00 436116 ----a-w- c:\windows\system32\perfh014.dat

2009-07-19 14:56 . 2009-07-13 20:29 -------- d-----w- c:\programfiler\Setup Files

2009-07-17 02:06 . 2009-07-13 19:17 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-07-16 23:46 . 2009-07-13 20:05 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys

2009-07-13 22:20 . 2009-07-13 22:20 -------- d--h--r- c:\documents and settings\Clinkz\Programdata\SecuROM

2009-07-13 21:39 . 2009-07-13 20:45 -------- d-----w- c:\documents and settings\Clinkz\Programdata\DAEMON Tools Lite

2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\documents and settings\All Users\Programdata\DAEMON Tools Lite

2009-07-13 20:59 . 2009-07-13 20:59 -------- d-----w- c:\programfiler\DAEMON Tools Toolbar

2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----r- c:\programfiler\Skype

2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\programfiler\Fellesfiler\Skype

2009-07-13 20:54 . 2009-07-13 20:54 -------- d-----w- c:\documents and settings\All Users\Programdata\Skype

2009-07-13 20:48 . 2009-07-13 20:47 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Winamp

2009-07-13 20:45 . 2009-07-13 20:45 721904 ----a-w- c:\windows\system32\drivers\sptd.sys

2009-07-13 20:35 . 2009-07-13 20:35 0 ----a-w- c:\windows\nsreg.dat

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Microsoft

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\Windows Live SkyDrive

2009-07-13 20:31 . 2009-07-13 20:31 -------- d-----w- c:\programfiler\MSI

2009-07-13 20:27 . 2009-07-13 20:27 -------- d-----w- c:\programfiler\Fellesfiler\Windows Live

2009-07-13 20:23 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\GameFace Messenger

2009-07-13 20:17 . 2009-07-13 20:15 -------- d-----w- c:\programfiler\Creative

2009-07-13 20:15 . 2009-07-13 19:50 -------- d-----w- c:\programfiler\Fellesfiler\InstallShield

2009-07-13 20:13 . 2009-07-13 20:08 -------- d-----w- c:\programfiler\Logitech

2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\documents and settings\Clinkz\Programdata\Logitech

2009-07-13 20:13 . 2009-07-13 20:13 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe

2009-07-13 20:13 . 2009-07-13 20:13 -------- d-----w- c:\programfiler\Fellesfiler\LogiShared

2009-07-13 20:11 . 2009-07-13 20:11 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe

2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf

2009-07-13 20:11 . 2009-07-13 20:11 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\programfiler\Fellesfiler\Logitech

2009-07-13 20:10 . 2009-07-13 20:10 10134 ----a-r- c:\documents and settings\Clinkz\Programdata\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe

2009-07-13 20:10 . 2009-07-13 20:10 -------- d-----w- c:\documents and settings\Clinkz\Programdata\InstallShield

2009-07-13 20:09 . 2009-07-13 20:09 -------- d-----w- c:\documents and settings\All Users\Programdata\LogiShrd

2009-07-13 20:08 . 2009-07-13 20:08 -------- d-----w- c:\documents and settings\All Users\Programdata\Logitech

2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple Computer

2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\programfiler\Apple Software Update

2009-07-13 20:03 . 2009-07-13 20:03 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple

2009-07-13 20:02 . 2009-07-13 20:02 410984 ----a-w- c:\windows\system32\deploytk.dll

2009-07-13 20:02 . 2009-07-13 20:02 -------- d-----w- c:\programfiler\Java

2009-07-13 20:02 . 2009-07-13 20:02 152576 ----a-w- c:\documents and settings\Clinkz\Programdata\Sun\Java\jre1.6.0_13\lzma.dll

2009-07-13 20:01 . 2009-07-13 20:01 -------- d-----w- c:\programfiler\Fellesfiler\Adobe AIR

2009-07-13 20:01 . 2009-07-13 20:00 -------- d-----w- c:\programfiler\Fellesfiler\Adobe

2009-07-13 19:56 . 2009-07-13 19:56 737280 ----a-w- c:\windows\iun6002.exe

2009-07-13 19:56 . 2009-07-13 19:56 -------- d-----w- c:\programfiler\ASUSTeK

2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\Realtek Sound Manager

2009-07-13 19:52 . 2009-07-13 19:52 -------- d-----w- c:\programfiler\AvRack

2009-07-13 19:18 . 2009-07-13 19:18 -------- d-----w- c:\programfiler\microsoft frontpage

2009-07-13 19:17 . 2009-07-13 19:17 -------- d-----w- c:\programfiler\Elektroniske tjenester

2009-07-13 19:16 . 2009-07-13 19:16 -------- d-----w- c:\programfiler\Fellesfiler\Tjenester

2009-07-13 19:15 . 2009-07-13 19:15 21704 ----a-w- c:\windows\system32\emptyregdb.dat

2009-07-03 17:01 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll

2009-06-16 14:43 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll

2009-06-16 14:43 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll

2009-06-03 19:11 . 2004-08-04 12:00 1294336 ----a-w- c:\windows\system32\quartz.dll

.

 

((((((((((((((((((((((((((((( SnapShot@2009-08-06_19.06.33 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-08-06 21:29 . 2009-08-06 21:29 16384 c:\windows\Temp\Perflib_Perfdata_7c4.dat

.

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))

.

.

*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\programfiler\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885400]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]

"Launch LGDCore"="c:\programfiler\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]

"Launch LCDMon"="c:\programfiler\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]

"LiveMonitor"="c:\programfiler\MSI\Live Update 3\LMonitor.exe" [2009-02-24 498688]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

"VF0060 STISvc"="V0060Pin.dll" - c:\windows\system32\V0060Pin.dll [2004-11-01 36864]

"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\Clinkz\Start-meny\Programmer\Oppstart\

hamachi.lnk - f:\hamachi\hamachi.exe [2009-2-5 625952]

 

c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\

Logitech SetPoint.lnk - c:\programfiler\Logitech\SetPoint\SetPoint.exe [2009-7-13 692224]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

@=""

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"f:\\uTorrent\\uTorrent.exe"=

"f:\\Garena\\Garena.exe"=

"f:\\Spotify\\spotify.exe"=

"d:\\Overlord II\\Overlord2.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Programfiler\\Skype\\Phone\\Skype.exe"=

 

R2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [04.08.2004 14:00 14336]

R3 V0060VID;Creative WebCam Live! Ultra;c:\windows\system32\drivers\V0060Vid.sys [15.07.2009 00:41 196409]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

wmcmgc

 

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

 

2009-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\programfiler\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

.

.

------- Tilleggsskanning -------

.

uInternet Connection Wizard,ShellNext = hxxp://tw.msi.com.tw/autobios/VerChk/LSeries.asp?MSIOCXVersion=3.76&WorkFunction=LMonitor

FF - ProfilePath - c:\documents and settings\Clinkz\Programdata\Mozilla\Firefox\Profiles\67k6v12c.default\

FF - component: f:\mozilla firefox\components\FFComm.dll

FF - component: f:\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll

FF - plugin: f:\adobe reader\Reader\browser\nppdf32.dll

FF - plugin: f:\mozilla firefox\plugins\npoctoshape.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin2.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin3.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin4.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin5.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin6.dll

FF - plugin: f:\quicktime\Plugins\npqtplugin7.dll

 

---- FIREFOX POLICIES ----

f:\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);

f:\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);

f:\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);

f:\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");

f:\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);

f:\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);

f:\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);

f:\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);

f:\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);

f:\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);

f:\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);

f:\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);

f:\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);

f:\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);

f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");

f:\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");

f:\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");

f:\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);

f:\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);

f:\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-08-06 23:30

Windows 5.1.2600 Service Pack 3 NTFS

 

skanner skjulte prosesser ...

 

skanner skjulte autostart-oppføringer ...

 

skanner skjulte filer ...

 

skanning vellykket

skjulte filer: 0

 

**************************************************************************

.

--------------------- LÅSTE REGISTERNØKLER ---------------------

 

[HKEY_USERS\S-1-5-21-329068152-1844823847-682003330-1004\Software\SecuROM\License information*]

"datasecu"=hex:25,47,3f,41,60,9a,c2,f0,93,11,89,3a,53,31,e2,19,fd,cc,67,ab,f4,

a2,2d,2b,f7,06,cc,c7,ee,d1,49,67,89,59,d6,6c,1a,41,28,1b,16,a9,42,77,3a,3a,\

"rkeysecu"=hex:8c,c2,22,e8,15,86,f7,44,b3,d5,d3,99,33,14,11,2b

.

--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

 

- - - - - - - > 'explorer.exe'(3700)

c:\programfiler\Logitech\SetPoint\GameHook.dll

c:\programfiler\Logitech\SetPoint\lgscroll.dll

c:\windows\system32\webcheck.dll

.

------------------------ Andre Kjørende Prosesser ------------------------

.

c:\windows\system32\rundll32.exe

c:\windows\system32\rundll32.exe

c:\programfiler\Logitech\G-series Software\Applets\LCDClock.exe

c:\programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.exe

c:\windows\ATKKBService.exe

c:\programfiler\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Tidspunkt ferdig: 2009-08-06 23:31 - maskinen ble startet på nytt

ComboFix-quarantined-files.txt 2009-08-06 21:31

ComboFix2.txt 2009-08-06 21:21

ComboFix3.txt 2009-08-06 19:08

 

Pre-Run: 17 037 234 176 byte ledig

Post-Run: 16 993 800 192 byte ledig

 

321 --- E O F --- 2009-08-02 06:18

Endret av BendItLikeBender
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...