norbat Skrevet 6. januar 2008 Forfatter Del Skrevet 6. januar 2008 Start HJT, velg "Do a system scan only", sett merke framfor følgendel linjer og klikk Fix checked: O4 - HKLM\..\Run: [irfud] F:\WINDOWS\system32\uddg\irfud.exe O4 - HKLM\..\RunServices: [iE Runtime] winlo.exe O4 - HKCU\..\Run: [iE Runtime] winlo.exe O4 - HKCU\..\RunServices: [iE Runtime] winlo.exe O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200411...llInstaller.exe O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2AD79297-69D1-4A5C-8FEB-630C5B50F448}: NameServer = 85.255.115.60,85.255.112.136 O17 - HKLM\System\CCS\Services\Tcpip\..\{4CE54553-3E1C-490D-9DB6-67159F4A5C80}: NameServer = 85.255.115.60,85.255.112.136 O17 - HKLM\System\CCS\Services\Tcpip\..\{E90B84EC-9F65-401C-BB12-F3A0359A88CA}: NameServer = 85.255.115.60,85.255.112.136 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.60 85.255.112.136 O17 - HKLM\System\CS1\Services\Tcpip\..\{2AD79297-69D1-4A5C-8FEB-630C5B50F448}: NameServer = 85.255.115.60,85.255.112.136 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.60 85.255.112.136 Hent Fixwareout Legg filen på skrivebordet og dobbeltklikk på den. Klikk Next -> Install. Sjekk at det er avkrysset i 'Run fixit'. Klikk Finish og fixet vil starte. Følg instruksjonen. Restart PC-en når du blir bedt om det. Oppstarten vil ta litt lengre tid en normalt ..... Når PC-en har restartet følger du bare instruksjonen som kommer på skjermen. Post en ny HJT-logg sammen med loggen fra Fixwareout (C:\fixwareout\report.txt) Lenke til kommentar
-=SjuR=- Skrevet 7. januar 2008 Del Skrevet 7. januar 2008 yes da var det gjort. HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:39:00, on 07.01.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\Ati2evxx.exe F:\WINDOWS\system32\svchost.exe F:\Programfiler\Windows Defender\MsMpEng.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\Ati2evxx.exe F:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\Explorer.EXE F:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe F:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe F:\Programfiler\Network Associates\Common Framework\FrameworkService.exe F:\Programfiler\Network Associates\VirusScan\mcshield.exe F:\Programfiler\Network Associates\VirusScan\vstskmgr.exe F:\WINDOWS\system32\PnkBstrA.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\wuauclt.exe F:\WINDOWS\system32\notepad.exe F:\WINDOWS\system32\RunDll32.exe F:\WINDOWS\system32\LVCOMSX.EXE F:\Programfiler\Network Associates\Common Framework\UpdaterUI.exe F:\Programfiler\Network Associates\VirusScan\SHSTAT.EXE F:\Programfiler\Fellesfiler\Network Associates\TalkBack\tbmon.exe F:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe F:\Programfiler\Windows Defender\MSASCui.exe F:\Programfiler\Logitech\Video\LogiTray.exe F:\WINDOWS\System32\svchost.exe F:\Programfiler\Hewlett-Packard\HP Software Update\HPWuSchd.exe F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe F:\Programfiler\Logitech\Video\FxSvr2.exe F:\Programfiler\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe F:\Programfiler\Macrogaming\SweetIM\SweetIM.exe F:\Programfiler\Fellesfiler\ACD Systems\EN\DevDetect.exe F:\Programfiler\Fellesfiler\Teleca Shared\CapabilityManager.exe F:\Games\iPod\iTunes\iTunesHelper.exe F:\WINDOWS\system32\ctfmon.exe F:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE F:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\ccc.exe F:\Programfiler\iPod\bin\iPodService.exe F:\Programfiler\Mozilla Firefox\firefox.exe C:\Programfiler\Trend Micro\HijackThis\test.exe.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - F:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - F:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - F:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - F:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Programfiler\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [LVCOMSX] F:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Programfiler\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [shStatEXE] "F:\Programfiler\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "F:\Programfiler\Fellesfiler\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [sunJavaUpdateSched] "F:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [Windows Defender] "F:\Programfiler\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Programfiler\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [LogitechVideoRepair] F:\Programfiler\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] F:\Programfiler\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [HP Component Manager] "F:\Programfiler\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "F:\Programfiler\Hewlett-Packard\HP Software Update\HPWuSchd.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe O4 - HKLM\..\Run: [DeviceDiscovery] F:\Programfiler\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [sony Ericsson PC Suite] "F:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [sweetIM] F:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun O4 - HKLM\..\Run: [QuickTime Task] "F:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "F:\Games\iPod\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] F:\Programfiler\Logitech\Video\ManifestEngine.exe boot O4 - HKCU\..\Run: [startCCC] F:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = ? O4 - Global Startup: Microsoft Office.lnk = F:\Programfiler\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: VPN Client.lnk = ? O8 - Extra context menu item: &Windows Live Search - res://F:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - F:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Games\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Games\ICQLite\ICQLite.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll O12 - Plugin for .spop: F:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - F:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - F:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - F:\Programfiler\iPod\bin\iPodService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Programfiler\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - F:\Programfiler\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - F:\Programfiler\Network Associates\VirusScan\vstskmgr.exe O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - F:\NORMAN\Nvc\BIN\nipsvc.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - F:\WINDOWS\system32\PnkBstrA.exe -- End of file - 11843 bytes Fixwareout Fixwareout Last edited 2/11/2007 Post this report in the forums please ... »»»»»Prerun check »»»»» System restarted »»»»» Postrun check HKLM\SOFTWARE\~\Winlogon\ "system"="" .... .... »»»»» Misc files. .... »»»»» Checking for older varients. .... Search five digit cs, dm, kd, jb, other, files. The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection. Click browse, find the file then click submit. http://www.virustotal.com/flash/index_en.html Or http://virusscan.jotti.org/ »»»»» Other »»»»» Current runs [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run] "Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd" "LVCOMSX"="F:\\WINDOWS\\system32\\LVCOMSX.EXE" "McAfeeUpdaterUI"="\"F:\\Programfiler\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey" "ShStatEXE"="\"F:\\Programfiler\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE" "Network Associates Error Reporting Service"="\"F:\\Programfiler\\Fellesfiler\\Network Associates\\TalkBack\\tbmon.exe\"" "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" "NvCplDaemon"="RUNDLL32.EXE F:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /install" "SunJavaUpdateSched"="\"F:\\Programfiler\\Java\\jre1.6.0_03\\bin\\jusched.exe\"" "Windows Defender"="\"F:\\Programfiler\\Windows Defender\\MSASCui.exe\" -hide" "Adobe Photo Downloader"="\"F:\\Programfiler\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\"" "LogitechVideoRepair"="F:\\Programfiler\\Logitech\\Video\\ISStart.exe " "LogitechVideoTray"="F:\\Programfiler\\Logitech\\Video\\LogiTray.exe" "HP Component Manager"="\"F:\\Programfiler\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"F:\\Programfiler\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\"" "HPDJ Taskbar Utility"="F:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe" "DeviceDiscovery"="F:\\Programfiler\\Hewlett-Packard\\Digital Imaging\\bin\\hpotdd01.exe" "NvMediaCenter"="RUNDLL32.EXE F:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "Sony Ericsson PC Suite"="\"F:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions" "SweetIM"="F:\\Programfiler\\Macrogaming\\SweetIM\\SweetIM.exe" "Device Detector"="DevDetect.exe -autorun" "QuickTime Task"="\"F:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"F:\\Games\\iPod\\iTunes\\iTunesHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\AutorunsDisabled] "HP Component Manager"="\"F:\\Programfiler\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"F:\\Programfiler\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\"" "iTunesHelper"="\"F:\\Games\\iPod\\iTunes\\iTunesHelper.exe\"" "IE Runtime"="winlo.exe" "lcquuc"="F:\\WINDOWS\\system32\\mcjjxq\\lcquuc.exe" "admx"="F:\\WINDOWS\\system32\\ugpacuh\\admx.exe" "bpkw"="F:\\WINDOWS\\system32\\rkuqs\\bpkw.exe" "cucjkop"="F:\\WINDOWS\\system32\\snuyh\\cucjkop.exe" "fracqhu"="F:\\WINDOWS\\system32\\qkwmvuvm\\fracqhu.exe" "mepxavm"="F:\\WINDOWS\\system32\\efdkk\\mepxavm.exe" "MsUpdate"="F:\\Programfiler\\MsUpdate\\MsUpdate.exe /auto" "NapsterShell"="F:\\Programfiler\\Napster\\napster.exe /systray" "obfvg"="F:\\WINDOWS\\system32\\bkkevl\\obfvg.exe" "smasry"="F:\\WINDOWS\\system32\\wqysi\\smasry.exe" "sobdujvb"="F:\\WINDOWS\\system32\\xqaurwnd\\sobdujvb.exe" "trirfva"="F:\\WINDOWS\\system32\\hyqpm\\trirfva.exe" "ubafqzob"="F:\\WINDOWS\\ubafqzob.exe" "yjrkc"="F:\\WINDOWS\\system32\\eajsn\\yjrkc.exe" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="F:\\WINDOWS\\system32\\ctfmon.exe" "LogitechSoftwareUpdate"="F:\\Programfiler\\Logitech\\Video\\ManifestEngine.exe boot" "StartCCC"="F:\\Programfiler\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe" .... Hosts file was reset, If you use a custom hosts file please replace it »»»»» End report »»»»» Takk for hjelpen så langt Lenke til kommentar
norbat Skrevet 7. januar 2008 Forfatter Del Skrevet 7. januar 2008 Kjør combofix på nytt og post loggen. Lenke til kommentar
Carlgutt Skrevet 7. januar 2008 Del Skrevet 7. januar 2008 (endret) carlgutt:Loggen ser fin ut. Ingen filer der som viser noen infeksjoner. Du kunne ha kjørt en rens og fått ryddet litt: 1. Avinstaller program du ikke bruker. 2. Last ned CCleaner. Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......." Klikk på 'Renser' og deretter 'Kjør CCleaner'. 3. Sjekk om det trengs en defragmentering: Tilbehør->systemverktøy->diskdefragmentering. Du kan også scanne med et antispywareprog: Last ned SAS, installer, oppdater og kjør en full (Complete) scan. gjorde alt du sa men ingenting virket..får vel sende datan inn til reparasjon da..er ikke så veldig flink med data egentlig edit: glemte så klart å takke for hjelpen Endret 7. januar 2008 av carlgutt Lenke til kommentar
norbat Skrevet 7. januar 2008 Forfatter Del Skrevet 7. januar 2008 carlgutt: Vi kan godt ta en titt på en combofix-logg også. Den kan kanskje fortelle noe mer: Hent Combofix, og legg det på skrivebordet Kjør combofix.exe, og følg veiledningen. Du må ikke klikke på vinduet mens programmet kjører. Post loggfilen fra combofix (c:\combofix.txt) Lenke til kommentar
Carlgutt Skrevet 7. januar 2008 Del Skrevet 7. januar 2008 "SoundMAXPnP"="C:\Programfiler\Analog Devices\Core\smax4pnp.exe" [2004-10-14 14:42 1404928] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496] "IAAnotif"="C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 11:23 135168] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035] "nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\SYSTEM32\nwiz.exe] "Windows Defender"="C:\Programfiler\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584] "HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152] "Telenor Online Start"="C:\Programfiler\Telenor\Online Start\Telenor.exe" [2006-11-30 14:51 178312] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016] "avgnt"="C:\Programfiler\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-11 14:23 249896] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360] "DWQueuedReporting"="C:\PROGRA~1\FELLES~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU] --a------ 2004-02-19 13:23 61440 c:\dell\bldbubg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher] --a------ 2005-01-27 01:02 86016 C:\Programfiler\Dell\Media Experience\DMXLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher] --------- 2004-10-12 16:54 57344 C:\Programfiler\filer\CyberLink\PowerDVD\DVDLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 2004-10-13 17:24 1694208 C:\Programfiler\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager] --a------ 2004-01-07 01:01 110592 C:\Programfiler\Fellesfiler\Sonic\Update Manager\sgtray.exe R0 viaagp;VIA AGP-bussfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 23:07] R2 IAANTMon;IAA Event Monitor;C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe [2004-06-29 11:22] *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder "2008-01-07 14:29:23 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Programfiler\Windows Defender\MpCmdRun.exe "2008-01-07 18:49:00 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job" - C:\Programfiler\Windows Live Toolbar\MSNTBUP.EXE . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-07 19:58:43 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-07 19:59:15 . 2008-01-04 14:15:38 --- E O F --- Lenke til kommentar
norbat Skrevet 7. januar 2008 Forfatter Del Skrevet 7. januar 2008 Savner toppen av combofix-loggen. Kunne du ha lagt ut den? Lenke til kommentar
Carlgutt Skrevet 7. januar 2008 Del Skrevet 7. januar 2008 (endret) Savner toppen av combofix-loggen. Kunne du ha lagt ut den? sånn? ComboFix 08-01-07.5 - bruker 2008-01-07 21:24:34.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.596 [GMT 1:00] Running from: C:\Documents and Settings\bruker\Skrivebord\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 ))))))))))))))))))))))))))))))) . 2008-01-07 19:54 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2008-01-07 18:51 . 2008-01-07 18:51 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Yahoo! Companion 2008-01-07 18:06 . 2008-01-07 18:06 <DIR> d-------- C:\Documents and Settings\bruker\SystemRequirementsLab 2008-01-06 20:29 . 2008-01-06 20:29 <DIR> d-------- C:\Documents and Settings\bruker\Programdata\Image Zone Express 2008-01-06 20:01 . 2008-01-06 20:02 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-01-06 20:01 . 2008-01-06 20:01 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-01-06 20:01 . 2008-01-06 20:01 <DIR> d-------- C:\Documents and Settings\bruker\Programdata\SUPERAntiSpyware.com 2008-01-06 20:01 . 2008-01-06 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-01-06 19:53 . 2008-01-06 21:05 <DIR> dr-h----- C:\Documents and Settings\bruker\Siste 2008-01-06 18:53 . 2008-01-06 18:53 <DIR> d-------- C:\Programfiler\Yahoo! 2008-01-06 13:07 . 2008-01-06 13:07 <DIR> d-------- C:\Programfiler\Trend Micro 2008-01-06 00:20 . 2008-01-06 00:20 <DIR> d-------- C:\Programfiler\Fellesfiler\Blizzard Entertainment 2008-01-06 00:14 . 2008-01-07 20:47 <DIR> d-------- C:\Programfiler\World of Warcraft . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-06 19:21 --------- d-----w C:\Programfiler\DivX 2008-01-06 18:03 --------- d-----w C:\Documents and Settings\All Users\Programdata\Spybot - Search & Destroy 2008-01-06 10:53 --------- d--h--w C:\Programfiler\InstallShield Installation Information 2008-01-06 10:38 --------- d-----w C:\Programfiler\BitLord 2008-01-06 01:27 --------- d-----w C:\Programfiler\Java 2007-11-30 11:42 --------- d-----w C:\Programfiler\Windows Live Toolbar 2007-11-15 15:04 --------- d-----w C:\Programfiler\7-Zip 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-10-30 23:30 3,590,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll 2007-10-29 22:45 1,290,752 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll 2007-10-29 22:45 1,290,752 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll 2007-10-25 16:44 8,466,432 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll 2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll 2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll 2007-10-10 23:54 824,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll 2007-10-10 23:54 232,960 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll 2007-10-10 23:53 671,232 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll 2007-10-10 23:53 63,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll 2007-10-10 23:53 6,065,664 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll 2007-10-10 23:53 52,224 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll 2007-10-10 23:53 478,208 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll 2007-10-10 23:53 459,264 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll 2007-10-10 23:53 44,544 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll 2007-10-10 23:53 384,512 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll 2007-10-10 23:53 383,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll 2007-10-10 23:53 27,648 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll 2007-10-10 23:53 267,776 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll 2007-10-10 23:53 230,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll 2007-10-10 23:53 214,528 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll 2007-10-10 23:53 193,024 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll 2007-10-10 23:53 153,088 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll 2007-10-10 23:53 132,608 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll 2007-10-10 23:53 124,928 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll 2007-10-10 23:53 105,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll 2007-10-10 23:53 102,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll 2007-10-10 23:53 1,159,680 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll 2007-10-10 11:02 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe 2007-10-10 11:02 625,152 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe 2007-10-10 10:59 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe 2007-10-10 05:46 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360] "MsnMsgr"="C:\Programfiler\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480] "SoundMAXPnP"="C:\Programfiler\Analog Devices\Core\smax4pnp.exe" [2004-10-14 14:42 1404928] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496] "IAAnotif"="C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 11:23 135168] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035] "nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\SYSTEM32\nwiz.exe] "Windows Defender"="C:\Programfiler\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584] "HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152] "Telenor Online Start"="C:\Programfiler\Telenor\Online Start\Telenor.exe" [2006-11-30 14:51 178312] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016] "avgnt"="C:\Programfiler\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-11 14:23 249896] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360] "DWQueuedReporting"="C:\PROGRA~1\FELLES~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU] --a------ 2004-02-19 13:23 61440 c:\dell\bldbubg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher] --a------ 2005-01-27 01:02 86016 C:\Programfiler\Dell\Media Experience\DMXLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher] --------- 2004-10-12 16:54 57344 C:\Programfiler\filer\CyberLink\PowerDVD\DVDLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 2004-10-13 17:24 1694208 C:\Programfiler\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager] --a------ 2004-01-07 01:01 110592 C:\Programfiler\Fellesfiler\Sonic\Update Manager\sgtray.exe R0 viaagp;VIA AGP-bussfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 23:07] R2 IAANTMon;IAA Event Monitor;C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe [2004-06-29 11:22] *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder "2008-01-07 14:29:23 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Programfiler\Windows Defender\MpCmdRun.exe "2008-01-07 19:49:13 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job" - C:\Programfiler\Windows Live Toolbar\MSNTBUP.EXE . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-07 21:26:20 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-07 21:26:52 ComboFix2.txt 2008-01-07 18:59:15 . 2008-01-04 14:15:38 --- E O F --- Endret 7. januar 2008 av carlgutt Lenke til kommentar
norbat Skrevet 7. januar 2008 Forfatter Del Skrevet 7. januar 2008 Kan ikke se noe som skal gjøre PC-en spesielt treg. Å levere inn PC-en til rep. vil antakelig føre til at Windows blir reinstallert, noe man forsåvidt kan gjøre selv (kanskje med litt hjelp fra noen som har gjort det før). Du kan sjekke om det er noen systemfiler som er i ulage: Klikk: Start->Kjør Skriv: sfc /scannow (mellomrom mellom sfc og / ) Mulig du trenger XP CD-en. Lenke til kommentar
Carlgutt Skrevet 7. januar 2008 Del Skrevet 7. januar 2008 har ikke de diskene tilgjengelig akkurat nå men har du noe aning om hva som kan være problemet? jeg sliter forsåvidt også med høy cpu altså at den går opp i 80-100 bare jeg ser en film på fks stag6. Beklager vis jeg maser fælt begynner bare å bli litt lei av at jeg aldri finner ut hva som er galt. Lenke til kommentar
norbat Skrevet 7. januar 2008 Forfatter Del Skrevet 7. januar 2008 Hvis du ser i prosesslista (høyreklikk på oppgavelinja, velg oppgavebehandling, velg arkfanen Prosesser), er det en spesiell prosess som bruker mye cpu? Lenke til kommentar
Carlgutt Skrevet 7. januar 2008 Del Skrevet 7. januar 2008 (endret) Hvis du ser i prosesslista (høyreklikk på oppgavelinja, velg oppgavebehandling, velg arkfanen Prosesser), er det en spesiell prosess som bruker mye cpu? Kommer helt an på hva jeg driver med vis jeg spiller World of Warcraft (et online rolle spill)hopper cpuen hele tiden opp og ned fra 67-100 på "wow exe" mens "system" går hele tiden opp og ned fra 00-20 Edit: kan vell legge med at dette aldri skjedde før i de siste ukene og i følge :System Requirements Lab skulle jeg ikke ha noe problem å kjøre det Endret 7. januar 2008 av carlgutt Lenke til kommentar
Grand Skrevet 12. januar 2008 Del Skrevet 12. januar 2008 (endret) jeg tror jeg har en trojaner. kan du se om jeg har en? Hjthis logg: Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2Scan saved at 00:50:18, on 14.01.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\MSN Messenger\MsnMsgr.Exe C:\Programfiler\Messenger\msmsgs.exe C:\Programfiler\Valve\Steam\Steam.exe C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Programfiler\Logitech\SetPoint\SetPoint.exe C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Programfiler\Xfire\xfire.exe C:\Programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.EXE C:\Programfiler\MSN Messenger\usnsvc.exe C:\Programfiler\Ventrilo\Ventrilo.exe C:\Programfiler\Windows Media Player\wmplayer.exe C:\Programfiler\Opera\Opera.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Eier\Skrivebord\ComboFix.exe C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a> R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.5\NppBho.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Programfiler\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [steam] "C:\Programfiler\Valve\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - S-1-5-18 Startup: Stardock ObjectDock.lnk = C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe (User 'SYSTEM') O4 - S-1-5-18 Startup: Xfire.lnk = C:\Programfiler\Xfire\xfire.exe (User 'SYSTEM') O4 - .DEFAULT Startup: Stardock ObjectDock.lnk = C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe (User 'Default user') O4 - .DEFAULT Startup: Xfire.lnk = C:\Programfiler\Xfire\xfire.exe (User 'Default user') O4 - Startup: Stardock ObjectDock.lnk = C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe O4 - Startup: Xfire.lnk = C:\Programfiler\Xfire\xfire.exe O4 - Global Startup: Logitech SetPoint.lnk = ? O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {5CE72DD0-4695-4D18-A4D3-3367ACD37578} (F-Secure Health Check 1.0) - <a href="http://support.f-secure.com/enu/home/onlin.../fshc/fscax.cab" target="_blank">http://support.f-secure.com/enu/home/onlin.../fshc/fscax.cab</a> O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\VAScanner\comHost.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe -- End of file - 8175 bytes her er combofix logg Klikk for å se/fjerne innholdet nedenfor ComboFix 08-01-13.1 - Eier 2008-01-14 0:48:34.3 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.1388 [GMT 1:00] Running from: C:\Documents and Settings\Eier\Skrivebord\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 ))))))))))))))))))))))))))))))) . 2008-01-13 23:19 . 2008-01-13 23:49 <DIR> dr-h----- C:\Documents and Settings\Eier\Siste 2008-01-12 23:01 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2008-01-12 22:57 . 2008-01-13 23:55 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-01-12 22:57 . 2008-01-13 23:53 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\SUPERAntiSpyware.com 2008-01-12 22:57 . 2008-01-12 22:57 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-01-12 21:15 . 2008-01-12 21:15 <DIR> d-------- C:\Documents and Settings\LocalService\Programdata\Xfire 2008-01-12 20:52 . 2008-01-12 21:15 <DIR> d-------- C:\Programfiler\Xfire 2008-01-12 20:52 . 2008-01-12 22:29 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\Xfire 2008-01-11 19:50 . 2008-01-11 19:50 <DIR> d-------- C:\Programfiler\Silent Grove Studios 2008-01-10 20:36 . 2008-01-12 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Spybot - Search & Destroy 2008-01-10 20:26 . 2008-01-10 20:26 <DIR> d-------- C:\fsaua.data 2008-01-09 20:06 . 2008-01-09 20:06 <DIR> d-------- C:\Programfiler\SIW 2008-01-05 21:17 . 2008-01-05 21:18 <DIR> d-------- C:\Programfiler\LaunchTab 2008-01-05 21:03 . 2008-01-05 21:03 <DIR> d-------- C:\Programfiler\Stardock 2008-01-05 21:03 . 2008-01-05 21:03 <DIR> d-------- C:\Programfiler\Fellesfiler\Stardock 2008-01-05 20:36 . 2008-01-05 22:35 <DIR> d-------- C:\Programfiler\Samurize 2008-01-04 19:16 . 2008-01-04 19:16 <DIR> d-------- C:\Programfiler\Opera 2008-01-01 13:12 . 2008-01-01 13:12 <DIR> d-------- C:\Programfiler\Yahoo! 2008-01-01 13:12 . 2008-01-01 13:13 <DIR> d-------- C:\Programfiler\CCleaner 2008-01-01 12:38 . 2008-01-01 12:38 <DIR> d-------- C:\Programfiler\Trend Micro 2007-12-26 19:12 . 2007-12-26 19:12 13,646 --a------ C:\WINDOWS\system32\wpa.bak 2007-12-26 00:28 . 2007-12-26 00:28 <DIR> d-------- C:\Program Files 2007-12-24 15:23 . 2007-12-24 15:23 <DIR> d-------- C:\Programfiler\Windows Media Connect 2 2007-12-24 15:22 . 2007-12-24 15:23 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF 2007-12-23 23:15 . 2007-12-23 23:15 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\Media Player Classic 2007-12-23 23:14 . 2007-12-23 23:15 <DIR> d-------- C:\Programfiler\MpcStar 2007-12-23 23:14 . 2007-12-23 23:14 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Apple Computer 2007-12-23 12:28 . 2008-01-06 21:24 <DIR> d-------- C:\Programfiler\SpeedFan 2007-12-23 12:28 . 2007-12-23 12:28 45 --a------ C:\WINDOWS\system32\initdebug.nfo 2007-12-22 13:53 . 2007-12-22 13:53 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\Logitech 2007-12-22 13:53 . 2007-12-22 13:53 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Logitech 2007-12-22 13:48 . 2006-06-30 00:13 155,648 --a------ C:\WINDOWS\system32\kemutb.dll 2007-12-22 13:48 . 2006-06-30 00:12 126,976 --a------ C:\WINDOWS\system32\KemUtil.dll 2007-12-22 13:48 . 2006-06-30 00:13 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll 2007-12-22 13:48 . 2006-05-10 09:56 71,680 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys 2007-12-22 13:48 . 2006-05-10 09:56 56,064 --a------ C:\WINDOWS\system32\drivers\L8042MOU.SYS 2007-12-22 13:48 . 2006-06-30 00:13 53,248 --a------ C:\WINDOWS\system32\KemXML.dll 2007-12-22 13:48 . 2006-05-10 09:56 13,568 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS 2007-12-22 13:48 . 2006-06-30 00:53 3,712 --a------ C:\WINDOWS\system32\drivers\LBeepKE.sys 2007-12-22 13:47 . 2008-01-01 13:04 <DIR> d-------- C:\Programfiler\Logitech 2007-12-22 13:47 . 2007-12-22 13:48 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech 2007-12-22 13:47 . 2006-05-10 09:48 94,208 --a------ C:\WINDOWS\KHALMNPR.Exe 2007-12-22 13:47 . 2006-05-10 09:56 27,264 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys 2007-12-19 20:14 . 2007-12-19 20:14 1,154 --a------ C:\WINDOWS\mozver.dat 2007-12-19 16:54 . 2007-12-19 16:54 0 --a------ C:\WINDOWS\nsreg.dat 2007-12-13 15:07 . 2007-12-13 15:07 <DIR> dr-h----- C:\Documents and Settings\Eier\Programdata\SecuROM 2007-12-13 15:07 . 2007-12-13 15:07 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-12-13 15:05 . 2007-12-13 15:06 <DIR> d-------- C:\WINDOWS\system32\URTTemp 2007-12-13 15:04 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2007-12-13 15:04 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-12-13 15:04 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll 2007-12-13 15:04 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll 2007-12-13 15:04 . 2007-12-13 15:04 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe 2007-12-13 15:04 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll 2007-12-13 15:04 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-12-13 15:04 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-12-13 15:04 . 2007-12-13 15:04 22,328 --a------ C:\Documents and Settings\Eier\Programdata\PnkBstrK.sys 2007-12-13 14:57 . 2007-05-29 13:55 22,112 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys 2007-12-13 14:57 . 2007-05-29 13:55 10,592 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat 2007-12-13 14:57 . 2007-05-29 13:55 705 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf 2007-12-13 14:52 . 2007-12-13 14:52 <DIR> d-------- C:\Programfiler\Electronic Arts . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-13 23:46 --------- d-----w C:\Programfiler\GameSpy Arcade 2008-01-13 22:53 --------- d-----w C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-01-13 22:49 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared 2008-01-13 22:38 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec 2008-01-13 22:14 --------- d-----w C:\Documents and Settings\Eier\Programdata\BitTorrent 2008-01-12 21:04 --------- d-----w C:\Documents and Settings\Eier\Programdata\LimeWire 2008-01-08 21:31 --------- d-----w C:\Programfiler\Warcraft III 2008-01-06 12:38 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-01-06 12:37 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2007-12-23 22:14 --------- d-----w C:\Programfiler\QuickTime 2007-12-22 12:49 --------- d--h--w C:\Programfiler\InstallShield Installation Information 2007-12-13 14:04 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2007-12-13 13:57 --------- d-----w C:\Programfiler\Norton Internet Security 2007-12-12 14:13 --------- d-----w C:\Programfiler\Fellesfiler\Adobe 2007-12-09 21:11 --------- d-----w C:\Documents and Settings\Eier\Programdata\Ventrilo 2007-12-09 18:52 --------- d-----w C:\Programfiler\BitTorrent 2007-12-08 18:20 --------- d-----w C:\Programfiler\Bethesda Softworks 2007-12-07 18:53 --------- d-----w C:\Programfiler\Java 2007-12-06 20:50 --------- d-----w C:\Programfiler\LimeWire 2007-12-06 20:48 --------- d-----w C:\Programfiler\Fellesfiler\Java 2007-12-06 19:19 139,264 ----a-w C:\WINDOWS\War3Unin.exe 2007-12-06 19:15 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF 2007-12-06 19:15 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL 2007-12-06 19:15 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-12-06 19:15 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT 2007-12-06 19:15 --------- d-----w C:\Programfiler\Symantec 2007-12-06 18:51 --------- d-----w C:\Programfiler\EA GAMES 2007-12-06 18:28 --------- d-----w C:\Programfiler\Valve 2007-12-06 17:46 --------- d-----w C:\Programfiler\MSN Messenger 2007-12-06 17:40 --------- d-----w C:\Programfiler\Ventrilo 2007-12-06 17:29 --------- d-----w C:\Programfiler\Realtek 2007-12-06 17:26 315,392 ----a-w C:\WINDOWS\HideWin.exe 2007-12-06 17:26 --------- d-----w C:\Programfiler\Fellesfiler\InstallShield 2007-12-06 17:19 --------- d-----w C:\Programfiler\Intel 2007-12-06 16:49 --------- d-----w C:\Programfiler\Fellesfiler\SpeechEngines 2007-12-06 16:49 --------- d-----w C:\Programfiler\Fellesfiler\ODBC 2007-12-06 15:58 --------- d-----w C:\Programfiler\microsoft frontpage 2007-12-06 15:57 --------- d-----w C:\Programfiler\Elektroniske tjenester 2007-12-06 15:56 --------- d-----w C:\Programfiler\Fellesfiler\Tjenester 2007-12-06 15:56 --------- d-----w C:\Programfiler\Fellesfiler\MSSoap 2007-11-30 22:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys 2007-11-30 22:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys 2007-11-30 22:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys 2007-11-30 22:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat 2007-11-30 22:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat 2007-11-30 22:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat 2007-11-30 22:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf 2007-11-30 22:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf 2007-11-30 22:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-11-07 09:30 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll 2007-10-29 22:45 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll 2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe . ((((((((((((((((((((((((((((( snapshot@2008-01-13_23.04.27,28 ))))))))))))))))))))))))))))))))))))))))) . + 2008-01-13 22:54:00 34,304 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF1.exe - 2008-01-12 21:57:44 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe + 2008-01-13 22:54:00 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360] "MsnMsgr"="C:\Programfiler\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352] "MSMSGS"="C:\Programfiler\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208] "Steam"="C:\Programfiler\Valve\Steam\Steam.exe" [2007-12-06 19:30 1266936] "SpybotSD TeaTimer"="C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2007-03-21 15:49 16126464 C:\WINDOWS\RTHDCPL.exe] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008] "nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14 81920] "ccApp"="C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816] "osCheck"="C:\Programfiler\Norton Internet Security\osCheck.exe" [2007-01-14 00:11 771704] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496] "Symantec PIF AlertEng"="C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048] "Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 09:48 94208 C:\WINDOWS\KHALMNPR.Exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] C:\Documents and Settings\Eier\Start-meny\Programmer\Oppstart\ Stardock ObjectDock.lnk - C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe [2008-01-05 21:03:15] Xfire.lnk - C:\Programfiler\Xfire\xfire.exe [2007-12-05 03:25:00] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ Logitech SetPoint.lnk - C:\Programfiler\Logitech\SetPoint\SetPoint.exe [2007-12-22 13:48:12] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-06-30 00:53] R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 15:12] *Newly Created Service* - APPMGMT *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder "2008-01-07 19:05:31 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Eier.job" - C:\Programfiler\Norton Internet Security\Norton AntiVirus\Navw32.exec/TASK: . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a> Rootkit scan 2008-01-14 00:49:08 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-14 0:49:21 . 2008-01-12 11:44:06 --- E O F --- Jeg fikk ikke noe logg av SaS Endret 13. januar 2008 av Sno Lenke til kommentar
norbat Skrevet 13. januar 2008 Forfatter Del Skrevet 13. januar 2008 Sno: Kan ikke se noe tegn på noen 'skumle' filer i de loggene. Hva er det som gjør at du tror du har en trojaner? Lenke til kommentar
Grand Skrevet 13. januar 2008 Del Skrevet 13. januar 2008 (endret) Jeg lasta ned en fil fra limewire, Det merkelige var at filen var på 4mb og den hadde .mp3 (pleier ikke å bruke limewire, men det var et engangs tilfelle nå). Hvertfall, når jeg skulle høre på den sangen, så ble jeg sendt til en side. Som sa at jeg skulle laste ned en fil på ca 30 kb. selfølgelig så laste jeg ikke ned den filen, tok avbryt med engang. imens jeg skulle ta avbryt. Så sa northon i fra at den fant noe snuks, jeg rakk ikke å lese hele. Men det sto at det var trojaner. Scanna PC-en etter på, men northon fant ingen ting. Tror du jeg har fått en vrien trojaner? eller tror du at det ikke er noe? PC-en min ble også veldig treg etter det. Den har ikke hvert så treig før. Endret 13. januar 2008 av Sno Lenke til kommentar
norbat Skrevet 13. januar 2008 Forfatter Del Skrevet 13. januar 2008 Hvis Norton har en logg, så kan det hende den kan fortell hva og hvor om denne filen. Sannsynlig så var det en temporær fil. Loggene viser som nevnt ingen tegn på noen infeksjoner. Saken er vel også at å bruke p2p vil føre til at man en eller annen gang får problemer. Men det er en annen diskusjon Lenke til kommentar
Grand Skrevet 13. januar 2008 Del Skrevet 13. januar 2008 (endret) Norton Logg: Klikk for å se/fjerne innholdet nedenfor Source: C:\Documents and Settings\Eier\Programdata\Opera\Opera\profile\cache4\opr00RW4.exe Risk category: Virus Overall Risk Impact: High Performance: 1 Click for more information about this risk : Trojan.Adclicker Action taken: Blocked SAS logg Klikk for å se/fjerne innholdet nedenfor SUPERAntiSpyware Scan Loghttp://www.superantispyware.com Generated 01/14/2008 at 09:32 PM Application Version : 3.9.1008 Core Rules Database Version : 3379 Trace Rules Database Version: 1373 Scan type : Complete Scan Total Scan Time : 00:13:58 Memory items scanned : 520 Memory threats detected : 0 Registry items scanned : 4214 Registry threats detected : 0 File items scanned : 23380 File threats detected : 2 Adware.Tracking Cookie C:\Documents and Settings\Eier\Cookies\eier@atdmt[2].txt C:\Documents and Settings\Eier\Cookies\eier@imrworldwide[1].txt Endret 13. januar 2008 av Sno Lenke til kommentar
mona14 Skrevet 13. januar 2008 Del Skrevet 13. januar 2008 NEIII : o Klarte såklart å bli lurt med denne linken; http://youtube.opendns.be/watchv=6QW0-5tkh8.youtube.com .... og ja, det var virus. HEEELP ME PLEASE Lenke til kommentar
norbat Skrevet 13. januar 2008 Forfatter Del Skrevet 13. januar 2008 NEIII : o Klarte såklart å bli lurt med denne linken; http://youtube.opendns.be/watchv=6QW0-5tkh8.youtube.com .... og ja, det var virus. HEEELP ME PLEASE Du er i godt selskap Hent Combofix, og legg det på skrivebordet Kjør combofix.exe, og følg veiledningen. Du må ikke klikke på vinduet mens programmet kjører. Post loggfilen fra combofix (c:\combofix.txt) i en ny tråd som du oppretter (Nytt emne) evt legg den i denne tråden: https://www.diskusjon.no/index.php?showtopic=893521 Lenke til kommentar
bskalle84 Skrevet 14. januar 2008 Del Skrevet 14. januar 2008 Fekk bilde link med viruset via ein kamerat i går kveld. Fant fila, og sletta den. Norton fant den ikkje. Har installert avg, og det fant 4-5 virus, som no er sletta har køyrd hijak, og fekk følgjande logg. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:49:49, on 13.01.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe C:\Programfiler\MSI\Live Update 3\LMonitor.exe C:\WINDOWS\TBPanel.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Programfiler\Creative\Shared Files\CAMTRAY.EXE C:\WINDOWS\system32\RunDLL32.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\Programfiler\iTunes\iTunesHelper.exe C:\Programfiler\QuickTime\qttask.exe C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\WINDOWS\SOUNDMAN.EXE C:\DOCUME~1\BJRNSK~1\LOKALE~1\Temp\services.exe C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Programfiler\Fellesfiler\Microsoft Shared\Media Manager\airsvcu.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\DAEMON Tools\daemon.exe C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Programfiler\Norton AntiVirus\navapsvc.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\nvsvc32.exe C:\Programfiler\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe C:\Programfiler\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe C:\Programfiler\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\svchost.exe C:\Programfiler\iPod\bin\iPodService.exe C:\Programfiler\MSN Messenger\usnsvc.exe C:\Programfiler\Skype\Phone\Skype.exe C:\Programfiler\Skype\Plugin Manager\skypePM.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\WINDOWS\system32\wuauclt.exe C:\Programfiler\Messenger\msmsgs.exe C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.no/0SENBNO/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.no/0SENBNO/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.online.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.no/0SENBNO/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programfiler\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programfiler\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar2.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [LiveMonitor] C:\Programfiler\MSI\Live Update 3\LMonitor.exe O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programfiler\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513 O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [ValueX] C:\DOCUME~1\BJRNSK~1\LOKALE~1\Temp\services.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Programfiler\Creative\Shared Files\CamTray.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [instantTray] C:\Programfiler\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe O4 - HKCU\..\Run: [iW_Drop_Icon] C:\Programfiler\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Introducing Media Manager.lnk = C:\Programfiler\Fellesfiler\Microsoft Shared\Media Manager\SPLASHA.EXE O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O15 - Trusted Zone: http://www.msi.com.tw O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1170529941843 O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.nfoto.no/upload/ImageUploader4_5.cab O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programfiler\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programfiler\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FELLES~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe -- End of file - 11421 bytes Er det vekke?Eller kan nokon hjelpe meg vidare? Kva skal eg fjerne for å få det vekk, hjelp meg nokon. grundig forklaring. ikkje innvikla. er ikkje inne på dette med data Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå