Gå til innhold

Poster utskilt fra veiledertråden-2


Anbefalte innlegg

Start HJT, velg "Do a system scan only", sett merke framfor følgendel linjer og klikk Fix checked:

 

O4 - HKLM\..\Run: [irfud] F:\WINDOWS\system32\uddg\irfud.exe

O4 - HKLM\..\RunServices: [iE Runtime] winlo.exe

O4 - HKCU\..\Run: [iE Runtime] winlo.exe

O4 - HKCU\..\RunServices: [iE Runtime] winlo.exe

O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200411...llInstaller.exe

O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2AD79297-69D1-4A5C-8FEB-630C5B50F448}: NameServer = 85.255.115.60,85.255.112.136

O17 - HKLM\System\CCS\Services\Tcpip\..\{4CE54553-3E1C-490D-9DB6-67159F4A5C80}: NameServer = 85.255.115.60,85.255.112.136

O17 - HKLM\System\CCS\Services\Tcpip\..\{E90B84EC-9F65-401C-BB12-F3A0359A88CA}: NameServer = 85.255.115.60,85.255.112.136

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.60 85.255.112.136

O17 - HKLM\System\CS1\Services\Tcpip\..\{2AD79297-69D1-4A5C-8FEB-630C5B50F448}: NameServer = 85.255.115.60,85.255.112.136

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.60 85.255.112.136

 

Hent Fixwareout

 

Legg filen på skrivebordet og dobbeltklikk på den. Klikk Next -> Install.

Sjekk at det er avkrysset i 'Run fixit'.

Klikk Finish og fixet vil starte. Følg instruksjonen.

 

Restart PC-en når du blir bedt om det. Oppstarten vil ta litt lengre tid en normalt .....

 

Når PC-en har restartet følger du bare instruksjonen som kommer på skjermen.

 

Post en ny HJT-logg sammen med loggen fra Fixwareout (C:\fixwareout\report.txt)

Lenke til kommentar
Videoannonse
Annonse

yes da var det gjort.

 

HijackThis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:39:00, on 07.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Boot mode: Normal

 

Running processes:

F:\WINDOWS\System32\smss.exe

F:\WINDOWS\system32\winlogon.exe

F:\WINDOWS\system32\services.exe

F:\WINDOWS\system32\lsass.exe

F:\WINDOWS\system32\Ati2evxx.exe

F:\WINDOWS\system32\svchost.exe

F:\Programfiler\Windows Defender\MsMpEng.exe

F:\WINDOWS\System32\svchost.exe

F:\WINDOWS\system32\Ati2evxx.exe

F:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe

F:\WINDOWS\system32\spoolsv.exe

F:\WINDOWS\Explorer.EXE

F:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

F:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe

F:\Programfiler\Network Associates\Common Framework\FrameworkService.exe

F:\Programfiler\Network Associates\VirusScan\mcshield.exe

F:\Programfiler\Network Associates\VirusScan\vstskmgr.exe

F:\WINDOWS\system32\PnkBstrA.exe

F:\WINDOWS\system32\svchost.exe

F:\WINDOWS\system32\wuauclt.exe

F:\WINDOWS\system32\notepad.exe

F:\WINDOWS\system32\RunDll32.exe

F:\WINDOWS\system32\LVCOMSX.EXE

F:\Programfiler\Network Associates\Common Framework\UpdaterUI.exe

F:\Programfiler\Network Associates\VirusScan\SHSTAT.EXE

F:\Programfiler\Fellesfiler\Network Associates\TalkBack\tbmon.exe

F:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

F:\Programfiler\Windows Defender\MSASCui.exe

F:\Programfiler\Logitech\Video\LogiTray.exe

F:\WINDOWS\System32\svchost.exe

F:\Programfiler\Hewlett-Packard\HP Software Update\HPWuSchd.exe

F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

F:\Programfiler\Logitech\Video\FxSvr2.exe

F:\Programfiler\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

F:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

F:\Programfiler\Fellesfiler\ACD Systems\EN\DevDetect.exe

F:\Programfiler\Fellesfiler\Teleca Shared\CapabilityManager.exe

F:\Games\iPod\iTunes\iTunesHelper.exe

F:\WINDOWS\system32\ctfmon.exe

F:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

F:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

F:\Programfiler\iPod\bin\iPodService.exe

F:\Programfiler\Mozilla Firefox\firefox.exe

C:\Programfiler\Trend Micro\HijackThis\test.exe.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - F:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - F:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - F:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - F:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Programfiler\Windows Live Toolbar\msntb.dll

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [LVCOMSX] F:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Programfiler\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey

O4 - HKLM\..\Run: [shStatEXE] "F:\Programfiler\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE

O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "F:\Programfiler\Fellesfiler\Network Associates\TalkBack\tbmon.exe"

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [sunJavaUpdateSched] "F:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [Windows Defender] "F:\Programfiler\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Programfiler\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [LogitechVideoRepair] F:\Programfiler\Logitech\Video\ISStart.exe

O4 - HKLM\..\Run: [LogitechVideoTray] F:\Programfiler\Logitech\Video\LogiTray.exe

O4 - HKLM\..\Run: [HP Component Manager] "F:\Programfiler\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [HP Software Update] "F:\Programfiler\Hewlett-Packard\HP Software Update\HPWuSchd.exe"

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

O4 - HKLM\..\Run: [DeviceDiscovery] F:\Programfiler\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [sony Ericsson PC Suite] "F:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [sweetIM] F:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun

O4 - HKLM\..\Run: [QuickTime Task] "F:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "F:\Games\iPod\iTunes\iTunesHelper.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] F:\Programfiler\Logitech\Video\ManifestEngine.exe boot

O4 - HKCU\..\Run: [startCCC] F:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = F:\Programfiler\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: VPN Client.lnk = ?

O8 - Extra context menu item: &Windows Live Search - res://F:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - F:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Games\ICQLite\ICQLite.exe

O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Games\ICQLite\ICQLite.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll

O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll

O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll

O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll

O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll

O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll

O12 - Plugin for .spop: F:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - F:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - F:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - F:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Programfiler\Network Associates\Common Framework\FrameworkService.exe

O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - F:\Programfiler\Network Associates\VirusScan\mcshield.exe

O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - F:\Programfiler\Network Associates\VirusScan\vstskmgr.exe

O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - F:\NORMAN\Nvc\BIN\nipsvc.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - F:\WINDOWS\system32\PnkBstrA.exe

 

--

End of file - 11843 bytes

 

 

 

Fixwareout

 

Fixwareout Last edited 2/11/2007

Post this report in the forums please

...

»»»»»Prerun check

 

»»»»» System restarted

 

»»»»» Postrun check

HKLM\SOFTWARE\~\Winlogon\ "system"=""

....

....

»»»»» Misc files.

....

»»»»» Checking for older varients.

....

 

Search five digit cs, dm, kd, jb, other, files.

The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.

 

 

 

Click browse, find the file then click submit.

http://www.virustotal.com/flash/index_en.html

Or http://virusscan.jotti.org/

 

»»»»» Other

 

 

 

»»»»» Current runs

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"

"LVCOMSX"="F:\\WINDOWS\\system32\\LVCOMSX.EXE"

"McAfeeUpdaterUI"="\"F:\\Programfiler\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey"

"ShStatEXE"="\"F:\\Programfiler\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE"

"Network Associates Error Reporting Service"="\"F:\\Programfiler\\Fellesfiler\\Network Associates\\TalkBack\\tbmon.exe\""

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"

"NvCplDaemon"="RUNDLL32.EXE F:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"

"nwiz"="nwiz.exe /install"

"SunJavaUpdateSched"="\"F:\\Programfiler\\Java\\jre1.6.0_03\\bin\\jusched.exe\""

"Windows Defender"="\"F:\\Programfiler\\Windows Defender\\MSASCui.exe\" -hide"

"Adobe Photo Downloader"="\"F:\\Programfiler\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""

"LogitechVideoRepair"="F:\\Programfiler\\Logitech\\Video\\ISStart.exe "

"LogitechVideoTray"="F:\\Programfiler\\Logitech\\Video\\LogiTray.exe"

"HP Component Manager"="\"F:\\Programfiler\\HP\\hpcoretech\\hpcmpmgr.exe\""

"HP Software Update"="\"F:\\Programfiler\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\""

"HPDJ Taskbar Utility"="F:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe"

"DeviceDiscovery"="F:\\Programfiler\\Hewlett-Packard\\Digital Imaging\\bin\\hpotdd01.exe"

"NvMediaCenter"="RUNDLL32.EXE F:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"

"Sony Ericsson PC Suite"="\"F:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

"SweetIM"="F:\\Programfiler\\Macrogaming\\SweetIM\\SweetIM.exe"

"Device Detector"="DevDetect.exe -autorun"

"QuickTime Task"="\"F:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime"

"iTunesHelper"="\"F:\\Games\\iPod\\iTunes\\iTunesHelper.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\AutorunsDisabled]

"HP Component Manager"="\"F:\\Programfiler\\HP\\hpcoretech\\hpcmpmgr.exe\""

"HP Software Update"="\"F:\\Programfiler\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\""

"iTunesHelper"="\"F:\\Games\\iPod\\iTunes\\iTunesHelper.exe\""

"IE Runtime"="winlo.exe"

"lcquuc"="F:\\WINDOWS\\system32\\mcjjxq\\lcquuc.exe"

"admx"="F:\\WINDOWS\\system32\\ugpacuh\\admx.exe"

"bpkw"="F:\\WINDOWS\\system32\\rkuqs\\bpkw.exe"

"cucjkop"="F:\\WINDOWS\\system32\\snuyh\\cucjkop.exe"

"fracqhu"="F:\\WINDOWS\\system32\\qkwmvuvm\\fracqhu.exe"

"mepxavm"="F:\\WINDOWS\\system32\\efdkk\\mepxavm.exe"

"MsUpdate"="F:\\Programfiler\\MsUpdate\\MsUpdate.exe /auto"

"NapsterShell"="F:\\Programfiler\\Napster\\napster.exe /systray"

"obfvg"="F:\\WINDOWS\\system32\\bkkevl\\obfvg.exe"

"smasry"="F:\\WINDOWS\\system32\\wqysi\\smasry.exe"

"sobdujvb"="F:\\WINDOWS\\system32\\xqaurwnd\\sobdujvb.exe"

"trirfva"="F:\\WINDOWS\\system32\\hyqpm\\trirfva.exe"

"ubafqzob"="F:\\WINDOWS\\ubafqzob.exe"

"yjrkc"="F:\\WINDOWS\\system32\\eajsn\\yjrkc.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="F:\\WINDOWS\\system32\\ctfmon.exe"

"LogitechSoftwareUpdate"="F:\\Programfiler\\Logitech\\Video\\ManifestEngine.exe boot"

"StartCCC"="F:\\Programfiler\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe"

....

Hosts file was reset, If you use a custom hosts file please replace it

»»»»» End report »»»»»

 

 

 

Takk for hjelpen så langt :D

Lenke til kommentar
carlgutt:

Loggen ser fin ut. Ingen filer der som viser noen infeksjoner.

 

Du kunne ha kjørt en rens og fått ryddet litt:

 

1. Avinstaller program du ikke bruker.

 

2. Last ned CCleaner. Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......." Klikk på 'Renser' og deretter 'Kjør CCleaner'.

 

3. Sjekk om det trengs en defragmentering: Tilbehør->systemverktøy->diskdefragmentering.

 

Du kan også scanne med et antispywareprog: Last ned SAS, installer, oppdater og kjør en full (Complete) scan.

 

 

 

 

gjorde alt du sa men ingenting virket..får vel sende datan inn til reparasjon da..er ikke så veldig flink med data egentlig :roll:

 

edit: glemte så klart å takke for hjelpen :)

Endret av carlgutt
Lenke til kommentar

carlgutt:

 

Vi kan godt ta en titt på en combofix-logg også. Den kan kanskje fortelle noe mer:

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix (c:\combofix.txt)

Lenke til kommentar

 

"SoundMAXPnP"="C:\Programfiler\Analog Devices\Core\smax4pnp.exe" [2004-10-14 14:42 1404928]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

"IAAnotif"="C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 11:23 135168]

"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035]

"nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\SYSTEM32\nwiz.exe]

"Windows Defender"="C:\Programfiler\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]

"HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]

"Telenor Online Start"="C:\Programfiler\Telenor\Online Start\Telenor.exe" [2006-11-30 14:51 178312]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]

"avgnt"="C:\Programfiler\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-11 14:23 249896]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]

"DWQueuedReporting"="C:\PROGRA~1\FELLES~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]

--a------ 2004-02-19 13:23 61440 c:\dell\bldbubg.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]

--a------ 2005-01-27 01:02 86016 C:\Programfiler\Dell\Media Experience\DMXLauncher.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]

--------- 2004-10-12 16:54 57344 C:\Programfiler\filer\CyberLink\PowerDVD\DVDLauncher.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--a------ 2004-10-13 17:24 1694208 C:\Programfiler\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]

--a------ 2004-01-07 01:01 110592 C:\Programfiler\Fellesfiler\Sonic\Update Manager\sgtray.exe

 

R0 viaagp;VIA AGP-bussfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 23:07]

R2 IAANTMon;IAA Event Monitor;C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe [2004-06-29 11:22]

 

*Newly Created Service* - PROCEXP90

.

Contents of the 'Scheduled Tasks' folder

"2008-01-07 14:29:23 C:\WINDOWS\Tasks\MP Scheduled Scan.job"

- C:\Programfiler\Windows Defender\MpCmdRun.exe

"2008-01-07 18:49:00 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job"

- C:\Programfiler\Windows Live Toolbar\MSNTBUP.EXE

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-07 19:58:43

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-07 19:59:15

.

2008-01-04 14:15:38 --- E O F ---

 

 

Lenke til kommentar
Savner toppen av combofix-loggen. Kunne du ha lagt ut den?

 

sånn?

 

ComboFix 08-01-07.5 - bruker 2008-01-07 21:24:34.3 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.596 [GMT 1:00]

Running from: C:\Documents and Settings\bruker\Skrivebord\ComboFix.exe

.

 

((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 )))))))))))))))))))))))))))))))

.

 

2008-01-07 19:54 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-07 18:51 . 2008-01-07 18:51 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Yahoo! Companion

2008-01-07 18:06 . 2008-01-07 18:06 <DIR> d-------- C:\Documents and Settings\bruker\SystemRequirementsLab

2008-01-06 20:29 . 2008-01-06 20:29 <DIR> d-------- C:\Documents and Settings\bruker\Programdata\Image Zone Express

2008-01-06 20:01 . 2008-01-06 20:02 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2008-01-06 20:01 . 2008-01-06 20:01 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-01-06 20:01 . 2008-01-06 20:01 <DIR> d-------- C:\Documents and Settings\bruker\Programdata\SUPERAntiSpyware.com

2008-01-06 20:01 . 2008-01-06 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-01-06 19:53 . 2008-01-06 21:05 <DIR> dr-h----- C:\Documents and Settings\bruker\Siste

2008-01-06 18:53 . 2008-01-06 18:53 <DIR> d-------- C:\Programfiler\Yahoo!

2008-01-06 13:07 . 2008-01-06 13:07 <DIR> d-------- C:\Programfiler\Trend Micro

2008-01-06 00:20 . 2008-01-06 00:20 <DIR> d-------- C:\Programfiler\Fellesfiler\Blizzard Entertainment

2008-01-06 00:14 . 2008-01-07 20:47 <DIR> d-------- C:\Programfiler\World of Warcraft

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-06 19:21 --------- d-----w C:\Programfiler\DivX

2008-01-06 18:03 --------- d-----w C:\Documents and Settings\All Users\Programdata\Spybot - Search & Destroy

2008-01-06 10:53 --------- d--h--w C:\Programfiler\InstallShield Installation Information

2008-01-06 10:38 --------- d-----w C:\Programfiler\BitLord

2008-01-06 01:27 --------- d-----w C:\Programfiler\Java

2007-11-30 11:42 --------- d-----w C:\Programfiler\Windows Live Toolbar

2007-11-15 15:04 --------- d-----w C:\Programfiler\7-Zip

2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys

2007-10-30 23:30 3,590,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll

2007-10-29 22:45 1,290,752 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll

2007-10-29 22:45 1,290,752 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll

2007-10-25 16:44 8,466,432 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll

2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll

2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll

2007-10-10 23:54 824,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll

2007-10-10 23:54 232,960 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll

2007-10-10 23:53 671,232 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll

2007-10-10 23:53 63,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll

2007-10-10 23:53 6,065,664 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll

2007-10-10 23:53 52,224 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll

2007-10-10 23:53 478,208 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll

2007-10-10 23:53 459,264 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll

2007-10-10 23:53 44,544 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll

2007-10-10 23:53 384,512 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll

2007-10-10 23:53 383,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll

2007-10-10 23:53 27,648 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll

2007-10-10 23:53 267,776 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll

2007-10-10 23:53 230,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll

2007-10-10 23:53 214,528 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll

2007-10-10 23:53 193,024 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll

2007-10-10 23:53 153,088 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll

2007-10-10 23:53 132,608 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll

2007-10-10 23:53 124,928 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll

2007-10-10 23:53 105,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll

2007-10-10 23:53 102,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll

2007-10-10 23:53 1,159,680 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll

2007-10-10 11:02 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe

2007-10-10 11:02 625,152 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe

2007-10-10 10:59 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe

2007-10-10 05:46 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]

"MsnMsgr"="C:\Programfiler\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]

"SoundMAXPnP"="C:\Programfiler\Analog Devices\Core\smax4pnp.exe" [2004-10-14 14:42 1404928]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

"IAAnotif"="C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 11:23 135168]

"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035]

"nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\SYSTEM32\nwiz.exe]

"Windows Defender"="C:\Programfiler\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]

"HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]

"Telenor Online Start"="C:\Programfiler\Telenor\Online Start\Telenor.exe" [2006-11-30 14:51 178312]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]

"avgnt"="C:\Programfiler\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-11 14:23 249896]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]

"DWQueuedReporting"="C:\PROGRA~1\FELLES~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]

--a------ 2004-02-19 13:23 61440 c:\dell\bldbubg.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]

--a------ 2005-01-27 01:02 86016 C:\Programfiler\Dell\Media Experience\DMXLauncher.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]

--------- 2004-10-12 16:54 57344 C:\Programfiler\filer\CyberLink\PowerDVD\DVDLauncher.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--a------ 2004-10-13 17:24 1694208 C:\Programfiler\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]

--a------ 2004-01-07 01:01 110592 C:\Programfiler\Fellesfiler\Sonic\Update Manager\sgtray.exe

 

R0 viaagp;VIA AGP-bussfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 23:07]

R2 IAANTMon;IAA Event Monitor;C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe [2004-06-29 11:22]

 

*Newly Created Service* - PROCEXP90

.

Contents of the 'Scheduled Tasks' folder

"2008-01-07 14:29:23 C:\WINDOWS\Tasks\MP Scheduled Scan.job"

- C:\Programfiler\Windows Defender\MpCmdRun.exe

"2008-01-07 19:49:13 C:\WINDOWS\Tasks\Se etter oppdateringer for Windows Live Toolbar.job"

- C:\Programfiler\Windows Live Toolbar\MSNTBUP.EXE

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-07 21:26:20

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-07 21:26:52

ComboFix2.txt 2008-01-07 18:59:15

.

2008-01-04 14:15:38 --- E O F ---

 

 

Endret av carlgutt
Lenke til kommentar

Kan ikke se noe som skal gjøre PC-en spesielt treg. Å levere inn PC-en til rep. vil antakelig føre til at Windows blir reinstallert, noe man forsåvidt kan gjøre selv (kanskje med litt hjelp fra noen som har gjort det før).

 

Du kan sjekke om det er noen systemfiler som er i ulage:

 

Klikk: Start->Kjør

Skriv: sfc /scannow (mellomrom mellom sfc og / )

Mulig du trenger XP CD-en.

Lenke til kommentar

har ikke de diskene tilgjengelig akkurat nå men har du noe aning om hva som kan være problemet? jeg sliter forsåvidt også med høy cpu altså at den går opp i 80-100 bare jeg ser en film på fks stag6. Beklager vis jeg maser fælt begynner bare å bli litt lei av at jeg aldri finner ut hva som er galt.

Lenke til kommentar
Hvis du ser i prosesslista (høyreklikk på oppgavelinja, velg oppgavebehandling, velg arkfanen Prosesser), er det en

spesiell prosess som bruker mye cpu?

 

 

Kommer helt an på hva jeg driver med vis jeg spiller World of Warcraft (et online rolle spill)hopper cpuen hele tiden opp og ned fra 67-100 på "wow exe" mens "system" går hele tiden opp og ned fra 00-20

Edit: kan vell legge med at dette aldri skjedde før i de siste ukene og i følge :System Requirements Lab skulle jeg ikke ha noe problem å kjøre det

Endret av carlgutt
Lenke til kommentar

jeg tror jeg har en trojaner. kan du se om jeg har en?

 

Hjthis logg:

 

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:50:18, on 14.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\MSN Messenger\MsnMsgr.Exe

C:\Programfiler\Messenger\msmsgs.exe

C:\Programfiler\Valve\Steam\Steam.exe

C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Programfiler\Logitech\SetPoint\SetPoint.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\Programfiler\Xfire\xfire.exe

C:\Programfiler\Fellesfiler\Logitech\KhalShared\KHALMNPR.EXE

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\Programfiler\Ventrilo\Ventrilo.exe

C:\Programfiler\Windows Media Player\wmplayer.exe

C:\Programfiler\Opera\Opera.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\Eier\Skrivebord\ComboFix.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Programfiler\Fellesfiler\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [osCheck] "C:\Programfiler\Norton Internet Security\osCheck.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [steam] "C:\Programfiler\Valve\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - S-1-5-18 Startup: Stardock ObjectDock.lnk = C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe (User 'SYSTEM')

O4 - S-1-5-18 Startup: Xfire.lnk = C:\Programfiler\Xfire\xfire.exe (User 'SYSTEM')

O4 - .DEFAULT Startup: Stardock ObjectDock.lnk = C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe (User 'Default user')

O4 - .DEFAULT Startup: Xfire.lnk = C:\Programfiler\Xfire\xfire.exe (User 'Default user')

O4 - Startup: Stardock ObjectDock.lnk = C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe

O4 - Startup: Xfire.lnk = C:\Programfiler\Xfire\xfire.exe

O4 - Global Startup: Logitech SetPoint.lnk = ?

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {5CE72DD0-4695-4D18-A4D3-3367ACD37578} (F-Secure Health Check 1.0) - <a href="http://support.f-secure.com/enu/home/onlin.../fshc/fscax.cab" target="_blank">http://support.f-secure.com/enu/home/onlin.../fshc/fscax.cab</a>

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\isPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe

 

--

End of file - 8175 bytes

 

her er combofix logg

 

Klikk for å se/fjerne innholdet nedenfor
ComboFix 08-01-13.1 - Eier 2008-01-14 0:48:34.3 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.1388 [GMT 1:00]

Running from: C:\Documents and Settings\Eier\Skrivebord\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))

.

 

2008-01-13 23:19 . 2008-01-13 23:49 <DIR> dr-h----- C:\Documents and Settings\Eier\Siste

2008-01-12 23:01 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-12 22:57 . 2008-01-13 23:55 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2008-01-12 22:57 . 2008-01-13 23:53 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\SUPERAntiSpyware.com

2008-01-12 22:57 . 2008-01-12 22:57 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-01-12 21:15 . 2008-01-12 21:15 <DIR> d-------- C:\Documents and Settings\LocalService\Programdata\Xfire

2008-01-12 20:52 . 2008-01-12 21:15 <DIR> d-------- C:\Programfiler\Xfire

2008-01-12 20:52 . 2008-01-12 22:29 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\Xfire

2008-01-11 19:50 . 2008-01-11 19:50 <DIR> d-------- C:\Programfiler\Silent Grove Studios

2008-01-10 20:36 . 2008-01-12 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Spybot - Search & Destroy

2008-01-10 20:26 . 2008-01-10 20:26 <DIR> d-------- C:\fsaua.data

2008-01-09 20:06 . 2008-01-09 20:06 <DIR> d-------- C:\Programfiler\SIW

2008-01-05 21:17 . 2008-01-05 21:18 <DIR> d-------- C:\Programfiler\LaunchTab

2008-01-05 21:03 . 2008-01-05 21:03 <DIR> d-------- C:\Programfiler\Stardock

2008-01-05 21:03 . 2008-01-05 21:03 <DIR> d-------- C:\Programfiler\Fellesfiler\Stardock

2008-01-05 20:36 . 2008-01-05 22:35 <DIR> d-------- C:\Programfiler\Samurize

2008-01-04 19:16 . 2008-01-04 19:16 <DIR> d-------- C:\Programfiler\Opera

2008-01-01 13:12 . 2008-01-01 13:12 <DIR> d-------- C:\Programfiler\Yahoo!

2008-01-01 13:12 . 2008-01-01 13:13 <DIR> d-------- C:\Programfiler\CCleaner

2008-01-01 12:38 . 2008-01-01 12:38 <DIR> d-------- C:\Programfiler\Trend Micro

2007-12-26 19:12 . 2007-12-26 19:12 13,646 --a------ C:\WINDOWS\system32\wpa.bak

2007-12-26 00:28 . 2007-12-26 00:28 <DIR> d-------- C:\Program Files

2007-12-24 15:23 . 2007-12-24 15:23 <DIR> d-------- C:\Programfiler\Windows Media Connect 2

2007-12-24 15:22 . 2007-12-24 15:23 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF

2007-12-23 23:15 . 2007-12-23 23:15 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\Media Player Classic

2007-12-23 23:14 . 2007-12-23 23:15 <DIR> d-------- C:\Programfiler\MpcStar

2007-12-23 23:14 . 2007-12-23 23:14 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Apple Computer

2007-12-23 12:28 . 2008-01-06 21:24 <DIR> d-------- C:\Programfiler\SpeedFan

2007-12-23 12:28 . 2007-12-23 12:28 45 --a------ C:\WINDOWS\system32\initdebug.nfo

2007-12-22 13:53 . 2007-12-22 13:53 <DIR> d-------- C:\Documents and Settings\Eier\Programdata\Logitech

2007-12-22 13:53 . 2007-12-22 13:53 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Logitech

2007-12-22 13:48 . 2006-06-30 00:13 155,648 --a------ C:\WINDOWS\system32\kemutb.dll

2007-12-22 13:48 . 2006-06-30 00:12 126,976 --a------ C:\WINDOWS\system32\KemUtil.dll

2007-12-22 13:48 . 2006-06-30 00:13 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll

2007-12-22 13:48 . 2006-05-10 09:56 71,680 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys

2007-12-22 13:48 . 2006-05-10 09:56 56,064 --a------ C:\WINDOWS\system32\drivers\L8042MOU.SYS

2007-12-22 13:48 . 2006-06-30 00:13 53,248 --a------ C:\WINDOWS\system32\KemXML.dll

2007-12-22 13:48 . 2006-05-10 09:56 13,568 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS

2007-12-22 13:48 . 2006-06-30 00:53 3,712 --a------ C:\WINDOWS\system32\drivers\LBeepKE.sys

2007-12-22 13:47 . 2008-01-01 13:04 <DIR> d-------- C:\Programfiler\Logitech

2007-12-22 13:47 . 2007-12-22 13:48 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech

2007-12-22 13:47 . 2006-05-10 09:48 94,208 --a------ C:\WINDOWS\KHALMNPR.Exe

2007-12-22 13:47 . 2006-05-10 09:56 27,264 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys

2007-12-19 20:14 . 2007-12-19 20:14 1,154 --a------ C:\WINDOWS\mozver.dat

2007-12-19 16:54 . 2007-12-19 16:54 0 --a------ C:\WINDOWS\nsreg.dat

2007-12-13 15:07 . 2007-12-13 15:07 <DIR> dr-h----- C:\Documents and Settings\Eier\Programdata\SecuROM

2007-12-13 15:07 . 2007-12-13 15:07 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll

2007-12-13 15:05 . 2007-12-13 15:06 <DIR> d-------- C:\WINDOWS\system32\URTTemp

2007-12-13 15:04 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll

2007-12-13 15:04 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll

2007-12-13 15:04 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll

2007-12-13 15:04 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll

2007-12-13 15:04 . 2007-12-13 15:04 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe

2007-12-13 15:04 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll

2007-12-13 15:04 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll

2007-12-13 15:04 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll

2007-12-13 15:04 . 2007-12-13 15:04 22,328 --a------ C:\Documents and Settings\Eier\Programdata\PnkBstrK.sys

2007-12-13 14:57 . 2007-05-29 13:55 22,112 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys

2007-12-13 14:57 . 2007-05-29 13:55 10,592 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat

2007-12-13 14:57 . 2007-05-29 13:55 705 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf

2007-12-13 14:52 . 2007-12-13 14:52 <DIR> d-------- C:\Programfiler\Electronic Arts

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-13 23:46 --------- d-----w C:\Programfiler\GameSpy Arcade

2008-01-13 22:53 --------- d-----w C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-01-13 22:49 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-01-13 22:38 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec

2008-01-13 22:14 --------- d-----w C:\Documents and Settings\Eier\Programdata\BitTorrent

2008-01-12 21:04 --------- d-----w C:\Documents and Settings\Eier\Programdata\LimeWire

2008-01-08 21:31 --------- d-----w C:\Programfiler\Warcraft III

2008-01-06 12:38 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys

2008-01-06 12:37 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe

2007-12-23 22:14 --------- d-----w C:\Programfiler\QuickTime

2007-12-22 12:49 --------- d--h--w C:\Programfiler\InstallShield Installation Information

2007-12-13 14:04 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe

2007-12-13 13:57 --------- d-----w C:\Programfiler\Norton Internet Security

2007-12-12 14:13 --------- d-----w C:\Programfiler\Fellesfiler\Adobe

2007-12-09 21:11 --------- d-----w C:\Documents and Settings\Eier\Programdata\Ventrilo

2007-12-09 18:52 --------- d-----w C:\Programfiler\BitTorrent

2007-12-08 18:20 --------- d-----w C:\Programfiler\Bethesda Softworks

2007-12-07 18:53 --------- d-----w C:\Programfiler\Java

2007-12-06 20:50 --------- d-----w C:\Programfiler\LimeWire

2007-12-06 20:48 --------- d-----w C:\Programfiler\Fellesfiler\Java

2007-12-06 19:19 139,264 ----a-w C:\WINDOWS\War3Unin.exe

2007-12-06 19:15 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF

2007-12-06 19:15 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL

2007-12-06 19:15 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS

2007-12-06 19:15 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT

2007-12-06 19:15 --------- d-----w C:\Programfiler\Symantec

2007-12-06 18:51 --------- d-----w C:\Programfiler\EA GAMES

2007-12-06 18:28 --------- d-----w C:\Programfiler\Valve

2007-12-06 17:46 --------- d-----w C:\Programfiler\MSN Messenger

2007-12-06 17:40 --------- d-----w C:\Programfiler\Ventrilo

2007-12-06 17:29 --------- d-----w C:\Programfiler\Realtek

2007-12-06 17:26 315,392 ----a-w C:\WINDOWS\HideWin.exe

2007-12-06 17:26 --------- d-----w C:\Programfiler\Fellesfiler\InstallShield

2007-12-06 17:19 --------- d-----w C:\Programfiler\Intel

2007-12-06 16:49 --------- d-----w C:\Programfiler\Fellesfiler\SpeechEngines

2007-12-06 16:49 --------- d-----w C:\Programfiler\Fellesfiler\ODBC

2007-12-06 15:58 --------- d-----w C:\Programfiler\microsoft frontpage

2007-12-06 15:57 --------- d-----w C:\Programfiler\Elektroniske tjenester

2007-12-06 15:56 --------- d-----w C:\Programfiler\Fellesfiler\Tjenester

2007-12-06 15:56 --------- d-----w C:\Programfiler\Fellesfiler\MSSoap

2007-11-30 22:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys

2007-11-30 22:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys

2007-11-30 22:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys

2007-11-30 22:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat

2007-11-30 22:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat

2007-11-30 22:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat

2007-11-30 22:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf

2007-11-30 22:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf

2007-11-30 22:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf

2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys

2007-11-07 09:30 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll

2007-10-29 22:45 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll

2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll

2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-01-13_23.04.27,28 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-01-13 22:54:00 34,304 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF1.exe

- 2008-01-12 21:57:44 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe

+ 2008-01-13 22:54:00 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

"MsnMsgr"="C:\Programfiler\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]

"MSMSGS"="C:\Programfiler\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]

"Steam"="C:\Programfiler\Valve\Steam\Steam.exe" [2007-12-06 19:30 1266936]

"SpybotSD TeaTimer"="C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 15:49 16126464 C:\WINDOWS\RTHDCPL.exe]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008]

"nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WINDOWS\system32\nwiz.exe]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14 81920]

"ccApp"="C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]

"osCheck"="C:\Programfiler\Norton Internet Security\osCheck.exe" [2007-01-14 00:11 771704]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

"Symantec PIF AlertEng"="C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]

"Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 09:48 94208 C:\WINDOWS\KHALMNPR.Exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

 

C:\Documents and Settings\Eier\Start-meny\Programmer\Oppstart\

Stardock ObjectDock.lnk - C:\Programfiler\Stardock\ObjectDock\ObjectDock.exe [2008-01-05 21:03:15]

Xfire.lnk - C:\Programfiler\Xfire\xfire.exe [2007-12-05 03:25:00]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

Logitech SetPoint.lnk - C:\Programfiler\Logitech\SetPoint\SetPoint.exe [2007-12-22 13:48:12]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-06-30 00:53]

R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 15:12]

 

*Newly Created Service* - APPMGMT

*Newly Created Service* - COMHOST

.

Contents of the 'Scheduled Tasks' folder

"2008-01-07 19:05:31 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Eier.job"

- C:\Programfiler\Norton Internet Security\Norton AntiVirus\Navw32.exec/TASK:

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a>

Rootkit scan 2008-01-14 00:49:08

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-14 0:49:21

.

2008-01-12 11:44:06 --- E O F ---

 

Jeg fikk ikke noe logg av SaS

Endret av Sno
Lenke til kommentar

Jeg lasta ned en fil fra limewire, Det merkelige var at filen var på 4mb og den hadde .mp3 (pleier ikke å bruke limewire, men det var et engangs tilfelle nå). Hvertfall, når jeg skulle høre på den sangen, så ble jeg sendt til en side. Som sa at jeg skulle laste ned en fil på ca 30 kb. selfølgelig så laste jeg ikke ned den filen, tok avbryt med engang. imens jeg skulle ta avbryt. Så sa northon i fra at den fant noe snuks, jeg rakk ikke å lese hele. Men det sto at det var trojaner. Scanna PC-en etter på, men northon fant ingen ting. Tror du jeg har fått en vrien trojaner? eller tror du at det ikke er noe?

 

PC-en min ble også veldig treg etter det. Den har ikke hvert så treig før.

Endret av Sno
Lenke til kommentar

Hvis Norton har en logg, så kan det hende den kan fortell hva og hvor om denne filen. Sannsynlig så var det en temporær fil. Loggene viser som nevnt ingen tegn på noen infeksjoner.

 

Saken er vel også at å bruke p2p vil føre til at man en eller annen gang får problemer. Men det er en annen diskusjon :)

Lenke til kommentar

Norton Logg:

 

Klikk for å se/fjerne innholdet nedenfor
Source: C:\Documents and Settings\Eier\Programdata\Opera\Opera\profile\cache4\opr00RW4.exe

Risk category: Virus

Overall Risk Impact: High

Performance: 1

Click for more information about this risk : Trojan.Adclicker

Action taken: Blocked

 

 

SAS logg

 

Klikk for å se/fjerne innholdet nedenfor
SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 01/14/2008 at 09:32 PM

 

Application Version : 3.9.1008

 

Core Rules Database Version : 3379

Trace Rules Database Version: 1373

 

Scan type : Complete Scan

Total Scan Time : 00:13:58

 

Memory items scanned : 520

Memory threats detected : 0

Registry items scanned : 4214

Registry threats detected : 0

File items scanned : 23380

File threats detected : 2

 

Adware.Tracking Cookie

C:\Documents and Settings\Eier\Cookies\eier@atdmt[2].txt

C:\Documents and Settings\Eier\Cookies\eier@imrworldwide[1].txt

Endret av Sno
Lenke til kommentar
NEIII : o Klarte såklart å bli lurt med denne linken;

 

http://youtube.opendns.be/watchv=6QW0-5tkh8.youtube.com

 

.... og ja, det var virus. HEEELP ME PLEASE

 

Du er i godt selskap :)

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix (c:\combofix.txt) i en ny tråd som du oppretter (Nytt emne) evt legg den i denne tråden: https://www.diskusjon.no/index.php?showtopic=893521

Lenke til kommentar

Fekk bilde link med viruset via ein kamerat i går kveld. Fant fila, og sletta den. Norton fant den ikkje.

 

Har installert avg, og det fant 4-5 virus, som no er sletta har køyrd hijak, og fekk følgjande logg.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:49:49, on 13.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe

C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe

C:\Programfiler\MSI\Live Update 3\LMonitor.exe

C:\WINDOWS\TBPanel.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Programfiler\Creative\Shared Files\CAMTRAY.EXE

C:\WINDOWS\system32\RunDLL32.exe

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

C:\Programfiler\iTunes\iTunesHelper.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\DOCUME~1\BJRNSK~1\LOKALE~1\Temp\services.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Media Manager\airsvcu.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\DAEMON Tools\daemon.exe

C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Programfiler\Norton AntiVirus\navapsvc.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Programfiler\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe

C:\Programfiler\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe

C:\Programfiler\Norton AntiVirus\SAVScan.exe

C:\WINDOWS\system32\svchost.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\Programfiler\Skype\Phone\Skype.exe

C:\Programfiler\Skype\Plugin Manager\skypePM.exe

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Messenger\msmsgs.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.no/0SENBNO/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.no/0SENBNO/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.online.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.no/0SENBNO/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar2.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programfiler\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programfiler\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar2.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O4 - HKLM\..\Run: [LiveMonitor] C:\Programfiler\MSI\Live Update 3\LMonitor.exe

O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe

O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programfiler\Creative\Shared Files\CAMTRAY.EXE

O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513

O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [ValueX] C:\DOCUME~1\BJRNSK~1\LOKALE~1\Temp\services.exe

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Programfiler\Creative\Shared Files\CamTray.exe"

O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [instantTray] C:\Programfiler\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe

O4 - HKCU\..\Run: [iW_Drop_Icon] C:\Programfiler\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Introducing Media Manager.lnk = C:\Programfiler\Fellesfiler\Microsoft Shared\Media Manager\SPLASHA.EXE

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.msi.com.tw

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1170529941843

O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.nfoto.no/upload/ImageUploader4_5.cab

O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programfiler\Norton AntiVirus\navapsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Programfiler\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FELLES~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe

 

--

End of file - 11421 bytes

 

 

 

Er det vekke?Eller kan nokon hjelpe meg vidare? Kva skal eg fjerne for å få det vekk, hjelp meg nokon. grundig forklaring. ikkje innvikla. er ikkje inne på dette med data

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...