DiscoDown Skrevet 1. juni 2010 Del Skrevet 1. juni 2010 Hei, jeg har fått meg et virus som sender ut spam fra hotmail kontoen min til kontakter på msnlisten min. Jeg tviler på at det er noen som har passordet mitt og sender det ut selv, fordi jeg logger sjeldent inn på selve mailkontoen og når jeg gjorde det i dag så kom det flere spam mails opp på sent, tidligere var det ingen.. Sjekket etter virus i 3 forskjellige antivirus / antispyware programmer men har ikke funnet noe særlig. Tok en combofix nå og legger ut logger her og håper at dere finner ut av noe... ComboFix 10-06-01.01 - Christian 01.06.2010 21:32:46.1.2 - x86Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2336 [GMT 2:00] Running from: c:\documents and settings\Christian\Local Settings\Application Data\Opera\Opera\temporary_downloads\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Christian\Application Data\.# c:\documents and settings\Christian\Application Data\.#\MBX@E08@3D41A8.### c:\documents and settings\Christian\Application Data\.#\MBX@E08@3D41D8.### c:\documents and settings\Christian\Application Data\.#\MBX@E08@3D4208.### c:\documents and settings\Christian\Application Data\IUpd721 c:\documents and settings\Christian\Application Data\IUpd721\Logs\scns.log c:\documents and settings\Christian\Application Data\nig212.tmp.exe c:\documents and settings\Christian\autorun.inf c:\documents and settings\Christian\dirtysock.dll c:\documents and settings\Christian\FIFA10Demo.exe c:\documents and settings\Christian\GDFBinary.dll c:\temp\PRE45 c:\temp\PRE45\pG8.log c:\windows\system32\22416.exe c:\windows\system32\sX3i19 . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ASC3550P ((((((((((((((((((((((((( Files Created from 2010-05-01 to 2010-06-01 ))))))))))))))))))))))))))))))) . 2010-06-01 19:12 . 2010-06-01 19:12 63488 ----a-w- c:\documents and settings\Christian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll 2010-06-01 19:12 . 2010-06-01 19:12 52224 ----a-w- c:\documents and settings\Christian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-06-01 15:27 . 2010-06-01 15:29 -------- d-----w- c:\program files\Rockstar Games 2010-05-28 19:31 . 2010-03-10 09:29 42144 ----a-w- c:\windows\system32\drivers\DKRtWrt.sys 2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\program files\Common Files\Diskeeper Corporation 2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Diskeeper Corporation 2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\program files\Windows Home Server 2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\program files\Diskeeper Corporation 2010-05-28 18:21 . 2009-03-03 18:18 73728 ----a-w- c:\windows\system32\RtNicProp32.dll 2010-05-28 18:21 . 2009-11-20 07:51 -------- d---a-w- C:\PCI_Install_XP_2K_5719_11202009 2010-05-24 14:32 . 2010-05-24 14:32 -------- d-----w- C:\fjerne securom 2010-05-24 14:30 . 2006-11-01 11:06 162616 ----a-w- C:\RegDelNull.exe 2010-05-23 15:31 . 2010-05-23 15:31 48388 ----a-w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll 2010-05-22 07:24 . 2010-05-22 07:24 61440 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-590f0ea9-n\decora-sse.dll 2010-05-22 07:24 . 2010-05-22 07:24 503808 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-704fa23c-n\msvcp71.dll 2010-05-22 07:24 . 2010-05-22 07:24 499712 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-704fa23c-n\jmc.dll 2010-05-22 07:24 . 2010-05-22 07:24 348160 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-704fa23c-n\msvcr71.dll 2010-05-22 07:24 . 2010-05-22 07:24 12800 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-590f0ea9-n\decora-d3d.dll 2010-05-15 11:51 . 2010-05-15 11:52 -------- d-----w- c:\documents and settings\Christian\Application Data\Braid 2010-05-14 19:50 . 2010-05-14 19:50 -------- d-----w- c:\documents and settings\Christian\Local Settings\Application Data\PunkBuster 2010-05-14 19:25 . 2010-05-14 20:26 138968 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-05-14 19:25 . 2010-05-14 19:25 139152 ----a-w- c:\documents and settings\Christian\Application Data\PnkBstrK.sys 2010-05-14 19:25 . 2010-05-14 20:26 214592 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-05-14 19:25 . 2010-05-14 19:25 794408 ----a-w- c:\windows\system32\pbsvc.exe 2010-05-14 19:25 . 2010-05-14 19:25 75064 ----a-w- c:\windows\system32\PnkBstrA.exe 2010-05-14 18:21 . 2010-05-14 18:21 503808 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4060d00a-n\msvcp71.dll 2010-05-14 18:21 . 2010-05-14 18:21 499712 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4060d00a-n\jmc.dll 2010-05-14 18:21 . 2010-05-14 18:21 348160 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4060d00a-n\msvcr71.dll 2010-05-14 18:21 . 2010-05-14 18:21 61440 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-611fae69-n\decora-sse.dll 2010-05-14 18:21 . 2010-05-14 18:21 12800 ----a-w- c:\documents and settings\Christian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-611fae69-n\decora-d3d.dll 2010-05-14 18:21 . 2010-04-12 15:29 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-05-13 13:33 . 2010-05-13 13:33 -------- d-----w- c:\documents and settings\Christian\Local Settings\Application Data\Rockstar Games 2010-05-13 13:26 . 2010-05-13 13:26 -------- d-sh--w- c:\documents and settings\All Users\Application Data\SecuROM 2010-05-11 17:01 . 2010-05-11 17:01 283936 ----a-w- c:\documents and settings\All Users\Application Data\VIZ_MPS\Christian\update_temp\VizkyX.dll 2010-05-11 17:01 . 2010-05-11 17:01 2348320 ----a-w- c:\documents and settings\All Users\Application Data\VIZ_MPS\Christian\update_temp\Vizky.exe 2010-05-11 17:01 . 2010-05-11 17:01 20992 ----a-w- c:\documents and settings\All Users\Application Data\VIZ_MPS\Christian\update_temp\WMFDecoderPlugin.dll 2010-05-11 17:01 . 2010-05-11 17:01 226592 ----a-w- c:\documents and settings\All Users\Application Data\VIZ_MPS\Christian\update_temp\npVizky.dll 2010-05-11 17:01 . 2010-05-11 17:01 20992 ----a-w- c:\documents and settings\All Users\Application Data\VIZ_MPS\Christian\update_temp\FFmpegPlugin.dll 2010-05-11 15:14 . 2010-05-11 15:14 -------- d-----w- c:\program files\IObit 2010-05-11 15:14 . 2010-05-11 15:14 -------- d-----w- c:\documents and settings\Christian\Application Data\IObit 2010-05-09 07:06 . 2010-05-09 07:06 -------- d-----w- c:\documents and settings\Christian\Local Settings\Application Data\Lowerping 2010-05-09 07:06 . 2010-03-28 15:00 196608 ----a-w- c:\windows\system32\lp.dll 2010-05-08 13:02 . 2010-05-08 13:02 -------- d-----w- c:\documents and settings\Christian\Application Data\NVIDIA 2010-05-08 12:45 . 2010-05-08 12:45 -------- d-----w- c:\documents and settings\Christian\Local Settings\Application Data\Blizzard Entertainment 2010-05-08 11:42 . 1999-12-12 23:01 44032 ------w- c:\windows\system32\CTSVCCDA.EXE 2010-05-08 11:42 . 1999-11-17 23:00 25088 ------w- c:\windows\system32\CTSVCCTL.EXE 2010-05-08 11:38 . 2010-05-08 11:39 12907880 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative WaveStudio 7.12.00__\WAVESTD_PCAPP_LB_7_12_00.exe 2010-05-08 11:36 . 2010-05-08 11:38 37634288 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.26.02__\CMS5_PCAPP_LB_5_26_02.exe 2010-05-08 11:32 . 2010-05-08 11:35 62059520 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative Console Launcher 2.60.35__\CSL_PCAPP_LB_2_60_35A.exe 2010-05-08 11:28 . 2010-05-08 11:32 62234496 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative Console Launcher 2.61.09__\CSL_PCAPP_LB_2_61_09.exe 2010-05-06 19:05 . 2010-05-06 19:07 -------- d-----w- c:\documents and settings\Christian\Local Settings\Application Data\Blizzard Entertainment old 2010-05-06 16:15 . 2010-04-03 22:55 61440 ----a-w- c:\windows\system32\OpenCL.dll 2010-05-06 16:15 . 2010-04-03 22:55 14757888 ----a-w- c:\windows\system32\nvoglnt.dll 2010-05-06 16:15 . 2010-04-03 22:55 4075520 ----a-w- c:\windows\system32\nvcuda.dll 2010-05-06 16:15 . 2010-04-03 22:55 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll 2010-05-06 16:15 . 2010-04-03 22:55 227944 ----a-w- c:\windows\system32\nvcodins.dll 2010-05-06 16:15 . 2010-04-03 22:55 227944 ----a-w- c:\windows\system32\nvcod.dll 2010-05-06 16:15 . 2010-04-03 22:55 2030184 ----a-w- c:\windows\system32\nvcuvid.dll 2010-05-06 16:15 . 2010-04-03 22:55 11647592 ----a-w- c:\windows\system32\nvcompiler.dll 2010-05-06 16:15 . 2010-04-03 22:55 1097728 ----a-w- c:\windows\system32\nvapi.dll 2010-05-06 16:15 . 2010-04-03 22:55 2183470 ----a-w- c:\windows\system32\nvdata.bin . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-01 19:37 . 2009-02-20 18:39 81984 ----a-w- c:\windows\system32\bdod.bin 2010-06-01 19:12 . 2009-11-13 07:36 117760 ----a-w- c:\documents and settings\Christian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-06-01 19:10 . 2009-11-13 07:35 -------- d-----w- c:\program files\SUPERAntiSpyware 2010-06-01 18:33 . 2008-05-19 21:34 -------- d-----w- c:\documents and settings\Christian\Application Data\uTorrent 2010-06-01 17:52 . 2008-05-18 03:59 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-06-01 16:40 . 2009-05-25 14:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2010-05-30 20:42 . 2008-12-09 15:41 -------- d-----w- c:\documents and settings\Christian\Application Data\Spotify 2010-05-28 20:06 . 2009-03-07 11:51 -------- d-----w- c:\program files\NVIDIA Corporation 2010-05-28 20:06 . 2009-09-16 12:06 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation 2010-05-28 19:58 . 2008-05-18 04:24 664 ----a-w- c:\windows\system32\d3d9caps.dat 2010-05-28 19:32 . 2010-02-25 20:46 -------- d-----w- c:\documents and settings\Christian\Application Data\Sports Interactive 2010-05-24 14:25 . 2009-10-04 21:13 -------- d-----w- c:\program files\TheHell 2010-05-24 14:24 . 2009-10-04 23:03 -------- d-----w- c:\program files\Kali95 2010-05-24 14:24 . 2009-10-13 20:06 -------- d-----w- c:\program files\ATMA V 2010-05-24 14:23 . 2010-05-02 10:38 -------- d-----w- c:\program files\Webteh 2010-05-24 14:22 . 2010-05-02 10:30 -------- d-----w- c:\program files\URUSoft 2010-05-24 13:54 . 2008-08-21 18:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2010-05-24 13:54 . 2008-11-11 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2010-05-23 15:31 . 2009-08-20 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment 2010-05-23 14:34 . 2008-11-11 23:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-05-14 19:25 . 2008-09-11 21:57 -------- d-----w- c:\program files\EA Sports 2010-05-14 18:31 . 2008-05-19 21:34 -------- d-----w- c:\program files\uTorrent 2010-05-14 18:22 . 2008-05-28 19:13 -------- d-----w- c:\program files\Common Files\Java 2010-05-14 18:21 . 2008-05-28 19:13 -------- d-----w- c:\program files\Java 2010-05-12 06:22 . 2009-10-14 17:55 -------- d-----w- c:\program files\Vizky 2010-05-09 09:08 . 2008-05-20 22:56 -------- d-----w- c:\program files\Warcraft III 2010-05-09 09:04 . 2008-05-20 22:57 99574 ----a-w- c:\windows\War3Unin.dat 2010-05-09 07:06 . 2008-05-18 04:15 18816 ----a-w- c:\documents and settings\Christian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-05-08 11:42 . 2008-05-19 21:21 -------- d-----w- c:\program files\Creative 2010-05-08 11:41 . 2008-05-19 21:26 -------- d--h--w- c:\program files\Creative Installation Information 2010-05-07 17:38 . 2009-06-09 14:28 -------- d-----w- c:\program files\Left 4 Dead 2010-05-07 17:33 . 2009-10-04 21:08 -------- d-----w- c:\program files\Diablo 2010-05-06 20:04 . 2008-11-11 13:44 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2010-05-02 15:54 . 2010-05-02 15:41 -------- d-----w- c:\program files\The Witcher Enhanced Edition 2010-05-02 15:54 . 2010-05-02 15:54 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys 2010-05-02 15:54 . 2010-05-02 15:54 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2010-05-02 10:38 . 2010-05-02 10:38 -------- d-----w- c:\documents and settings\Christian\Application Data\BSplayer Pro 2010-04-30 19:11 . 2008-05-18 04:49 -------- d-----w- c:\program files\Opera 2010-04-29 13:39 . 2008-11-11 23:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-29 13:39 . 2008-11-11 23:03 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-04-29 13:03 . 2010-04-29 13:03 655360 ----a-w- c:\documents and settings\Christian\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll 2010-04-29 13:03 . 2010-04-29 13:03 282624 ----a-w- c:\documents and settings\Christian\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll 2010-04-29 13:03 . 2010-04-29 13:03 208896 ----a-w- c:\documents and settings\Christian\Application Data\Spotify\Gracenote\gnsdk_dsp.dll 2010-04-24 21:46 . 2010-04-24 21:46 -------- d-----w- c:\program files\UPHClean 2010-04-23 21:21 . 2009-04-15 13:13 146312 ----a-w- c:\windows\system32\drivers\bdfm.sys 2010-04-23 21:17 . 2010-04-23 21:17 53248 ----a-r- c:\documents and settings\Christian\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2010-04-23 21:17 . 2010-04-23 21:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd 2010-04-23 21:17 . 2008-05-29 02:11 -------- d-----w- c:\program files\Common Files\Logishrd 2010-04-23 21:16 . 2010-04-23 21:16 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2010-04-23 21:16 . 2008-05-29 02:11 -------- d-----w- c:\program files\Logitech 2010-04-23 21:13 . 2010-04-23 21:01 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender 2010-04-23 21:11 . 2010-04-23 21:11 -------- d-----w- c:\documents and settings\Christian\Application Data\Logishrd 2010-04-23 21:11 . 2008-05-29 02:12 -------- d-----w- c:\documents and settings\Christian\Application Data\Logitech 2010-04-23 21:01 . 2010-04-23 21:01 -------- d-----w- c:\documents and settings\Christian\Application Data\BitDefender 2010-04-23 21:01 . 2010-04-23 21:00 -------- d-----w- c:\program files\Common Files\BitDefender 2010-04-23 21:01 . 2010-04-23 21:01 -------- d-----w- c:\program files\BitDefender 2010-04-23 20:50 . 2009-11-11 00:44 -------- d-----w- c:\program files\NextGenTel 2010-04-23 20:45 . 2009-11-11 00:31 -------- d-----w- c:\documents and settings\All Users\Application Data\f-secure 2010-04-20 20:00 . 2009-11-27 16:41 1 ----a-w- c:\documents and settings\Christian\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-04-14 10:26 . 2010-04-14 10:26 -------- d-----w- c:\documents and settings\Christian\Application Data\dvdcss 2010-04-12 13:47 . 2009-11-03 02:22 -------- d-----w- c:\program files\Dragon Age 2010-04-06 19:05 . 2010-04-06 19:05 234 ----a-w- c:\documents and settings\Christian\Application Data\TVU networks\TVU AutoUpgrade\TVUPlayer2.5.2.2.exe 2010-04-04 10:11 . 2010-04-04 10:11 -------- d-----w- c:\program files\Image-Line 2010-04-04 10:11 . 2010-04-04 10:11 -------- d-----w- c:\program files\Outsim 2010-04-03 22:55 . 2008-05-18 04:31 600680 ----a-w- c:\windows\system32\nvudisp.exe 2010-04-03 22:55 . 2008-05-18 04:30 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys 2010-04-03 22:55 . 2008-05-18 04:30 6432128 ----a-w- c:\windows\system32\nv4_disp.dll 2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll 2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe 2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe 2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll 2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll 2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll 2010-04-03 14:40 . 2009-08-21 21:52 -------- d-----w- c:\program files\Heroes of Newerth 2010-04-02 20:18 . 2010-04-02 20:18 110592 ----a-w- c:\documents and settings\Christian\Application Data\nigC.tmp.bat 2010-04-02 20:18 . 2010-04-02 20:18 110592 ----a-w- c:\documents and settings\Christian\Application Data\nigC.tmp.bat 2010-04-02 20:18 . 2010-04-02 20:18 0 ----a-w- c:\documents and settings\Christian\Application Data\nigC.tmp 2010-04-02 14:54 . 2008-05-18 04:31 600680 ----a-w- c:\windows\system32\NVUNINST.EXE 2010-04-02 02:37 . 2010-04-02 02:37 0 ----a-w- c:\documents and settings\Christian\Application Data\nig5B1.tmp 2010-03-27 13:06 . 2010-03-27 13:06 0 ----a-w- c:\documents and settings\Christian\Application Data\nig212.tmp 2010-03-25 17:07 . 2009-08-27 16:08 1925088 ----a-w- c:\documents and settings\Christian\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe 2010-03-24 19:34 . 2009-03-12 10:02 38784 ----a-w- c:\documents and settings\Christian\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-03-24 19:26 . 2009-10-06 22:11 36557 ----a-w- c:\windows\DIIUnin.dat 2010-03-11 12:38 . 2008-04-14 03:42 832512 ----a-w- c:\windows\system32\wininet.dll 2010-03-11 12:38 . 2008-04-14 03:41 78336 ----a-w- c:\windows\system32\ieencode.dll 2010-03-11 12:38 . 2008-04-14 03:41 17408 ----a-w- c:\windows\system32\corpol.dll 2010-03-09 11:09 . 2008-04-14 03:42 430080 ----a-w- c:\windows\system32\vbscript.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136] "WindowsLivePhone"="c:\program files\Windows Live\Device Manager\msgrdvmn.exe" [2008-12-22 787816] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SkyTel"="SkyTel.EXE" [2006-05-16 2879488] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864] "36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-05-25 1957888] "AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "WindowsLivePhone"="c:\program files\Windows Live\Device Manager\msgrdvmn.exe" [2008-12-22 787816] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224] "RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224] "AlcWzrd"="ALCWZRD.EXE" [2006-05-04 2808832] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-01-27 1312848] "VizkyUpdate"="c:\program files\Vizky\VizkyUpdate.exe" [2010-05-11 312608] "CTxfiHlp"="CTXFIHLP.EXE" [2009-06-03 25600] "SoundMan"="SOUNDMAN.EXE" [2006-07-21 86016] "CTHelper"="CTHELPER.EXE" [2008-02-20 19456] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "CTAutoUpdate"="c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe" [2009-01-15 430968] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2010-01-29 21:17 64592 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^Christian^Start Menu^Programs^Startup^GIGABYTE VGA Utility.lnk] path=c:\documents and settings\Christian\Start Menu\Programs\Startup\GIGABYTE VGA Utility.lnk backup=c:\windows\pss\GIGABYTE VGA Utility.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Christian^Start Menu^Programs^Startup^Logitech . Produktregistrering.lnk] path=c:\documents and settings\Christian\Start Menu\Programs\Startup\Logitech . Produktregistrering.lnk backup=c:\windows\pss\Logitech . Produktregistrering.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Christian^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk] path=c:\documents and settings\Christian\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater] 2007-03-01 08:37 2321600 ----a-r- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier] 2008-07-22 18:42 116040 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent] 2010-04-23 21:21 782336 ----a-w- c:\program files\BitDefender\BitDefender 2009\bdagent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe] 2007-07-17 09:03 868352 ------w- c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] 2008-02-18 14:29 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2008-02-28 07:59 570664 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services] 2009-01-08 13:44 70936 ----a-w- c:\documents and settings\Christian\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb] 2008-04-01 01:54 507904 ----a-w- c:\program files\Winamp Remote\bin\OrbTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2008-05-27 08:50 413696 ----a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] 2010-02-20 08:30 1217872 ----a-w- c:\program files\Steam\steam.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware] 2010-06-01 19:10 2397424 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2008-05-20 06:17 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel] 2006-07-13 12:11 122880 ------w- c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2008-04-01 18:49 36352 ----a-w- c:\program files\Winamp\winampa.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat] 2007-09-26 16:05 734264 ----a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "aawservice"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"= "c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"= "c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\Spotify\\spotify.exe"= "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "c:\\Program Files\\FlashFXP\\FlashFXP.exe"= "c:\\Program Files\\CAPCOM\\RESIDENT EVIL 5\\RE5DX9.EXE"= "c:\\Program Files\\CAPCOM\\RESIDENT EVIL 5\\RE5DX10.EXE"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"= "c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\Mass Effect 2\\Binaries\\MassEffect2.exe"= "c:\\Program Files\\Mass Effect 2\\MassEffect2Launcher.exe"= "h:\\Mass Effect\\Binaries\\MassEffect.exe"= "h:\\Mass Effect\\MassEffectLauncher.exe"= "c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"= "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "h:\\Sports Interactive\\fm.exe"= "c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "8395:TCP"= 8395:TCP:League of Legends Launcher "8395:UDP"= 8395:UDP:League of Legends Launcher "8396:TCP"= 8396:TCP:League of Legends Launcher "8396:UDP"= 8396:UDP:League of Legends Launcher "8397:TCP"= 8397:TCP:League of Legends Launcher "8397:UDP"= 8397:UDP:League of Legends Launcher "8398:TCP"= 8398:TCP:League of Legends Launcher "8398:UDP"= 8398:UDP:League of Legends Launcher "8399:TCP"= 8399:TCP:League of Legends Launcher "8399:UDP"= 8399:UDP:League of Legends Launcher R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [11.11.2009 11:44 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11.11.2009 11:44 67656] R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [15.04.2009 15:13 146312] R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [04.06.2009 03:46 171032] R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [04.06.2009 03:46 1324056] R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [04.06.2009 03:46 72728] R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [28.05.2010 21:31 42144] S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20.05.2008 01:41 717296] S3 ALLOW-IO;ALLOW-IO;\??\d:\allow-io.sys --> d:\ALLOW-IO.sys [?] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [13.02.2010 11:17 79360] S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [04.06.2009 03:46 171032] S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [04.06.2009 03:46 1324056] S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [04.06.2009 03:46 72728] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [15.12.2009 22:07 25832] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [06.11.2007 22:22 34064] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11.11.2009 11:44 12872] --- Other Services/Drivers In Memory --- *Deregistered* - uphcleanhlp [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bdx REG_MULTI_SZ scan [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E] \Shell\AutoRun\command - E:\autorun.exe . Contents of the 'Scheduled Tasks' folder 2010-06-01 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2010-02-14 21:18] . . ------- Supplementary Scan ------- . uStart Page = www.google.com uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} - hxxp://fifa-online.easports.com/fo3-theme/addons/EAFO3AXLauncher.cab FF - ProfilePath - c:\documents and settings\Christian\Application Data\Mozilla\Firefox\Profiles\z0gpwd17.default\ FF - prefs.js: network.proxy.type - 1 FF - plugin: c:\documents and settings\Christian\Application Data\Mozilla\plugins\npoctoshape.dll FF - plugin: c:\documents and settings\Christian\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Veetle\Player\npvlc.dll FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll FF - plugin: c:\program files\Vizky\npVizky.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - ORPHANS REMOVED - - - - HKCU-Run-NVIDIA nTune - c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe HKLM-Run-nwiz - nwiz.exe HKU-Default-RunOnce-tscuninstall - c:\windows\system32\tscupgrd.exe HKLM-Explorer_Run-Microsoft Corp - c:\documents and settings\Christian\Application Data\svchosts.exe MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe MSConfigStartUp-F-Secure Manager - c:\program files\NextGenTel\Common\FSM32.EXE MSConfigStartUp-F-Secure TNB - c:\program files\NextGenTel\FSGUI\TNBUtil.exe MSConfigStartUp-NVIDIA nTune - c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\Christian\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-06-01 21:39 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-789336058-606747145-1417001333-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:bd,c8,b4,5b,c6,ba,b3,c5,31,31,c4,b9,42,09,3a,7f,40,d5,3c,22,9b,17,eb, 34,4b,8c,00,77,75,47,48,b4,67,72,3b,b3,de,9f,14,90,5b,a1,80,e1,95,f4,32,39,\ "??"=hex:3a,02,4f,2a,48,0b,da,d7,91,81,c8,64,2c,2e,86,13 [HKEY_USERS\S-1-5-21-789336058-606747145-1417001333-1003\Software\SecuROM\License information*] "datasecu"=hex:c9,cc,b6,a2,b0,aa,cb,fb,77,5f,c3,db,4c,8e,90,e5,a4,3c,6f,45,9e, 91,f3,1e,8a,65,56,10,22,8e,db,e7,12,32,7e,d8,54,cd,2d,0e,2c,2e,8c,11,93,58,\ "rkeysecu"=hex:c2,25,ac,f8,9e,79,2f,2b,10,47,9c,a3,ad,9c,59,7a . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1024) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - - - - - - - > 'explorer.exe'(3732) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\nvsvc32.exe c:\program files\Creative\Shared Files\CTAudSvc.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\CTsvcCDA.exe c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\windows\system32\IoctlSvc.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\program files\UPHClean\uphclean.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\windows\SOUNDMAN.EXE c:\windows\system32\RUNDLL32.EXE c:\windows\SYSTEM32\CTXFISPI.EXE c:\program files\Common Files\Nero\Lib\NMIndexingService.exe c:\program files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE . ************************************************************************** . Completion time: 2010-06-01 21:44:26 - machine was rebooted ComboFix-quarantined-files.txt 2010-06-01 19:44 Pre-Run: 76 636 286 976 bytes free Post-Run: 76 681 773 056 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer Current=3 Default=3 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5 - - End Of File - - 3957D614DD4A50BB131363395446CD0E Lenke til kommentar
geir__hk Skrevet 1. juni 2010 Del Skrevet 1. juni 2010 Det første skrittet du bør ta er å benytte en annen virusfri maskin* til å logge inn på hotmail kontoen og endre passordet. Det er meget stor sannsynlighet at det programmet som sender ut spam har fått tak i passordet. Når du har gjort dette, så kan du starte å renske maskinen for virus/spam. * Du kan også benytte el linux live-cd direkte i samme maskinen. Lenke til kommentar
snippsat Skrevet 2. juni 2010 Del Skrevet 2. juni 2010 (endret) Combofix loggen ser bra ut nå,noe grums ble fjernet. Du kan fjerne combofix ved å skrive combofix /u fra kjør-vinduet. Denne kommandoen gjør at filer i karantene og backups blir slette. Systemgjenopprettingsmappa nullstilt etc. Følg rådet til geir_hk,oftes er det botnettverk som kjører internt på hotmail som lager problemer. At du ikke er pålogget så mye betyr ikke at passordet ditt ikke har kommet på avveie. Endret 2. juni 2010 av SNIPPSAT Lenke til kommentar
DiscoDown Skrevet 2. juni 2010 Forfatter Del Skrevet 2. juni 2010 Takk for hjelpa. Når jeg skrev combofix /u i run så ble bare combofix kjørt på normal måte igjen med en ny virus sjekk osv. Lenke til kommentar
snippsat Skrevet 2. juni 2010 Del Skrevet 2. juni 2010 Husk mellomrom f /u http://billy-oneal.com/forums/Canned%20Speeches/speechimages/allclean/removecf.png Det kan også kjøre malewarebytes. Last ned MBAM til skrivebordet. Velg Norsk språkdrakt-->kjør hurtig systemskann. Når MBAM er ferdig åpner den en logg,den poster du. Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå