KimBo82 Skrevet 5. juni 2010 Del Skrevet 5. juni 2010 Her poster jeg loggen både fra SAS og HijackThis som jeg har kjørt etter jeg får stadig malware/spam/popups eller hva det er fra Internett Explorer mens jeg bruker Google Chrome som nettleser. Kan noen hjelpe meg med å fortelle detaljert hva jeg skal gjøre videre for å bli kvitt dette? SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 06/04/2010 at 09:32 PM Application Version : 4.38.1004 Core Rules Database Version : 5033 Trace Rules Database Version: 2845 Scan type : Quick Scan Total Scan Time : 00:32:49 Memory items scanned : 1162 Memory threats detected : 3 Registry items scanned : 568 Registry threats detected : 11 File items scanned : 22568 File threats detected : 104 Trojan.Agent/Gen-CDesc[Gen] C:\WINDOWS\GXIVYB.EXE C:\WINDOWS\GXIVYB.EXE C:\WINDOWS\GXIVYA.EXE Trojan.Agent/Gen-SSHNas[FakeAlert] C:\WINDOWS\SYSTEM32\SSHNAS21.DLL C:\WINDOWS\SYSTEM32\SSHNAS21.DLL Trojan.Agent/Gen-CDesc[broad] C:\USERS\EIER\APPDATA\LOCAL\TEMP\GFL.EXE C:\USERS\EIER\APPDATA\LOCAL\TEMP\GFL.EXE [M5T8QL3YW3] C:\USERS\EIER\APPDATA\LOCAL\TEMP\GFL.EXE Adware.Tracking Cookie C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@questionmarket[2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@invitemedia[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@mediaplex[2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@yieldmanager[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@myroitracking[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@trafficengine[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@atdmt[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@advertise[2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@clicksor[2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@tribalfusion[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@adecn[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@tradedoubler[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@adbrite[2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@serving-sys[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@apmebf[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@overture[2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@eyewonder[1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\eier\AppData\Roaming\Microsoft\Windows\Cookies\eier@doubleclick[1].txt Adware.Flash Tracking Cookie C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\BC.YOUPORN.COM C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\STATIC.YOUPORN.COM C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\WWW.PORNBASE.ORG C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\WWWSTATIC.MEGAPORN.COM C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\MEDIA.NOOB.US C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\MEDIA1.BREAK.COM C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\MSNBCMEDIA.MSN.COM C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\NAIADSYSTEMS.COM C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\WWW.NAIADSYSTEMS.COM C:\Users\eier\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\SWRJ9YKW\SECURE-US.IMRWORLDWIDE.COM Adware.DoubleD HKLM\Software\HottieStar Toolbar HKLM\Software\HottieStar Toolbar#aff HKLM\Software\HottieStar Toolbar#aff2 HKLM\Software\HottieStar Toolbar#fid HKLM\Software\{D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} HKLM\Software\{D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2}#Uninstall HKLM\Software\{D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2}#ProductID C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_Logo.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_Option.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_RSS.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_Search.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_Smiley_Config.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_WebDropdown_01.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_WebDropdown_02.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_WebDropdown_03.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_WebDropdown_04.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_WebDropdown_05.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\Module_WebDropdown_06.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\pixel.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\ProductInfo.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\profile.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\SearchEngineList.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\tbcore.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\ToolbarLayout.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\UpdateCentre.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data\UpdateCentreBk.mx C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Data C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\About.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Component_ComboBox.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_Logo.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_Option.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_Option_Menu.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_RSS.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_RSS.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_RSS_Menu.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_RSS_Menu.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_Search.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_01.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_01.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_02.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_02.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_03.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_03.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_04.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_04.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_05.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_05.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_06.mg C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons\Module_WebDropdown_06.png C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Icons C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Skins\myskin1.skf C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Skins\myskin2.skf C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Skins\myskin3.skf C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Skins\myskin4.skf C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750\Skins C:\Program Files\HOTTIESTAR TOOLBAR\2.1.1.5750 C:\Program Files\HOTTIESTAR TOOLBAR Malware.Trace C:\Windows\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job HKU\S-1-5-21-2139186075-2229331976-1679872080-1000\Software\M5T8QL3YW3 HKU\S-1-5-21-2139186075-2229331976-1679872080-1000\SOFTWARE\XML HKU\S-1-5-21-2139186075-2229331976-1679872080-1000\SOFTWARE\QZAIB7KITK Adware.Generic C:\PROGRAMDATA\{177084F3-865E-4D1D-90B2-BB06FB1B7CCD}\OFFLINE\48C8FBD2\B94081D6\PRODUCTINFO.DLL C:\PROGRAMDATA\{177084F3-865E-4D1D-90B2-BB06FB1B7CCD}\OFFLINE\MFILEBAGIDE.DLL\BAG\PRODUCTINFO.DLL Application.Agent/Gen-TempZ C:\PROGRAMDATA\{177084F3-865E-4D1D-90B2-BB06FB1B7CCD}\OFFLINE\MFILEBAGIDE.DLL\BAG\MVBTERM.EXE Her kommer fra HijackThis: Logfile of HijackThis v1.99.1 Scan saved at 22:11:48, on 04.06.2010 Platform: Unknown Windows (WinNT 6.00.1906 SP2) MSIE: Internet Explorer v8.00 (8.00.6001.18904) Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\System32\rundll32.exe C:\Windows\PLFSetI.exe C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Steam\steam.exe C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Acer\Acer VCM\AcerVCM.exe C:\Users\eier\AppData\Local\Temp\RtkBtMnt.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Acer\Acer VCM\acp2HID.exe C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe C:\Users\eier\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\eier\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe C:\Users\eier\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0414&s=2&o=vp32&d=0909&m=aspire_6930g R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0414&s=2&o=vp32&d=0909&m=aspire_6930g R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0414&s=2&o=vp32&d=0909&m=aspire_6930g R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100517220133.dll O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" O4 - HKLM\..\Run: [bkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" O4 - HKLM\..\Run: [skytel] Skytel.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [Google Update] "C:\Users\eier\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray O4 - HKCU\..\Run: [Halo2] rundll32.exe C:\Windows\system32\sshnas21.dll,GetMainWnd O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe O4 - Global Startup: Acer VCM.lnk = ? O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll O20 - Winlogon Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Personal Firewall (McMPFSvc) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing) O23 - Service: McAfee Services (mcmscsvc) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing) O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing) O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing) O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing) O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - Unknown owner - c:\PROGRA~1\mcafee\msk\msksrver.exe (file missing) O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: ServiceLayer - Nokia - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe Lenke til kommentar
snippsat Skrevet 5. juni 2010 Del Skrevet 5. juni 2010 Start HijackThis "scan" finn disse linjene merk dem,så trykk fix checked. R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll O4 - HKCU\..\Run: [Halo2] rundll32.exe C:\Windows\system32\sshnas21.dll,GetMainWnd Last ned MBAM til skrivebordet. Velg Norsk språkdrakt-->kjør hurtig systemskann. Når MBAM er ferdig åpner den en logg,den poster du. Last ned DDS.scr Post loggen den lager. Lenke til kommentar
KimBo82 Skrevet 5. juni 2010 Forfatter Del Skrevet 5. juni 2010 Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Databaseversjon: 4170 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18904 05.06.2010 18:04:13 mbam-log-2010-06-05 (18-04-13).txt Skanntype: Hurtigsøk Objekter skannet: 126742 Tid tilbakelagt: 8 minutt(er), 52 sekund(er) Minneprosesser infisert: 0 Minnemoduler infisert: 0 Registernøkler infisert: 2 Registerverdier infisert: 0 Registerfiler infisert: 0 Mapper infisert: 0 Filer infisert 3 Minneprosesser infisert: (Ingen skadelige objekter funnet) Minnemoduler infisert: (Ingen skadelige objekter funnet) Registernøkler infisert: HKEY_CURRENT_USER\{D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. Registerverdier infisert: (Ingen skadelige objekter funnet) Registerfiler infisert: (Ingen skadelige objekter funnet) Mapper infisert: (Ingen skadelige objekter funnet) Filer infisert C:\Users\eier\AppData\Local\Temp\Gfj.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully. C:\Users\eier\AppData\Local\Temp\Gfm.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully. C:\Users\eier\AppData\Local\Temp\sshnas21.dll (Trojan.Downloader) -> Quarantined and deleted successfully. Det var loggen fra MBAM, og her kommer loggen fra DDS.scr: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 23.09.2009 10:41:30 System Uptime: 06.05.2010 18:07:18 (720 hours ago) Motherboard: Acer, Inc. | | Makalu Processor: Intel® Core2 Duo CPU T5800 @ 2.00GHz | U2E1 | 2000/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 144 GiB total, 60,67 GiB free. D: is FIXED (NTFS) - 298 GiB total, 278,215 GiB free. E: is FIXED (NTFS) - 140 GiB total, 140,408 GiB free. G: is CDROM (UDF) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== ==== Installed Programs ====================== Acer Arcade Deluxe Acer Bio Protection Acer Crystal Eye Webcam 2.0.8 Acer eAudio Management Acer eDataSecurity Management Acer Empowering Technology Acer ePower Management Acer eRecovery Management Acer eSettings Management Acer GameZone Console 2.0.1.1 Acer GridVista Acer Mobility Center Plug-In Acer ScreenSaver Acer VCM Activation Assistant for the 2007 Microsoft Office suites Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.2.2 Agatha Christie Death on the Nile Alice Greenfingers Apple Application Support Apple Mobile Device Support Apple Software Update Ask Toolbar Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver µTorrent Azada Backspin Billiards Big Kahuna Reef Bonjour Bookworm Deluxe Bricks of Egypt Cake Mania Chicken Invaders 3 Chuzzle CyberLink PowerDirector Diner Dash Flo on the Go eSobi v2 Flip Words 2 Football Manager 2010 FrostWire 4.18.3 Google Chrome Google Desktop HDAUDIO Soft Data Fax Modem with SmartCP Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel PROSet Wireless Intel® PROSet/Wireless WiFi-programvare Intel® Matrix Storage Manager iTunes Java Auto Updater Java 6 Update 20 Jewel Quest Solitaire Kick N Rush Launch Manager LightScribe 1.4.142.1 Mahjong Escape Ancient China Mahjongg Artifacts Malwarebytes' Anti-Malware McAfee Total Protection Microsoft .NET Framework 3.5 Language Pack SP1 - nor Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel 2007 Help Oppdatering (KB963678) Microsoft Office Excel MUI (Norwegian (Bokmål)) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (Norwegian (Bokmål)) 2007 Microsoft Office Powerpoint 2007 Help Oppdatering (KB963669) Microsoft Office PowerPoint MUI (Norwegian (Bokmål)) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proof (Norwegian (Bokmål)) 2007 Microsoft Office Proof (Norwegian (Nynorsk)) 2007 Microsoft Office Proofing (Norwegian (Bokmål)) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (Norwegian (Bokmål)) 2007 Microsoft Office Word 2007 Help Oppdatering (KB963665) Microsoft Office Word MUI (Norwegian (Bokmål)) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works MSVC80_x86_v2 MSVC90_x86 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Mystery Case Files - Huntsville Mystery Solitaire - Secret Island Nokia Ovi Suite NTI Backup Now 5 NTI Backup Now Standard NTI Media Maker 8 NVIDIA Drivers OGA Notifier 2.0.0048.0 OpenOffice.org 3.1 Opera 10.00 Opplastingsverktøy for Windows Live Orion Ovi Desktop Sync Engine OviMPlatform PC Connectivity Solution PhotoNow! Påloggingsassistent for Windows Live QuickTime Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for 2007 Microsoft Office System (KB978380) Security Update for Microsoft Office Excel 2007 (KB978382) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Skype™ 4.1 SPBA 5.8 Spotify Språkpakke for Microsoft .NET Framework 3.5 SP1 - NOR Steam SUPERAntiSpyware Synaptics Pointing Device Driver Turbo Pizza Update for 2007 Microsoft Office System (KB967642) Update for 2007 Microsoft Office System (KB981715) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office InfoPath 2007 (KB976416) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office Word 2007 (KB974561) Vizrt Vizky version 1.5.8 VLC media player 0.9.9 Winbond CIR Device Drivers Windows-driverpakke - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Media Player Firefox Plugin WinRAR archiver Zuma Deluxe ==== End Of File =========================== Lenke til kommentar
snippsat Skrevet 5. juni 2010 Del Skrevet 5. juni 2010 UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT Det var ikke den dds loggen,den lager 2 post den andre. Den heter DDS.txt Lenke til kommentar
KimBo82 Skrevet 5. juni 2010 Forfatter Del Skrevet 5. juni 2010 Her er den riktige:) DDS (Ver_10-03-17.01) - NTFSx86 Run by eier at 20:32:10,83 on 05.06.2010 Internet Explorer: 8.0.6001.18904 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.47.1044.18.3066.1767 [GMT 2:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe C:\Program Files\Acer\Empowering Technology\Service\ETService.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Acer\Acer Bio Protection\BASVC.exe C:\Windows\system32\rundll32.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\SPBA\upeksvr.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe C:\Windows\system32\rundll32.exe C:\Acer\Mobility Center\MobilityService.exe C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files\Cyberlink\Shared files\RichVideo.exe C:\Program Files\Acer\Acer VCM\RS_Service.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\System32\rundll32.exe C:\Windows\PLFSetI.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Steam\steam.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Acer\Acer VCM\AcerVCM.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Acer\Acer VCM\acp2HID.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\Common Files\Steam\SteamService.exe C:\Windows\system32\conime.exe C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Users\eier\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\eier\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\eier\AppData\Local\Google\Chrome\Application\chrome.exe c:\PROGRA~1\mcafee.com\agent\mcupdate.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\eier\Downloads\dds (2).scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0414&s=2&o=vp32&d=0909&m=aspire_6930g uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0414&s=2&o=vp32&d=0909&m=aspire_6930g mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0414&s=2&o=vp32&d=0909&m=aspire_6930g uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20100517220133.dll BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll BHO: Påloggingshjelp for Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [Google Update] "c:\users\eier\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [steam] "c:\program files\steam\Steam.exe" -silent uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" uRun: [<NO NAME>] uRun: [NokiaOviSuite2] c:\program files\nokia\nokia ovi suite\NokiaOviSuite.exe -tray uRun: [sUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [iAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [synTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe mRun: [eAudio] "c:\program files\acer\empowering technology\eaudio\eAudio.exe" mRun: [bkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe" mRun: [WarReg_PopUp] c:\program files\acer\wr_popup\WarReg_PopUp.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [PLFSetI] c:\windows\PLFSetI.exe mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE mRun: [eRecoveryService] mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe mRun: [ZPdtWzdVitaKey MC3000] "c:\program files\acer\acer bio protection\PdtWzd.exe" show mRun: [ArcadeDeluxeAgent] "c:\program files\acer arcade deluxe\acer arcade deluxe\ArcadeDeluxeAgent.exe" mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe" mRun: [PlayMovie] "c:\program files\acer arcade deluxe\playmovie\PMVService.exe" mRun: [skytel] Skytel.exe mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles startup mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\users\eier\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\acervc~1.lnk - c:\program files\acer\acer vcm\AcerVCM.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: DisableCAD = 1 (0x1) IE: E&ksporter til Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\acer\acer bio protection\PwdBank.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AWinNotifyVitaKey MC3000 - c:\program files\acer\acer bio protection\WinNotify.dll Notify: spba - c:\program files\common files\spba\homefus2.dll AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL LSA: Notification Packages = scecli c:\program files\acer\acer bio protection\PwdFilter ============= SERVICES / DRIVERS =============== R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [2009-9-23 42608] R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-3-16 385880] R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2010-3-16 64304] R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-3-16 160720] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2009-9-23 61424] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384] R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2009-9-23 81504] R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-8-11 24576] R2 IGBASVC;iGroupTec Service;c:\program files\acer\acer bio protection\BASVC.exe [2009-9-23 3602432] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-10-2 206112] R2 McMPFSvc;McAfee Personal Firewall;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-3-16 271480] R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-3-16 271480] R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-3-16 271480] R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-3-16 170144] R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-3-16 188136] R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-3-16 141792] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-25 45056] R2 NTIPPKernel;NTIPPKernel;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\NTIPPKernel.sys [2009-9-23 122368] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-25 131072] R2 RS_Service;Raw Socket Service;c:\program files\acer\acer vcm\RS_Service.exe [2009-9-23 233472] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-3-16 55456] R3 FontCache;Windows skriftbuffertjeneste;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-3-16 152320] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-3-16 51688] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-3-16 312616] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-6-25 44064] R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\drivers\winbondcir.sys [2007-3-28 43008] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-9-23 30192] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-3-16 83496] =============== Created Last 30 ================ 2010-06-05 15:25:49 0 d-----w- c:\users\eier\appdata\roaming\Malwarebytes 2010-06-05 15:25:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-05 15:25:38 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-06-05 15:25:38 0 d-----w- c:\programdata\Malwarebytes 2010-06-05 15:25:38 0 d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-06-04 18:53:53 0 d-----w- c:\users\eier\appdata\roaming\SUPERAntiSpyware.com 2010-06-04 18:53:53 0 d-----w- c:\programdata\SUPERAntiSpyware.com 2010-06-04 18:53:49 0 d-----w- c:\program files\SUPERAntiSpyware 2010-05-25 18:11:44 2048 ----a-w- c:\windows\system32\tzres.dll 2010-05-18 17:25:25 0 d-----w- c:\users\eier\appdata\roaming\Spotify 2010-05-18 17:25:23 0 d-----w- c:\program files\Spotify 2010-05-12 17:54:49 738816 ----a-w- c:\windows\system32\inetcomm.dll ==================== Find3M ==================== 2010-06-05 18:32:05 84172 ----a-w- c:\programdata\nvModes.dat 2010-06-05 16:13:26 76478 ----a-w- c:\windows\system32\perfc014.dat 2010-06-05 16:13:26 452326 ----a-w- c:\windows\system32\perfh014.dat 2010-06-04 18:00:00 86016 ----a-w- c:\windows\inf\infstor.dat 2010-06-04 18:00:00 51200 ----a-w- c:\windows\inf\infpub.dat 2010-06-04 18:00:00 143360 ----a-w- c:\windows\inf\infstrng.dat 2010-04-27 15:16:24 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys 2010-04-27 15:16:24 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys 2010-04-27 15:16:24 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys 2010-04-27 15:16:24 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys 2010-04-27 15:16:24 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys 2010-04-27 15:16:24 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2010-04-27 15:16:24 385880 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2010-04-27 15:16:24 312616 ----a-w- c:\windows\system32\drivers\mfefirek.sys 2010-04-27 15:16:24 160720 ----a-w- c:\windows\system32\drivers\mfewfpk.sys 2010-04-27 15:16:24 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2010-04-12 15:29:19 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-04-08 11:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll 2010-04-08 11:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe 2009-11-18 10:29:59 665600 ----a-w- c:\windows\inf\drvindex.dat 2008-01-21 06:13:40 35166 ----a-w- c:\windows\inf\perflib\0414\perfd.dat 2008-01-21 06:13:40 35166 ----a-w- c:\windows\inf\perflib\0414\perfc.dat 2008-01-21 06:13:40 294254 ----a-w- c:\windows\inf\perflib\0414\perfi.dat 2008-01-21 06:13:40 294254 ----a-w- c:\windows\inf\perflib\0414\perfh.dat 2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat 2010-01-17 20:24:36 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat 2010-01-17 20:24:36 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat 2010-01-17 20:24:36 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat 2009-11-02 17:56:26 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat 2009-10-14 19:47:19 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat 2009-10-02 13:32:37 32768 --sha-w- c:\windows\temp\cookies\index.dat 2009-10-02 13:32:37 32768 --sha-w- c:\windows\temp\history\history.ie5\index.dat 2009-10-02 13:32:37 32768 --sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat ============= FINISH: 20:32:50,81 =============== Lenke til kommentar
snippsat Skrevet 5. juni 2010 Del Skrevet 5. juni 2010 DDS loggen ser bra,og du har nå ingen malware som kjører. Kjør en runde med CCleaner og se om det er blitt bra. Lenke til kommentar
KimBo82 Skrevet 5. juni 2010 Forfatter Del Skrevet 5. juni 2010 Okey, da laster jeg ned og kjører en runde med CCleaner. Tusen takk for hjelpen Ha en strålende helg videre Kim Lenke til kommentar
KimBo82 Skrevet 5. juni 2010 Forfatter Del Skrevet 5. juni 2010 Jeg er ikke så god på data som du skjønner, men er CCleaner noe jeg må laste ned og bare kjøre? Lenke til kommentar
snippsat Skrevet 6. juni 2010 Del Skrevet 6. juni 2010 (endret) Ja. http://www.simplehelp.net/2008/06/21/how-to-use-ccleaner-to-free-up-disk-space-on-your-windows-pc/no/ Endret 6. juni 2010 av SNIPPSAT Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå