Gå til innhold

{Løst} Trojaner, rpcc.dll - med HJT logg *utvidet*


Anbefalte innlegg

Brute Force Uninstaller logg:

Klikk for å se/fjerne innholdet nedenfor
BFU v1.00.9

Windows XP SP2 (WinNT 5.01.2600 SP2)

Script started at 22:58:29, on 06-12-30

 

Failed: DllUnregister C:\WINDOWS\DH.dll|1 (file not found)

Failed: DllUnregister C:\Programfiler\Deskbar\deskbar.dll|1 (file not found)

Failed: DllUnregister \asappsrv.dll|1 (file not found)

Failed: DllUnregister \MyToolBar.dll|1 (file not found)

Failed: DllUnregister \888Bar.dll|1 (file not found)

Failed: ServiceStop Network Monitor (service not found)

Failed: ServiceStop cmdService (service not found)

Failed: ServiceDisable Network Monitor (service not found)

Failed: ServiceDisable cmdService (service not found)

Failed: ServiceDelete Network Monitor (service not found)

Failed: ServiceDelete cmdService (service not found)

Failed: RegDelValue HKCU\System\CurrentControlSet\Control\Lsa|p2pnetwork (key not found)

Failed: RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe (key not found)

Option pause between commands: 300 ms

Option pause between commands: 50 ms

Failed: FolderDelete C:\Programfiler\MsConfigs (folder not found)

Failed: FolderDelete C:\Programfiler\winupdates (folder not found)

Failed: FolderDelete C:\Programfiler\winupdate (folder not found)

Failed: FolderDelete C:\Programfiler\winsupdater (folder not found)

Failed: FolderDelete C:\Programfiler\MsMovies (folder not found)

Failed: FolderDelete C:\Programfiler\wmplayer (folder not found)

Failed: FolderDelete C:\Programfiler\outlook (folder not found)

Failed: FileDelete C:\Programfiler\Common Files\mc-*-*.exe (operation failed)

Failed: FileDelete C:\Programfiler\Common Files\Windows\mc-*-*.exe (operation failed)

Failed: FileDelete C:\Programfiler\Common Files\Download\mc-*-*.exe (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-1033-*-*}\update.exe (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-1033-*-*}\services.dll (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-1033-*-*}\activate.exe (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-1033-*-*}\MyToolBar.dll (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-2057-*-*}\update.exe (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-2057-*-*}\services.dll (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-2057-*-*}\activate.exe (operation failed)

Failed: FileDelete C:\Programfiler\common files\{*-*-2057-*-*}\MyToolBar.dll (operation failed)

Failed: FolderDelete C:\Programfiler\toolbar888 (folder not found)

Failed: FolderDelete C:\Programfiler\e-mailpaysu toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\EMUSIC TOOLBAR (folder not found)

Failed: FolderDelete C:\Programfiler\find dvd toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\GULESIDER VERKTøYLINJE (folder not found)

Failed: FolderDelete C:\Programfiler\sesam-p4 toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\slownik ling (folder not found)

Failed: FolderDelete C:\Programfiler\MediaPipe (folder not found)

Failed: FolderDelete C:\Programfiler\p2pnetworks (folder not found)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\Perflib_Perfdata_d4.dat (operation failed)

Failed: FolderDelete C:\DOCUME~1\Server\LOKALE~1\Temp\Ultra$ISO (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DF5289.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DFB4B6.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DFEDD3.tmp (operation failed)

Failed: FolderDelete C:\Documents and Settings\Server\Lokale innstillinger\Temporary Internet Files\Content.IE5\4PKX2JOD (operation failed)

Failed: FolderDelete C:\Documents and Settings\Server\Lokale innstillinger\Temporary Internet Files\Content.IE5\4T2RWT2V (operation failed)

Failed: FolderDelete C:\Programfiler\Maxifiles (folder not found)

Failed: FolderDelete C:\Programfiler\EQAdvice (folder not found)

Failed: FolderDelete C:\Programfiler\FCAdvice (folder not found)

Failed: FolderDelete C:\Programfiler\PSCastor (folder not found)

Failed: FolderDelete C:\Programfiler\CMIntex (folder not found)

Failed: FolderDelete C:\Programfiler\PadsysAssistant (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\FreeProd1 (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\FreeProd2 (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\InetGet (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\InetGet2 (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\svchostsys (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\simtest (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\misc001 (folder not found)

Failed: FolderDelete C:\Programfiler\InetGet2 (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\VCClient (folder not found)

Failed: FolderDelete C:\Programfiler\Network Monitor (folder not found)

Failed: FolderDelete C:\WINDOWS\inet20001 (folder not found)

Failed: FolderDelete C:\Programfiler\Update06 (folder not found)

Failed: FolderDelete C:\Programfiler\Update03 (folder not found)

Failed: FolderDelete C:\Programfiler\Update04 (folder not found)

Failed: FolderDelete C:\Programfiler\Update08 (folder not found)

Failed: FolderDelete C:\Programfiler\W-Update (folder not found)

Failed: FolderDelete C:\Programfiler\Yazzle Sudoku (folder not found)

Failed: FolderDelete C:\Programfiler\Cas (folder not found)

Failed: FolderDelete C:\Programfiler\CasStub (folder not found)

Failed: FolderDelete C:\Programfiler\Cas2Stub (folder not found)

Failed: FolderDelete C:\Programfiler\ipwins (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\Snowball Wars (folder not found)

Failed: FolderDelete C:\Programfiler\folder.js (folder not found)

Failed: FolderDelete C:\Programfiler\ini.ini (folder not found)

Failed: FolderDelete C:\temp (folder not found)

Failed: FolderDelete C:\WINDOWS\mdrive (folder not found)

Failed: FolderDelete C:\WINDOWS\system32\crunner (folder not found)

Failed: FolderDelete C:\Programfiler\PECarlin (folder not found)

Failed: FolderDelete C:\Programfiler\AXVenore (folder not found)

Failed: FolderDelete C:\Programfiler\SDVita (folder not found)

Failed: FolderDelete C:\Programfiler\EQBranch (folder not found)

Failed: FolderDelete C:\Programfiler\EQArticle (folder not found)

Failed: FolderDelete C:\Programfiler\PSHope (folder not found)

Failed: FolderDelete C:\Programfiler\Batty (folder not found)

Failed: FolderDelete C:\Programfiler\Batty2 (folder not found)

Failed: FolderDelete C:\Programfiler\AXFibula (folder not found)

Failed: FolderDelete C:\Programfiler\CMFibula (folder not found)

Failed: FolderDelete C:\Programfiler\PSLister (folder not found)

Failed: FolderDelete C:\Programfiler\PSCloner (folder not found)

Failed: FolderDelete C:\Programfiler\PSDream (folder not found)

Failed: FolderDelete C:\Programfiler\cmapp (folder not found)

Failed: FolderDelete C:\Programfiler\cmman (folder not found)

Failed: FolderDelete C:\Programfiler\cmsystem (folder not found)

Failed: FolderDelete C:\Programfiler\fcengine (folder not found)

Failed: FolderDelete C:\Programfiler\wincmapp (folder not found)

Failed: FolderDelete C:\Programfiler\Deskbar\Cache (folder not found)

Failed: FolderDelete C:\Programfiler\popupwithcast (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\cloader (folder not found)

Failed: FolderDelete C:\Programfiler\Common Files\misc001 (folder not found)

Failed: FileMove C:\WINDOWS\win*-*.exe|C:\bintheredunthat (source file not found)

Script completed.

 

Får ikke til Combofix enda men skal prøve noen ganger til.....

Lenke til kommentar
Videoannonse
Annonse

Jeg tror vi tar skriptet på en annen måte:

Kopier adressen under og lim den inn i adressefeltet i nettleseren. Kopier innholdet i notisblokk.

 

http://metallica.geekstogo.com/alcanshorty.bfu

 

Fordi skriptet er laget for engelsk versjon av WinXP, heter Fellesfiler for Common files. Kunne du ha byttet ut alle 'Common files' med 'Fellesfiler' i scriptet. Det er ikke så mange :)

 

Lagre skriptet på skrivebordet, kall det for f.eks. test.bfu

 

Start BFU igjen

Velg 'Open script files...' (mappeikonet i øvre høyre hjørne)

Du skal velge 'test.bfu'

 

Kjør scripet.

Endret av norbat
Lenke til kommentar

Ny BFU Logg:

Klikk for å se/fjerne innholdet nedenfor
BFU v1.00.9

Windows XP SP2 (WinNT 5.01.2600 SP2)

Script started at 23:50:33, on 06-12-30

 

Option Unload Explorer: Yes

Failed: DllUnregister C:\WINDOWS\DH.dll|1 (file not found)

Failed: DllUnregister C:\Programfiler\Deskbar\deskbar.dll|1 (file not found)

Failed: DllUnregister \asappsrv.dll|1 (file not found)

Failed: DllUnregister \MyToolBar.dll|1 (file not found)

Failed: DllUnregister \888Bar.dll|1 (file not found)

Failed: ServiceStop Network Monitor (service not found)

Failed: ServiceStop cmdService (service not found)

Failed: ServiceDisable Network Monitor (service not found)

Failed: ServiceDisable cmdService (service not found)

Failed: ServiceDelete Network Monitor (service not found)

Failed: ServiceDelete cmdService (service not found)

Failed: RegDelValue HKCU\System\CurrentControlSet\Control\Lsa|p2pnetwork (key not found)

Failed: RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe (key not found)

Option pause between commands: 300 ms

Option pause between commands: 50 ms

Failed: FolderDelete C:\Programfiler\MsConfigs (folder not found)

Failed: FolderDelete C:\Programfiler\winupdates (folder not found)

Failed: FolderDelete C:\Programfiler\winupdate (folder not found)

Failed: FolderDelete C:\Programfiler\winsupdater (folder not found)

Failed: FolderDelete C:\Programfiler\MsUpdate (folder not found)

Failed: FolderDelete C:\Programfiler\MsMovies (folder not found)

Failed: FolderDelete C:\Programfiler\wmplayer (folder not found)

Failed: FolderDelete C:\Programfiler\outlook (folder not found)

Failed: FileDelete C:\Programfiler\Fellesfiler\Windows\mc-*-*.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\update.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\services.dll (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\activate.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\MyToolBar.dll (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\update.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\services.dll (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\activate.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\MyToolBar.dll (operation failed)

Failed: FolderDelete C:\Programfiler\toolbar888 (folder not found)

Failed: FolderDelete C:\Programfiler\e-mailpaysu toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\EMUSIC TOOLBAR (folder not found)

Failed: FolderDelete C:\Programfiler\find dvd toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\GULESIDER VERKTøYLINJE (folder not found)

Failed: FolderDelete C:\Programfiler\sesam-p4 toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\slownik ling (folder not found)

Failed: FolderDelete C:\Programfiler\MediaPipe (folder not found)

Failed: FolderDelete C:\Programfiler\p2pnetworks (folder not found)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\Perflib_Perfdata_d4.dat (operation failed)

Failed: FolderDelete C:\DOCUME~1\Server\LOKALE~1\Temp\Ultra$ISO (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DFB61E.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DFEDD3.tmp (operation failed)

Failed: FolderDelete C:\Documents and Settings\Server\Lokale innstillinger\Temporary Internet Files\Content.IE5\4T2RWT2V (operation failed)

Failed: FolderDelete C:\Programfiler\Maxifiles (folder not found)

Failed: FolderDelete C:\Programfiler\DNS (folder not found)

Failed: FolderDelete C:\Programfiler\EQAdvice (folder not found)

Failed: FolderDelete C:\Programfiler\FCAdvice (folder not found)

Failed: FolderDelete C:\Programfiler\PSCastor (folder not found)

Failed: FolderDelete C:\Programfiler\CMIntex (folder not found)

Failed: FolderDelete C:\Programfiler\PadsysAssistant (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\FreeProd1 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\FreeProd2 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\svchostsys (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\simtest (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\misc001 (folder not found)

Failed: FolderDelete C:\Programfiler\InetGet2 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\VCClient (folder not found)

Failed: FolderDelete C:\Programfiler\Network Monitor (folder not found)

Failed: FolderDelete C:\WINDOWS\inet20001 (folder not found)

Failed: FolderDelete C:\Programfiler\Update06 (folder not found)

Failed: FolderDelete C:\Programfiler\Update03 (folder not found)

Failed: FolderDelete C:\Programfiler\Update04 (folder not found)

Failed: FolderDelete C:\Programfiler\Update08 (folder not found)

Failed: FolderDelete C:\Programfiler\W-Update (folder not found)

Failed: FolderDelete C:\Programfiler\Yazzle Sudoku (folder not found)

Failed: FolderDelete C:\Programfiler\Cas (folder not found)

Failed: FolderDelete C:\Programfiler\CasStub (folder not found)

Failed: FolderDelete C:\Programfiler\Cas2Stub (folder not found)

Failed: FolderDelete C:\Programfiler\ipwins (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\Snowball Wars (folder not found)

Failed: FolderDelete C:\Programfiler\folder.js (folder not found)

Failed: FolderDelete C:\Programfiler\ini.ini (folder not found)

Failed: FolderDelete C:\temp (folder not found)

Failed: FolderDelete C:\WINDOWS\mdrive (folder not found)

Failed: FolderDelete C:\WINDOWS\system32\crunner (folder not found)

Failed: FolderDelete C:\Programfiler\PECarlin (folder not found)

Failed: FolderDelete C:\Programfiler\AXVenore (folder not found)

Failed: FolderDelete C:\Programfiler\SDVita (folder not found)

Failed: FolderDelete C:\Programfiler\EQBranch (folder not found)

Failed: FolderDelete C:\Programfiler\EQArticle (folder not found)

Failed: FolderDelete C:\Programfiler\PSHope (folder not found)

Failed: FolderDelete C:\Programfiler\Batty (folder not found)

Failed: FolderDelete C:\Programfiler\Batty2 (folder not found)

Failed: FolderDelete C:\Programfiler\AXFibula (folder not found)

Failed: FolderDelete C:\Programfiler\CMFibula (folder not found)

Failed: FolderDelete C:\Programfiler\PSLister (folder not found)

Failed: FolderDelete C:\Programfiler\PSCloner (folder not found)

Failed: FolderDelete C:\Programfiler\PSDream (folder not found)

Failed: FolderDelete C:\Programfiler\cmapp (folder not found)

Failed: FolderDelete C:\Programfiler\cmman (folder not found)

Failed: FolderDelete C:\Programfiler\cmsystem (folder not found)

Failed: FolderDelete C:\Programfiler\fcengine (folder not found)

Failed: FolderDelete C:\Programfiler\wincmapp (folder not found)

Failed: FolderDelete C:\Programfiler\Deskbar\Cache (folder not found)

Failed: FolderDelete C:\Programfiler\popupwithcast (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\cloader (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\misc001 (folder not found)

Failed: FolderCreate C:\bintheredunthat (folder already exists)

Failed: FileMove C:\WINDOWS\win*-*.exe|C:\bintheredunthat (source file not found)

Script completed.

 

Det gikk fint det å putte inn Fellesfiler :)

 

Hva kommer nå da?

Lenke til kommentar

Kan du sjekke om du har linja (i bold) i skripet som du har laget:

 

FolderDelete %PROGRAMFILES%\Common Files\FreeProd1

FolderDelete %PROGRAMFILES%\Common Files\FreeProd2

FolderDelete %PROGRAMFILES%\Fellesfiler\inetget

FolderDelete %PROGRAMFILES%\Common Files\indetget2

FolderDelete %PROGRAMFILES%\Common Files\svchostsys

FolderDelete %PROGRAMFILES%\Common Files\simtest

 

Kan ikke se den i den siste loggen din.

Lenke til kommentar

Gjorde enda en ny BFU "scann":

 

Klikk for å se/fjerne innholdet nedenfor
BFU v1.00.9

Windows XP SP2 (WinNT 5.01.2600 SP2)

Script started at 00:15:22, on 06-12-31

 

Option Unload Explorer: Yes

Failed: DllUnregister C:\WINDOWS\DH.dll|1 (file not found)

Failed: DllUnregister C:\Programfiler\Deskbar\deskbar.dll|1 (file not found)

Failed: DllUnregister \asappsrv.dll|1 (file not found)

Failed: DllUnregister \MyToolBar.dll|1 (file not found)

Failed: DllUnregister \888Bar.dll|1 (file not found)

Failed: ServiceStop Network Monitor (service not found)

Failed: ServiceStop cmdService (service not found)

Failed: ServiceDisable Network Monitor (service not found)

Failed: ServiceDisable cmdService (service not found)

Failed: ServiceDelete Network Monitor (service not found)

Failed: ServiceDelete cmdService (service not found)

Failed: RegDelValue HKCU\System\CurrentControlSet\Control\Lsa|p2pnetwork (key not found)

Failed: RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe (key not found)

Option pause between commands: 300 ms

Option pause between commands: 50 ms

Failed: FolderDelete C:\Programfiler\MsConfigs (folder not found)

Failed: FolderDelete C:\Programfiler\winupdates (folder not found)

Failed: FolderDelete C:\Programfiler\winupdate (folder not found)

Failed: FolderDelete C:\Programfiler\winsupdater (folder not found)

Failed: FolderDelete C:\Programfiler\MsUpdate (folder not found)

Failed: FolderDelete C:\Programfiler\MsMovies (folder not found)

Failed: FolderDelete C:\Programfiler\wmplayer (folder not found)

Failed: FolderDelete C:\Programfiler\outlook (folder not found)

Failed: FileDelete C:\Programfiler\Fellesfiler\Windows\mc-*-*.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\update.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\services.dll (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\activate.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-1033-*-*}\MyToolBar.dll (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\update.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\services.dll (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\activate.exe (operation failed)

Failed: FileDelete C:\Programfiler\Fellesfiler\{*-*-2057-*-*}\MyToolBar.dll (operation failed)

Failed: FolderDelete C:\Programfiler\toolbar888 (folder not found)

Failed: FolderDelete C:\Programfiler\e-mailpaysu toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\EMUSIC TOOLBAR (folder not found)

Failed: FolderDelete C:\Programfiler\find dvd toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\GULESIDER VERKTøYLINJE (folder not found)

Failed: FolderDelete C:\Programfiler\sesam-p4 toolbar (folder not found)

Failed: FolderDelete C:\Programfiler\slownik ling (folder not found)

Failed: FolderDelete C:\Programfiler\MediaPipe (folder not found)

Failed: FolderDelete C:\Programfiler\p2pnetworks (folder not found)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\Perflib_Perfdata_d4.dat (operation failed)

Failed: FolderDelete C:\DOCUME~1\Server\LOKALE~1\Temp\Ultra$ISO (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DF2CEA.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DF2CF5.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DF9CEC.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DF9D1C.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DFB61E.tmp (operation failed)

Failed: FileDelete C:\DOCUME~1\Server\LOKALE~1\Temp\~DFEDD3.tmp (operation failed)

Failed: FolderDelete C:\Documents and Settings\Server\Lokale innstillinger\Temporary Internet Files\Content.IE5\4T2RWT2V (operation failed)

Failed: FolderDelete C:\Documents and Settings\Server\Lokale innstillinger\Temporary Internet Files\Content.IE5\YL41KLWR (operation failed)

Failed: FolderDelete C:\Programfiler\Maxifiles (folder not found)

Failed: FolderDelete C:\Programfiler\DNS (folder not found)

Failed: FolderDelete C:\Programfiler\EQAdvice (folder not found)

Failed: FolderDelete C:\Programfiler\FCAdvice (folder not found)

Failed: FolderDelete C:\Programfiler\PSCastor (folder not found)

Failed: FolderDelete C:\Programfiler\CMIntex (folder not found)

Failed: FolderDelete C:\Programfiler\PadsysAssistant (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\FreeProd1 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\FreeProd2 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\InetGet (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\InetGet2 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\svchostsys (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\simtest (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\misc001 (folder not found)

Failed: FolderDelete C:\Programfiler\InetGet2 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\VCClient (folder not found)

Failed: FolderDelete C:\Programfiler\Network Monitor (folder not found)

Failed: FolderDelete C:\WINDOWS\inet20001 (folder not found)

Failed: FolderDelete C:\Programfiler\Update06 (folder not found)

Failed: FolderDelete C:\Programfiler\Update03 (folder not found)

Failed: FolderDelete C:\Programfiler\Update04 (folder not found)

Failed: FolderDelete C:\Programfiler\Update08 (folder not found)

Failed: FolderDelete C:\Programfiler\W-Update (folder not found)

Failed: FolderDelete C:\Programfiler\Yazzle Sudoku (folder not found)

Failed: FolderDelete C:\Programfiler\Cas (folder not found)

Failed: FolderDelete C:\Programfiler\CasStub (folder not found)

Failed: FolderDelete C:\Programfiler\Cas2Stub (folder not found)

Failed: FolderDelete C:\Programfiler\ipwins (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\Snowball Wars (folder not found)

Failed: FolderDelete C:\Programfiler\folder.js (folder not found)

Failed: FolderDelete C:\Programfiler\ini.ini (folder not found)

Failed: FolderDelete C:\temp (folder not found)

Failed: FolderDelete C:\WINDOWS\mdrive (folder not found)

Failed: FolderDelete C:\WINDOWS\system32\crunner (folder not found)

Failed: FolderDelete C:\Programfiler\PECarlin (folder not found)

Failed: FolderDelete C:\Programfiler\AXVenore (folder not found)

Failed: FolderDelete C:\Programfiler\SDVita (folder not found)

Failed: FolderDelete C:\Programfiler\EQBranch (folder not found)

Failed: FolderDelete C:\Programfiler\EQArticle (folder not found)

Failed: FolderDelete C:\Programfiler\PSHope (folder not found)

Failed: FolderDelete C:\Programfiler\Batty (folder not found)

Failed: FolderDelete C:\Programfiler\Batty2 (folder not found)

Failed: FolderDelete C:\Programfiler\AXFibula (folder not found)

Failed: FolderDelete C:\Programfiler\CMFibula (folder not found)

Failed: FolderDelete C:\Programfiler\PSLister (folder not found)

Failed: FolderDelete C:\Programfiler\PSCloner (folder not found)

Failed: FolderDelete C:\Programfiler\PSDream (folder not found)

Failed: FolderDelete C:\Programfiler\cmapp (folder not found)

Failed: FolderDelete C:\Programfiler\cmman (folder not found)

Failed: FolderDelete C:\Programfiler\cmsystem (folder not found)

Failed: FolderDelete C:\Programfiler\fcengine (folder not found)

Failed: FolderDelete C:\Programfiler\wincmapp (folder not found)

Failed: FolderDelete C:\Programfiler\Deskbar\Cache (folder not found)

Failed: FolderDelete C:\Programfiler\popupwithcast (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\cloader (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\misc001 (folder not found)

Failed: FolderCreate C:\bintheredunthat (folder already exists)

Failed: FileMove C:\WINDOWS\win*-*.exe|C:\bintheredunthat (source file not found)

Script completed.

 

Failed: FolderDelete C:\Programfiler\Fellesfiler\FreeProd1 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\FreeProd2 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\InetGet (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\InetGet2 (folder not found)

Failed: FolderDelete C:\Programfiler\Fellesfiler\svchostsys (folder not found)

 

Fant den i den nye loggen men i den forrige var den ikke der :hmm: .

Lenke til kommentar

Kunne du forandret navnet InetGet til inetget, bare for sikkerhets skyld. Kjør skriptet. Trenger ikke å se loggen (du kan gi beskjed om det gir noen resultat ang. inetget)

 

Når dette er ferdig, poster du en ny HJT-logg for litt opprydding.

Hvis du har en hastighet på 1600 (isteden for 2500) er ikke det uvanlig hos telenor. :)

Endret av norbat
Lenke til kommentar

Den er enda i loggen så ingen forandring = Ikke funnet.....

 

Failed: FolderDelete C:\Programfiler\Fellesfiler\inetget (folder not found)

 

HJT logg nå:

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 00:50, on 06-12-31

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0011)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Programfiler\Java\jre1.5.0_02\bin\jusched.exe

C:\WINDOWS\system32\CTHELPER.EXE

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Programfiler\Logitech\Video\LogiTray.exe

C:\Programfiler\SoftDisc\softdisc.exe

C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe

C:\WINDOWS\MXOALDR.EXE

C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

C:\Programfiler\Winamp\winampa.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\BMT MouseTracker\MouseTrack.exe

C:\Programfiler\Pulse\Pulse.exe

C:\Programfiler\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe

C:\Programfiler\Microsoft Encarta\Encarta Premium DVD 2006\EDICT.EXE

C:\Programfiler\Logitech\MouseWare\system\em_exec.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\FinePixViewer\QuickDCF2.exe

C:\Programfiler\InterVideo\Common\Bin\WinCinemaMgr.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Works Shared\wkcalrem.exe

C:\Programfiler\Logitech\Video\FxSvr2.exe

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe

C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

C:\WINDOWS\system32\bgsvcgen.exe

C:\WINDOWS\system32\CTsvcCDA.EXE

C:\WINDOWS\system32\drivers\KodakCCS.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\VS7Debug\mdm.exe

C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Programfiler\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\Server\Skrivebord\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programfiler\TechSmith\SnagIt 8\SnagItBHO.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programfiler\BitComet\tools\BitCometBHO.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\system32\smiehlp.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - blank (file missing)

O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)

O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programfiler\TechSmith\SnagIt 8\SnagItIEAddin.dll

O4 - HKLM\..\Run: [updReg] C:\WINDOWS\Updreg.exe

O4 - HKLM\..\Run: [CTStartup] C:\Programfiler\Creative\SBAudigy\Program\CTEaxSpl.EXE /run

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_02\bin\jusched.exe

O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programfiler\Intel\NCS\PROSet\PRONoMgr.exe

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe

O4 - HKLM\..\Run: [WorksFUD] C:\Programfiler\Microsoft Works\wkfud.exe

O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programfiler\Microsoft Works\WksSb.exe /AllUsers

O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programfiler\Microsoft Works\WkDetect.exe

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programfiler\Logitech\Video\ISStart.exe

O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programfiler\Logitech\Video\LogiTray.exe

O4 - HKLM\..\Run: [softDisc] "C:\Programfiler\SoftDisc\softdisc.exe" -hide

O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe

O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe

O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE

O4 - HKLM\..\Run: [RemoteControl] C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [Jet Detection] C:\Programfiler\Creative\SBAudigy\PROGRAM\ADGJDet.exe

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\winampa.exe

O4 - HKLM\..\Run: [ATICCC] "C:\Programfiler\ATI Technologies\ATI.ACE\CLIStart.exe"

O4 - HKLM\..\Run: [REGSHAVE] C:\Programfiler\REGSHAVE\REGSHAVE.EXE /AUTORUN

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programfiler\Logitech\Video\ManifestEngine.exe boot

O4 - HKCU\..\Run: [bMT] C:\Programfiler\BMT MouseTracker\MouseTrack.exe

O4 - HKCU\..\Run: [Pulse] C:\Programfiler\Pulse\Pulse.exe -splash

O4 - HKCU\..\Run: [FreeRAM XP] "C:\Programfiler\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win

O4 - HKCU\..\Run: [E06AXLRD_16125156] "C:\Programfiler\Microsoft Encarta\Encarta Premium DVD 2006\EDICT.EXE" -m

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Startup: Mamut Online Backup.lnk = ?

O4 - Startup: World Community Grid Agent.lnk = C:\Programfiler\WorldCommunityGrid\UD.EXE

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Exif Launcher 2.lnk = ?

O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programfiler\InterVideo\Common\Bin\WinCinemaMgr.exe

O4 - Global Startup: Påminnelser for Microsoft Works Kalender.lnk = ?

O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: &Google Search - res://c:\programfiler\google\GoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: Backward Links - res://c:\programfiler\google\GoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programfiler\google\GoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://c:\programfiler\google\GoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://c:\programfiler\google\GoogleToolbar2.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programfiler\Fellesfiler\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programfiler\PartyGaming\PartyPoker\RunApp.exe

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programfiler\PartyGaming\PartyPoker\RunApp.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab

O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15009/CTSUEng.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.tvkoo.com/update/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1118175952031

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - http://www.icanal.no/spill/commerce/catalo...es/ExentCtl.ocx

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1118175849265

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/msnmesse...pdownloader.cab

O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.ladbrokes.com/instant-p...-en/FlashAX.cab

O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by18fd.bay18.hotmail.msn.com/activex/HMAtchmt.ocx

O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - http://chat.msn.com/bin/msnchat45.cab

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15010/CTPID.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{6978F5E5-3FD8-4CB7-80FF-52CDF6E3D714}: NameServer = 193.213.112.4 130.67.15.198

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe

O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Programfiler\Intel\NCS\Sync\NetSvc.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe (file missing)

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\Security Center\SymWSC.exe (file missing)

 

Itavisens speedometer viser:

 

Nedlastingshastighet: 22 kbit/s

Opplastingshastighet: 430 kbit/s

 

Jeg laster ikke ned noe, eller har noen programmer som er kjent av meg som gjør det.

Lenke til kommentar

Kjør HJT og fix:

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - blank (file missing)

O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

 

Hvis du kjenner til dette programmet

C:\Programfiler\Pulse\Pulse.exe

 

er HJT-loggen ok.

 

Står litt stille ang. lav hastighet. Kanskje reinstallere nettverkskortet?

Brukes det noen programmer som kan fordele båndbredde og så forårsaker dette?

 

Prøv å kjør en sfc /scannow (mellomrom mellom sfc og / ) fra Start->Kjør . Du trenger WinXP cd'n. Du får ikke noe beskjed om det er fixet noe. Restart når det er ferdig å sjekk hastigheten.

Endret av norbat
Lenke til kommentar

Ja pulse kjenner jeg til (programm som ser hvor mange trykk jeg har på keybordet).

 

Måtte først finne Windows cd'en hehe :!:

 

Kjørte Scanningen med windows cd'en og restartet etterpå men hastigheten er den samme.

 

Står litt stille ang. lav hastighet. Kanskje reinstallere nettverkskortet?

Brukes det noen programmer som kan fordele båndbredde og så forårsaker dette?

 

Da gjenstår det disse to tingene da....

Endret av tha_man
Lenke til kommentar

Last ned SDfix og pakk det (normalt til C:\SDfix )

 

Åpne SDfix-mappa og kjør RunTHis.bat. Trykk 'y' for å bekrefte at du kjører skiptet på egen risiko

 

Du vil bli bedt om å restarte pc'n. Når pc'n er startet igjen vil skriptet kjøres ferdig og du vil få melding når det er ferdig. Klikk en tast for å få skrivebordsikonene fram.

 

Det lages en logg i SDfix-mappa - Report.txt. Post den her.

 

Vi skal også prøve et annet glimrende antispywareprog - AVG. Kjør en full scan. Velg å 'Save report' og post loggen her.

Endret av norbat
Lenke til kommentar

SDfix rapport:

 

Klikk for å se/fjerne innholdet nedenfor
SDFix: Version 1.53

****************

 

06-12-31 - 14:07:19.07

 

Microsoft Windows XP [Versjon 5.1.2600]

 

Running From: C:\SDFix

 

Stage One - Safe Mode

 

Checking Services...

 

Service Name:

 

 

File Path:

 

 

 

Starting Registry Repairs...

 

Restoring Default Hosts File...

 

Stage One Complete

 

Rebooting...

 

Stage Two - Normal Mode

 

Checking For Malware:

--------------------

 

C:\WINDOWS\system32\SysPr.prx

 

Backing Up and Removing any Files Found...

 

Alternate Stream Check:

 

C:\WINDOWS\system32

No streams found.

Final Check:

 

Remaining Services:

------------------

 

 

 

Remaining Files:

---------------

 

Backups Folder: - C:\SDFix\backups\backups.zip

 

Checking for files with Hidden Attributes:

 

C:\olddrivers\cdplayer.exe.manifest

C:\olddrivers\logonui.exe.manifest

C:\WINDOWS\system32\cdplayer.exe.manifest

C:\WINDOWS\system32\logonui.exe.manifest

C:\hiberfil.sys

C:\IO.SYS

C:\MSDOS.SYS

C:\MSSYS.SYS

C:\pagefile.sys

C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp

C:\Documents and Settings\All Users\Programdata\Microsoft\Media Player\FQUPhdtC5\p4vdBLq7zb.tmp

C:\Documents and Settings\All Users\Programdata\PACE Anti-Piracy\2BFQUPhdtC5Axy\p4vdBLq7zb.tmp

C:\WINDOWS\system32\config\default.tmp.LOG

C:\WINDOWS\system32\config\software.tmp.LOG

C:\WINDOWS\system32\config\system.tmp.LOG

 

FINISHED!

 

AVG er mitt primære anti-virus programm (Har profesional), kjører full test nå....

Lenke til kommentar

---------------------------------------------------------

AVG Anti-Spyware - Scan Report

---------------------------------------------------------

 

+ Created at: 02:55 07-01-01

 

+ Scan result:

 

 

 

C:\Documents and Settings\Server\Cookies\server@advertising[2].txt -> TrackingCookie.Advertising : No action taken.

C:\Documents and Settings\Server\Cookies\server@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.

 

 

::Report end

 

Nedlastings hastigheten min er borti 70 kbit/s men det er enda bare 1/25 av linja!?

Endret av tha_man
Lenke til kommentar

Loggene dine ser ok ut så jeg klarer ikke helt å se hva som evt. kan forårsake strupingen av hastigheten.

 

At du ikke får kjørt Combofix er også litt merkelig. Kanskje det lar seg gjøre fra sikker modus?

 

Har du prøvd å avinstallere nettverkskortet og reinstallert det?

 

Om ikke det over hjelper, er en repair en mulig løsning. Om du ikke har gjort dette før er det enkelt forklart:

1. Boot med WinXP cd'n

2. Velg å foreta en installasjon av Windows.

3. Installasjonen vil lete etter installerte operativsystemer

4. Du vil få valget om å bla. reparere det installerte operativsys., noe du velger

5. Det vil bli foretatt en reparering - fortoner seg som en vanlig installering.

6. Du vil i utg.pkt ikke miste noe som helst av data, men regner med at du må hente oppdateringene for windows som har kommet i etterkant av cd'n. Det er også lurt å ta backup av data du ikke vil miste. Just in case.

 

Hvis dette ikke hjelper tror jeg du har to valg:

1. Prøv et nytt nettverkskort

2. Foreta en formatering og legg inn windows helt på nytt.

Lenke til kommentar

I sikkermodus gikk det med Combofix....

 

Combofix logg:

Klikk for å se/fjerne innholdet nedenfor
Server - 07-01-01 14:44:53.85 Service Pack 2

ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Server\Skrivebord\combofix"

 

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\Documents and Settings\Server\Programdata\Install.dat

C:\Programfiler\Fellesfiler\download

 

 

((((((((((((((((((((((((((((((( Files Created from 2006-11-29 to 2006-12-29 ))))))))))))))))))))))))))))))))))

 

 

2006-12-31 14:53 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2006-12-31 13:50 <DIR> dr-h----- C:\Documents and Settings\Server\Siste

2006-12-31 13:49 <DIR> d-------- C:\SDFix

2006-12-30 23:00 <DIR> d-------- C:\bintheredunthat

2006-12-30 22:26 <DIR> d-------- C:\BFU

2006-12-30 13:32 <DIR> d-------- C:\WINDOWS\WBEM

2006-12-30 13:32 <DIR> d-------- C:\WINDOWS\system32\nb-no

2006-12-30 13:31 <DIR> d--h-c--- C:\WINDOWS\ie7

2006-12-30 13:29 121,856 --------- C:\WINDOWS\system32\xmllite.dll

2006-12-30 13:21 <DIR> d-------- C:\Programfiler\Windows Media Connect 2

2006-12-30 13:19 <DIR> d-------- C:\WINDOWS\system32\LogFiles

2006-12-30 13:19 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF

2006-12-29 20:40 <DIR> d-------- C:\afe32085786b18b0af89948f0063446e

2006-12-29 20:19 <DIR> d-------- C:\fa6067dbda5aa9979c501f

2006-12-29 14:23 <DIR> d-------- C:\Documents and Settings\Server\DoctorWeb

2006-12-29 13:22 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2006-12-29 13:22 <DIR> d-------- C:\Documents and Settings\Server\Programdata\SUPERAntiSpyware.com

2006-12-29 12:35 <DIR> d-------- C:\Programfiler\CCleaner

2006-12-22 16:07 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll

2006-12-22 16:07 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll

2006-12-22 15:58 <DIR> d-------- C:\Programfiler\PIXELA

2006-12-22 15:56 106,496 --a------ C:\WINDOWS\system32\FPXS2Pro.dll

2006-12-22 15:54 81,924 --------- C:\WINDOWS\system32\drivers\VC4CB104.SYS

2006-12-22 15:54 69,632 --------- C:\WINDOWS\system32\FREGSHEX.DLL

2006-12-22 15:54 65,536 --------- C:\WINDOWS\system32\FINFCHECK.dll

2006-12-22 15:54 45,056 --------- C:\WINDOWS\system32\FINFCOPY.dll

2006-12-22 15:54 45,056 --------- C:\WINDOWS\system32\FCLKBTN.DLL

2006-12-22 15:54 <DIR> d-------- C:\Programfiler\REGSHAVE

2006-12-22 15:30 <DIR> d-------- C:\Documents and Settings\Server\Programdata\FUJIFILM

2006-12-22 15:29 <DIR> d-------- C:\Programfiler\FinePixViewer

2006-12-22 15:12 86,016 --------- C:\WINDOWS\system32\bgsvcgen.exe

2006-12-22 15:12 57,344 --------- C:\WINDOWS\system32\GenSvcInst.exe

2006-12-22 15:12 49,152 --------- C:\WINDOWS\system32\setupsvc.dll

2006-12-22 15:12 32,256 --------- C:\WINDOWS\system32\drivers\cdrbsdrv.sys

2006-12-22 15:10 274,432 --a------ C:\WINDOWS\system32\FFTIFF16.dll

2006-12-22 15:10 155,648 --a------ C:\WINDOWS\system32\FFRAFLIB.DLL

2006-12-21 00:57 <DIR> dr-h----- C:\$VAULT$.AVG

2006-12-21 00:47 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys

2006-12-21 00:47 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys

2006-12-21 00:47 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys

2006-12-21 00:47 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys

2006-12-21 00:47 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys

2006-12-21 00:47 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys

2006-12-21 00:47 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll

2006-12-21 00:47 <DIR> d-------- C:\Programfiler\Grisoft

2006-12-21 00:47 <DIR> d-------- C:\Documents and Settings\Server\Programdata\AVG7

2006-12-21 00:47 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Grisoft

2006-12-20 23:55 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Avg7

2006-12-11 17:57 <DIR> d-------- C:\Programfiler\SEGA

2006-12-11 17:55 <DIR> d-------- C:\Documents and Settings\Server\Programdata\InstallShield

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2006-12-31 15:24 -------- d-------- C:\Programfiler\WorldCommunityGrid

2006-12-30 13:35 -------- d-------- C:\Programfiler\Internet Explorer

2006-12-30 13:21 -------- d-------- C:\Programfiler\Windows Media Player

2006-12-30 03:26 2560 --a------ C:\WINDOWS\system32\BitCometRes.dll

2006-12-30 03:26 -------- d-------- C:\Programfiler\BitComet

2006-12-29 19:51 -------- d--h----- C:\Programfiler\InstallShield Installation Information

2006-12-29 19:51 -------- d-------- C:\Programfiler\Logitech

2006-12-29 16:58 -------- d-------- C:\Programfiler\LimeWire

2006-12-29 13:21 -------- d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2006-12-22 15:14 -------- d-------- C:\Documents and Settings\Server\Programdata\Skype

2006-12-21 15:25 -------- d-------- C:\Documents and Settings\Server\Programdata\teamspeak2

2006-12-21 13:33 -------- d-------- C:\Programfiler\QuickTime

2006-12-21 12:59 -------- d-------- C:\Documents and Settings\Server\Programdata\Winamp

2006-12-21 12:58 -------- d-------- C:\Programfiler\Winamp

2006-12-21 12:37 -------- d-------- C:\Programfiler\InetGet

2006-12-20 23:11 -------- d---s---- C:\Programfiler\Xfire

2006-12-20 22:30 -------- d-------- C:\Documents and Settings\Server\Programdata\Xfire

2006-12-16 03:03 -------- d-a------ C:\Programfiler\Outlook Express

2006-12-16 03:03 -------- d-------- C:\Programfiler\Fellesfiler\System

2006-12-03 19:26 -------- d-------- C:\Programfiler\Electronic Arts

2006-12-03 19:24 -------- d-------- C:\Programfiler\Skype

2006-12-03 19:19 -------- d-------- C:\Programfiler\America's Army Server Manager

2006-12-03 19:19 -------- d-------- C:\Programfiler\America's Army

2006-11-29 13:35 -------- d-------- C:\Programfiler\WinRAR

2006-11-22 10:52 520192 --------- C:\WINDOWS\system32\ati2sgag.exe

2006-11-22 04:25 2829824 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys

2006-11-22 04:25 261120 --a------ C:\WINDOWS\system32\ati2dvag.dll

2006-11-22 04:20 118784 --a------ C:\WINDOWS\system32\atipdlxx.dll

2006-11-22 04:20 106496 --a------ C:\WINDOWS\system32\Oemdspif.dll

2006-11-22 04:19 90112 --a------ C:\WINDOWS\system32\ati2evxx.dll

2006-11-22 04:19 42496 --a------ C:\WINDOWS\system32\ati2edxx.dll

2006-11-22 04:19 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe

2006-11-22 04:18 430080 --a------ C:\WINDOWS\system32\ati2evxx.exe

2006-11-22 04:17 53248 --a------ C:\WINDOWS\system32\ATIDDC.DLL

2006-11-22 04:12 2526688 --a------ C:\WINDOWS\system32\ati3duag.dll

2006-11-22 04:11 5279744 --a------ C:\WINDOWS\system32\atioglxx.dll

2006-11-22 04:08 1090016 --a------ C:\WINDOWS\system32\ativvaxx.dll

2006-11-22 03:57 217088 --a------ C:\WINDOWS\system32\atikvmag.dll

2006-11-22 03:56 17408 --a------ C:\WINDOWS\system32\atitvo32.dll

2006-11-22 03:51 294912 --a------ C:\WINDOWS\system32\ati2cqag.dll

2006-11-22 03:50 6684672 --a------ C:\WINDOWS\system32\atioglx1.dll

2006-11-22 03:49 307200 --a------ C:\WINDOWS\system32\atiiiexx.dll

2006-11-22 03:21 303104 --a------ C:\WINDOWS\system32\ATIDEMGR.dll

2006-11-15 11:07 8247296 --a------ C:\WINDOWS\system32\wmploc.dll

2006-11-15 10:46 99840 --a------ C:\WINDOWS\system32\wmpshell.dll

2006-11-15 10:45 225280 --a------ C:\WINDOWS\system32\wmerror.dll

2006-11-15 10:43 7168 --a------ C:\WINDOWS\system32\asferror.dll

2006-11-08 06:08 679424 --a------ C:\WINDOWS\system32\inetcomm.dll

2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll

2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll

2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll

2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll

2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll

2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll

2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll

2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll

2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll

2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll

2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll

2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe

2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll

2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll

2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe

2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll

2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll

2006-11-04 13:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll

2006-11-02 11:52 38912 --------- C:\WINDOWS\system32\wpdshextres.dll

2006-10-20 02:39 713728 --a------ C:\WINDOWS\system32\sxs.dll

2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe

2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\uwdf.exe

2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll

2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\WMNetMgr.dll

2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\WMVSENCD.dll

2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\WMADMOD.dll

2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\WMVXENCD.dll

2006-10-18 21:47 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll

2006-10-18 21:47 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll

2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll

2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\WMSPDMOD.dll

2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll

2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll

2006-10-18 21:47 429056 --a------ C:\WINDOWS\system32\wmdrmdev.dll

2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\WMVADVE.DLL

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\WMVADVD.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wdfapi.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MPG4DMOD.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MP4SDMOD.dll

2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MP43DMOD.dll

2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll

2006-10-18 21:47 35840 --a------ C:\WINDOWS\system32\wpdconns.dll

2006-10-18 21:47 356352 --a------ C:\WINDOWS\system32\wpdsp.dll

2006-10-18 21:47 348672 --a------ C:\WINDOWS\system32\wmdrmnet.dll

2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll

2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll

2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\MP4SDECD.dll

2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll

2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll

2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\PortableDeviceApi.dll

2006-10-18 21:47 276992 --a------ C:\WINDOWS\system32\audiodev.dll

2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll

2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\WpdShext.dll

2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\MPG4DECD.dll

2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\MP43DECD.dll

2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll

2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll

2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll

2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\WMASF.dll

2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\MFPLAT.dll

2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll

2006-10-18 21:47 204288 --a------ C:\WINDOWS\system32\wmpsrcwp.dll

2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\PortableDeviceWMDRM.dll

2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll

2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll

2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\PortableDeviceTypes.dll

2006-10-18 21:47 1661440 --a------ C:\WINDOWS\system32\wmpencen.dll

2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\WMVENCOD.dll

2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll

2006-10-18 21:47 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll

2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\WMVDECOD.dll

2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\WMVSDECD.dll

2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\WPDShServiceObj.dll

2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\WMSPDMOE.dll

2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\PortableDeviceWiaCompat.dll

2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll

2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\LAPRXY.dll

2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\WMADMOE.dll

2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\PortableDeviceClassExtension.dll

2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe

2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe

2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe

2006-10-17 12:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll

2006-10-17 12:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll

2006-10-17 12:05 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe

2006-10-17 12:05 105984 --a------ C:\WINDOWS\system32\url.dll

2006-10-17 12:04 101376 --a------ C:\WINDOWS\system32\occache.dll

2006-10-17 12:03 17408 --a------ C:\WINDOWS\system32\corpol.dll

2006-10-17 11:58 61952 --------- C:\WINDOWS\system32\icardie.dll

2006-10-17 11:58 12288 --------- C:\WINDOWS\system32\msfeedssync.exe

2006-10-17 11:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll

2006-10-17 11:57 266752 --------- C:\WINDOWS\system32\iertutil.dll

2006-10-17 11:56 45568 --a------ C:\WINDOWS\system32\mshta.exe

2006-10-17 11:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll

2006-10-17 11:27 380928 --------- C:\WINDOWS\system32\ieapfltr.dll

2006-10-13 13:41 141824 --a------ C:\WINDOWS\system32\nwprovau.dll

2006-10-02 15:28 312128 --------- C:\WINDOWS\system32\msdelta.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

*Note* empty entries are not shown

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"

"LogitechSoftwareUpdate"="C:\\Programfiler\\Logitech\\Video\\ManifestEngine.exe boot"

"BMT"="C:\\Programfiler\\BMT MouseTracker\\MouseTrack.exe"

"Pulse"="C:\\Programfiler\\Pulse\\Pulse.exe -splash"

"FreeRAM XP"="\"C:\\Programfiler\\YourWare Solutions\\FreeRAM XP Pro\\FreeRAM XP Pro.exe\" -win"

"E06AXLRD_16125156"="\"C:\\Programfiler\\Microsoft Encarta\\Encarta Premium DVD 2006\\EDICT.EXE\" -m"

"SUPERAntiSpyware"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"UpdReg"="C:\\WINDOWS\\Updreg.exe"

"CTStartup"="C:\\Programfiler\\Creative\\SBAudigy\\Program\\CTEaxSpl.EXE /run"

"SunJavaUpdateSched"="C:\\Programfiler\\Java\\jre1.5.0_02\\bin\\jusched.exe"

"PRONoMgr.exe"="C:\\Programfiler\\Intel\\NCS\\PROSet\\PRONoMgr.exe"

"CTHelper"="CTHELPER.EXE"

"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"

"WorksFUD"="C:\\Programfiler\\Microsoft Works\\wkfud.exe"

"Microsoft Works Portfolio"="C:\\Programfiler\\Microsoft Works\\WksSb.exe /AllUsers"

"Microsoft Works Update Detection"="C:\\Programfiler\\Microsoft Works\\WkDetect.exe"

"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"

"LogitechVideoRepair"="C:\\Programfiler\\Logitech\\Video\\ISStart.exe"

"LogitechVideoTray"="C:\\Programfiler\\Logitech\\Video\\LogiTray.exe"

"SoftDisc"="\"C:\\Programfiler\\SoftDisc\\softdisc.exe\" -hide"

"Logitech Utility"="Logi_MwX.Exe"

"MaxtorOneTouch"="C:\\PROGRA~1\\Maxtor\\OneTouch\\Utils\\OneTouch.exe"

"MXO Auto Loader"="C:\\WINDOWS\\MXOALDR.EXE"

"RemoteControl"="C:\\Programfiler\\CyberLink\\PowerDVD\\PDVDServ.exe"

"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"

"Jet Detection"="C:\\Programfiler\\Creative\\SBAudigy\\PROGRAM\\ADGJDet.exe"

"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"

"WinampAgent"="C:\\Programfiler\\Winamp\\winampa.exe"

"ATICCC"="\"C:\\Programfiler\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""

"REGSHAVE"="C:\\Programfiler\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"

"!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]

"Installed"="1"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]

"Installed"="1"

"NoChange"="1"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]

"Installed"="1"

 

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]

"DeskHtmlVersion"=dword:00000110

"DeskHtmlMinorVersion"=dword:00000005

"Settings"=dword:00000001

"GeneralFlags"=dword:00000001

 

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]

"Source"="About:Home"

"SubscribedURL"="About:Home"

"FriendlyName"="Min gjeldende hjemmeside"

"Flags"=dword:00000002

"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\

00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00

"CurrentState"=hex:04,00,00,40

"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\

ff,ff,04,00,00,00

"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,b9,00,00,00,7c,00,00,00,72,00,\

00,00,01,00,00,00

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

 

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]

"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]

"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"

"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

@=""

"NoDriveTypeAutoRun"=dword:0000009d

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"dontdisplaylastusername"=dword:00000000

"legalnoticecaption"=""

"legalnoticetext"=""

"shutdownwithoutlogon"=hex:01,00,00,00

"undockwithoutlogon"=dword:00000001

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NoDriveTypeAutoRun"=dword:00000091

 

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]

"NoDriveTypeAutoRun"=dword:00000091

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]

"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"

"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"

"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"

"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^SECRETMAKER.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\SECRETMAKER.lnk"

"backup"="C:\\WINDOWS\\pss\\SECRETMAKER.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\SECRET~1\\SECRET~1.EXE /Logon"

"item"="SECRETMAKER"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Server^Start-meny^Programmer^Oppstart^HDDlife.lnk]

"path"="C:\\Documents and Settings\\Server\\Start-meny\\Programmer\\Oppstart\\HDDlife.lnk"

"backup"="C:\\WINDOWS\\pss\\HDDlife.lnkStartup"

"location"="Startup"

"command"="C:\\Programfiler\\HDDlife\\HDDlife.exe "

"item"="HDDlife"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Server^Start-meny^Programmer^Oppstart^PowerReg Scheduler.exe]

"path"="C:\\Documents and Settings\\Server\\Start-meny\\Programmer\\Oppstart\\PowerReg Scheduler.exe"

"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"

"location"="Startup"

"command"="C:\\Documents and Settings\\Server\\Start-meny\\Programmer\\Oppstart\\PowerReg Scheduler.exe"

"item"="PowerReg Scheduler"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Server^Start-meny^Programmer^Oppstart^Registration Silent Hunter III.LNK]

"path"="C:\\Documents and Settings\\Server\\Start-meny\\Programmer\\Oppstart\\Registration Silent Hunter III.LNK"

"backup"="C:\\WINDOWS\\pss\\Registration Silent Hunter III.LNKStartup"

"location"="Startup"

"command"="C:\\Programfiler\\Ubisoft\\SilentHunterIII\\Support\\Register\\RegistrationReminder.exe -d 802361 -l english -r 7 -g Silent Hunter III -c us -i 2172"

"item"="Registration Silent Hunter III"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Server^Start-meny^Programmer^Oppstart^Xfire.lnk]

"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\Xfire\\Xfire.exe "

"item"="Xfire"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CashFiesta]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Cashfiesta"

"hkey"="HKCU"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="daemon"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\D-Tools\\daemon.exe\" -lang 1033"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="mnyexpr"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\Microsoft Money\\System\\mnyexpr.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ms-update]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKLM"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="msnmsgr"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uptime-Project]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="client"

"hkey"="HKCU"

"command"="C:\\Documents and Settings\\Server\\Skrivebord\\client\\client.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="zlclient"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Zone Labs\\ZoneAlarm\\zlclient.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"ZESOFT"=dword:00000002

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

 

Completion time: 07-01-01 14:47:35.51

C:\ComboFix.txt ... 07-01-01 14:47

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...