Gå til innhold

Trenger analyse av HJT-logg [LØST]


Anbefalte innlegg

SAS-LOGG

Klikk for å se/fjerne innholdet nedenfor
SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 04/30/2007 at 01:36 AM

 

Application Version : 3.7.1018

 

Core Rules Database Version : 3227Trace Rules Database Version: 1238

 

Scan type : Complete Scan

Total Scan Time : 00:33:33

 

Memory items scanned : 197

Memory threats detected : 0

Registry items scanned : 5474

Registry threats detected : 230

File items scanned : 30714

File threats detected : 14

 

Trojan.Smitfraud Variant

HKLM\Software\Classes\CLSID\{b23dc537-3e13-44c7-bf67-d8405eb377f7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\RCOHTY.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{b23dc537-3e13-44c7-bf67-d8405eb377f7}

 

Adware.ToolBar888

HKLM\Software\Classes\CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32#ThreadingModel

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\ProgID

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\Programmable

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\TypeLib

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\VersionIndependentProgID

C:\PROGRAMFILER\TOOLBAR888\MYTOOLBAR.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKLM\Software\Microsoft\Internet Explorer\Toolbar#{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\MyToolBar.MyToolBarObj.1

HKCR\MyToolBar.MyToolBarObj.1\CLSID

HKCR\MyToolBar.MyToolBarObj

HKCR\MyToolBar.MyToolBarObj\CLSID

HKCR\MyToolBar.MyToolBarObj\CurVer

HKCR\TypeLib\{CD2A09D7-EE7E-4c25-993C-C2678ECFAD01}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version

HKLM\Software\Classes\MyToolBar.MyToolBarObj

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CLSID

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CurVer

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID

HKU\S-1-5-21-1645522239-484061587-839522115-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

 

Trojan.Media-Codec/V2

HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\BPVOL.DLL

HKLM\Software\Classes\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories\{00021493-0000-0000-C000-000000000046}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\SPLUG.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString

 

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007

HKCR\WAP6.PCheck

HKCR\WAP6.PCheck\CLSID

HKCR\WAP6.PCheck\CurVer

HKCR\WAP6.PCheck.1

HKCR\WAP6.PCheck.1\CLSID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version

 

Trojan.Unknown Origin

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#SystemComponent

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#Installer

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation#CODEBASE

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion#LastModified

 

Trojan.ZQuest

C:\WINDOWS\dh.ini

 

Trojan.DollarRevenue

C:\WINDOWS\newname.dat

C:\WINDOWS\keyboard1.dat

 

Trojan.ErrorSafe

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32#ThreadingModel

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\ProgID

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Programmable

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\TypeLib

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\VersionIndependentProgID

 

Browser Hijacker.Deskbar

HKCR\DBTB00001.DBTB00001

HKCR\DBTB00001.DBTB00001\CLSID

HKCR\DBTB00001.DBTB00001\CurVer

HKCR\DBTB00001.DBTB00001.1

HKCR\DBTB00001.DBTB00001.1\CLSID

HKCR\DBTB00001.DeskBar

HKCR\DBTB00001.DeskBar\CLSID

HKCR\DBTB00001.DeskBar\CurVer

HKCR\DBTB00001.DeskBar.1

HKCR\DBTB00001.DeskBar.1\CLSID

HKCR\DBTB00001.deskbarBHO

HKCR\DBTB00001.deskbarBHO\CLSID

HKCR\DBTB00001.deskbarBHO\CurVer

HKCR\DBTB00001.deskbarBHO.1

HKCR\DBTB00001.deskbarBHO.1\CLSID

HKCR\DBTB00001.DeskbarEnabler

HKCR\DBTB00001.DeskbarEnabler\CLSID

HKCR\DBTB00001.DeskbarEnabler.1

HKCR\DBTB00001.DeskbarEnabler.1\CLSID

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid32

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib#Version

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid32

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib#Version

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid32

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib#Version

 

Trojan.Media-Codec

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#user32.dll [ C:\Programfiler\Video AX Object\bpmon.exe ]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#rare [ C:\Programfiler\Video AX Object\smmain.exe ]

 

Malware.SpyLocked

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32#ThreadingModel

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\OtiLglrhUikvj

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\podtlbEyd

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\pysFxsmg

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\rxirdocusi

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\TypeLib

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\uCniqDrba

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\wnFySqsxcxws

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0\win32

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\FLAGS

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\HELPDIR

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid32

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib#Version

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid32

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib#Version

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid32

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib#Version

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid32

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib#Version

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid32

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib#Version

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid32

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib#Version

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid32

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib#Version

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid32

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib#Version

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid32

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib#Version

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid32

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib#Version

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid32

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib#Version

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid32

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib#Version

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid32

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib#Version

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid32

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib#Version

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid32

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib#Version

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid32

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib#Version

 

Worm.Alcra Variant

C:\WINDOWS\SYSTEM32\CMD.COM

C:\WINDOWS\SYSTEM32\NETSTAT.COM

C:\WINDOWS\SYSTEM32\PING.COM

C:\WINDOWS\SYSTEM32\REGEDIT.COM

C:\WINDOWS\SYSTEM32\TASKKILL.COM

C:\WINDOWS\SYSTEM32\TASKLIST.COM

C:\WINDOWS\SYSTEM32\TRACERT.COM

 

HJT-Logg

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 01:48:14, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\msnlogm.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\msnlogs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\notepad.exe

C:\PROGRA~1\Mozilla Firefox\firefox.exe

C:\Documents and Settings\- Nils\Skrivebord\rootchk.exe

C:\WINDOWS\system32\cmd.exe

C:\DOCUME~1\-NILS~1\LOKALE~1\Temp\Rootchk\catchme.exe

C:\Programfiler\HijackThis\HijackThis.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Programfiler\Start.no Turbo\components\NOWImaging.dll (file missing)

O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing)

O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing)

O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing)

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe

O4 - HKLM\..\Run: [defender] C:\\dfndrff_e37.exe

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [newname] C:\\nwnmff_e37.exe

O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e37.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: bw+0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: offline-8876480 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

 

Rootchk Logg

Klikk for å se/fjerne innholdet nedenfor
******************************** ROOTCHK-(25-04-07)-LOG, by ejvindh

30.04.07 1:46:49,21

 

Driver nm (visible) is present. Run COMBOFIX by sUBs.

 

********************************* ROOTCHK-LOG-end

 

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 01:46:50

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

msnsyslog = C:\WINDOWS\msnlogm.exe??X?2??|d?2??|p?2??|??8[??H??|8??|??2??|?|?|??%?@?R?B~??%?@?\?B~??@?@?

 

scanning hidden files ...

 

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 102

 

Har jeg noe ufine ting? :thumbdown:

Og hvordan fjerner jeg hvis jeg har? :dontgetit:

Endret av trysilgutt
Lenke til kommentar
Videoannonse
Annonse
WOW.... :dribble: Der var det endel og ta tak i ser jeg...Midt beste forslag akkurat er og gå på denne siden og følge guiden som er satt opp der....Når det er gjort så legger du ut en ny logg....

8499132[/snapback]

 

Legge til en SAS-Logg?

 

Edit: Nå skjønte jeg :)

Endret av trysilgutt
Lenke til kommentar

SAS-LOGG

Klikk for å se/fjerne innholdet nedenfor
SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 04/30/2007 at 01:36 AM

 

Application Version : 3.7.1018

 

Core Rules Database Version : 3227Trace Rules Database Version: 1238

 

Scan type : Complete Scan

Total Scan Time : 00:33:33

 

Memory items scanned : 197

Memory threats detected : 0

Registry items scanned : 5474

Registry threats detected : 230

File items scanned : 30714

File threats detected : 14

 

Trojan.Smitfraud Variant

HKLM\Software\Classes\CLSID\{b23dc537-3e13-44c7-bf67-d8405eb377f7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32

HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\RCOHTY.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{b23dc537-3e13-44c7-bf67-d8405eb377f7}

 

Adware.ToolBar888

HKLM\Software\Classes\CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32#ThreadingModel

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\ProgID

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\Programmable

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\TypeLib

HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\VersionIndependentProgID

C:\PROGRAMFILER\TOOLBAR888\MYTOOLBAR.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKLM\Software\Microsoft\Internet Explorer\Toolbar#{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

HKCR\MyToolBar.MyToolBarObj.1

HKCR\MyToolBar.MyToolBarObj.1\CLSID

HKCR\MyToolBar.MyToolBarObj

HKCR\MyToolBar.MyToolBarObj\CLSID

HKCR\MyToolBar.MyToolBarObj\CurVer

HKCR\TypeLib\{CD2A09D7-EE7E-4c25-993C-C2678ECFAD01}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS

HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib

HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version

HKLM\Software\Classes\MyToolBar.MyToolBarObj

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CLSID

HKLM\Software\Classes\MyToolBar.MyToolBarObj\CurVer

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1

HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID

HKU\S-1-5-21-1645522239-484061587-839522115-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}

 

Trojan.Media-Codec/V2

HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32

HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\BPVOL.DLL

HKLM\Software\Classes\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories\{00021493-0000-0000-C000-000000000046}

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32

HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32#ThreadingModel

C:\PROGRAMFILER\VIDEO AX OBJECT\SPLUG.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString

 

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007

HKCR\WAP6.PCheck

HKCR\WAP6.PCheck\CLSID

HKCR\WAP6.PCheck\CurVer

HKCR\WAP6.PCheck.1

HKCR\WAP6.PCheck.1\CLSID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable

HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS

HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib

HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version

 

Trojan.Unknown Origin

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#SystemComponent

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#Installer

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation#CODEBASE

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion#LastModified

 

Trojan.ZQuest

C:\WINDOWS\dh.ini

 

Trojan.DollarRevenue

C:\WINDOWS\newname.dat

C:\WINDOWS\keyboard1.dat

 

Trojan.ErrorSafe

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32#ThreadingModel

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\ProgID

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Programmable

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\TypeLib

HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\VersionIndependentProgID

 

Browser Hijacker.Deskbar

HKCR\DBTB00001.DBTB00001

HKCR\DBTB00001.DBTB00001\CLSID

HKCR\DBTB00001.DBTB00001\CurVer

HKCR\DBTB00001.DBTB00001.1

HKCR\DBTB00001.DBTB00001.1\CLSID

HKCR\DBTB00001.DeskBar

HKCR\DBTB00001.DeskBar\CLSID

HKCR\DBTB00001.DeskBar\CurVer

HKCR\DBTB00001.DeskBar.1

HKCR\DBTB00001.DeskBar.1\CLSID

HKCR\DBTB00001.deskbarBHO

HKCR\DBTB00001.deskbarBHO\CLSID

HKCR\DBTB00001.deskbarBHO\CurVer

HKCR\DBTB00001.deskbarBHO.1

HKCR\DBTB00001.deskbarBHO.1\CLSID

HKCR\DBTB00001.DeskbarEnabler

HKCR\DBTB00001.DeskbarEnabler\CLSID

HKCR\DBTB00001.DeskbarEnabler.1

HKCR\DBTB00001.DeskbarEnabler.1\CLSID

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid32

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib

HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib#Version

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid32

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib

HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib#Version

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid32

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib

HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib#Version

 

Trojan.Media-Codec

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#user32.dll [ C:\Programfiler\Video AX Object\bpmon.exe ]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#rare [ C:\Programfiler\Video AX Object\smmain.exe ]

 

Malware.SpyLocked

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32#ThreadingModel

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\OtiLglrhUikvj

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\podtlbEyd

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\pysFxsmg

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\rxirdocusi

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\TypeLib

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\uCniqDrba

HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\wnFySqsxcxws

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0\win32

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\FLAGS

HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\HELPDIR

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid32

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib

HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib#Version

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid32

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib

HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib#Version

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid32

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib

HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib#Version

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid32

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib

HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib#Version

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid32

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib

HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib#Version

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid32

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib

HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib#Version

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid32

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib

HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib#Version

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid32

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib

HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib#Version

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid32

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib

HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib#Version

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid32

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib

HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib#Version

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid32

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib

HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib#Version

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid32

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib

HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib#Version

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid32

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib

HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib#Version

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid32

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib

HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib#Version

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid32

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib

HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib#Version

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid32

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib

HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib#Version

 

Worm.Alcra Variant

C:\WINDOWS\SYSTEM32\CMD.COM

C:\WINDOWS\SYSTEM32\NETSTAT.COM

C:\WINDOWS\SYSTEM32\PING.COM

C:\WINDOWS\SYSTEM32\REGEDIT.COM

C:\WINDOWS\SYSTEM32\TASKKILL.COM

C:\WINDOWS\SYSTEM32\TASKLIST.COM

C:\WINDOWS\SYSTEM32\TRACERT.COM

 

HJT-Logg

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 01:48:14, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\msnlogm.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\msnlogs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\notepad.exe

C:\PROGRA~1\Mozilla Firefox\firefox.exe

C:\Documents and Settings\- Nils\Skrivebord\rootchk.exe

C:\WINDOWS\system32\cmd.exe

C:\DOCUME~1\-NILS~1\LOKALE~1\Temp\Rootchk\catchme.exe

C:\Programfiler\HijackThis\HijackThis.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Programfiler\Start.no Turbo\components\NOWImaging.dll (file missing)

O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing)

O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing)

O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing)

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe

O4 - HKLM\..\Run: [defender] C:\\dfndrff_e37.exe

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [newname] C:\\nwnmff_e37.exe

O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e37.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: bw+0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: offline-8876480 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

 

Rootchk Logg

Klikk for å se/fjerne innholdet nedenfor
******************************** ROOTCHK-(25-04-07)-LOG, by ejvindh

30.04.07 1:46:49,21

 

Driver nm (visible) is present. Run COMBOFIX by sUBs.

 

********************************* ROOTCHK-LOG-end

 

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 01:46:50

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

msnsyslog = C:\WINDOWS\msnlogm.exe??X?2??|d?2??|p?2??|??8[??H??|8??|??2??|?|?|????%?@???R?B~??%?@?\?B~??????@?@?

 

scanning hidden files ...

 

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 102

Endret av trysilgutt
Lenke til kommentar

Avinstaller om mulig, fra legg til/fjern programmer:

Logitech desktop messenger

MSN Content Plus

 

Kjør HJT, sett merke framfor følgende linjer og klikk 'Fix checked':

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing)

O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing)

O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing)

O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe

O4 - HKLM..Run: [defender] C:\dfndrff_e37.exe

O4 - HKLM..Run: [newname] C:\nwnmff_e37.exe

O4 - HKLM..Run: [keyboard] C:\kybrdff_e37.exe

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab

 

 

Hent Combofix og legg det på skrivebordet. Lukk alle andre programmer. Kjør programmet. Ikke klikk på noe annet.

 

Når programmet er ferdig åpnes en loggfil: combofix.txt

Den loggfilen poster du senere.

 

Sørg for at du kan se skjulte filer og mapper:

Kontrollpanel->mappealt.->vis->"vis skjulte filer og mapper"

 

Restart i sikker modus (tapp F8 under oppstart)

 

Bruk utforsker til å finne og slette (i fet):

C:\WINDOWS\msnlogm.exe

C:\WINDOWS\msnlogs.exe

 

Restart i normal tilstand

 

Post en ny HJT-logg + loggen fra combofix.

Endret av norbat
Lenke til kommentar

HJT LOGG

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 13:50:46, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\VTTimer.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\HijackThis\HijackThis.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

 

COMBO-FIX LOG

Klikk for å se/fjerne innholdet nedenfor
"- Nils" - 07-04-30 13:04:28 Service Pack 2

ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\"

 

 

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\qoobox\purity\C\Programfiler\MCROSO~1.NET

C:\qoobox\purity\C\WINDOWS\PPATCH~1

C:\qoobox\purity\C\WINDOWS\system32\FNTS~1

 

 

((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\nm

-------\LEGACY_NM

-------\LEGACY_NPF

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 ))))))))))))))))))))))))))))))))))

 

 

2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-04-30 03:17 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste

2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner

2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca

2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp

2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts

2007-04-29 23:23 1,048,576 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask

2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord

2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT

2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata

2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter

2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp

2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts

2007-04-29 15:16 1,310,720 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT

2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask

2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord

2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr

2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir

2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft

2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet

2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared

2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour

2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software

2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes

2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain

2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes

2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no

2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic

2007-03-31 17:32 <DIR> d-------- C:\Programfiler\Duplicate File Finder

2007-03-30 15:38 118,784 --------- C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe

2007-03-30 15:37 13,440 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS

2007-03-30 15:36 68,864 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys

2007-03-30 15:36 55,040 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys

2007-03-30 15:36 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe

2007-03-30 15:36 26,112 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys

2007-03-30 15:36 258,352 --a------ C:\WINDOWS\system32\unicows.dll

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Logitech

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech

2007-03-28 21:19 <DIR> d-------- C:\Programfiler\Windows Media Connect 2

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson

2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared

2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp

2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7

2007-04-23 19:06 -------- d-------- C:\Programfiler\opera

2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod

2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime

2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2

2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire

2007-03-30 15:38 -------- d--h----- C:\Programfiler\installshield installation information

2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat

2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat

2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll

2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp

2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture

2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger

2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys

2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll

2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll

2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll

2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys

2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus

2007-03-06 18:36 -------- d-------- C:\Programfiler\utorrent

2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent

2007-02-28 21:25 -------- d-------- C:\Programfiler\msn messenger

2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe

2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat

2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini

2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

{784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"VTTimer"="VTTimer.exe"

"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"

"!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages REG_MULTI_SZ msv1_0\0\0

Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages REG_MULTI_SZ scecli\0\0

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma Loader"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start"

"item"="Logitech Desktop Messenger"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe "

"item"="Logitech SetPoint"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk"

"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"

"item"="Microsoft Office"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk"

"backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE "

"item"="MagicDisc"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk"

"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"

"location"="Startup"

"command"="C:\\Programfiler\\Xfire\\xfire.exe "

"item"="Xfire"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="avgas"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ashDisp"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="bittorrent"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="daemon"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="UDC2006"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\DriveCleaner 2006 Free\\UDC2006.exe\" /min"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="InCD"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iTunesHelper"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="dumprep 0 -k"

"hkey"="HKLM"

"command"="%systemroot%\\system32\\dumprep 0 -k"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LogitechDesktopMessenger"

"hkey"="HKCU"

"command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="lxczbmgr"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NCLAUNCH"

"hkey"="HKCU"

"command"="C:\\WINDOWS\\NCLAUNCH.EXe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NeroCheck"

"hkey"="HKLM"

"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LAUNCH~1"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="PCTAV"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="pvmodule"

"hkey"="HKLM"

"command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="qttask"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Skype"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Application Launcher"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SOUNDMAN"

"hkey"="HKLM"

"command"="SOUNDMAN.EXE"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="jusched"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SUPERAntiSpyware"

"hkey"="HKCU"

"command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="VCDDaemon"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="CAMTHINS"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="winampa"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Winamp\\winampa.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="xfiremusic"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="MultiIM"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"PCTAVSvc"=dword:00000002

"usnjsvc"=dword:00000003

"UserAccess7"=dword:00000002

"rpcapd"=dword:00000003

"LexBceS"=dword:00000002

"iPod Service"=dword:00000003

"InCDsrv"=dword:00000002

"IDriverT"=dword:00000003

"Adobe LM Service"=dword:00000003

"NVCScheduler"=dword:00000003

"Norman ZANDA"=dword:00000002

"Norman NJeeves"=dword:00000003

"NipSvc"=dword:00000003

"nvcoas"=dword:00000003

"Bonjour Service"=dword:00000002

"avast! Web Scanner"=dword:00000003

"avast! Mail Scanner"=dword:00000003

"avast! Antivirus"=dword:00000002

"aswUpdSv"=dword:00000002

"FLEXnet Licensing Service"=dword:00000003

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter REG_MULTI_SZ HTTPFilter\0\0

LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService REG_MULTI_SZ DnsCache\0\0

DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

rpcss REG_MULTI_SZ RpcSs\0\0

imgsvc REG_MULTI_SZ StiSvc\0\0

termsvcs REG_MULTI_SZ TermService\0\0

WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

 

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 13:08:51

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 07-04-30 13:09:21

C:\ComboFix-quarantined-files.txt ... 07-04-30 13:09

C:\ComboFix2.txt ... 07-04-30 13:01

Lenke til kommentar

Åpne Notisblokk og kopier og lim inn det som står under (i fet):

 

REGEDIT4

 

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]

 

(PS. sørg for at det ikke er noe luft over REGEDIT4 - altså den skal stå aller øverst i notisblokkvinduet)

 

Klikk 'Lagre som', velg 'Alle filer' som filtype. Lagre file med filnavn: fix.reg på skrivebordet.

 

Dobbeltklikk på fila (fix.reg), og si ja til å legge inn/flette inn i registeret.

 

Kjør HJT, sett merke framfor følgende linjer og klikk 'Fix checked':

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx

O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.ca

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

 

Hvis du ikke allerede har programmet: Hent CCleaner.

Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......."

Klikk på 'Renser' og deretter 'Kjør CCleaner'.

Kjør også noen runder med 'Saker' til det ikke finner flere feil.

 

Nullstille gjenopprettingsmappa

Kontrollpanel->system->systemgjenoppretting .

Sett merke framfor "Slå av .....",

restart pc,

fjern merket igjen for å aktivere funksjonen.

 

Kjør på ny en scan med Combofix

 

Post deretter combofix-loggen samt en ny HJT-logg (Før du kjører HJT, forandrer du programnavnet, hijackthis, til noe annet, feks. test )

 

Fortell også hvordan pc'n kjører.

 

I mens noen sjekker de siste loggene, kjører du på ny en complete scan med SAS. Fortell gjerne om den finner noe :)

Endret av norbat
Lenke til kommentar

HJT-LOGG

 

Klikk for å se/fjerne innholdet nedenfor
Logfile of HijackThis v1.99.1

Scan saved at 18:17:15, on 30.04.07

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\VTTimer.exe

C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\Mozilla Firefox\firefox.exe

C:\Programfiler\HijackThis\Test.exe

 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe

 

COMBOFIX Logg

 

Klikk for å se/fjerne innholdet nedenfor
- Nils" - 07-04-30 18:06:14 Service Pack 2

ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\"

 

 

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\qoobox\purity\C\Programfiler\MCROSO~1.NET

C:\qoobox\purity\C\WINDOWS\PPATCH~1

C:\qoobox\purity\C\WINDOWS\system32\FNTS~1

 

 

((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\nm

-------\LEGACY_NM

-------\LEGACY_NPF

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 ))))))))))))))))))))))))))))))))))

 

 

2007-04-30 17:53 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste

2007-04-30 17:11 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\AdobeUM

2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner

2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca

2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp

2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts

2007-04-29 23:23 1,048,576 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask

2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord

2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT

2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata

2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter

2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp

2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts

2007-04-29 15:16 1,310,720 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT

2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask

2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord

2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr

2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir

2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft

2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet

2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared

2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour

2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software

2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes

2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain

2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes

2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no

2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic

2007-03-31 17:32 <DIR> d-------- C:\Programfiler\Duplicate File Finder

2007-03-30 15:37 13,440 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS

2007-03-30 15:36 68,864 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys

2007-03-30 15:36 55,040 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys

2007-03-30 15:36 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe

2007-03-30 15:36 26,112 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys

2007-03-30 15:36 258,352 --a------ C:\WINDOWS\system32\unicows.dll

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Logitech

2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech

2007-03-28 21:19 <DIR> d-------- C:\Programfiler\Windows Media Connect 2

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson

2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared

2007-04-30 00:22 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\teleca

2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp

2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7

2007-04-23 19:06 -------- d-------- C:\Programfiler\opera

2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod

2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime

2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2

2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire

2007-03-30 15:38 -------- d--h----- C:\Programfiler\installshield installation information

2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat

2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat

2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll

2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp

2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture

2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger

2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys

2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll

2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll

2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll

2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys

2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus

2007-03-06 18:36 -------- d-------- C:\Programfiler\utorrent

2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent

2007-02-28 21:25 -------- d-------- C:\Programfiler\msn messenger

2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe

2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat

2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini

2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

{784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"VTTimer"="VTTimer.exe"

"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"

"!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages REG_MULTI_SZ msv1_0\0\0

Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages REG_MULTI_SZ scecli\0\0

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma Loader"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start"

"item"="Logitech Desktop Messenger"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe "

"item"="Logitech SetPoint"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk"

"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"

"item"="Microsoft Office"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk"

"backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE "

"item"="MagicDisc"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk"

"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"

"location"="Startup"

"command"="C:\\Programfiler\\Xfire\\xfire.exe "

"item"="Xfire"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="avgas"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ashDisp"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="bittorrent"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="daemon"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="InCD"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iTunesHelper"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="dumprep 0 -k"

"hkey"="HKLM"

"command"="%systemroot%\\system32\\dumprep 0 -k"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LogitechDesktopMessenger"

"hkey"="HKCU"

"command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="lxczbmgr"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NCLAUNCH"

"hkey"="HKCU"

"command"="C:\\WINDOWS\\NCLAUNCH.EXe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NeroCheck"

"hkey"="HKLM"

"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LAUNCH~1"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="PCTAV"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="pvmodule"

"hkey"="HKLM"

"command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="qttask"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Skype"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Application Launcher"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SOUNDMAN"

"hkey"="HKLM"

"command"="SOUNDMAN.EXE"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="jusched"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SUPERAntiSpyware"

"hkey"="HKCU"

"command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="VCDDaemon"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="CAMTHINS"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="winampa"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Winamp\\winampa.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="xfiremusic"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="MultiIM"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"PCTAVSvc"=dword:00000002

"usnjsvc"=dword:00000003

"UserAccess7"=dword:00000002

"rpcapd"=dword:00000003

"LexBceS"=dword:00000002

"iPod Service"=dword:00000003

"InCDsrv"=dword:00000002

"IDriverT"=dword:00000003

"Adobe LM Service"=dword:00000003

"NVCScheduler"=dword:00000003

"Norman ZANDA"=dword:00000002

"Norman NJeeves"=dword:00000003

"NipSvc"=dword:00000003

"nvcoas"=dword:00000003

"Bonjour Service"=dword:00000002

"avast! Web Scanner"=dword:00000003

"avast! Mail Scanner"=dword:00000003

"avast! Antivirus"=dword:00000002

"aswUpdSv"=dword:00000002

"FLEXnet Licensing Service"=dword:00000003

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter REG_MULTI_SZ HTTPFilter\0\0

LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService REG_MULTI_SZ DnsCache\0\0

DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

rpcss REG_MULTI_SZ RpcSs\0\0

imgsvc REG_MULTI_SZ StiSvc\0\0

termsvcs REG_MULTI_SZ TermService\0\0

WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

 

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-04-30 18:11:54

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 07-04-30 18:12:41

C:\ComboFix-quarantined-files.txt ... 07-04-30 18:12

C:\ComboFix2.txt ... 07-04-30 13:09

C:\ComboFix3.txt ... 07-04-30 13:01

 

Takk For all hjelp :thumbup:

 

Datan går raskere, den bootere hvertfall raskere.. Det er vel det eneste jeg har lagt merke til - Hvertfall til nå : )

 

EDIT: SAS fant ingenting :w00t:

 

EDIT2: Spilte noen spill nå, ikke en eneste lagg :w00t: !

Endret av trysilgutt
Lenke til kommentar

ComboFix Logg

 

Klikk for å se/fjerne innholdet nedenfor
"- Nils" - 07-05-01 11:47:17 Service Pack 2

ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\"

 

 

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\qoobox\purity\C\Programfiler\MCROSO~1.NET

C:\qoobox\purity\C\WINDOWS\PPATCH~1

C:\qoobox\purity\C\WINDOWS\system32\FNTS~1

 

 

((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\nm

-------\LEGACY_NM

-------\LEGACY_NPF

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-04-01 to 2007-05-01 ))))))))))))))))))))))))))))))))))

 

 

2007-05-01 11:42 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste

2007-05-01 00:05 <DIR> d-------- C:\Programfiler\LEGO Island

2007-05-01 00:03 <DIR> d-------- C:\Programfiler\DaemonTools_WhenUSave_Installer

2007-05-01 00:01 <DIR> d-------- C:\Programfiler\DAEMON Tools

2007-04-30 19:05 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\uTorrent

2007-04-30 17:11 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\AdobeUM

2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com

2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner

2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca

2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp

2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts

2007-04-29 23:23 1,310,720 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste

2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter

2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger

2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask

2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord

2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT

2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata

2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger

2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter

2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter

2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp

2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts

2007-04-29 15:16 1,572,864 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT

2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter

2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger

2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask

2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord

2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr

2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir

2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft

2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet

2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared

2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour

2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software

2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes

2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain

2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes

2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no

2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

2007-05-01 11:40 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\utorrent

2007-05-01 01:05 -------- d--h----- C:\Programfiler\installshield installation information

2007-04-30 23:57 682232 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2007-04-30 12:47 -------- d-------- C:\Programfiler\logitech

2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson

2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared

2007-04-30 00:22 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\teleca

2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp

2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7

2007-04-23 19:06 -------- d-------- C:\Programfiler\opera

2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod

2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime

2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2

2007-03-31 17:39 -------- d-------- C:\Programfiler\duplicate file finder

2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire

2007-03-28 21:19 -------- d-------- C:\Programfiler\windows media connect 2

2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat

2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat

2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll

2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp

2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture

2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger

2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys

2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll

2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll

2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll

2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys

2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus

2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent

2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe

2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat

2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini

2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll

{784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]

"VTTimer"="VTTimer.exe"

"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"

"!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]

"msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background"

"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

"DAEMON Tools"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

 

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa

Authentication Packages REG_MULTI_SZ msv1_0\0\0

Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0

Notification Packages REG_MULTI_SZ scecli\0\0

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma Loader"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start"

"item"="Logitech Desktop Messenger"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk"

"backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe "

"item"="Logitech SetPoint"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk]

"path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk"

"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"

"location"="Common Startup"

"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"

"item"="Microsoft Office"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk"

"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "

"item"="Adobe Gamma"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk"

"backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup"

"location"="Startup"

"command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE "

"item"="MagicDisc"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk]

"path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk"

"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"

"location"="Startup"

"command"="C:\\Programfiler\\Xfire\\xfire.exe "

"item"="Xfire"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="avgas"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ashDisp"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="bittorrent"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="daemon"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="InCD"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iTunesHelper"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="dumprep 0 -k"

"hkey"="HKLM"

"command"="%systemroot%\\system32\\dumprep 0 -k"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LogitechDesktopMessenger"

"hkey"="HKCU"

"command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="lxczbmgr"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NCLAUNCH"

"hkey"="HKCU"

"command"="C:\\WINDOWS\\NCLAUNCH.EXe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NeroCheck"

"hkey"="HKLM"

"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="LAUNCH~1"

"hkey"="HKLM"

"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="PCTAV"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="pvmodule"

"hkey"="HKLM"

"command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="qttask"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Skype"

"hkey"="HKCU"

"command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Application Launcher"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SOUNDMAN"

"hkey"="HKLM"

"command"="SOUNDMAN.EXE"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"=""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="jusched"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SUPERAntiSpyware"

"hkey"="HKCU"

"command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="VCDDaemon"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="CAMTHINS"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="winampa"

"hkey"="HKLM"

"command"="C:\\Programfiler\\Winamp\\winampa.exe"

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="xfiremusic"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="MultiIM"

"hkey"="HKLM"

"command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\""

"inimapping"="0"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"PCTAVSvc"=dword:00000002

"usnjsvc"=dword:00000003

"UserAccess7"=dword:00000002

"rpcapd"=dword:00000003

"LexBceS"=dword:00000002

"iPod Service"=dword:00000003

"InCDsrv"=dword:00000002

"IDriverT"=dword:00000003

"Adobe LM Service"=dword:00000003

"NVCScheduler"=dword:00000003

"Norman ZANDA"=dword:00000002

"Norman NJeeves"=dword:00000003

"NipSvc"=dword:00000003

"nvcoas"=dword:00000003

"Bonjour Service"=dword:00000002

"avast! Web Scanner"=dword:00000003

"avast! Mail Scanner"=dword:00000003

"avast! Antivirus"=dword:00000002

"aswUpdSv"=dword:00000002

"FLEXnet Licensing Service"=dword:00000003

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]

HTTPFilter REG_MULTI_SZ HTTPFilter\0\0

LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0

NetworkService REG_MULTI_SZ DnsCache\0\0

DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

rpcss REG_MULTI_SZ RpcSs\0\0

imgsvc REG_MULTI_SZ StiSvc\0\0

termsvcs REG_MULTI_SZ TermService\0\0

WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

 

 

 

Contents of the 'Scheduled Tasks' folder

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

 

********************************************************************

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-01 11:52:20

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

********************************************************************

 

Completion time: 07-05-01 11:52:59

C:\ComboFix-quarantined-files.txt ... 07-05-01 11:52

C:\ComboFix2.txt ... 07-04-30 18:12

C:\ComboFix3.txt ... 07-04-30 13:09

 

Er det noe galt? :dontgetit:

 

 

Åpne Notisblokk og kopier og lim inn det som står under (i fet):

 

REGEDIT4

 

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]

 

(PS. sørg for at det ikke er noe luft over REGEDIT4 - altså den skal stå aller øverst i notisblokkvinduet)

 

Klikk 'Lagre som', velg 'Alle filer' som filtype. Lagre file med filnavn: fix.reg på skrivebordet.

 

Dobbeltklikk på fila (fix.reg), og si ja til å legge inn/flette inn i registeret.

 

Kan jeg slette den fra skriverbordet mitt nå? :)

Endret av trysilgutt
Lenke til kommentar

Haha, sorry.

 

Rootchk logg

 

Klikk for å se/fjerne innholdet nedenfor
********************************* ROOTCHK-(30-04-07)-LOG, by ejvindh

01.05.07 22:29:44,64

 

The rootkits that are detected by this tool were not found.

 

********************************* ROOTCHK-LOG-end

 

 

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-01 22:29:45

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db

C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 102

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...