Etnies Skrevet 29. april 2007 Del Skrevet 29. april 2007 (endret) SAS-LOGG Klikk for å se/fjerne innholdet nedenfor SUPERAntiSpyware Scan Loghttp://www.superantispyware.com Generated 04/30/2007 at 01:36 AM Application Version : 3.7.1018 Core Rules Database Version : 3227Trace Rules Database Version: 1238 Scan type : Complete Scan Total Scan Time : 00:33:33 Memory items scanned : 197 Memory threats detected : 0 Registry items scanned : 5474 Registry threats detected : 230 File items scanned : 30714 File threats detected : 14 Trojan.Smitfraud Variant HKLM\Software\Classes\CLSID\{b23dc537-3e13-44c7-bf67-d8405eb377f7} HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7} HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32 HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32#ThreadingModel C:\WINDOWS\SYSTEM32\RCOHTY.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{b23dc537-3e13-44c7-bf67-d8405eb377f7} Adware.ToolBar888 HKLM\Software\Classes\CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A} HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A} HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A} HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32 HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32#ThreadingModel HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\ProgID HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\Programmable HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\TypeLib HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\VersionIndependentProgID C:\PROGRAMFILER\TOOLBAR888\MYTOOLBAR.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A} HKLM\Software\Microsoft\Internet Explorer\Toolbar#{CBCC61FA-0221-4ccc-B409-CEE865CACA3A} HKCR\MyToolBar.MyToolBarObj.1 HKCR\MyToolBar.MyToolBarObj.1\CLSID HKCR\MyToolBar.MyToolBarObj HKCR\MyToolBar.MyToolBarObj\CLSID HKCR\MyToolBar.MyToolBarObj\CurVer HKCR\TypeLib\{CD2A09D7-EE7E-4c25-993C-C2678ECFAD01} HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208} HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0 HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0 HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32 HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B} HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32 HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version HKLM\Software\Classes\MyToolBar.MyToolBarObj HKLM\Software\Classes\MyToolBar.MyToolBarObj\CLSID HKLM\Software\Classes\MyToolBar.MyToolBarObj\CurVer HKLM\Software\Classes\MyToolBar.MyToolBarObj.1 HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID HKU\S-1-5-21-1645522239-484061587-839522115-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A} Trojan.Media-Codec/V2 HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32 HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel C:\PROGRAMFILER\VIDEO AX OBJECT\BPVOL.DLL HKLM\Software\Classes\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories\{00021493-0000-0000-C000-000000000046} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32 HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32#ThreadingModel C:\PROGRAMFILER\VIDEO AX OBJECT\SPLUG.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString Trojan.WinAntiSpyware/WinAntiVirus 2006/2007 HKCR\WAP6.PCheck HKCR\WAP6.PCheck\CLSID HKCR\WAP6.PCheck\CurVer HKCR\WAP6.PCheck.1 HKCR\WAP6.PCheck.1\CLSID HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F} HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32 HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235} HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0 HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0 HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32 HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123} HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32 HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version Trojan.Unknown Origin HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658} HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#SystemComponent HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#Installer HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation#CODEBASE HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion#LastModified Trojan.ZQuest C:\WINDOWS\dh.ini Trojan.DollarRevenue C:\WINDOWS\newname.dat C:\WINDOWS\keyboard1.dat Trojan.ErrorSafe HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d} HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32 HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32#ThreadingModel HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\ProgID HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Programmable HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\TypeLib HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\VersionIndependentProgID Browser Hijacker.Deskbar HKCR\DBTB00001.DBTB00001 HKCR\DBTB00001.DBTB00001\CLSID HKCR\DBTB00001.DBTB00001\CurVer HKCR\DBTB00001.DBTB00001.1 HKCR\DBTB00001.DBTB00001.1\CLSID HKCR\DBTB00001.DeskBar HKCR\DBTB00001.DeskBar\CLSID HKCR\DBTB00001.DeskBar\CurVer HKCR\DBTB00001.DeskBar.1 HKCR\DBTB00001.DeskBar.1\CLSID HKCR\DBTB00001.deskbarBHO HKCR\DBTB00001.deskbarBHO\CLSID HKCR\DBTB00001.deskbarBHO\CurVer HKCR\DBTB00001.deskbarBHO.1 HKCR\DBTB00001.deskbarBHO.1\CLSID HKCR\DBTB00001.DeskbarEnabler HKCR\DBTB00001.DeskbarEnabler\CLSID HKCR\DBTB00001.DeskbarEnabler.1 HKCR\DBTB00001.DeskbarEnabler.1\CLSID HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D} HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid32 HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib#Version HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C} HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid32 HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib#Version HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108} HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid32 HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib#Version Trojan.Media-Codec HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#user32.dll [ C:\Programfiler\Video AX Object\bpmon.exe ] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#rare [ C:\Programfiler\Video AX Object\smmain.exe ] Malware.SpyLocked HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657} HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32 HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32#ThreadingModel HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\OtiLglrhUikvj HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\podtlbEyd HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\pysFxsmg HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\rxirdocusi HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\TypeLib HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\uCniqDrba HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\wnFySqsxcxws HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2} HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0 HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0 HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0\win32 HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\FLAGS HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\HELPDIR HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF} HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid32 HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib#Version HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51} HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid32 HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib#Version HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D} HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid32 HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib#Version HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B} HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid32 HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib#Version HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF} HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid32 HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib#Version HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8} HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid32 HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib#Version HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F} HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid32 HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib#Version HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248} HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid32 HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib#Version HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35} HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid32 HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib#Version HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617} HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid32 HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib#Version HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92} HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid32 HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib#Version HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E} HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid32 HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib#Version HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E} HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid32 HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib#Version HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38} HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid32 HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib#Version HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8} HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid32 HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib#Version HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73} HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid32 HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib#Version Worm.Alcra Variant C:\WINDOWS\SYSTEM32\CMD.COM C:\WINDOWS\SYSTEM32\NETSTAT.COM C:\WINDOWS\SYSTEM32\PING.COM C:\WINDOWS\SYSTEM32\REGEDIT.COM C:\WINDOWS\SYSTEM32\TASKKILL.COM C:\WINDOWS\SYSTEM32\TASKLIST.COM C:\WINDOWS\SYSTEM32\TRACERT.COM HJT-Logg Klikk for å se/fjerne innholdet nedenfor Logfile of HijackThis v1.99.1Scan saved at 01:48:14, on 30.04.07 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\msnlogm.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\msnlogs.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Documents and Settings\- Nils\Skrivebord\rootchk.exe C:\WINDOWS\system32\cmd.exe C:\DOCUME~1\-NILS~1\LOKALE~1\Temp\Rootchk\catchme.exe C:\Programfiler\HijackThis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Programfiler\Start.no Turbo\components\NOWImaging.dll (file missing) O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing) O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing) O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing) O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe O4 - HKLM\..\Run: [defender] C:\\dfndrff_e37.exe O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [newname] C:\\nwnmff_e37.exe O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e37.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International* O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077 O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: bw+0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: offline-8876480 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll Rootchk Logg Klikk for å se/fjerne innholdet nedenfor ******************************** ROOTCHK-(25-04-07)-LOG, by ejvindh30.04.07 1:46:49,21 Driver nm (visible) is present. Run COMBOFIX by sUBs. ********************************* ROOTCHK-LOG-end catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-04-30 01:46:50 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run msnsyslog = C:\WINDOWS\msnlogm.exe??X?2??|d?2??|p?2??|??8[??H??|8??|??2??|?|?|??%?@?R?B~??%?@?\?B~??@?@? scanning hidden files ... C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3 C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 102 Har jeg noe ufine ting? Og hvordan fjerner jeg hvis jeg har? Endret 2. mai 2007 av trysilgutt Lenke til kommentar
Znoken Skrevet 29. april 2007 Del Skrevet 29. april 2007 WOW.... Der var det endel og ta tak i ser jeg...Midt beste forslag akkurat er og gå på denne siden og følge guiden som er satt opp der....Når det er gjort så legger du ut en ny logg.... Lenke til kommentar
Etnies Skrevet 29. april 2007 Forfatter Del Skrevet 29. april 2007 (endret) WOW.... Der var det endel og ta tak i ser jeg...Midt beste forslag akkurat er og gå på denne siden og følge guiden som er satt opp der....Når det er gjort så legger du ut en ny logg.... 8499132[/snapback] Legge til en SAS-Logg? Edit: Nå skjønte jeg Endret 29. april 2007 av trysilgutt Lenke til kommentar
Etnies Skrevet 29. april 2007 Forfatter Del Skrevet 29. april 2007 (endret) SAS-LOGG Klikk for å se/fjerne innholdet nedenfor SUPERAntiSpyware Scan Loghttp://www.superantispyware.com Generated 04/30/2007 at 01:36 AM Application Version : 3.7.1018 Core Rules Database Version : 3227Trace Rules Database Version: 1238 Scan type : Complete Scan Total Scan Time : 00:33:33 Memory items scanned : 197 Memory threats detected : 0 Registry items scanned : 5474 Registry threats detected : 230 File items scanned : 30714 File threats detected : 14 Trojan.Smitfraud Variant HKLM\Software\Classes\CLSID\{b23dc537-3e13-44c7-bf67-d8405eb377f7} HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7} HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32 HKCR\CLSID\{B23DC537-3E13-44C7-BF67-D8405EB377F7}\InProcServer32#ThreadingModel C:\WINDOWS\SYSTEM32\RCOHTY.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{b23dc537-3e13-44c7-bf67-d8405eb377f7} Adware.ToolBar888 HKLM\Software\Classes\CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A} HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A} HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A} HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32 HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\InprocServer32#ThreadingModel HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\ProgID HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\Programmable HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\TypeLib HKCR\CLSID\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}\VersionIndependentProgID C:\PROGRAMFILER\TOOLBAR888\MYTOOLBAR.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A} HKLM\Software\Microsoft\Internet Explorer\Toolbar#{CBCC61FA-0221-4ccc-B409-CEE865CACA3A} HKCR\MyToolBar.MyToolBarObj.1 HKCR\MyToolBar.MyToolBarObj.1\CLSID HKCR\MyToolBar.MyToolBarObj HKCR\MyToolBar.MyToolBarObj\CLSID HKCR\MyToolBar.MyToolBarObj\CurVer HKCR\TypeLib\{CD2A09D7-EE7E-4c25-993C-C2678ECFAD01} HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208} HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0 HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0 HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32 HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B} HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32 HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version HKLM\Software\Classes\MyToolBar.MyToolBarObj HKLM\Software\Classes\MyToolBar.MyToolBarObj\CLSID HKLM\Software\Classes\MyToolBar.MyToolBarObj\CurVer HKLM\Software\Classes\MyToolBar.MyToolBarObj.1 HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID HKU\S-1-5-21-1645522239-484061587-839522115-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A} Trojan.Media-Codec/V2 HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32 HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel C:\PROGRAMFILER\VIDEO AX OBJECT\BPVOL.DLL HKLM\Software\Classes\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\Implemented Categories\{00021493-0000-0000-C000-000000000046} HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32 HKCR\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}\InprocServer32#ThreadingModel C:\PROGRAMFILER\VIDEO AX OBJECT\SPLUG.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString Trojan.WinAntiSpyware/WinAntiVirus 2006/2007 HKCR\WAP6.PCheck HKCR\WAP6.PCheck\CLSID HKCR\WAP6.PCheck\CurVer HKCR\WAP6.PCheck.1 HKCR\WAP6.PCheck.1\CLSID HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F} HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32 HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235} HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0 HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0 HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32 HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123} HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32 HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version Trojan.Unknown Origin HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658} HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#SystemComponent HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#Installer HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation#CODEBASE HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion#LastModified Trojan.ZQuest C:\WINDOWS\dh.ini Trojan.DollarRevenue C:\WINDOWS\newname.dat C:\WINDOWS\keyboard1.dat Trojan.ErrorSafe HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d} HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32 HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32#ThreadingModel HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\ProgID HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Programmable HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\TypeLib HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\VersionIndependentProgID Browser Hijacker.Deskbar HKCR\DBTB00001.DBTB00001 HKCR\DBTB00001.DBTB00001\CLSID HKCR\DBTB00001.DBTB00001\CurVer HKCR\DBTB00001.DBTB00001.1 HKCR\DBTB00001.DBTB00001.1\CLSID HKCR\DBTB00001.DeskBar HKCR\DBTB00001.DeskBar\CLSID HKCR\DBTB00001.DeskBar\CurVer HKCR\DBTB00001.DeskBar.1 HKCR\DBTB00001.DeskBar.1\CLSID HKCR\DBTB00001.deskbarBHO HKCR\DBTB00001.deskbarBHO\CLSID HKCR\DBTB00001.deskbarBHO\CurVer HKCR\DBTB00001.deskbarBHO.1 HKCR\DBTB00001.deskbarBHO.1\CLSID HKCR\DBTB00001.DeskbarEnabler HKCR\DBTB00001.DeskbarEnabler\CLSID HKCR\DBTB00001.DeskbarEnabler.1 HKCR\DBTB00001.DeskbarEnabler.1\CLSID HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D} HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid32 HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib#Version HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C} HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid32 HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib#Version HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108} HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid32 HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib#Version Trojan.Media-Codec HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#user32.dll [ C:\Programfiler\Video AX Object\bpmon.exe ] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#rare [ C:\Programfiler\Video AX Object\smmain.exe ] Malware.SpyLocked HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657} HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32 HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\InprocServer32#ThreadingModel HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\OtiLglrhUikvj HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\podtlbEyd HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\pysFxsmg HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\rxirdocusi HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\TypeLib HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\uCniqDrba HKCR\CLSID\{0B847A1A-A872-95FC-8E22-F8B4AE044657}\wnFySqsxcxws HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2} HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0 HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0 HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\0\win32 HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\FLAGS HKCR\TypeLib\{DB926F0D-182A-4088-9B2A-1DB210619AC2}\1.0\HELPDIR HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF} HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\ProxyStubClsid32 HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib HKCR\Interface\{28C185E0-2782-4C11-B414-C749654CEBEF}\TypeLib#Version HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51} HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\ProxyStubClsid32 HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib HKCR\Interface\{2D9C224E-1640-400D-83D0-3DE904F3CD51}\TypeLib#Version HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D} HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\ProxyStubClsid32 HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib HKCR\Interface\{3BD36779-FABD-4974-B681-95B79900603D}\TypeLib#Version HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B} HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\ProxyStubClsid32 HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib HKCR\Interface\{3FBD43FB-45D9-4AD6-97C5-DB2A208DBE1B}\TypeLib#Version HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF} HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\ProxyStubClsid32 HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib HKCR\Interface\{458338B4-8CF4-4F76-B05A-391EFCB91DAF}\TypeLib#Version HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8} HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\ProxyStubClsid32 HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib HKCR\Interface\{49792BDF-272E-485A-8EDC-0F26F3B499A8}\TypeLib#Version HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F} HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\ProxyStubClsid32 HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib HKCR\Interface\{4D3DD52E-F48A-46F2-BE86-7F9B4BA7BB2F}\TypeLib#Version HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248} HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\ProxyStubClsid32 HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib HKCR\Interface\{6DAEFDEA-1466-4A40-A530-E390FF58D248}\TypeLib#Version HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35} HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\ProxyStubClsid32 HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib HKCR\Interface\{725BAD2A-8A0E-42D5-A028-B51794238C35}\TypeLib#Version HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617} HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\ProxyStubClsid32 HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib HKCR\Interface\{9692D0FB-693D-4B8C-8D61-040DBBE5D617}\TypeLib#Version HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92} HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\ProxyStubClsid32 HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib HKCR\Interface\{C099E01B-9751-46F7-AAC8-386F3B4EEC92}\TypeLib#Version HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E} HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\ProxyStubClsid32 HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib HKCR\Interface\{CAB9D558-0A83-4528-988A-CB1D7A69022E}\TypeLib#Version HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E} HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\ProxyStubClsid32 HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib HKCR\Interface\{CC17B63E-CB49-4D83-A33E-91ED305AB85E}\TypeLib#Version HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38} HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\ProxyStubClsid32 HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib HKCR\Interface\{D5531EF6-EFDA-4894-9A24-8DA190940C38}\TypeLib#Version HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8} HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\ProxyStubClsid32 HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib HKCR\Interface\{E916C096-5854-432E-8624-AFCF464D57F8}\TypeLib#Version HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73} HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\ProxyStubClsid32 HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib HKCR\Interface\{FC55856C-204B-45B0-9467-4FBAE8D8FE73}\TypeLib#Version Worm.Alcra Variant C:\WINDOWS\SYSTEM32\CMD.COM C:\WINDOWS\SYSTEM32\NETSTAT.COM C:\WINDOWS\SYSTEM32\PING.COM C:\WINDOWS\SYSTEM32\REGEDIT.COM C:\WINDOWS\SYSTEM32\TASKKILL.COM C:\WINDOWS\SYSTEM32\TASKLIST.COM C:\WINDOWS\SYSTEM32\TRACERT.COM HJT-Logg Klikk for å se/fjerne innholdet nedenfor Logfile of HijackThis v1.99.1Scan saved at 01:48:14, on 30.04.07 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\msnlogm.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\msnlogs.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Documents and Settings\- Nils\Skrivebord\rootchk.exe C:\WINDOWS\system32\cmd.exe C:\DOCUME~1\-NILS~1\LOKALE~1\Temp\Rootchk\catchme.exe C:\Programfiler\HijackThis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Programfiler\Start.no Turbo\components\NOWImaging.dll (file missing) O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing) O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing) O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing) O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe O4 - HKLM\..\Run: [defender] C:\\dfndrff_e37.exe O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [newname] C:\\nwnmff_e37.exe O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e37.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International* O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077 O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: bw+0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: offline-8876480 - {17440C8A-E758-431C-93AC-CDFF676E2C79} - C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll Rootchk Logg Klikk for å se/fjerne innholdet nedenfor ******************************** ROOTCHK-(25-04-07)-LOG, by ejvindh30.04.07 1:46:49,21 Driver nm (visible) is present. Run COMBOFIX by sUBs. ********************************* ROOTCHK-LOG-end catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-04-30 01:46:50 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run msnsyslog = C:\WINDOWS\msnlogm.exe??X?2??|d?2??|p?2??|??8[??H??|8??|??2??|?|?|????%?@???R?B~??%?@?\?B~??????@?@? scanning hidden files ... C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3 C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 102 Endret 29. april 2007 av trysilgutt Lenke til kommentar
norbat Skrevet 30. april 2007 Del Skrevet 30. april 2007 (endret) Avinstaller om mulig, fra legg til/fjern programmer: Logitech desktop messenger MSN Content Plus Kjør HJT, sett merke framfor følgende linjer og klikk 'Fix checked': O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {CA48BC8F-2338-74B6-10FC-01E2E9737694} - C:\WINDOWS\system32\xjaww.dll (file missing) O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~2\PRINTV~1\PRINTH~1.DLL (file missing) O2 - BHO: (no name) - {F789DB71-1D9F-4E1C-E180-6664718B4E90} - C:\WINDOWS\system32\ilkau.dll (file missing) O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe O4 - HKLM..Run: [defender] C:\dfndrff_e37.exe O4 - HKLM..Run: [newname] C:\nwnmff_e37.exe O4 - HKLM..Run: [keyboard] C:\kybrdff_e37.exe O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab Hent Combofix og legg det på skrivebordet. Lukk alle andre programmer. Kjør programmet. Ikke klikk på noe annet. Når programmet er ferdig åpnes en loggfil: combofix.txt Den loggfilen poster du senere. Sørg for at du kan se skjulte filer og mapper: Kontrollpanel->mappealt.->vis->"vis skjulte filer og mapper" Restart i sikker modus (tapp F8 under oppstart) Bruk utforsker til å finne og slette (i fet): C:\WINDOWS\msnlogm.exe C:\WINDOWS\msnlogs.exe Restart i normal tilstand Post en ny HJT-logg + loggen fra combofix. Endret 30. april 2007 av norbat Lenke til kommentar
Etnies Skrevet 30. april 2007 Forfatter Del Skrevet 30. april 2007 HJT LOGG Klikk for å se/fjerne innholdet nedenfor Logfile of HijackThis v1.99.1Scan saved at 13:50:46, on 30.04.07 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\VTTimer.exe C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\HijackThis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International* O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077 O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe COMBO-FIX LOG Klikk for å se/fjerne innholdet nedenfor "- Nils" - 07-04-30 13:04:28 Service Pack 2 ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\qoobox\purity\C\Programfiler\MCROSO~1.NET C:\qoobox\purity\C\WINDOWS\PPATCH~1 C:\qoobox\purity\C\WINDOWS\system32\FNTS~1 ((((((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\nm -------\LEGACY_NM -------\LEGACY_NPF ((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 )))))))))))))))))))))))))))))))))) 2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-04-30 03:17 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste 2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com 2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com 2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner 2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca 2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp 2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts 2007-04-29 23:23 1,048,576 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT 2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste 2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask 2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord 2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata 2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter 2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp 2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts 2007-04-29 15:16 1,310,720 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT 2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask 2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord 2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr 2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir 2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft 2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet 2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared 2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour 2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software 2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes 2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain 2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes 2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no 2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic 2007-03-31 17:32 <DIR> d-------- C:\Programfiler\Duplicate File Finder 2007-03-30 15:38 118,784 --------- C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe 2007-03-30 15:37 13,440 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS 2007-03-30 15:36 68,864 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys 2007-03-30 15:36 55,040 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys 2007-03-30 15:36 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe 2007-03-30 15:36 26,112 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys 2007-03-30 15:36 258,352 --a------ C:\WINDOWS\system32\unicows.dll 2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Logitech 2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech 2007-03-28 21:19 <DIR> d-------- C:\Programfiler\Windows Media Connect 2 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson 2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared 2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp 2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7 2007-04-23 19:06 -------- d-------- C:\Programfiler\opera 2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod 2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime 2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2 2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire 2007-03-30 15:38 -------- d--h----- C:\Programfiler\installshield installation information 2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat 2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat 2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll 2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp 2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture 2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger 2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll 2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll 2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll 2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys 2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus 2007-03-06 18:36 -------- d-------- C:\Programfiler\utorrent 2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent 2007-02-28 21:25 -------- d-------- C:\Programfiler\msn messenger 2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe 2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini 2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll {784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "VTTimer"="VTTimer.exe" "MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto" "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" "!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages REG_MULTI_SZ scecli\0\0 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE " "item"="Adobe Gamma Loader" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk" "backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start" "item"="Logitech Desktop Messenger" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk" "backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe " "item"="Logitech SetPoint" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE " "item"="Adobe Gamma" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk" "backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE " "item"="MagicDisc" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk" "backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup" "location"="Startup" "command"="C:\\Programfiler\\Xfire\\xfire.exe " "item"="Xfire" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="avgas" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ashDisp" "hkey"="HKLM" "command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="bittorrent" "hkey"="HKCU" "command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKCU" "command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="UDC2006" "hkey"="HKLM" "command"="\"C:\\Programfiler\\DriveCleaner 2006 Free\\UDC2006.exe\" /min" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="InCD" "hkey"="HKLM" "command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -k" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -k" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LogitechDesktopMessenger" "hkey"="HKCU" "command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="lxczbmgr" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NCLAUNCH" "hkey"="HKCU" "command"="C:\\WINDOWS\\NCLAUNCH.EXe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LAUNCH~1" "hkey"="HKLM" "command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PCTAV" "hkey"="HKLM" "command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="pvmodule" "hkey"="HKLM" "command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Application Launcher" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SOUNDMAN" "hkey"="HKLM" "command"="SOUNDMAN.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SUPERAntiSpyware" "hkey"="HKCU" "command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCDDaemon" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CAMTHINS" "hkey"="HKLM" "command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winampa" "hkey"="HKLM" "command"="C:\\Programfiler\\Winamp\\winampa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="xfiremusic" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MultiIM" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "PCTAVSvc"=dword:00000002 "usnjsvc"=dword:00000003 "UserAccess7"=dword:00000002 "rpcapd"=dword:00000003 "LexBceS"=dword:00000002 "iPod Service"=dword:00000003 "InCDsrv"=dword:00000002 "IDriverT"=dword:00000003 "Adobe LM Service"=dword:00000003 "NVCScheduler"=dword:00000003 "Norman ZANDA"=dword:00000002 "Norman NJeeves"=dword:00000003 "NipSvc"=dword:00000003 "nvcoas"=dword:00000003 "Bonjour Service"=dword:00000002 "avast! Web Scanner"=dword:00000003 "avast! Mail Scanner"=dword:00000003 "avast! Antivirus"=dword:00000002 "aswUpdSv"=dword:00000002 "FLEXnet Licensing Service"=dword:00000003 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-04-30 13:08:51 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-04-30 13:09:21 C:\ComboFix-quarantined-files.txt ... 07-04-30 13:09 C:\ComboFix2.txt ... 07-04-30 13:01 Lenke til kommentar
Gjest medlem-105082 Skrevet 30. april 2007 Del Skrevet 30. april 2007 Var litt av en liste fra SAS det der Lenke til kommentar
Etnies Skrevet 30. april 2007 Forfatter Del Skrevet 30. april 2007 Var litt av en liste fra SAS det der 8504279[/snapback] Shit happen when you download porn! Men forresten, takk for all hjelp =) Lenke til kommentar
Gjest medlem-105082 Skrevet 30. april 2007 Del Skrevet 30. april 2007 Haha, ja sånn går det Men norbat fikser og ser gjennom de loggene, så skal du se at alt blir fjernet. Lenke til kommentar
norbat Skrevet 30. april 2007 Del Skrevet 30. april 2007 (endret) Åpne Notisblokk og kopier og lim inn det som står under (i fet): REGEDIT4 [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free] (PS. sørg for at det ikke er noe luft over REGEDIT4 - altså den skal stå aller øverst i notisblokkvinduet) Klikk 'Lagre som', velg 'Alle filer' som filtype. Lagre file med filnavn: fix.reg på skrivebordet. Dobbeltklikk på fila (fix.reg), og si ja til å legge inn/flette inn i registeret. Kjør HJT, sett merke framfor følgende linjer og klikk 'Fix checked': O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://domecam.uridium.ch/kxhcm10.ocx O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://aucam.dyndns.biz/activex/AMC.ca O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab Hvis du ikke allerede har programmet: Hent CCleaner. Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......." Klikk på 'Renser' og deretter 'Kjør CCleaner'. Kjør også noen runder med 'Saker' til det ikke finner flere feil. Nullstille gjenopprettingsmappa Kontrollpanel->system->systemgjenoppretting . Sett merke framfor "Slå av .....", restart pc, fjern merket igjen for å aktivere funksjonen. Kjør på ny en scan med Combofix Post deretter combofix-loggen samt en ny HJT-logg (Før du kjører HJT, forandrer du programnavnet, hijackthis, til noe annet, feks. test ) Fortell også hvordan pc'n kjører. I mens noen sjekker de siste loggene, kjører du på ny en complete scan med SAS. Fortell gjerne om den finner noe Endret 30. april 2007 av norbat Lenke til kommentar
Etnies Skrevet 30. april 2007 Forfatter Del Skrevet 30. april 2007 (endret) HJT-LOGG Klikk for å se/fjerne innholdet nedenfor Logfile of HijackThis v1.99.1Scan saved at 18:17:15, on 30.04.07 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\VTTimer.exe C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Programfiler\HijackThis\Test.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: FoxyTunes Toolbar Helper - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O3 - Toolbar: FoxyTunes Toolbar - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International* O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.mpw.no/TvNorge/KooPlayer.ocx O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125581468077 O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam.datainstituttet.no/activex/AMC.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe COMBOFIX Logg Klikk for å se/fjerne innholdet nedenfor - Nils" - 07-04-30 18:06:14 Service Pack 2 ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\qoobox\purity\C\Programfiler\MCROSO~1.NET C:\qoobox\purity\C\WINDOWS\PPATCH~1 C:\qoobox\purity\C\WINDOWS\system32\FNTS~1 ((((((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\nm -------\LEGACY_NM -------\LEGACY_NPF ((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 )))))))))))))))))))))))))))))))))) 2007-04-30 17:53 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste 2007-04-30 17:11 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\AdobeUM 2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com 2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com 2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner 2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca 2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp 2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts 2007-04-29 23:23 1,048,576 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT 2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste 2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask 2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord 2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata 2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter 2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp 2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts 2007-04-29 15:16 1,310,720 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT 2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask 2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord 2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr 2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir 2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft 2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet 2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared 2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour 2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software 2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes 2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain 2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes 2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no 2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic 2007-03-31 17:32 <DIR> d-------- C:\Programfiler\Duplicate File Finder 2007-03-30 15:37 13,440 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS 2007-03-30 15:36 68,864 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys 2007-03-30 15:36 55,040 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys 2007-03-30 15:36 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe 2007-03-30 15:36 26,112 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys 2007-03-30 15:36 258,352 --a------ C:\WINDOWS\system32\unicows.dll 2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Logitech 2007-03-30 15:36 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech 2007-03-28 21:19 <DIR> d-------- C:\Programfiler\Windows Media Connect 2 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson 2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared 2007-04-30 00:22 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\teleca 2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp 2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7 2007-04-23 19:06 -------- d-------- C:\Programfiler\opera 2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod 2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime 2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2 2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire 2007-03-30 15:38 -------- d--h----- C:\Programfiler\installshield installation information 2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat 2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat 2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll 2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp 2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture 2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger 2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll 2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll 2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll 2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys 2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus 2007-03-06 18:36 -------- d-------- C:\Programfiler\utorrent 2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent 2007-02-28 21:25 -------- d-------- C:\Programfiler\msn messenger 2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe 2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini 2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll {784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "VTTimer"="VTTimer.exe" "MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto" "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" "!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages REG_MULTI_SZ scecli\0\0 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE " "item"="Adobe Gamma Loader" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk" "backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start" "item"="Logitech Desktop Messenger" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk" "backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe " "item"="Logitech SetPoint" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE " "item"="Adobe Gamma" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk" "backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE " "item"="MagicDisc" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk" "backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup" "location"="Startup" "command"="C:\\Programfiler\\Xfire\\xfire.exe " "item"="Xfire" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="avgas" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ashDisp" "hkey"="HKLM" "command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="bittorrent" "hkey"="HKCU" "command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKCU" "command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="InCD" "hkey"="HKLM" "command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -k" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -k" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LogitechDesktopMessenger" "hkey"="HKCU" "command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="lxczbmgr" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NCLAUNCH" "hkey"="HKCU" "command"="C:\\WINDOWS\\NCLAUNCH.EXe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LAUNCH~1" "hkey"="HKLM" "command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PCTAV" "hkey"="HKLM" "command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="pvmodule" "hkey"="HKLM" "command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Application Launcher" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SOUNDMAN" "hkey"="HKLM" "command"="SOUNDMAN.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SUPERAntiSpyware" "hkey"="HKCU" "command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCDDaemon" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CAMTHINS" "hkey"="HKLM" "command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winampa" "hkey"="HKLM" "command"="C:\\Programfiler\\Winamp\\winampa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="xfiremusic" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MultiIM" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "PCTAVSvc"=dword:00000002 "usnjsvc"=dword:00000003 "UserAccess7"=dword:00000002 "rpcapd"=dword:00000003 "LexBceS"=dword:00000002 "iPod Service"=dword:00000003 "InCDsrv"=dword:00000002 "IDriverT"=dword:00000003 "Adobe LM Service"=dword:00000003 "NVCScheduler"=dword:00000003 "Norman ZANDA"=dword:00000002 "Norman NJeeves"=dword:00000003 "NipSvc"=dword:00000003 "nvcoas"=dword:00000003 "Bonjour Service"=dword:00000002 "avast! Web Scanner"=dword:00000003 "avast! Mail Scanner"=dword:00000003 "avast! Antivirus"=dword:00000002 "aswUpdSv"=dword:00000002 "FLEXnet Licensing Service"=dword:00000003 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-04-30 18:11:54 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-04-30 18:12:41 C:\ComboFix-quarantined-files.txt ... 07-04-30 18:12 C:\ComboFix2.txt ... 07-04-30 13:09 C:\ComboFix3.txt ... 07-04-30 13:01 Takk For all hjelp Datan går raskere, den bootere hvertfall raskere.. Det er vel det eneste jeg har lagt merke til - Hvertfall til nå : ) EDIT: SAS fant ingenting EDIT2: Spilte noen spill nå, ikke en eneste lagg ! Endret 30. april 2007 av trysilgutt Lenke til kommentar
norbat Skrevet 1. mai 2007 Del Skrevet 1. mai 2007 Hei, Kjør rootchk en gang til og legge ut loggen Lenke til kommentar
Etnies Skrevet 1. mai 2007 Forfatter Del Skrevet 1. mai 2007 (endret) ComboFix Logg Klikk for å se/fjerne innholdet nedenfor "- Nils" - 07-05-01 11:47:17 Service Pack 2 ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\- Nils\Skrivebord\" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\qoobox\purity\C\Programfiler\MCROSO~1.NET C:\qoobox\purity\C\WINDOWS\PPATCH~1 C:\qoobox\purity\C\WINDOWS\system32\FNTS~1 ((((((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\nm -------\LEGACY_NM -------\LEGACY_NPF ((((((((((((((((((((((((((((((( Files Created from 2007-04-01 to 2007-05-01 )))))))))))))))))))))))))))))))))) 2007-05-01 11:42 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Siste 2007-05-01 00:05 <DIR> d-------- C:\Programfiler\LEGO Island 2007-05-01 00:03 <DIR> d-------- C:\Programfiler\DaemonTools_WhenUSave_Installer 2007-05-01 00:01 <DIR> d-------- C:\Programfiler\DAEMON Tools 2007-04-30 19:05 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\uTorrent 2007-04-30 17:11 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\AdobeUM 2007-04-30 13:00 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-04-30 02:47 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-04-30 00:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\SUPERAntiSpyware.com 2007-04-30 00:45 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2007-04-30 00:45 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\SUPERAntiSpyware.com 2007-04-30 00:43 <DIR> d-------- C:\Programfiler\CCleaner 2007-04-30 00:22 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Teleca 2007-04-30 00:03 <DIR> d-------- C:\DOCUME~1\-SILJE~1\PROGRA~1\Winamp 2007-04-29 23:36 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Contacts 2007-04-29 23:23 1,310,720 --ah----- C:\DOCUME~1\-SILJE~1\NTUSER.DAT 2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Siste 2007-04-29 23:23 <DIR> dr-h----- C:\DOCUME~1\-SILJE~1\Programdata 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Start-meny 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Mine dokumenter 2007-04-29 23:23 <DIR> dr------- C:\DOCUME~1\-SILJE~1\Favoritter 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Skrivere 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Maler 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\Lokale innstillinger 2007-04-29 23:23 <DIR> d--h----- C:\DOCUME~1\-SILJE~1\AndrMask 2007-04-29 23:23 <DIR> d-------- C:\DOCUME~1\-SILJE~1\Skrivebord 2007-04-29 19:01 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-04-29 19:01 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Programdata 2007-04-29 19:01 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Start-meny 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skrivere 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Siste 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Maler 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale innstillinger 2007-04-29 19:01 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\AndrMask 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mine dokumenter 2007-04-29 19:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritter 2007-04-29 18:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2007-04-29 16:01 <DIR> d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\Winamp 2007-04-29 15:18 <DIR> d-------- C:\DOCUME~1\-NILS~1\Contacts 2007-04-29 15:16 1,572,864 --ah----- C:\DOCUME~1\-NILS~1\NTUSER.DAT 2007-04-29 15:16 <DIR> dr-h----- C:\DOCUME~1\-NILS~1\Programdata 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Start-meny 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Mine dokumenter 2007-04-29 15:16 <DIR> dr------- C:\DOCUME~1\-NILS~1\Favoritter 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Skrivere 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Maler 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\Lokale innstillinger 2007-04-29 15:16 <DIR> d--h----- C:\DOCUME~1\-NILS~1\AndrMask 2007-04-29 15:16 <DIR> d-------- C:\DOCUME~1\-NILS~1\Skrivebord 2007-04-29 14:41 520,192 --a------ C:\WINDOWS\system32\monoface.scr 2007-04-29 14:41 <DIR> d-------- C:\WINDOWS\system32\monoface dir 2007-04-14 21:29 <DIR> d-------- C:\Programfiler\UUUSoft 2007-04-09 21:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet 2007-04-09 21:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared 2007-04-09 21:29 <DIR> d-------- C:\Programfiler\Bonjour 2007-04-09 19:38 <DIR> d-------- C:\Programfiler\Alwil Software 2007-04-08 14:49 <DIR> d-------- C:\Programfiler\iTunes 2007-04-06 14:53 <DIR> d-------- C:\Programfiler\Cain 2007-04-02 13:54 <DIR> d-------- C:\Programfiler\FoxyTunes 2007-04-02 13:33 <DIR> d-------- C:\WINDOWS\system32\nb-no 2007-04-02 13:24 <DIR> d-------- C:\WINDOWS\network diagnostic (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-01 11:40 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\utorrent 2007-05-01 01:05 -------- d--h----- C:\Programfiler\installshield installation information 2007-04-30 23:57 682232 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-04-30 12:47 -------- d-------- C:\Programfiler\logitech 2007-04-30 00:22 -------- d-------- C:\Programfiler\sony ericsson 2007-04-30 00:22 -------- d-------- C:\Programfiler\Fellesfiler\teleca shared 2007-04-30 00:22 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\teleca 2007-04-29 16:13 -------- d-------- C:\DOCUME~1\-NILS~1\PROGRA~1\winamp 2007-04-29 01:17 -------- d-------- C:\Programfiler\smartdraw 7 2007-04-23 19:06 -------- d-------- C:\Programfiler\opera 2007-04-08 14:50 -------- d-------- C:\Programfiler\ipod 2007-04-08 14:40 -------- d-------- C:\Programfiler\quicktime 2007-04-06 20:50 -------- d-------- C:\Programfiler\postal2 2007-03-31 17:39 -------- d-------- C:\Programfiler\duplicate file finder 2007-03-31 15:06 -------- d-------- C:\Programfiler\limewire 2007-03-28 21:19 -------- d-------- C:\Programfiler\windows media connect 2 2007-03-25 12:30 70906 --a------ C:\WINDOWS\system32\perfc014.dat 2007-03-25 12:30 405254 --a------ C:\WINDOWS\system32\perfh014.dat 2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll 2007-03-16 19:06 -------- d-------- C:\Programfiler\winamp 2007-03-10 23:04 -------- d-------- C:\Programfiler\quick screen capture 2007-03-09 21:27 -------- d-------- C:\Programfiler\messenger 2007-03-08 22:52 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll 2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll 2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll 2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys 2007-03-06 21:20 -------- d-------- C:\Programfiler\azureus 2007-03-06 17:59 -------- d-------- C:\Programfiler\bittorrent 2007-02-11 21:07 61440 --a------ C:\WINDOWS\diabunin.exe 2007-02-08 20:54 23424 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-02-08 20:43 62 --ahs---- C:\DOCUME~1\-NILS~1\PROGRA~1\desktop.ini 2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll {784D8FBC-4165-4D88-90FB-62907ACDD045} C:\Programfiler\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "VTTimer"="VTTimer.exe" "MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto" "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" "!AVG Anti-Spyware"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "msnmsgr"="\"C:\\Programfiler\\MSN Messenger\\msnmsgr.exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "DAEMON Tools"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages REG_MULTI_SZ scecli\0\0 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Adobe Gamma Loader.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma Loader.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE " "item"="Adobe Gamma Loader" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech Desktop Messenger.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech Desktop Messenger.lnk" "backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Logitech\\DESKTO~1\\8876480\\Program\\LDMConf.exe /start" "item"="Logitech Desktop Messenger" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Logitech SetPoint.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Logitech SetPoint.lnk" "backup"="C:\\WINDOWS\\pss\\Logitech SetPoint.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Logitech\\SetPoint\\SetPoint.exe " "item"="Logitech SetPoint" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Adobe Gamma.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\FELLES~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE " "item"="Adobe Gamma" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^MagicDisc.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\MagicDisc.lnk" "backup"="C:\\WINDOWS\\pss\\MagicDisc.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\MAGICD~1\\MAGICD~1.EXE " "item"="MagicDisc" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NIls^Start-meny^Programmer^Oppstart^Xfire.lnk] "path"="C:\\Documents and Settings\\NIls\\Start-meny\\Programmer\\Oppstart\\Xfire.lnk" "backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup" "location"="Startup" "command"="C:\\Programfiler\\Xfire\\xfire.exe " "item"="Xfire" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="avgas" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ashDisp" "hkey"="HKLM" "command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="bittorrent" "hkey"="HKCU" "command"="\"C:\\Programfiler\\BitTorrent\\bittorrent.exe\" --force_start_minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKCU" "command"="\"C:\\Programfiler\\DAEMON Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="InCD" "hkey"="HKLM" "command"="C:\\Programfiler\\Ahead\\InCD\\InCD.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -k" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -k" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LogitechDesktopMessenger" "hkey"="HKCU" "command"="C:\\Programfiler\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="lxczbmgr" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Lexmark 1200 Series\\lxczbmgr.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCLaunch] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NCLAUNCH" "hkey"="HKCU" "command"="C:\\WINDOWS\\NCLAUNCH.EXe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LAUNCH~1" "hkey"="HKLM" "command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -onlytray" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PCTAV" "hkey"="HKLM" "command"="\"C:\\Programfiler\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="pvmodule" "hkey"="HKLM" "command"="C:\\PROGRA~2\\PRINTV~1\\pvmodule.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Programfiler\\Skype\\Phone\\Skype.exe\" /nosplash /minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Application Launcher" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SOUNDMAN" "hkey"="HKLM" "command"="SOUNDMAN.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SUPERAntiSpyware" "hkey"="HKCU" "command"="C:\\Programfiler\\SUPERAntiSpyware\\SUPERAntiSpyware.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCDDaemon" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxMoniter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CAMTHINS" "hkey"="HKLM" "command"="\"C:\\Programfiler\\WebcamMax\\CAMTHINS.exe\" /m" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winampa" "hkey"="HKLM" "command"="C:\\Programfiler\\Winamp\\winampa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xfire Music] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="xfiremusic" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Xfire\\xfiremusic.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFP: Multi-IM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MultiIM" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Xfire Plus\\Multi-IM\\MultiIM.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "PCTAVSvc"=dword:00000002 "usnjsvc"=dword:00000003 "UserAccess7"=dword:00000002 "rpcapd"=dword:00000003 "LexBceS"=dword:00000002 "iPod Service"=dword:00000003 "InCDsrv"=dword:00000002 "IDriverT"=dword:00000003 "Adobe LM Service"=dword:00000003 "NVCScheduler"=dword:00000003 "Norman ZANDA"=dword:00000002 "Norman NJeeves"=dword:00000003 "NipSvc"=dword:00000003 "nvcoas"=dword:00000003 "Bonjour Service"=dword:00000002 "avast! Web Scanner"=dword:00000003 "avast! Mail Scanner"=dword:00000003 "avast! Antivirus"=dword:00000002 "aswUpdSv"=dword:00000002 "FLEXnet Licensing Service"=dword:00000003 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-01 11:52:20 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-05-01 11:52:59 C:\ComboFix-quarantined-files.txt ... 07-05-01 11:52 C:\ComboFix2.txt ... 07-04-30 18:12 C:\ComboFix3.txt ... 07-04-30 13:09 Er det noe galt? Åpne Notisblokk og kopier og lim inn det som står under (i fet): REGEDIT4 [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free] (PS. sørg for at det ikke er noe luft over REGEDIT4 - altså den skal stå aller øverst i notisblokkvinduet) Klikk 'Lagre som', velg 'Alle filer' som filtype. Lagre file med filnavn: fix.reg på skrivebordet. Dobbeltklikk på fila (fix.reg), og si ja til å legge inn/flette inn i registeret. Kan jeg slette den fra skriverbordet mitt nå? Endret 1. mai 2007 av trysilgutt Lenke til kommentar
norbat Skrevet 1. mai 2007 Del Skrevet 1. mai 2007 (endret) Du kan slette fix.reg Ikke combofix men rootchk er ønskelig Endret 1. mai 2007 av norbat Lenke til kommentar
Etnies Skrevet 1. mai 2007 Forfatter Del Skrevet 1. mai 2007 Haha, sorry. Rootchk logg Klikk for å se/fjerne innholdet nedenfor ********************************* ROOTCHK-(30-04-07)-LOG, by ejvindh01.05.07 22:29:44,64 The rootkits that are detected by this tool were not found. ********************************* ROOTCHK-LOG-end catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-01 22:29:45 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc75\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc99\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0229.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\DSCN0230.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc307\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc336\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\54.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Bra Musikk.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\cnzxklcn lkds[ nfoøidarc pmeow9uria.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Gaute Ormåsen.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Goflon Band.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Idol.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Lillians mix.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Limewire2.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\musikk(=.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Opptak.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\På mp3 (2).wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\PÅ mp3.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Rock 2005.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Svenne Rubins.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\The carburetors.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc437\Til Mariell.wpl C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc150\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc160\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc165\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Desktop.ini C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc249\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Fine damer og musikk.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Helt normal.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Hva skjer.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Kjærlighet er mer enn forelskelse.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Mammas lille venn.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Protein vitamin.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Singel.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Sommer hele året.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Usminka sjel.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc256\Utpå bygda.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\Hallelujah.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\miss a thing.wma C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC01.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC02.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC03.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc257\REC04.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc258\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3 C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Bjørn2.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Brannmann Sam.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Fra Grease.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Svein Krogstad.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Med mp3\Ørjan 3.3.06.wav C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc259\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\10B.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen med sine kjære;).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Gjengen.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Halve 10B.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline og meg.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline på jakt.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline tenker på sin kjære=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Oline2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Ida Olinee3.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Konfirmasjon3.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Kristoffer.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Maiken og Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Meg & Ida Oline.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Oss to=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\På Kjølen.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Robin syng.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje og Silje=).JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Silje2.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc296\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Elvis.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Jonna og Ole Runar.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Nickolas.JPG C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Ole Runar og Sigurd.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Sigurd.jpg C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc298\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc330\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc335\Thumbs.db:encryptable 0 bytes hidden from API C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db C:\RECYCLER\S-1-5-21-1645522239-484061587-839522115-1006\Dc435\Thumbs.db:encryptable 0 bytes hidden from API scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 102 Lenke til kommentar
norbat Skrevet 1. mai 2007 Del Skrevet 1. mai 2007 Dette ser bra ut det, trysilgutt. Lenke til kommentar
Etnies Skrevet 2. mai 2007 Forfatter Del Skrevet 2. mai 2007 Takk for all hjelp Takk norbat Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå