Gå til innhold

Anbefalte innlegg

Jge var saa dum at jeg lastet ned 3wplayer for aa se siste sopranos episode. Videofilen ser ut som en hvilken som hels DivX, men naar den spilles av i en vanlig mediespiller ber den deg gaa til en nettside for aa laste ned en annen spiller. Sopranos-iveren tok overhand og naa har jeg en drittprosess som heter "Hide close part.exe" som bruker masse cpu (50%, en av to kjerner hos meg).

 

Skal proeve http://www.superantispyware.com/ som jeg las om i en annen post.

 

Andre som har vaert borti dette?

Lenke til kommentar
Videoannonse
Annonse

Etter en runde med superantispyware kan du hente NoLop.exe, legg det på skrivebordet.

 

Kjør programmet. Trykk "Search and Destroy"-knappen. Hvis den finner noe, bli du bedt om å trykke på Reboot-knappen.

 

Hent deretter Hijackthis, legg det i en egen mappe på skrivebordet. Start programmet, velg "Do a system scan and save a logfile". Loggfilen kopierer du og poster.

Lenke til kommentar
  • 4 uker senere...
  • 2 måneder senere...
  • 4 uker senere...
  • 3 uker senere...

Unngå opplagte løsninger ? Mer fake ?

 

Jeg sjekket løsninger for et annet forum i denne saken (ItPro). 3WPLAYER, PLAY3W eller DIVOCODEC inneholder malware. Det flommer over av advarsler i ulike forum på nettet.

 

Trojan:

I følge Wikipedia er 3wplayer infisert med Trojan.Win32.obfuscated.en - sjekk Wikipedia i denne linken: http://en.wikipedia.org/wiki/3wplayer

 

Fake løsning ?

En "løsning" tilbys høyt oppe på søkelisten i Google - NO.PCTHREAT.COM.

Jeg bruker McAfee Site Advisor, og reagerte på at ingen av nettstedene som tilhørte PCthreat noensinne var blitt testet der.

 

Fra samme firma ?

En nærmere sjekk av PCthreat.com viste tilknytning / lisens till et firma i USA.

Sjekk av 3WPLAY.COM viste tilknytning / lisens til samme firma.

 

Jeg har bevisst holdt tilbake navn på firmaet i dette innlegget for å unngå brudd på regler i søkeverktøyet jeg brukte.

 

Det virker som om samme firma både lager malware og er aktive i å markedsføre løsninger ?

 

Kjente kopier av nettstedet:

pcthreat.com - no.pcthreat.com - de.pcthreat.com - fr.pcthreat.com

 

Noen som kjenner til andre kopier ?

 

Kjente kopier av 3WPlayer:

PLAYON.PLAY3W - PLAY3W - 3WPLAYER - PLAY.DIVOCODEC

 

Noen som kjenner andre kopier ?

 

Link til McAfee Site Analyzer ang. PCTHREAT (mulig at det kun er mitt innlegg der foreløpig, men ...):

http://www.siteadvisor.com/sites/pcthreat....t_type=IEPlugin

Lenke til kommentar
  • 3 uker senere...

Var det dette jeg skulle poste...skjønte ikke helt det der...uannsett så har jeg fortsatt problemer:(

 

 

Logfile of HijackThis v1.99.1

Scan saved at 21:48:15, on 20.10.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16544)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe

C:\Programfiler\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programfiler\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\Programfiler\Spyware Doctor\svcntaux.exe

C:\Programfiler\Spyware Doctor\swdsvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Spyware Doctor\SDTrayApp.exe

C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\stealthp.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\Programfiler\DAEMON Tools\daemon.exe

C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe

C:\Programfiler\PowerISO\PWRISOVM.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\alg.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\Programfiler\Internet Explorer\IEXPLORE.EXE

C:\Programfiler\Opera\Opera.exe

C:\Programfiler\Internet Explorer\IEXPLORE.EXE

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Documents and Settings\Morten\Skrivebord\NoLop.exe

C:\Program Files\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [stealthPlug Control Panel] "C:\WINDOWS\system32\stealthp.exe" -min

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [MsgCenterExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\RealOneMessageCenter.exe" -osboot

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Programfiler\PowerISO\PWRISOVM.EXE

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Programdata\great coal love default\Creative free.exe

O4 - HKLM\..\Run: [sDTray] "C:\Programfiler\Spyware Doctor\SDTrayApp.exe"

O4 - HKCU\..\Run: [Axis Bags] C:\DOCUME~1\Morten\PROGRA~1\BINDBR~1\Audio Drive Bat.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273110921

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273085781

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programfiler\Fellesfiler\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FELLES~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programfiler\Spyware Doctor\svcntaux.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programfiler\Spyware Doctor\swdsvc.exe

 

 

 

Etter at jeg lastet ned 3wplayer, så fikk jeg problemer med at internett explorer stadig popper opp med reklame, og når jeg surfer i Opera så får jeg forespørsel om å laste ned en fil...I prosseser står det alltid 2 iexplore.exe...hvis jeg fjerner noen av dem kommer de tilbake med en gang...Er dette vanlig?? og hvordan fikser man det??

 

slik ser det ut når jeg får spørsmål om å laste ned en fil...

post-134718-1192910918_thumb.jpg

Lenke til kommentar

Hvis du ikke har kjørt NoLop, gjør du det:

 

Hent NoLop.exe, legg det på skrivebordet.

 

Kjør programmet. Trykk "Search and Destroy"-knappen. Hvis den finner noe, bli du bedt om å trykke på Reboot-knappen.

 

Kjør HJT, velg "Do a system scan only", sett merke framfor følgende linjer og klikk 'Fix checked':

 

O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Programdata\great coal love default\Creative free.exe

O4 - HKCU\..\Run: [Axis Bags] C:\DOCUME~1\Morten\PROGRA~1\BINDBR~1\Audio Drive Bat.exe

 

Bruk utforsker til å finne og slett følgende to mapper (i fet)

C:\Documents and Settings\All Users\Programdata\great coal love default

C:\DOCUME~1\Morten\PROGRA~1\BINDBR~1 (~1= forkortelse. Finn ei mappe som begynner på BIND..... og som det ligger en fil ved navn Audio Driver Bat.exe)

 

Hvis du ikke får slettet dem, må du restarte PC-en i sikker modus (tapp F8 under oppstart, velg sikker modus).

 

Når du har gjort dette, fortsetter du med:

Last ned CCleaner. Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......." Klikk på 'Renser' og deretter 'Kjør CCleaner'.

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix (c:\combofix.txt) + ny hjt-logg.

Lenke til kommentar

Her er fra ComboFix:

 

ComboFix 07-10-20.6 - Morten 2007-10-20 22:42:02.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1044.18.1049 [GMT 2:00]

Running from: C:\Documents and Settings\Morten\Skrivebord\ComboFix.exe

* Created a new restore point

.

 

((((((((((((((((((((((((( Files Created from 2007-09-20 to 2007-10-20 )))))))))))))))))))))))))))))))

.

 

2007-10-20 22:40 51,200 --a------ C:\WINDOWS\NirCmd.exe

2007-10-20 22:35 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny

2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere

2007-10-20 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord

2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Siste

2007-10-20 22:35 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata

2007-10-20 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter

2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler

2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger

2007-10-20 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter

2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask

2007-10-20 22:28 106 --a------ C:\delete.bat

2007-10-20 21:47 <DIR> d-------- C:\Program Files

2007-10-20 21:34 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2007-10-20 21:34 <DIR> d-------- C:\Documents and Settings\Morten\Programdata\SUPERAntiSpyware.com

2007-10-20 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2007-10-20 14:07 <DIR> d-------- C:\Programfiler\Spyware Doctor

2007-10-20 14:07 <DIR> d-------- C:\Documents and Settings\Morten\Programdata\PC Tools

2007-10-20 14:07 <DIR> d-a------ C:\Documents and Settings\All Users\Programdata\TEMP

2007-10-20 14:07 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

2007-10-20 14:07 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys

2007-10-20 14:07 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys

2007-10-20 14:07 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys

2007-10-20 14:07 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys

2007-10-20 12:27 <DIR> C:\Documents and Settings\Morten\Siste

2007-10-19 23:26 <DIR> d-------- C:\Programfiler\Bind Browse Pure

2007-10-13 13:04 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll

2007-10-09 22:23 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll

2007-10-09 22:23 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys

2007-10-09 22:23 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys

2007-10-09 22:23 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll

2007-09-25 19:52 <DIR> d-------- C:\Documents and Settings\Morten\Programdata\fretsonfire

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2007-10-20 19:33 --------- d-----w C:\Programfiler\Fellesfiler\Wise Installation Wizard

2007-10-20 18:52 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys

2007-10-20 18:50 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe

2007-10-20 12:49 --------- d-----w C:\Programfiler\DAEMON Tools

2007-10-20 11:52 --------- d-----w C:\Programfiler\Java

2007-10-18 16:24 --------- d-----w C:\Programfiler\Winamp

2007-10-17 20:41 --------- d-----w C:\Documents and Settings\Morten\Programdata\LimeWire

2007-10-13 16:37 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help

2007-09-19 20:35 --------- d-----w C:\Documents and Settings\Morten\Programdata\SecondLife

2007-09-19 14:25 --------- d-----w C:\Programfiler\SecondLife

2007-09-17 19:01 --------- d-----w C:\Programfiler\MSN Messenger

2007-09-17 11:34 --------- d-----w C:\Programfiler\CLUE

2007-09-16 20:45 --------- d-----w C:\Programfiler\Ventrilo

2007-09-16 20:12 --------- d-----w C:\Programfiler\Fellesfiler\Adobe

2007-09-16 20:10 --------- d-----w C:\Documents and Settings\Morten\Programdata\AdobeUM

2007-09-14 17:17 --------- d-----w C:\Programfiler\UltraStar

2007-09-08 18:21 --------- d-----w C:\Documents and Settings\All Users\Programdata\FLEXnet

2007-09-08 16:56 --------- d-----w C:\Programfiler\Bonjour

2007-09-08 16:55 --------- d-----w C:\Documents and Settings\Morten\Programdata\Apple Computer

2007-09-08 16:46 --------- d-----w C:\Programfiler\Fellesfiler\Macrovision Shared

2007-09-08 09:12 --------- d-----w C:\Programfiler\Fellesfiler\Adobe Systems Shared

2007-09-07 16:33 --------- d-----w C:\Programfiler\PowerISO

2007-09-06 18:28 --------- d-----w C:\Programfiler\QuickTime

2007-09-06 18:27 --------- d-----w C:\Documents and Settings\All Users\Programdata\Apple Computer

2007-09-06 18:26 --------- d-----w C:\Programfiler\Apple Software Update

2007-09-06 18:26 --------- d-----w C:\Documents and Settings\All Users\Programdata\Apple

2007-08-25 10:48 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe

2007-08-22 15:14 --------- d-----w C:\Programfiler\MSBuild

2007-08-22 15:14 --------- d-----w C:\Programfiler\Microsoft Works

2007-08-22 15:12 --------- d-----w C:\Programfiler\Microsoft.NET

2007-08-22 15:11 --------- d-----w C:\Programfiler\Microsoft Visual Studio 8

2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

2007-08-20 16:35 --------- d-----w C:\Programfiler\Fellesfiler\Ahead

2007-08-20 16:34 --------- d-----w C:\Programfiler\Nero

2007-08-20 16:34 --------- d-----w C:\Documents and Settings\Morten\Programdata\Ahead

2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll

2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll

2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe

2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll

2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll

2007-07-30 17:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll

2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll

2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll

2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll

2007-07-30 17:18 207,736 ----a-w C:\WINDOWS\system32\muweb.dll

2007-07-28 03:37 8,237,056 ----a-w C:\WINDOWS\system32\atioglx2.dll

2007-07-28 03:31 344,064 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll

2007-07-28 03:30 269,312 ----a-w C:\WINDOWS\system32\ati2dvag.dll

2007-07-28 03:24 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll

2007-07-28 03:23 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll

2007-07-28 03:23 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll

2007-07-28 03:22 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll

2007-07-28 03:22 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe

2007-07-28 03:22 118,784 ----a-w C:\WINDOWS\system32\ati2evxx.dll

2007-07-28 03:21 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe

2007-07-28 03:20 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL

2007-07-28 03:12 3,067,712 ----a-w C:\WINDOWS\system32\ati3duag.dll

2007-07-28 03:06 176,128 ----a-w C:\WINDOWS\system32\atiok3x2.dll

2007-07-28 03:01 1,550,208 ----a-w C:\WINDOWS\system32\ativvaxx.dll

2007-07-28 02:50 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll

2007-07-28 02:47 266,240 ----a-w C:\WINDOWS\system32\atikvmag.dll

2007-07-28 02:46 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll

2007-07-28 02:40 450,560 ----a-w C:\WINDOWS\system32\ati2cqag.dll

2007-07-27 19:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe

2007-07-26 03:06 144,704 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe

2007-07-26 02:53 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe

2007-07-26 02:53 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll

2007-07-26 02:53 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll

2007-07-26 02:53 129,784 ------w C:\WINDOWS\system32\pxafs.dll

2007-07-26 02:53 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe

2007-07-26 02:53 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe

2007-07-26 02:53 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll

2007-07-26 02:50 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll

2007-07-26 02:50 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll

2007-07-26 02:50 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll

2007-07-26 02:50 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll

2007-07-26 02:50 740,442 ----a-w C:\WINDOWS\system32\DivX.dll

2007-07-26 02:50 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll

2007-07-26 02:50 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll

2007-07-26 02:50 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll

2007-07-26 02:50 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll

2007-07-26 02:50 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll

2007-07-26 02:50 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll

2007-07-26 02:50 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll

2007-07-26 02:49 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 C:\WINDOWS\soundman.exe]

"StealthPlug Control Panel"="C:\WINDOWS\system32\stealthp.exe" [2006-10-06 10:51]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

"DAEMON Tools"="C:\Programfiler\DAEMON Tools\daemon.exe" [2006-11-12 12:48]

"MsgCenterExe"="C:\Programfiler\Fellesfiler\Real\Update_OB\RealOneMessageCenter.exe" []

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]

"GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]

"QuickTime Task"="C:\Programfiler\QuickTime\QTTask.exe" [2007-06-29 06:24]

"PWRISOVM.EXE"="C:\Programfiler\PowerISO\PWRISOVM.EXE" [2006-09-09 11:16]

"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-18 18:13]

"SDTray"="C:\Programfiler\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:03]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Hurtigstart for Adobe Reader.lnk]

path=C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\Hurtigstart for Adobe Reader.lnk

backup=C:\WINDOWS\pss\Hurtigstart for Adobe Reader.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Morten^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk]

path=C:\Documents and Settings\Morten\Start-meny\Programmer\Oppstart\Adobe Gamma.lnk

backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

"C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

C:\Programfiler\Winamp\winampa.exe

 

R3 IKStealthPlug;IK Multimedia StealthPlug Low-Level Driver;C:\WINDOWS\system32\Drivers\IKStealthPlugLL.sys

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]

AutoRun\command - L:\Setup.exe

 

*Newly Created Service* - CATCHME

*Newly Created Service* - HTTPFILTER

.

Contents of the 'Scheduled Tasks' folder

"2007-10-12 17:52:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

.

**************************************************************************

 

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-10-20 22:45:13

Windows 5.1.2600 Service Pack 2 NTFS

 

detected NTDLL code modification:

ZwClose

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2007-10-20 22:46:04

.

--- E O F ---

 

 

Også den andre...:

 

Logfile of HijackThis v1.99.1

Scan saved at 22:47:25, on 20.10.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16544)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe

C:\Programfiler\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\stealthp.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\Programfiler\DAEMON Tools\daemon.exe

C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe

C:\Programfiler\PowerISO\PWRISOVM.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Programfiler\Spyware Doctor\SDTrayApp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\Programfiler\Spyware Doctor\svcntaux.exe

C:\Programfiler\Spyware Doctor\swdsvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe

C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\explorer.exe

C:\Programfiler\Opera\Opera.exe

C:\Program Files\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [stealthPlug Control Panel] "C:\WINDOWS\system32\stealthp.exe" -min

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [MsgCenterExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\RealOneMessageCenter.exe" -osboot

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Programfiler\PowerISO\PWRISOVM.EXE

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [sDTray] "C:\Programfiler\Spyware Doctor\SDTrayApp.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273110921

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273085781

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programfiler\Fellesfiler\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FELLES~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programfiler\Spyware Doctor\svcntaux.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programfiler\Spyware Doctor\swdsvc.exe

 

 

 

 

 

Det føles i hvertfall ut som alt er greit nå...(enn så lenge)

 

Joda...Alt ser normalt ut...tusen takk for hjelpen Norbat:D

Lenke til kommentar

Bruk utforsker til å slette følgende mappe hvis tilstede (i fet):

C:\Programfiler\Bind Browse Pure

 

Ut over dette ser hjt-loggen grei ut.

 

Du bør nullstille gjenopprettingsmappa slik at du ikke blir infisert ved en evt. systemgjenoppretting.

Kontrollpanel->system->systemgjenoppretting . Sett merke framfor "Slå av Systemgjenopprettingen .....",

restart pc, fjern merket igjen for å aktivere funksjonen.

Lenke til kommentar
  • 2 uker senere...

arh har lasta ner dn forbanna dicocodecen eg...:(

 

her e hijac griene noen sommkan hjelpe skjønner ingenting....

 

 

Logfile of HijackThis v1.99.1

Scan saved at 22:56:53, on 01.11.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\norman\Npm\bin\ELOGSVC.EXE

C:\norman\Npm\Bin\Zanda.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\norman\Npf\BIN\NPFSVICE.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\norman\Npm\bin\ZLH.EXE

C:\Programfiler\D-Tools\daemon.exe

C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe

C:\quicktime\iTunesHelper.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\norman\Nvc\BIN\NIP.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe

C:\norman\Npf\BIN\npfmsg2.exe

C:\norman\Npm\bin\NJEEVES.EXE

C:\Programfiler\Internet Explorer\iexplore.exe

C:\norman\Nvc\BIN\NVCSCHED.EXE

C:\Programfiler\Internet Explorer\iexplore.exe

C:\norman\Nvc\bin\nvcoas.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe

C:\WINDOWS\System32\alg.exe

C:\norman\Nvc\bin\cclaw.exe

C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe

C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE

C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Programfiler\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programfiler\Winamp Toolbar\winamptb.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programfiler\Winamp Toolbar\winamptb.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Norman ZANDA] C:\norman\Npm\bin\ZLH.EXE /LOAD /SPLASH

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programfiler\Fellesfiler\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\quicktime\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan

O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [aconti] C:\\WINDOWS\\aconti.exe -auto

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [Anti Dog Beep Grid] C:\Documents and Settings\All Users\Programdata\Open Ante Anti Dog\Blah Intra.exe

O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\wianmpa.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [mRouterConfig] "C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe"

O4 - HKCU\..\Run: [bike bait] C:\DOCUME~1\TORSIG~1\PROGRA~1\POKEST~1\Else Htm.exe

O4 - HKCU\..\Run: [Orb] "C:\Programfiler\Winamp Remote\bin\OrbTray.exe" /background

O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/229?0dde09a38183410883c625d7316174c0

O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/230?0dde09a38183410883c625d7316174c0

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe

O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing)

O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\norman\Npm\bin\ELOGSVC.EXE

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: Norman NJeeves - Unknown owner - C:\norman\Npm\bin\NJEEVES.EXE

O23 - Service: Norman Type-R - Unknown owner - C:\norman\Npf\BIN\NPFSVICE.EXE

O23 - Service: Norman ZANDA - Norman ASA - C:\norman\Npm\Bin\Zanda.exe

O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\norman\Nvc\bin\nvcoas.exe

O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\norman\Nvc\BIN\NVCSCHED.EXE

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Lenke til kommentar

Heisann,

 

Hent NoLop.exe, legg det på skrivebordet.

 

Kjør programmet. Trykk "Search and Destroy"-knappen. Hvis den finner noe, bli du bedt om å trykke på Reboot-knappen.

 

Last deretter ned SAS (gratisversjonen), installer, oppdater og kjør en full (Complete) scan.

 

Post SAS-loggen (preferences->statistics/logs) + ny hjt-logg.

Lenke til kommentar

Logfile of HijackThis v1.99.1

Scan saved at 00:57:02, on 03.11.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\norman\Npm\bin\ELOGSVC.EXE

C:\norman\Npm\Bin\Zanda.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\norman\Npf\BIN\NPFSVICE.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\norman\Npm\bin\NJEEVES.EXE

C:\norman\Nvc\BIN\NVCSCHED.EXE

C:\norman\Nvc\bin\nvcoas.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\norman\Npm\bin\ZLH.EXE

C:\Programfiler\D-Tools\daemon.exe

C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\norman\Nvc\BIN\NIP.EXE

C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe

C:\quicktime\iTunesHelper.exe

C:\norman\Npf\BIN\npfmsg2.exe

C:\norman\Nvc\bin\cclaw.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe

C:\Programfiler\Winamp Remote\bin\OrbTray.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\Winamp Remote\bin\Orb.exe

C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe

C:\Programfiler\Fellesfiler\Teleca Shared\CapabilityManager.exe

C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE

C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\Program Files\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programfiler\Winamp Toolbar\winamptb.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programfiler\Winamp Toolbar\winamptb.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Norman ZANDA] C:\norman\Npm\bin\ZLH.EXE /LOAD /SPLASH

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programfiler\Fellesfiler\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\quicktime\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan

O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [aconti] C:\\WINDOWS\\aconti.exe -auto

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\wianmpa.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [mRouterConfig] "C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe"

O4 - HKCU\..\Run: [Orb] "C:\Programfiler\Winamp Remote\bin\OrbTray.exe" /background

O4 - HKCU\..\Run: [msnmsgr] ~"C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/229?0dde09a38183410883c625d7316174c0

O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/230?0dde09a38183410883c625d7316174c0

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe

O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing)

O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\norman\Npm\bin\ELOGSVC.EXE

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: Norman NJeeves - Unknown owner - C:\norman\Npm\bin\NJEEVES.EXE

O23 - Service: Norman Type-R - Unknown owner - C:\norman\Npf\BIN\NPFSVICE.EXE

O23 - Service: Norman ZANDA - Norman ASA - C:\norman\Npm\Bin\Zanda.exe

O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\norman\Nvc\bin\nvcoas.exe

O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\norman\Nvc\BIN\NVCSCHED.EXE

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

 

 

sas

 

 

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 11/02/2007 at 11:17 PM

 

Application Version : 3.9.1008

 

Core Rules Database Version : 3336

Trace Rules Database Version: 1337

 

Scan type : Complete Scan

Total Scan Time : 00:32:29

 

Memory items scanned : 588

Memory threats detected : 0

Registry items scanned : 4474

Registry threats detected : 18

File items scanned : 27808

File threats detected : 71

 

Adware.Lop-Variant

[Anti Dog Beep Grid] C:\DOCUMENTS AND SETTINGS\ALL USERS\PROGRAMDATA\OPEN ANTE ANTI DOG\BLAH INTRA.EXE

C:\DOCUMENTS AND SETTINGS\ALL USERS\PROGRAMDATA\OPEN ANTE ANTI DOG\BLAH INTRA.EXE

[bike bait] C:\DOCUME~1\TORSIG~1\PROGRA~1\POKEST~1\ELSE HTM.EXE

C:\DOCUME~1\TORSIG~1\PROGRA~1\POKEST~1\ELSE HTM.EXE

C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\BEOFCICR.EXE

C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\ELSE HTM.EXE

C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\EXIT MULTI BAGS.EXE

C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\MXUPLOMP.EXE

C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\QPCGYRZG.EXE

C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\SIFNLYLV.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052289.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052292.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052293.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052375.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052383.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052416.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052596.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052602.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052603.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052604.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP428\A0052671.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP428\A0052683.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP429\A0052691.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP430\A0052697.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP430\A0052705.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP431\A0052851.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP432\A0052875.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP432\A0052887.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP433\A0053038.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP433\A0053044.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP434\A0053050.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053105.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053246.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053465.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053592.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053733.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053739.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053749.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053760.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP437\A0053777.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP437\A0054761.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP437\A0054769.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP438\A0054787.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP439\A0054794.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP439\A0054921.EXE

C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP439\A0054930.EXE

C:\WINDOWS\Prefetch\BLAH INTRA.EXE-130992E9.pf

C:\WINDOWS\Prefetch\ELSE HTM.EXE-0A27C6D3.pf

 

Adware.Tracking Cookie

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@tradedoubler[2].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred [email protected][1].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred [email protected][1].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@fastclick[1].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@pacificpoker[2].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@partypoker[1].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@xiti[1].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred [email protected][2].txt

C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@advertising[1].txt

 

Trojan.Error Safe Free

C:\Programfiler\Error Safe Free\activate.dat

C:\Programfiler\Error Safe Free\bnlink.dat

C:\Programfiler\Error Safe Free\ers.url

C:\Programfiler\Error Safe Free\ersd.sys

C:\Programfiler\Error Safe Free\FRec.dll

C:\Programfiler\Error Safe Free\pv.dat

C:\Programfiler\Error Safe Free\support.url

C:\Programfiler\Error Safe Free\unins000.dat

C:\Programfiler\Error Safe Free\unins000.exe

C:\Programfiler\Error Safe Free\up.dat

C:\Programfiler\Error Safe Free\updater.dat

C:\Programfiler\Error Safe Free\Updater.exe

C:\Programfiler\Error Safe Free

HKU\S-1-5-21-1214440339-1757981266-1801674531-1004\Software\Error Safe Free

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Setup Version

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: App Path

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#InstallLocation

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Icon Group

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: User

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#UninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#QuietUninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Publisher

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLInfoAbout

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#HelpLink

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLUpdateInfo

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoModify

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoRepair

 

Trojan.ErrorSafe

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Avisntallerer ErrorSafe.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Error Safe.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version

Lenke til kommentar

Kjør hjt, sett merke framfor følgende linjer og klikk Fix checked:

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan

O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKLM..Run: [aconti] C:\WINDOWS\aconti.exe -auto

O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing)

 

Bruk utforsker til å finne og slette, hvis tilstede (i fet):

C:\Programfiler\Macrogaming

C:\Programfiler\Error Safe Free

C:\WINDOWS\aconti.exe

C:\Programfiler\crazyvegasMPP

 

Restart og post ny hjt-logg.

Lenke til kommentar

Logfile of HijackThis v1.99.1

Scan saved at 23:31:21, on 03.11.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\norman\Npm\bin\ELOGSVC.EXE

C:\norman\Npm\Bin\Zanda.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\norman\Npf\BIN\NPFSVICE.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\norman\Npm\bin\NJEEVES.EXE

C:\norman\Nvc\BIN\NVCSCHED.EXE

C:\norman\Nvc\bin\nvcoas.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\norman\Npm\bin\ZLH.EXE

C:\Programfiler\D-Tools\daemon.exe

C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\norman\Nvc\BIN\NIP.EXE

C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe

C:\quicktime\iTunesHelper.exe

C:\norman\Npf\BIN\npfmsg2.exe

C:\norman\Nvc\bin\cclaw.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe

C:\Programfiler\Winamp Remote\bin\OrbTray.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\Winamp Remote\bin\Orb.exe

C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe

C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe

C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE

C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe

C:\Programfiler\MSN Messenger\usnsvc.exe

C:\Programfiler\Winamp\winamp.exe

C:\spill\fm2007\fm.exe

C:\DOCUME~1\TORSIG~1\LOKALE~1\Temp\~e5.0001

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\HijackThis\HijackThis.exe

C:\norman\npm\bin\niu.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programfiler\Winamp Toolbar\winamptb.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programfiler\Winamp Toolbar\winamptb.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Norman ZANDA] C:\norman\Npm\bin\ZLH.EXE /LOAD /SPLASH

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programfiler\Fellesfiler\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\quicktime\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan

O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [aconti] C:\\WINDOWS\\aconti.exe -auto

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\wianmpa.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [mRouterConfig] "C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe"

O4 - HKCU\..\Run: [Orb] "C:\Programfiler\Winamp Remote\bin\OrbTray.exe" /background

O4 - HKCU\..\Run: [msnmsgr] ~"C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/229?0dde09a38183410883c625d7316174c0

O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/230?0dde09a38183410883c625d7316174c0

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe

O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing)

O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\norman\Npm\bin\ELOGSVC.EXE

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: Norman NJeeves - Unknown owner - C:\norman\Npm\bin\NJEEVES.EXE

O23 - Service: Norman Type-R - Unknown owner - C:\norman\Npf\BIN\NPFSVICE.EXE

O23 - Service: Norman ZANDA - Norman ASA - C:\norman\Npm\Bin\Zanda.exe

O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\norman\Nvc\bin\nvcoas.exe

O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\norman\Nvc\BIN\NVCSCHED.EXE

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

men d e itje mer spam me all dn popupen nå.... dessuten så fekk eg itje sletta macrogaming

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...