turbojomar Skrevet 23. mai 2007 Del Skrevet 23. mai 2007 Jge var saa dum at jeg lastet ned 3wplayer for aa se siste sopranos episode. Videofilen ser ut som en hvilken som hels DivX, men naar den spilles av i en vanlig mediespiller ber den deg gaa til en nettside for aa laste ned en annen spiller. Sopranos-iveren tok overhand og naa har jeg en drittprosess som heter "Hide close part.exe" som bruker masse cpu (50%, en av to kjerner hos meg). Skal proeve http://www.superantispyware.com/ som jeg las om i en annen post. Andre som har vaert borti dette? Lenke til kommentar
norbat Skrevet 23. mai 2007 Del Skrevet 23. mai 2007 Etter en runde med superantispyware kan du hente NoLop.exe, legg det på skrivebordet. Kjør programmet. Trykk "Search and Destroy"-knappen. Hvis den finner noe, bli du bedt om å trykke på Reboot-knappen. Hent deretter Hijackthis, legg det i en egen mappe på skrivebordet. Start programmet, velg "Do a system scan and save a logfile". Loggfilen kopierer du og poster. Lenke til kommentar
turbojomar Skrevet 24. mai 2007 Forfatter Del Skrevet 24. mai 2007 Takk norbat, skal huske de to. I dette tilfellet gjorde superantispyware en super jobb og jeg er kvitt problemet. Lenke til kommentar
norbat Skrevet 24. mai 2007 Del Skrevet 24. mai 2007 Oppfordrer deg allikevel til å lage en hijackthis-logg. Denne kan fortelle om det må noen flere grep for at pc'n skal bli spywarefri Lenke til kommentar
Wooho Skrevet 20. juni 2007 Del Skrevet 20. juni 2007 He he, la inn 3wplayer inne i Google søkemotoren og det første som dukket opp var denne posten. Da holder jeg meg unna spilleren. Fikk beskjed at TMNT ikke kunne spilles av i noen andre spillere enn kun 3wplayer. Lenke til kommentar
mhsalangli Skrevet 16. september 2007 Del Skrevet 16. september 2007 men hvordan skal man liksom få tak i noe som klarer å spille av disse filmene? dette er ekstremt frustrerende Lenke til kommentar
norbat Skrevet 16. september 2007 Del Skrevet 16. september 2007 Kanskje VLC er et alternativ? Lenke til kommentar
Barry White Skrevet 17. september 2007 Del Skrevet 17. september 2007 filmer som kommer med 3wplayer er det mange kaller en fake Lenke til kommentar
Morten58 Skrevet 4. oktober 2007 Del Skrevet 4. oktober 2007 Unngå opplagte løsninger ? Mer fake ? Jeg sjekket løsninger for et annet forum i denne saken (ItPro). 3WPLAYER, PLAY3W eller DIVOCODEC inneholder malware. Det flommer over av advarsler i ulike forum på nettet. Trojan: I følge Wikipedia er 3wplayer infisert med Trojan.Win32.obfuscated.en - sjekk Wikipedia i denne linken: http://en.wikipedia.org/wiki/3wplayer Fake løsning ? En "løsning" tilbys høyt oppe på søkelisten i Google - NO.PCTHREAT.COM. Jeg bruker McAfee Site Advisor, og reagerte på at ingen av nettstedene som tilhørte PCthreat noensinne var blitt testet der. Fra samme firma ? En nærmere sjekk av PCthreat.com viste tilknytning / lisens till et firma i USA. Sjekk av 3WPLAY.COM viste tilknytning / lisens til samme firma. Jeg har bevisst holdt tilbake navn på firmaet i dette innlegget for å unngå brudd på regler i søkeverktøyet jeg brukte. Det virker som om samme firma både lager malware og er aktive i å markedsføre løsninger ? Kjente kopier av nettstedet: pcthreat.com - no.pcthreat.com - de.pcthreat.com - fr.pcthreat.com Noen som kjenner til andre kopier ? Kjente kopier av 3WPlayer: PLAYON.PLAY3W - PLAY3W - 3WPLAYER - PLAY.DIVOCODEC Noen som kjenner andre kopier ? Link til McAfee Site Analyzer ang. PCTHREAT (mulig at det kun er mitt innlegg der foreløpig, men ...): http://www.siteadvisor.com/sites/pcthreat....t_type=IEPlugin Lenke til kommentar
Opedal Skrevet 20. oktober 2007 Del Skrevet 20. oktober 2007 Var det dette jeg skulle poste...skjønte ikke helt det der...uannsett så har jeg fortsatt problemer:( Logfile of HijackThis v1.99.1 Scan saved at 21:48:15, on 20.10.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe C:\Programfiler\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Programfiler\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Programfiler\Spyware Doctor\svcntaux.exe C:\Programfiler\Spyware Doctor\swdsvc.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Spyware Doctor\SDTrayApp.exe C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\stealthp.exe C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe C:\Programfiler\DAEMON Tools\daemon.exe C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe C:\Programfiler\PowerISO\PWRISOVM.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\alg.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\Programfiler\MSN Messenger\usnsvc.exe C:\Programfiler\Internet Explorer\IEXPLORE.EXE C:\Programfiler\Opera\Opera.exe C:\Programfiler\Internet Explorer\IEXPLORE.EXE C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Documents and Settings\Morten\Skrivebord\NoLop.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [stealthPlug Control Panel] "C:\WINDOWS\system32\stealthp.exe" -min O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [MsgCenterExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\RealOneMessageCenter.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Programfiler\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Programdata\great coal love default\Creative free.exe O4 - HKLM\..\Run: [sDTray] "C:\Programfiler\Spyware Doctor\SDTrayApp.exe" O4 - HKCU\..\Run: [Axis Bags] C:\DOCUME~1\Morten\PROGRA~1\BINDBR~1\Audio Drive Bat.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273110921 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273085781 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programfiler\Fellesfiler\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FELLES~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programfiler\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programfiler\Spyware Doctor\swdsvc.exe Etter at jeg lastet ned 3wplayer, så fikk jeg problemer med at internett explorer stadig popper opp med reklame, og når jeg surfer i Opera så får jeg forespørsel om å laste ned en fil...I prosseser står det alltid 2 iexplore.exe...hvis jeg fjerner noen av dem kommer de tilbake med en gang...Er dette vanlig?? og hvordan fikser man det?? slik ser det ut når jeg får spørsmål om å laste ned en fil... Lenke til kommentar
norbat Skrevet 20. oktober 2007 Del Skrevet 20. oktober 2007 Hvis du ikke har kjørt NoLop, gjør du det: Hent NoLop.exe, legg det på skrivebordet. Kjør programmet. Trykk "Search and Destroy"-knappen. Hvis den finner noe, bli du bedt om å trykke på Reboot-knappen. Kjør HJT, velg "Do a system scan only", sett merke framfor følgende linjer og klikk 'Fix checked': O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Programdata\great coal love default\Creative free.exe O4 - HKCU\..\Run: [Axis Bags] C:\DOCUME~1\Morten\PROGRA~1\BINDBR~1\Audio Drive Bat.exe Bruk utforsker til å finne og slett følgende to mapper (i fet) C:\Documents and Settings\All Users\Programdata\great coal love default C:\DOCUME~1\Morten\PROGRA~1\BINDBR~1 (~1= forkortelse. Finn ei mappe som begynner på BIND..... og som det ligger en fil ved navn Audio Driver Bat.exe) Hvis du ikke får slettet dem, må du restarte PC-en i sikker modus (tapp F8 under oppstart, velg sikker modus). Når du har gjort dette, fortsetter du med: Last ned CCleaner. Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......." Klikk på 'Renser' og deretter 'Kjør CCleaner'. Hent Combofix, og legg det på skrivebordet Kjør combofix.exe, og følg veiledningen. Du må ikke klikke på vinduet mens programmet kjører. Post loggfilen fra combofix (c:\combofix.txt) + ny hjt-logg. Lenke til kommentar
Opedal Skrevet 20. oktober 2007 Del Skrevet 20. oktober 2007 Tusen takk..skal prøve dette;) Lenke til kommentar
Opedal Skrevet 20. oktober 2007 Del Skrevet 20. oktober 2007 Her er fra ComboFix: ComboFix 07-10-20.6 - Morten 2007-10-20 22:42:02.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1044.18.1049 [GMT 2:00] Running from: C:\Documents and Settings\Morten\Skrivebord\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-09-20 to 2007-10-20 ))))))))))))))))))))))))))))))) . 2007-10-20 22:40 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-20 22:35 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny 2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere 2007-10-20 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord 2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Siste 2007-10-20 22:35 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata 2007-10-20 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter 2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler 2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger 2007-10-20 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter 2007-10-20 22:35 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask 2007-10-20 22:28 106 --a------ C:\delete.bat 2007-10-20 21:47 <DIR> d-------- C:\Program Files 2007-10-20 21:34 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2007-10-20 21:34 <DIR> d-------- C:\Documents and Settings\Morten\Programdata\SUPERAntiSpyware.com 2007-10-20 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2007-10-20 14:07 <DIR> d-------- C:\Programfiler\Spyware Doctor 2007-10-20 14:07 <DIR> d-------- C:\Documents and Settings\Morten\Programdata\PC Tools 2007-10-20 14:07 <DIR> d-a------ C:\Documents and Settings\All Users\Programdata\TEMP 2007-10-20 14:07 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-10-20 14:07 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys 2007-10-20 14:07 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys 2007-10-20 14:07 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys 2007-10-20 14:07 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys 2007-10-20 12:27 <DIR> C:\Documents and Settings\Morten\Siste 2007-10-19 23:26 <DIR> d-------- C:\Programfiler\Bind Browse Pure 2007-10-13 13:04 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-09 22:23 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-10-09 22:23 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-10-09 22:23 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys 2007-10-09 22:23 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-09-25 19:52 <DIR> d-------- C:\Documents and Settings\Morten\Programdata\fretsonfire . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-20 19:33 --------- d-----w C:\Programfiler\Fellesfiler\Wise Installation Wizard 2007-10-20 18:52 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2007-10-20 18:50 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2007-10-20 12:49 --------- d-----w C:\Programfiler\DAEMON Tools 2007-10-20 11:52 --------- d-----w C:\Programfiler\Java 2007-10-18 16:24 --------- d-----w C:\Programfiler\Winamp 2007-10-17 20:41 --------- d-----w C:\Documents and Settings\Morten\Programdata\LimeWire 2007-10-13 16:37 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help 2007-09-19 20:35 --------- d-----w C:\Documents and Settings\Morten\Programdata\SecondLife 2007-09-19 14:25 --------- d-----w C:\Programfiler\SecondLife 2007-09-17 19:01 --------- d-----w C:\Programfiler\MSN Messenger 2007-09-17 11:34 --------- d-----w C:\Programfiler\CLUE 2007-09-16 20:45 --------- d-----w C:\Programfiler\Ventrilo 2007-09-16 20:12 --------- d-----w C:\Programfiler\Fellesfiler\Adobe 2007-09-16 20:10 --------- d-----w C:\Documents and Settings\Morten\Programdata\AdobeUM 2007-09-14 17:17 --------- d-----w C:\Programfiler\UltraStar 2007-09-08 18:21 --------- d-----w C:\Documents and Settings\All Users\Programdata\FLEXnet 2007-09-08 16:56 --------- d-----w C:\Programfiler\Bonjour 2007-09-08 16:55 --------- d-----w C:\Documents and Settings\Morten\Programdata\Apple Computer 2007-09-08 16:46 --------- d-----w C:\Programfiler\Fellesfiler\Macrovision Shared 2007-09-08 09:12 --------- d-----w C:\Programfiler\Fellesfiler\Adobe Systems Shared 2007-09-07 16:33 --------- d-----w C:\Programfiler\PowerISO 2007-09-06 18:28 --------- d-----w C:\Programfiler\QuickTime 2007-09-06 18:27 --------- d-----w C:\Documents and Settings\All Users\Programdata\Apple Computer 2007-09-06 18:26 --------- d-----w C:\Programfiler\Apple Software Update 2007-09-06 18:26 --------- d-----w C:\Documents and Settings\All Users\Programdata\Apple 2007-08-25 10:48 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2007-08-22 15:14 --------- d-----w C:\Programfiler\MSBuild 2007-08-22 15:14 --------- d-----w C:\Programfiler\Microsoft Works 2007-08-22 15:12 --------- d-----w C:\Programfiler\Microsoft.NET 2007-08-22 15:11 --------- d-----w C:\Programfiler\Microsoft Visual Studio 8 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-20 16:35 --------- d-----w C:\Programfiler\Fellesfiler\Ahead 2007-08-20 16:34 --------- d-----w C:\Programfiler\Nero 2007-08-20 16:34 --------- d-----w C:\Documents and Settings\Morten\Programdata\Ahead 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-07-30 17:18 207,736 ----a-w C:\WINDOWS\system32\muweb.dll 2007-07-28 03:37 8,237,056 ----a-w C:\WINDOWS\system32\atioglx2.dll 2007-07-28 03:31 344,064 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll 2007-07-28 03:30 269,312 ----a-w C:\WINDOWS\system32\ati2dvag.dll 2007-07-28 03:24 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll 2007-07-28 03:23 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll 2007-07-28 03:23 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll 2007-07-28 03:22 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll 2007-07-28 03:22 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe 2007-07-28 03:22 118,784 ----a-w C:\WINDOWS\system32\ati2evxx.dll 2007-07-28 03:21 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe 2007-07-28 03:20 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL 2007-07-28 03:12 3,067,712 ----a-w C:\WINDOWS\system32\ati3duag.dll 2007-07-28 03:06 176,128 ----a-w C:\WINDOWS\system32\atiok3x2.dll 2007-07-28 03:01 1,550,208 ----a-w C:\WINDOWS\system32\ativvaxx.dll 2007-07-28 02:50 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll 2007-07-28 02:47 266,240 ----a-w C:\WINDOWS\system32\atikvmag.dll 2007-07-28 02:46 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll 2007-07-28 02:40 450,560 ----a-w C:\WINDOWS\system32\ati2cqag.dll 2007-07-27 19:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe 2007-07-26 03:06 144,704 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2007-07-26 02:53 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2007-07-26 02:53 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2007-07-26 02:53 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2007-07-26 02:53 129,784 ------w C:\WINDOWS\system32\pxafs.dll 2007-07-26 02:53 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe 2007-07-26 02:53 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe 2007-07-26 02:53 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2007-07-26 02:50 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2007-07-26 02:50 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2007-07-26 02:50 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2007-07-26 02:50 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2007-07-26 02:50 740,442 ----a-w C:\WINDOWS\system32\DivX.dll 2007-07-26 02:50 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll 2007-07-26 02:50 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll 2007-07-26 02:50 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll 2007-07-26 02:50 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll 2007-07-26 02:50 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll 2007-07-26 02:50 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll 2007-07-26 02:50 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll 2007-07-26 02:49 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 C:\WINDOWS\soundman.exe] "StealthPlug Control Panel"="C:\WINDOWS\system32\stealthp.exe" [2006-10-06 10:51] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "DAEMON Tools"="C:\Programfiler\DAEMON Tools\daemon.exe" [2006-11-12 12:48] "MsgCenterExe"="C:\Programfiler\Fellesfiler\Real\Update_OB\RealOneMessageCenter.exe" [] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50] "GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47] "QuickTime Task"="C:\Programfiler\QuickTime\QTTask.exe" [2007-06-29 06:24] "PWRISOVM.EXE"="C:\Programfiler\PowerISO\PWRISOVM.EXE" [2006-09-09 11:16] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-18 18:13] "SDTray"="C:\Programfiler\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:03] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Hurtigstart for Adobe Reader.lnk] path=C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\Hurtigstart for Adobe Reader.lnk backup=C:\WINDOWS\pss\Hurtigstart for Adobe Reader.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Morten^Start-meny^Programmer^Oppstart^Adobe Gamma.lnk] path=C:\Documents and Settings\Morten\Start-meny\Programmer\Oppstart\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] C:\Programfiler\Winamp\winampa.exe R3 IKStealthPlug;IK Multimedia StealthPlug Low-Level Driver;C:\WINDOWS\system32\Drivers\IKStealthPlugLL.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L] AutoRun\command - L:\Setup.exe *Newly Created Service* - CATCHME *Newly Created Service* - HTTPFILTER . Contents of the 'Scheduled Tasks' folder "2007-10-12 17:52:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" . ************************************************************************** catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-20 22:45:13 Windows 5.1.2600 Service Pack 2 NTFS detected NTDLL code modification: ZwClose scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-20 22:46:04 . --- E O F --- Også den andre...: Logfile of HijackThis v1.99.1 Scan saved at 22:47:25, on 20.10.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe C:\Programfiler\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\stealthp.exe C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe C:\Programfiler\DAEMON Tools\daemon.exe C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe C:\Programfiler\PowerISO\PWRISOVM.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Programfiler\Spyware Doctor\SDTrayApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Programfiler\Spyware Doctor\svcntaux.exe C:\Programfiler\Spyware Doctor\swdsvc.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Programfiler\Opera\Opera.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [stealthPlug Control Panel] "C:\WINDOWS\system32\stealthp.exe" -min O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [MsgCenterExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\RealOneMessageCenter.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Programfiler\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [sDTray] "C:\Programfiler\Spyware Doctor\SDTrayApp.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\programfiler\bonjour\mdnsnsp.dll O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273110921 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192273085781 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programfiler\Fellesfiler\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FELLES~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programfiler\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programfiler\Spyware Doctor\swdsvc.exe Det føles i hvertfall ut som alt er greit nå...(enn så lenge) Joda...Alt ser normalt ut...tusen takk for hjelpen Norbat:D Lenke til kommentar
norbat Skrevet 20. oktober 2007 Del Skrevet 20. oktober 2007 Bruk utforsker til å slette følgende mappe hvis tilstede (i fet): C:\Programfiler\Bind Browse Pure Ut over dette ser hjt-loggen grei ut. Du bør nullstille gjenopprettingsmappa slik at du ikke blir infisert ved en evt. systemgjenoppretting. Kontrollpanel->system->systemgjenoppretting . Sett merke framfor "Slå av Systemgjenopprettingen .....", restart pc, fjern merket igjen for å aktivere funksjonen. Lenke til kommentar
sigfred Skrevet 1. november 2007 Del Skrevet 1. november 2007 arh har lasta ner dn forbanna dicocodecen eg... her e hijac griene noen sommkan hjelpe skjønner ingenting.... Logfile of HijackThis v1.99.1 Scan saved at 22:56:53, on 01.11.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\norman\Npm\bin\ELOGSVC.EXE C:\norman\Npm\Bin\Zanda.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\norman\Npf\BIN\NPFSVICE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\SOUNDMAN.EXE C:\norman\Npm\bin\ZLH.EXE C:\Programfiler\D-Tools\daemon.exe C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe C:\quicktime\iTunesHelper.exe C:\Programfiler\QuickTime\qttask.exe C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\norman\Nvc\BIN\NIP.EXE C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe C:\norman\Npf\BIN\npfmsg2.exe C:\norman\Npm\bin\NJEEVES.EXE C:\Programfiler\Internet Explorer\iexplore.exe C:\norman\Nvc\BIN\NVCSCHED.EXE C:\Programfiler\Internet Explorer\iexplore.exe C:\norman\Nvc\bin\nvcoas.exe C:\Programfiler\iPod\bin\iPodService.exe C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe C:\WINDOWS\System32\alg.exe C:\norman\Nvc\bin\cclaw.exe C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Programfiler\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programfiler\Winamp Toolbar\winamptb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programfiler\Winamp Toolbar\winamptb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Norman ZANDA] C:\norman\Npm\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programfiler\Fellesfiler\Roxio Shared\System\EngUtil.exe" O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\quicktime\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [aconti] C:\\WINDOWS\\aconti.exe -auto O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Anti Dog Beep Grid] C:\Documents and Settings\All Users\Programdata\Open Ante Anti Dog\Blah Intra.exe O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\wianmpa.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [mRouterConfig] "C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe" O4 - HKCU\..\Run: [bike bait] C:\DOCUME~1\TORSIG~1\PROGRA~1\POKEST~1\Else Htm.exe O4 - HKCU\..\Run: [Orb] "C:\Programfiler\Winamp Remote\bin\OrbTray.exe" /background O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/229?0dde09a38183410883c625d7316174c0 O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/230?0dde09a38183410883c625d7316174c0 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing) O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\norman\Npm\bin\ELOGSVC.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: Norman NJeeves - Unknown owner - C:\norman\Npm\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\norman\Npf\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Norman ASA - C:\norman\Npm\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe Lenke til kommentar
norbat Skrevet 1. november 2007 Del Skrevet 1. november 2007 Heisann, Hent NoLop.exe, legg det på skrivebordet. Kjør programmet. Trykk "Search and Destroy"-knappen. Hvis den finner noe, bli du bedt om å trykke på Reboot-knappen. Last deretter ned SAS (gratisversjonen), installer, oppdater og kjør en full (Complete) scan. Post SAS-loggen (preferences->statistics/logs) + ny hjt-logg. Lenke til kommentar
sigfred Skrevet 3. november 2007 Del Skrevet 3. november 2007 Logfile of HijackThis v1.99.1 Scan saved at 00:57:02, on 03.11.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\norman\Npm\bin\ELOGSVC.EXE C:\norman\Npm\Bin\Zanda.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\norman\Npf\BIN\NPFSVICE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\norman\Npm\bin\NJEEVES.EXE C:\norman\Nvc\BIN\NVCSCHED.EXE C:\norman\Nvc\bin\nvcoas.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\norman\Npm\bin\ZLH.EXE C:\Programfiler\D-Tools\daemon.exe C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe C:\norman\Nvc\BIN\NIP.EXE C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe C:\quicktime\iTunesHelper.exe C:\norman\Npf\BIN\npfmsg2.exe C:\norman\Nvc\bin\cclaw.exe C:\Programfiler\QuickTime\qttask.exe C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe C:\Programfiler\iPod\bin\iPodService.exe C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe C:\Programfiler\Winamp Remote\bin\OrbTray.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\Winamp Remote\bin\Orb.exe C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe C:\WINDOWS\system32\wuauclt.exe C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe C:\Programfiler\Fellesfiler\Teleca Shared\CapabilityManager.exe C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe C:\Programfiler\MSN Messenger\usnsvc.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programfiler\Winamp Toolbar\winamptb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programfiler\Winamp Toolbar\winamptb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Norman ZANDA] C:\norman\Npm\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programfiler\Fellesfiler\Roxio Shared\System\EngUtil.exe" O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\quicktime\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [aconti] C:\\WINDOWS\\aconti.exe -auto O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\wianmpa.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [mRouterConfig] "C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe" O4 - HKCU\..\Run: [Orb] "C:\Programfiler\Winamp Remote\bin\OrbTray.exe" /background O4 - HKCU\..\Run: [msnmsgr] ~"C:\Programfiler\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/229?0dde09a38183410883c625d7316174c0 O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/230?0dde09a38183410883c625d7316174c0 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing) O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\norman\Npm\bin\ELOGSVC.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: Norman NJeeves - Unknown owner - C:\norman\Npm\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\norman\Npf\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Norman ASA - C:\norman\Npm\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe sas SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 11/02/2007 at 11:17 PM Application Version : 3.9.1008 Core Rules Database Version : 3336 Trace Rules Database Version: 1337 Scan type : Complete Scan Total Scan Time : 00:32:29 Memory items scanned : 588 Memory threats detected : 0 Registry items scanned : 4474 Registry threats detected : 18 File items scanned : 27808 File threats detected : 71 Adware.Lop-Variant [Anti Dog Beep Grid] C:\DOCUMENTS AND SETTINGS\ALL USERS\PROGRAMDATA\OPEN ANTE ANTI DOG\BLAH INTRA.EXE C:\DOCUMENTS AND SETTINGS\ALL USERS\PROGRAMDATA\OPEN ANTE ANTI DOG\BLAH INTRA.EXE [bike bait] C:\DOCUME~1\TORSIG~1\PROGRA~1\POKEST~1\ELSE HTM.EXE C:\DOCUME~1\TORSIG~1\PROGRA~1\POKEST~1\ELSE HTM.EXE C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\BEOFCICR.EXE C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\ELSE HTM.EXE C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\EXIT MULTI BAGS.EXE C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\MXUPLOMP.EXE C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\QPCGYRZG.EXE C:\DOCUMENTS AND SETTINGS\TOR SIGFRED ENGEDAL\PROGRAMDATA\POKE START PART\SIFNLYLV.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052289.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052292.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052293.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052375.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052383.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP426\A0052416.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052596.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052602.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052603.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP427\A0052604.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP428\A0052671.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP428\A0052683.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP429\A0052691.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP430\A0052697.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP430\A0052705.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP431\A0052851.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP432\A0052875.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP432\A0052887.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP433\A0053038.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP433\A0053044.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP434\A0053050.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053105.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053246.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053465.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP435\A0053592.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053733.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053739.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053749.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP436\A0053760.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP437\A0053777.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP437\A0054761.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP437\A0054769.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP438\A0054787.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP439\A0054794.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP439\A0054921.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{CBE6EADF-2CBB-4AAB-A8FE-CA12BF8F784E}\RP439\A0054930.EXE C:\WINDOWS\Prefetch\BLAH INTRA.EXE-130992E9.pf C:\WINDOWS\Prefetch\ELSE HTM.EXE-0A27C6D3.pf Adware.Tracking Cookie C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@tradedoubler[2].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred [email protected][1].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred [email protected][1].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@fastclick[1].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@pacificpoker[2].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@partypoker[1].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@xiti[1].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred [email protected][2].txt C:\Documents and Settings\Tor Sigfred Engedal\Cookies\tor sigfred engedal@advertising[1].txt Trojan.Error Safe Free C:\Programfiler\Error Safe Free\activate.dat C:\Programfiler\Error Safe Free\bnlink.dat C:\Programfiler\Error Safe Free\ers.url C:\Programfiler\Error Safe Free\ersd.sys C:\Programfiler\Error Safe Free\FRec.dll C:\Programfiler\Error Safe Free\pv.dat C:\Programfiler\Error Safe Free\support.url C:\Programfiler\Error Safe Free\unins000.dat C:\Programfiler\Error Safe Free\unins000.exe C:\Programfiler\Error Safe Free\up.dat C:\Programfiler\Error Safe Free\updater.dat C:\Programfiler\Error Safe Free\Updater.exe C:\Programfiler\Error Safe Free HKU\S-1-5-21-1214440339-1757981266-1801674531-1004\Software\Error Safe Free HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Setup Version HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: App Path HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#InstallLocation HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Icon Group HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: User HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#UninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#QuietUninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Publisher HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLInfoAbout HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#HelpLink HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLUpdateInfo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoModify HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoRepair Trojan.ErrorSafe C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Avisntallerer ErrorSafe.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Error Safe.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version Lenke til kommentar
norbat Skrevet 3. november 2007 Del Skrevet 3. november 2007 Kjør hjt, sett merke framfor følgende linjer og klikk Fix checked: R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM..Run: [aconti] C:\WINDOWS\aconti.exe -auto O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing) Bruk utforsker til å finne og slette, hvis tilstede (i fet): C:\Programfiler\Macrogaming C:\Programfiler\Error Safe Free C:\WINDOWS\aconti.exe C:\Programfiler\crazyvegasMPP Restart og post ny hjt-logg. Lenke til kommentar
sigfred Skrevet 3. november 2007 Del Skrevet 3. november 2007 Logfile of HijackThis v1.99.1 Scan saved at 23:31:21, on 03.11.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\norman\Npm\bin\ELOGSVC.EXE C:\norman\Npm\Bin\Zanda.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\norman\Npf\BIN\NPFSVICE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\norman\Npm\bin\NJEEVES.EXE C:\norman\Nvc\BIN\NVCSCHED.EXE C:\norman\Nvc\bin\nvcoas.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\norman\Npm\bin\ZLH.EXE C:\Programfiler\D-Tools\daemon.exe C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe C:\norman\Nvc\BIN\NIP.EXE C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe C:\quicktime\iTunesHelper.exe C:\norman\Npf\BIN\npfmsg2.exe C:\norman\Nvc\bin\cclaw.exe C:\Programfiler\QuickTime\qttask.exe C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe C:\Programfiler\iPod\bin\iPodService.exe C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe C:\Programfiler\Winamp Remote\bin\OrbTray.exe C:\Programfiler\MSN Messenger\msnmsgr.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\Winamp Remote\bin\Orb.exe C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe C:\Programfiler\MSN Messenger\usnsvc.exe C:\Programfiler\Winamp\winamp.exe C:\spill\fm2007\fm.exe C:\DOCUME~1\TORSIG~1\LOKALE~1\Temp\~e5.0001 C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\HijackThis\HijackThis.exe C:\norman\npm\bin\niu.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programfiler\Winamp Toolbar\winamptb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programfiler\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programfiler\Winamp Toolbar\winamptb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Norman ZANDA] C:\norman\Npm\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programfiler\Fellesfiler\Roxio Shared\System\EngUtil.exe" O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programfiler\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\quicktime\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Error Safe] C:\Programfiler\Error Safe Free\ers.exe /scan O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Programfiler\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [aconti] C:\\WINDOWS\\aconti.exe -auto O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\wianmpa.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [sweetIM] C:\Programfiler\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [mRouterConfig] "C:\Programfiler\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe" O4 - HKCU\..\Run: [Orb] "C:\Programfiler\Winamp Remote\bin\OrbTray.exe" /background O4 - HKCU\..\Run: [msnmsgr] ~"C:\Programfiler\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/229?0dde09a38183410883c625d7316174c0 O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui/230?0dde09a38183410883c625d7316174c0 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe O9 - Extra button: Crazy Poker - {8A8A3162-B5FA-4c54-A862-4E62CBE8A255} - C:\Programfiler\crazyvegasMPP\MPPoker.exe (file missing) O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\norman\Npm\bin\ELOGSVC.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: Norman NJeeves - Unknown owner - C:\norman\Npm\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\norman\Npf\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Norman ASA - C:\norman\Npm\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe men d e itje mer spam me all dn popupen nå.... dessuten så fekk eg itje sletta macrogaming Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå