2bb1 Skrevet 23. januar 2008 Del Skrevet 23. januar 2008 Hei! Var på lan hos en kamerat her om dagen, og noen av de andre på lanet klarte å trykke på det msn-viruset. Vet ikke om det har noe med det å gjøre, men etter det har pcen gått utrolig seint, så lurer på om det kan være noe rusk i systemet. Legger derfor ved logg fra nevnte program. Noen som kan se noe mystisk der? SAS-logg: Klikk for å se/fjerne innholdet nedenfor SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/23/2008 at 07:27 PM Application Version : 3.9.1008 Core Rules Database Version : 3386 Trace Rules Database Version: 1380 Scan type : Complete Scan Total Scan Time : 01:34:40 Memory items scanned : 450 Memory threats detected : 0 Registry items scanned : 5968 Registry threats detected : 0 File items scanned : 124702 File threats detected : 76 Adware.Tracking Cookie C:\Documents and Settings\Torbjørn\Cookies\torbjørn@tradedoubler[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@2o7[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@adbrite[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@advertising[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@atwola[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@clicktorrent[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@doubleclick[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@hitbox[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@serving-sys[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\torbjorn@statcounter[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@2o7[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@adbrite[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@adtech[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@advertising[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@atdmt[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@clicktorrent[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@doubleclick[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@fastclick[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@goclick[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@imrworldwide[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@indexstats[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@linksynergy[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@mediaplex[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@overture[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@pornotube[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@revsci[1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@serving-sys[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@statcounter[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@tradedoubler[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@upspiral[2].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt H:\Users\Torbjorn\AppData\Roaming\Microsoft\Windows\Cookies\torbjorn@zedo[2].txt ComboFix-logg: Klikk for å se/fjerne innholdet nedenfor ComboFix 08-01-23.1 - Torbj›rn 2008-01-23 19:44:19.1 - NTFSx86 Running from: C:\Documents and Settings\Torbj›rn\Skrivebord\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 ))))))))))))))))))))))))))))))) . 2008-01-23 19:43 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe 2008-01-22 23:28 . 2008-01-22 23:28 <DIR> d-------- C:\Programfiler\Trend Micro 2008-01-22 23:26 . 2008-01-22 23:26 <DIR> d-------- C:\Programfiler\CCleaner 2008-01-22 22:33 . 2008-01-23 19:42 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-01-21 22:21 . 2008-01-21 22:21 <DIR> d-------- C:\Programfiler\Ventrilo 2008-01-20 17:25 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys 2008-01-20 17:25 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys 2008-01-20 15:09 . 2008-01-20 15:09 <DIR> d-------- C:\Programfiler\Atari 2008-01-20 03:10 . 2008-01-20 03:10 244 --ah----- C:\sqmnoopt14.sqm 2008-01-20 03:10 . 2008-01-20 03:10 232 --ah----- C:\sqmdata14.sqm 2008-01-20 02:59 . 2008-01-20 02:59 244 --ah----- C:\sqmnoopt13.sqm 2008-01-20 02:59 . 2008-01-20 02:59 232 --ah----- C:\sqmdata13.sqm 2008-01-20 02:25 . 2008-01-20 02:25 244 --ah----- C:\sqmnoopt12.sqm 2008-01-20 02:25 . 2008-01-20 02:25 232 --ah----- C:\sqmdata12.sqm 2008-01-20 02:10 . 2008-01-20 02:10 244 --ah----- C:\sqmnoopt11.sqm 2008-01-20 02:10 . 2008-01-20 02:10 232 --ah----- C:\sqmdata11.sqm 2008-01-20 02:01 . 2008-01-20 02:01 244 --ah----- C:\sqmnoopt10.sqm 2008-01-20 02:01 . 2008-01-20 02:01 232 --ah----- C:\sqmdata10.sqm 2008-01-20 00:15 . 2008-01-20 00:15 <DIR> d-------- C:\Programfiler\RivaTuner v2.06 2008-01-19 20:35 . 2008-01-19 20:35 <DIR> d-------- C:\Programfiler\Windows Live 2008-01-19 20:35 . 2008-01-19 20:35 <DIR> d-------- C:\Programfiler\Messenger Plus! Live 2008-01-19 19:03 . 2004-08-03 22:59 43,136 --a------ C:\WINDOWS\system32\drivers\sbp2port.sys 2008-01-19 19:03 . 2004-08-03 22:59 43,136 --a--c--- C:\WINDOWS\system32\dllcache\sbp2port.sys 2008-01-19 02:15 . 2008-01-19 02:15 <DIR> d-------- C:\Programfiler\PowerISO 2008-01-16 20:38 . 2008-01-16 20:38 <DIR> d-------- C:\WINDOWS\Sun 2008-01-14 18:51 . 2008-01-14 18:51 <DIR> d-------- C:\Programfiler\Logitech 2008-01-14 18:51 . 2008-01-14 18:51 <DIR> d-------- C:\Programfiler\Fellesfiler\Logitech 2008-01-14 18:51 . 2006-06-06 15:34 192,512 --a------ C:\WINDOWS\system32\WmJoyFrc.dll 2008-01-14 18:51 . 2006-06-06 15:37 46,208 --a------ C:\WINDOWS\system32\drivers\WmXlCore.sys 2008-01-14 18:51 . 2006-06-06 15:37 21,632 --a------ C:\WINDOWS\system32\drivers\WmFilter.sys 2008-01-14 18:51 . 2006-06-06 15:37 20,864 --a------ C:\WINDOWS\system32\drivers\WmHidLo.sys 2008-01-14 18:51 . 2006-06-06 15:37 11,136 --a------ C:\WINDOWS\system32\drivers\WmBEnum.sys 2008-01-14 18:51 . 2006-06-06 15:37 6,400 --a------ C:\WINDOWS\system32\drivers\WmVirHid.sys 2008-01-14 18:29 . 2008-01-14 18:29 <DIR> d-------- C:\Programfiler\Codemasters 2008-01-12 21:32 . 2008-01-12 21:34 <DIR> d-------- C:\Programfiler\DAEMON Tools Lite 2008-01-11 23:19 . 2008-01-11 23:19 <DIR> d-------- C:\Programfiler\Bonjour 2008-01-11 23:14 . 2008-01-11 23:14 <DIR> d-------- C:\Programfiler\Fellesfiler\Macrovision Shared 2008-01-11 13:34 . 2008-01-15 21:11 <DIR> d-------- C:\Programfiler\DC++ 2008-01-10 20:13 . 2008-01-10 20:21 1,138 --a------ C:\WINDOWS\checkip.dat 2008-01-06 02:13 . 2008-01-06 02:13 <DIR> d-------- C:\Programfiler\Fellesfiler\MainConcept 2008-01-06 01:58 . 2008-01-06 01:58 244 --ah----- C:\sqmnoopt09.sqm 2008-01-06 01:58 . 2008-01-06 01:58 232 --ah----- C:\sqmdata09.sqm 2008-01-05 21:42 . 2008-01-05 21:42 <DIR> d-------- C:\Programfiler\uTorrent 2007-12-24 02:22 . 2007-12-24 02:22 244 --ah----- C:\sqmnoopt07.sqm 2007-12-24 02:22 . 2007-12-24 02:22 232 --ah----- C:\sqmdata07.sqm 2007-12-23 21:40 . 2007-12-23 21:40 244 --ah----- C:\sqmnoopt06.sqm 2007-12-23 21:40 . 2007-12-23 21:40 232 --ah----- C:\sqmdata06.sqm 2007-12-23 21:24 . 2007-12-23 21:24 244 --ah----- C:\sqmnoopt05.sqm 2007-12-23 21:24 . 2007-12-23 21:24 232 --ah----- C:\sqmdata05.sqm 2007-12-23 19:58 . 2007-12-23 19:58 244 --ah----- C:\sqmnoopt04.sqm 2007-12-23 19:58 . 2007-12-23 19:58 232 --ah----- C:\sqmdata04.sqm 2007-12-23 19:52 . 2007-12-23 19:52 <DIR> d-------- C:\Programfiler\VID_0E8F&PID_0003 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-23 18:40 --------- d-----w C:\Programfiler\Steam 2008-01-22 22:26 --------- d-----w C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-01-22 21:30 --------- d-----w C:\Programfiler\mIRC 2008-01-21 21:00 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2008-01-19 19:35 --------- d-----w C:\Programfiler\MSN Messenger 2008-01-14 17:51 --------- d--h--w C:\Programfiler\InstallShield Installation Information 2008-01-12 20:39 --------- d-----w C:\Programfiler\MagicTune Premium 2008-01-12 20:30 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys 2008-01-11 22:19 --------- d-----w C:\Programfiler\Fellesfiler\Adobe 2007-12-23 18:58 --------- d-----w C:\Programfiler\TrackMania Nations ESWC 2007-12-07 20:13 --------- d-----w C:\Programfiler\Hamachi 2007-12-07 20:13 --------- d-----w C:\Programfiler\Azureus 2007-11-30 23:29 --------- d-----w C:\Programfiler\ASUS 2007-11-30 23:25 --------- d-----w C:\Programfiler\TerraTec 2007-11-07 09:30 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll 2007-10-29 22:45 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-28 17:02 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE 2007-10-28 15:52 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-10-28 15:52 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-10-28 15:52 8,531,968 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-10-28 15:52 757,760 ----a-w C:\WINDOWS\system32\nvcplui.exe 2007-10-28 15:52 6,901,760 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-10-28 15:52 6,541,312 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-10-28 15:52 5,768,320 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-10-28 15:52 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll 2007-10-28 15:52 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-10-28 15:52 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe 2007-10-28 15:52 425,984 ----a-w C:\WINDOWS\system32\keystone.exe 2007-10-28 15:52 380,928 ----a-w C:\WINDOWS\system32\nvapi.dll 2007-10-28 15:52 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe 2007-10-28 15:52 35,328 ----a-w C:\WINDOWS\system32\nvcodins.dll 2007-10-28 15:52 35,328 ----a-w C:\WINDOWS\system32\nvcod.dll 2007-10-28 15:52 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll 2007-10-28 15:52 3,698,688 ----a-w C:\WINDOWS\system32\nvvitvs.dll 2007-10-28 15:52 3,407,872 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-10-28 15:52 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll 2007-10-28 15:52 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll 2007-10-28 15:52 2,486,272 ----a-w C:\WINDOWS\system32\nvwss.dll 2007-10-28 15:52 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll 2007-10-28 15:52 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe 2007-10-28 15:52 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe 2007-10-28 15:52 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll 2007-10-28 15:52 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe 2007-10-28 15:52 1,478,656 ----a-w C:\WINDOWS\system32\nview.dll 2007-10-28 15:52 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe 2007-10-28 15:52 1,212,416 ----a-w C:\WINDOWS\system32\nvmobls.dll 2007-10-28 15:52 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll 2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll 2007-10-24 00:47 96,760 ----a-w C:\WINDOWS\system32\dfshim.dll 2007-10-24 00:47 84,480 ----a-w C:\WINDOWS\system32\mscories.dll 2007-10-24 00:47 282,112 ----a-w C:\WINDOWS\system32\mscoree.dll 2007-10-24 00:47 158,720 ----a-w C:\WINDOWS\system32\mscorier.dll 2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\programfiler\steam\steam.exe" [2007-12-01 00:19 1266936] "MsnMsgr"="C:\Programfiler\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360] "WMPNSCFG"="C:\Programfiler\Windows Media Player\WMPNSCFG.exe" [2006-11-15 09:46 204288] "Start WingMan Profiler"="" [] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 07:36 36864] "36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-21 09:23 1953792] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-28 18:53 579072] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496] "GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016] "SoundMAXPnP"="C:\Programfiler\Analog Devices\Core\smax4pnp.exe" [2006-12-18 20:34 868352] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-28 16:52 8531968] "nwiz"="nwiz.exe" [2007-10-28 16:52 1626112 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-28 16:52 81920] "RivaTunerStartupDaemon"="C:\Programfiler\RivaTuner v2.06\RivaTuner.exe" [2007-10-30 19:05 2650112] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 15:25 219136] "Nokia.PCSync"="C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 09:17 1241088] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ GammaTray.lnk - C:\Programfiler\MagicTune Premium\GammaTray.exe [2007-10-01 22:01:13 36864] NCProTray.lnk - C:\Programfiler\SEC\Natural Color Pro\NCProTray.exe [2007-10-01 21:50:57 49220] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^ASUS WiFi-AP Solo.lnk] path=C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ASUS WiFi-AP Solo.lnk backup=C:\WINDOWS\pss\ASUS WiFi-AP Solo.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^ATITool.lnk] path=C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ATITool.lnk backup=C:\WINDOWS\pss\ATITool.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2007-05-11 02:06 40048 C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] --a------ 2007-12-29 13:05 486856 C:\Programfiler\DAEMON Tools Lite\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune] C:\Programfiler\NVIDIA Corporation\nTune\nTuneCmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication] --a------ 2007-06-18 14:10 271360 C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE] --a------ 2007-08-07 01:05 200704 C:\Programfiler\PowerISO\PWRISOVM.EXE *Newly Created Service* - PROCEXP90 . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-23 19:45:49 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-23 19:46:16 . 2008-01-22 23:06:11 --- E O F --- HiJackThis-logg: Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:47:14, on 23.01.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Programfiler\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\svchost.exe C:\Programfiler\MagicTune Premium\MagicTuneEngine.exe C:\WINDOWS\system32\nvsvc32.exe C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\CNAC1RPK.EXE C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe C:\Programfiler\MagicTune Premium\MagicTune.exe C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe C:\Programfiler\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\programfiler\steam\steam.exe C:\Programfiler\MSN Messenger\MsnMsgr.Exe C:\Programfiler\Windows Media Player\WMPNSCFG.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\MagicTune Premium\GammaTray.exe C:\Programfiler\SEC\Natural Color Pro\NCProTray.exe C:\WINDOWS\system32\wscntfy.exe C:\Programfiler\Opera\Opera.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\explorer.exe C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Programfiler\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Programfiler\RivaTuner v2.06\RivaTuner.exe" /S O4 - HKCU\..\Run: [steam] "c:\programfiler\steam\steam.exe" -silent O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-21-448539723-308236825-682003330-1003\..\Run: [steam] "c:\programfiler\steam\steam.exe" -silent (User '?') O4 - HKUS\S-1-5-21-448539723-308236825-682003330-1003\..\Run: [start WingMan Profiler] (User '?') O4 - HKUS\S-1-5-21-448539723-308236825-682003330-1003\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: GammaTray.lnk = ? O4 - Global Startup: NCProTray.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{AEB397F1-EB51-46EC-8FFF-509B6BE2060C}: NameServer = 130.67.60.68,130.67.15.198 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: MagicTuneEngine - Unknown owner - C:\Programfiler\MagicTune Premium\MagicTuneEngine.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: DiRT Drivers Auto Removal (pr2ah4nc) (pr2ah4nc) - CODEMASTERS - C:\WINDOWS\system32\pr2ah4nc.exe O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -- End of file - 7528 bytes Legger også ved en Roothchk i tilfelle det skulle være noe der: Klikk for å se/fjerne innholdet nedenfor ********************************* ROOTCHK-(28-12-07)-LOG, by ejvindh 23.01.2008 19:55:48,45 The rootkits that are detected by this tool were not found. ********************************* ROOTCHK-LOG-end catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-23 19:55:48 Windows 5.1.2600 Service Pack 2 scanning hidden processes ... IPC error: 2 Systemet finner ikke angitt fil. scanning hidden services & system hive ... IPC error: 2 Systemet finner ikke angitt fil. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:2df9c43f "s2"=dword:110480d0 "h0"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04] "p0"="C:\Programfiler\Alcohol Soft\Alcohol 120\" "h0"=dword:00000001 "ujdew"=hex:e9,93,50,d3,11,e6,16,cf,96,28,dd,97,1a,21,f8,cc,e6,16,b1,50,64,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC] "h0"=dword:00000000 "hdf12"=hex:98,85,47,e1,28,be,02,67,63,2f,44,34,8f,ad,6c,00,5d,f8,c8,2b,20,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Programfiler\DAEMON Tools Lite\" "h0"=dword:00000002 "khjeh"=hex:3b,c0,21,84,0e,c9,c4,5b,90,03,9e,44,c8,db,b5,e5,e3,9c,f9,18,29,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001] "a0"=hex:20,01,00,00,7c,11,90,e7,0d,a9,d5,3f,dc,14,f1,85,60,5c,13,a7,92,.. "khjeh"=hex:8b,b7,57,f7,04,75,d2,f7,3a,27,63,41,51,dd,5b,e1,76,43,45,4e,72,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001Jf40] "khjeh"=hex:b2,21,a4,1c,17,a3,a5,66,6b,49,5c,6c,e6,a1,31,44,16,bf,e3,47,7e,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04] "p0"="C:\Programfiler\Alcohol Soft\Alcohol 120\" "h0"=dword:00000001 "ujdew"=hex:d3,d7,30,e5,9c,39,0e,8c,8b,eb,40,27,eb,a6,24,1a,4f,48,18,f6,18,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC] "h0"=dword:00000000 "hdf12"=hex:98,85,47,e1,28,be,02,67,63,2f,44,34,8f,ad,6c,00,5d,f8,c8,2b,20,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Programfiler\DAEMON Tools Lite\" "h0"=dword:00000002 "khjeh"=hex:3b,c0,21,84,0e,c9,c4,5b,90,03,9e,44,c8,db,b5,e5,e3,9c,f9,18,29,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001] "a0"=hex:20,01,00,00,7c,11,90,e7,0d,a9,d5,3f,dc,14,f1,85,60,5c,13,a7,92,.. "khjeh"=hex:8b,b7,57,f7,04,75,d2,f7,3a,27,63,41,51,dd,5b,e1,76,43,45,4e,72,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA40000001Jf40] "khjeh"=hex:b2,21,a4,1c,17,a3,a5,66,6b,49,5c,6c,e6,a1,31,44,16,bf,e3,47,7e,.. scanning hidden registry entries ... scanning hidden files ... IPC error: 2 Systemet finner ikke angitt fil. hidden processes: 0 hidden services: 0 hidden files: 0 Lenke til kommentar
r2d290 Skrevet 23. januar 2008 Del Skrevet 23. januar 2008 I hijack this, sett fix foran: O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) (kan noen fortelle meg hvorfor jeg ser denne i nesten alle logger?) O4 - HKUS\S-1-5-21-448539723-308236825-682003330-1003\..\Run: [start WingMan Profiler] (User '?') (ikke fix denne før det er blitt bekreftet av noen andre) O17 - HKLM\System\CCS\Services\Tcpip\..\{AEB397F1-EB51-46EC-8FFF-509B6BE2060C}: NameServer = 130.67.60.68,130.67.15.198 (ikke fix denne før det er blitt bekreftet av noen andre) Lenke til kommentar
Tallyho Skrevet 23. januar 2008 Del Skrevet 23. januar 2008 (endret) Ja. Også bør du slette C:\WINDOWS\Nircmd.exe, med mindre det er du selv som har lagt den der. Dette progammet kan brukes til mye rart uten at du merker det: NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface. By running NirCmd with simple command-line option, you can write and delete values and keys in the Registry, write values into INI file, dial to your internet account or connect to a VPN network, restart windows or shut down the computer, create shortcut to a file, change the created/modified date of a file, change your display settings, turn off your monitor, open the door of your CD-ROM drive, and more... Endret 23. januar 2008 av Tallyho Lenke til kommentar
2bb1 Skrevet 23. januar 2008 Forfatter Del Skrevet 23. januar 2008 I hijack this, sett fix foran:O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) (kan noen fortelle meg hvorfor jeg ser denne i nesten alle logger?) O4 - HKUS\S-1-5-21-448539723-308236825-682003330-1003\..\Run: [start WingMan Profiler] (User '?') (ikke fix denne før det er blitt bekreftet av noen andre) O17 - HKLM\System\CCS\Services\Tcpip\..\{AEB397F1-EB51-46EC-8FFF-509B6BE2060C}: NameServer = 130.67.60.68,130.67.15.198 (ikke fix denne før det er blitt bekreftet av noen andre) Ok, fjernet den første nå. Noen som kan bekrefte om jeg skal fjerne de to siste? Ja. Også bør du slette C:\WINDOWS\Nircmd.exe, med mindre det er du selv som har lagt den der. Dette progammet kan brukes til mye rart uten at du merker det: NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface. By running NirCmd with simple command-line option, you can write and delete values and keys in the Registry, write values into INI file, dial to your internet account or connect to a VPN network, restart windows or shut down the computer, create shortcut to a file, change the created/modified date of a file, change your display settings, turn off your monitor, open the door of your CD-ROM drive, and more... Ok, da var det gjort. Takker Lenke til kommentar
norbat Skrevet 23. januar 2008 Del Skrevet 23. januar 2008 (endret) Den første linja (02) er knyttet til messenger live. Kan normalt fjernes uten problemer. Den andre linja (04) er vel knyttet til noe fra Logitech (spillkontroller e.l). Om den har noe funksjon slik den framstår er jeg usikker på. Det tyder på at den ikke er knyttet til noen fil, så jeg vil tro den kan fjernes. (017) er knyttet til din ISP (Telenor). Den lar du være i fred. Endret 23. januar 2008 av norbat Lenke til kommentar
2bb1 Skrevet 23. januar 2008 Forfatter Del Skrevet 23. januar 2008 Må si jeg er litt nysgjerrig på hvordan du i alle dager klarer å se at de tallene der står for MSN, Logitech osv, hehe. Har Logitech G25 (ratt og pedaler), så lar den være i fred ilag med ISP-en. Så resten ser noen lunde ok ut? Lenke til kommentar
Programvare Skrevet 24. januar 2008 Del Skrevet 24. januar 2008 Jeg har kikka gjennom nå og synes at det ser rimelig greit ut nå. Kjører du Ccleaner jevnlig? Lenke til kommentar
2bb1 Skrevet 24. januar 2008 Forfatter Del Skrevet 24. januar 2008 Nei, kun i slike tilfeller hvor jeg spør etter hjelp. Bør jeg kjøre den gjevnlig? Og hvilke områder er det Ccleaner "angriper"? Lenke til kommentar
Programvare Skrevet 24. januar 2008 Del Skrevet 24. januar 2008 Ccleaner bare rensker systemet ditt for masse unødvendige filer osv. En kompis fjerna 4 GB første gang han prøvde det. Tenk deg 4 GB kun med undødvendig søppel! Jeg er blitt skikkelig paranoid for det nå, så jeg kjører det hele tiden. Minst 3-4 ganger i uka. Er ikke nødvenig å kjøre det så ofte hvis du ikke bruker PC-en ekstremt mye da. Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå