Her er loggerne.
Disken i drev C er -Cram01-
Diskens serienummer er E02D-2F9E
Indhold af C:\Documents and Settings\Administrator\Application Data
22-05-2005 22:57 <DIR> Identities
0 fil(er) 0 byte
1 mappe(r) 159.978.803.200 byte ledig
Disken i drev C er -Cram01-
Diskens serienummer er E02D-2F9E
Indhold af C:\Documents and Settings\All Users\Application Data
19-10-2005 13:56 <DIR> Adobe
06-11-2005 22:19 <DIR> idolbikelongdrv
20-06-2005 16:24 <DIR> McAfee.com
13-10-2005 14:10 <DIR> Skype
07-11-2005 16:35 <DIR> Spybot - Search & Destroy
20-06-2005 17:10 <DIR> Symantec
31-07-2005 16:57 <DIR> Windows Genuine Advantage
0 fil(er) 0 byte
7 mappe(r) 159.978.799.104 byte ledig
Disken i drev C er -Cram01-
Diskens serienummer er E02D-2F9E
Indhold af C:\Documents and Settings\Marc Thomson\Application Data
07-09-2005 22:03 <DIR> .bittorrent
19-10-2005 13:56 <DIR> Adobe
01-11-2005 15:39 <DIR> AdobeUM
15-08-2005 02:55 <DIR> Ascaron Entertainment
12-10-2005 22:22 <DIR> ATI
26-07-2005 11:41 <DIR> Black Sea Studios
10-09-2005 20:56 <DIR> Gearbox Software
23-05-2005 02:02 <DIR> GlobalSCAPE
28-06-2005 21:02 <DIR> Help
22-05-2005 23:02 <DIR> Identities
07-11-2005 07:48 <DIR> IDS_COMPANY
04-06-2005 19:45 <DIR> Lavasoft
01-06-2005 21:23 <DIR> Leadertech
23-05-2005 02:30 <DIR> Logitech
23-05-2005 02:01 <DIR> Macromedia
18-10-2005 10:50 <DIR> Media Player Classic
23-05-2005 01:42 <DIR> Mozilla
30-10-2005 13:59 <DIR> My Games
07-11-2005 16:11 <DIR> site flap face
16-10-2005 13:38 <DIR> Skype
23-05-2005 16:40 <DIR> Sun
20-06-2005 16:38 <DIR> Symantec
23-05-2005 01:42 <DIR> Talkback
08-07-2005 02:13 <DIR> teamspeak2
23-05-2005 01:45 <DIR> Thunderbird
06-11-2005 23:39 <DIR> Ventrilo
0 fil(er) 0 byte
26 mappe(r) 159.978.799.104 byte ledig
Disken i drev C er -Cram01-
Diskens serienummer er E02D-2F9E
Indhold af C:\Documents and Settings\Default User\Application Data
23-05-2005 00:37 <DIR> .
23-05-2005 00:37 <DIR> ..
23-05-2005 00:37 62 desktop.ini
1 fil(er) 62 byte
2 mappe(r) 159.978.799.104 byte ledig
Disken i drev C er -Cram01-
Diskens serienummer er E02D-2F9E
Indhold af C:\Documents and Settings\LocalService\Application Data
Disken i drev C er -Cram01-
Diskens serienummer er E02D-2F9E
Indhold af C:\Documents and Settings\NetworkService\Application Data
[TRACE] Enumerating jobs and queues
[TRACE] Activating job 'B128DBB5919F52C1.job'
[TRACE] Printing all job properties
ApplicationName: 'c:\docume~1\marcth~1\applic~1\sitefl~1\Heart hole bore.exe'
Parameters: ''
WorkingDirectory: ''
Comment: ''
Creator: 'Marc Thomson'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 11/07/2005 16:00:00
NextRun: 11/07/2005 23:00:00
StartError: 0x80070002
ExitCode: 0
Status: SCHED_S_TASK_READY
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 1
TaskFlags: 0
1 Trigger
Trigger 0:
Type: Daily
DaysInterval: 1
StartDate: 02/09/2000
EndDate: 00/00/0000
StartTime: 00:00
MinutesDuration: 1440
MinutesInterval: 60
Flags:
HasEndDate = 0
KillAtDuration = 0
Disabled = 0
Ad-Aware og Avast er stoppet med at registrere programmet.
Men jeg kan selv se ting der stadigvæk ikke er renset.
01: 07-11-2005 16:11 <DIR> site flap face
02: ApplicationName: 'c:\docume~1\marcth~1\applic~1\sitefl~1\Heart hole bore.exe'
Så er der andre jeg ikke ved hvad er?
01: 07-11-2005 07:48 <DIR> IDS_COMPANY
02: 01-06-2005 21:23 <DIR> Leadertech
03: 23-05-2005 01:42 <DIR> Talkback
Her er den nye HJT:
Logfile of HijackThis v1.99.1
Scan saved at 22:27:41, on 07-11-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\Java\jre1.5.0_02\bin\jusched.exe
C:\Programmer\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\Programmer\Fælles filer\Logitech\KHAL\KHALMNPR.EXE
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
E:\-Cram World-\Internet\Anti spyware\Virus\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.altavista.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.altavista.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [LiveMonitor] C:\Programmer\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmer\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [CaAvTray] "C:\Programmer\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Programmer\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Programmer\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) -
http://gamingzone.ubisoft.com/dev/packages/GSManager.cabO16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1116799274812O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125085653718O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Programmer\SiSoftware\SiSoftware Sandra Professional 2005.SR2a\RpcSandraSrv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Håber den er ren.
Der er dog andre ting jeg ikke ved hvordan man slipper af med.
O4 - HKLM\..\Run: [CaAvTray] "C:\Programmer\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Programmer\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
Disse tre entries har jeg prøvet at slippe af med da programmeren ikke er installeret mere.
Så er der en manglende fil.
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)