Avatar billede a-class Nybegynder
02. februar 2008 - 13:59 Der er 18 kommentarer

services.exe tager al min cpu-kraft

I Windows Jobliste er der en proces: services.exe. Den rykker ca. hvert 10. sekund op mod toppen af listen og bruger omkring 60-87% af cpu-kraften. Er det en virus? Jeg har downloadet TrojanHunter og fjernet hvad den fandt, men det har ikke hjulpet.Hvad kan jeg gøre?
02. februar 2008 - 14:45 #1
... for en go' ordens skyld; stik os/mig en HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)

------------------
02. februar 2008 - 14:46 #2
Velkommen til Eksperten.dk
Generelt -> http://expfaq.dk/
Avatar billede a-class Nybegynder
02. februar 2008 - 18:09 #3
HiJackThis logfil. Håber der kan findes noget?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:05:26, on 02-02-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe
C:\Programmer\Digidesign\Drivers\MMERefresh.exe
C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe
C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\Ahead\InCD\InCD.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\CyberLink\PCM4Everio\EverioService.exe
C:\Programmer\Logitech\Gaming Software\LWEMon.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Nikon\PictureProject\NkbMonitor.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\TrojanHunter 5.0\THGuard.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Downloads\0 efter 080201\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Norton-værktøjslinjen - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FÆLLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EverioService] "C:\Programmer\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Programmer\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Programmer\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [{FD1C41EC-B9AC-4F08-9BDB-CC8ECC8FC1B3}] "C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = ? (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Programmer\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-BF4DBB38B8E7} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på den mobile enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://130.228.229.80/homeskyline/TEInstall/TE.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.30/uploader2.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) - http://foto.tdconline.dk/upload-classes/Uploader.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://titan.tv2.dk/sre/ICSScanner.cab
O16 - DPF: {9C196458-4145-46AF-8A77-1506878DFECA} (FirstClass® Control) - ftp://ftp.sektornet.dk/sektornet/skolekom/fcplugin.cab
O16 - DPF: {B4CB50E4-0309-4906-86EA-10B6641C8392} (SlimClient Class) - https://titan.tv2.dk/SNX/CSHELL/extender.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O18 - Protocol: fcp - {B3133379-8789-4D3C-9593-C205D7297501} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Check Point SSL Network Extender (cpextender) - Check Point Software Technologies - C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Programmer\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Programmer\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: MacDriveServiceD - Mediafour Corporation - C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: (no name) - http://soundlution.dk/index-filer/image403.jpg

--
End of file - 13354 bytes
Avatar billede a-class Nybegynder
02. februar 2008 - 18:10 #4
Hov, det skulle vist sendes som kommentar -

HiJackThis logfil. Håber der kan findes noget?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:05:26, on 02-02-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe
C:\Programmer\Digidesign\Drivers\MMERefresh.exe
C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe
C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\Ahead\InCD\InCD.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\CyberLink\PCM4Everio\EverioService.exe
C:\Programmer\Logitech\Gaming Software\LWEMon.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Nikon\PictureProject\NkbMonitor.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\TrojanHunter 5.0\THGuard.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Downloads\0 efter 080201\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Norton-værktøjslinjen - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FÆLLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EverioService] "C:\Programmer\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Programmer\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Programmer\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [{FD1C41EC-B9AC-4F08-9BDB-CC8ECC8FC1B3}] "C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = ? (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Programmer\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-BF4DBB38B8E7} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på den mobile enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://130.228.229.80/homeskyline/TEInstall/TE.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.30/uploader2.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) - http://foto.tdconline.dk/upload-classes/Uploader.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://titan.tv2.dk/sre/ICSScanner.cab
O16 - DPF: {9C196458-4145-46AF-8A77-1506878DFECA} (FirstClass® Control) - ftp://ftp.sektornet.dk/sektornet/skolekom/fcplugin.cab
O16 - DPF: {B4CB50E4-0309-4906-86EA-10B6641C8392} (SlimClient Class) - https://titan.tv2.dk/SNX/CSHELL/extender.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O18 - Protocol: fcp - {B3133379-8789-4D3C-9593-C205D7297501} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Check Point SSL Network Extender (cpextender) - Check Point Software Technologies - C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Programmer\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Programmer\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: MacDriveServiceD - Mediafour Corporation - C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: (no name) - http://soundlution.dk/index-filer/image403.jpg

--
End of file - 13354 bytes
02. februar 2008 - 22:09 #5
Hmmm...

... Nu er det ikke alle (u)ønskede elementer som viser sig med en HiJackThis Log; så gennemfør proceduren herfra -> http://www.eksperten.dk/artikler/1123
Avatar billede a-class Nybegynder
03. februar 2008 - 12:49 #6
HJT+Combofix+Rootchk og SuperAntiSpyware-logs. Håber det giver mening for kloge mennesker?



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:23, on 03-02-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe
C:\Programmer\Digidesign\Drivers\MMERefresh.exe
C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe
C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe
C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
C:\Programmer\Ahead\InCD\InCD.exe
C:\Programmer\Dell\Media Experience\DMXLauncher.exe
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\CyberLink\PCM4Everio\EverioService.exe
C:\Programmer\Logitech\Gaming Software\LWEMon.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Nikon\PictureProject\NkbMonitor.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Programmer\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\Programmer\Symantec\LiveUpdate\AUPDATE.EXE
C:\Programmer\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programmer\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programmer\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programmer\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programmer\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Downloads\0 efter 080201\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Norton-værktøjslinjen - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Programmer\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EverioService] "C:\Programmer\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Programmer\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Programmer\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [{FD1C41EC-B9AC-4F08-9BDB-CC8ECC8FC1B3}] "C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Programmer\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-BF4DBB38B8E7} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på den mobile enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://130.228.229.80/homeskyline/TEInstall/TE.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.30/uploader2.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) - http://foto.tdconline.dk/upload-classes/Uploader.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://titan.tv2.dk/sre/ICSScanner.cab
O16 - DPF: {9C196458-4145-46AF-8A77-1506878DFECA} (FirstClass® Control) - ftp://ftp.sektornet.dk/sektornet/skolekom/fcplugin.cab
O16 - DPF: {B4CB50E4-0309-4906-86EA-10B6641C8392} (SlimClient Class) - https://titan.tv2.dk/SNX/CSHELL/extender.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O18 - Protocol: fcp - {B3133379-8789-4D3C-9593-C205D7297501} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Check Point SSL Network Extender (cpextender) - Check Point Software Technologies - C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Programmer\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Programmer\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmer\Fælles filer\EPSON\EBAPI\SAgent2.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: MacDriveServiceD - Mediafour Corporation - C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: (no name) - http://soundlution.dk/index-filer/image403.jpg

--
End of file - 13424 bytes









ComboFix 08-02.03.1 - Peter Aclass 2008-02-03 11:47:02.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.1539 [GMT 1:00]
Running from: C:\Downloads\0 efter 080201\Problemløsere\ComboFix\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

----- BITS: Possible infected sites -----

hxxp://www.download.windowsupdate.com
.
(((((((((((((((((((((((((  Files Created from 2008-01-03 to 2008-02-03  )))))))))))))))))))))))))))))))
.

2008-02-03 00:47 . 2008-02-03 11:35    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-02-03 00:47 . 2008-02-03 00:47    <DIR>    d--------    C:\Documents and Settings\Peter Aclass\Application Data\SUPERAntiSpyware.com
2008-02-03 00:47 . 2008-02-03 00:47    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-03 00:37 . 2008-02-03 00:37    <DIR>    d--------    C:\Programmer\CCleaner
2008-02-02 14:22 . 2008-02-02 14:22    <DIR>    d--------    C:\Programmer\Lavasoft
2008-02-02 14:22 . 2008-02-02 14:22    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-02 13:24 . 2008-02-02 13:24    <DIR>    d--------    C:\Documents and Settings\Peter Aclass\Application Data\TrojanHunter
2008-02-02 12:19 . 2008-02-02 12:19    <DIR>    d--------    C:\Programmer\TrojanHunter 5.0
2008-01-26 13:42 . 2008-01-26 13:42    <DIR>    d--------    C:\Programmer\Mediafour
2008-01-26 13:42 . 2008-01-26 13:42    <DIR>    d--------    C:\Programmer\Fælles filer\Mediafour
2008-01-26 13:42 . 2008-01-26 13:42    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Mediafour
2008-01-26 13:34 . 2008-01-26 13:34    <DIR>    d--------    C:\Programmer\Fælles filer\Avid
2008-01-26 13:31 . 2007-10-31 02:12    2,545,766    --a------    C:\WINDOWS\system32\dgfwdio.dll
2008-01-26 13:31 . 2007-10-30 23:03    270,336    --a------    C:\WINDOWS\system32\DigiPlatformSupport.dll
2008-01-26 13:31 . 2006-03-29 15:11    233,472    --a------    C:\WINDOWS\system32\REX Shared Library.dll
2008-01-26 13:31 . 2007-10-31 02:15    24,080    --a------    C:\WINDOWS\system32\drivers\dgfwboot.sys
2008-01-26 13:31 . 2007-10-31 02:16    16,400    --a------    C:\WINDOWS\system32\drivers\diginet.sys
2008-01-26 13:28 . 2008-01-26 13:28    <DIR>    d--------    C:\Documents and Settings\Peter Aclass\Application Data\InstallShield
2008-01-22 19:20 . 2008-01-22 19:20    <DIR>    d--------    C:\Programmer\Windows Sidebar
2008-01-22 19:18 . 2008-01-23 08:12    <DIR>    d--------    C:\Programmer\Norton Internet Security
2008-01-22 19:16 . 2008-01-23 08:03    123,952    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-22 19:16 . 2008-01-23 08:03    60,800    --a------    C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-22 19:16 . 2008-01-23 08:03    10,740    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-22 19:16 . 2008-01-23 08:03    805    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-14 19:49 . 2008-01-14 19:49    <DIR>    d--------    C:\BRKP080113
2008-01-11 23:25 . 2008-01-11 23:25    <DIR>    d--------    C:\Programmer\iTunes
2008-01-11 23:25 . 2008-01-11 23:25    <DIR>    d--------    C:\Programmer\iPod
2008-01-11 23:25 . 2008-02-03 10:44    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
2008-01-11 23:25 . 2008-01-11 23:25    1,409    --a------    C:\WINDOWS\QTFont.for
2008-01-11 23:23 . 2008-01-11 23:24    <DIR>    d--------    C:\Programmer\QuickTime

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-03 10:48    ---------    d-----w    C:\Programmer\Fælles filer\Symantec Shared
2008-02-03 09:58    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-02 23:47    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-02-02 17:28    ---------    d-----w    C:\Documents and Settings\Peter Aclass\Application Data\Digidesign
2008-02-02 10:50    ---------    d-----w    C:\Documents and Settings\Peter Aclass\Application Data\Lavasoft
2008-01-26 12:40    54,256    ----a-w    C:\WINDOWS\system32\drivers\iLokDrvr.sys
2008-01-26 12:34    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2008-01-26 12:31    ---------    d-----w    C:\Programmer\Digidesign
2008-01-26 07:18    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-23 07:03    ---------    d-----w    C:\Programmer\Symantec
2008-01-22 18:25    ---------    d-----w    C:\Documents and Settings\Peter Aclass\Application Data\Symantec
2008-01-15 08:54    10,537    ----a-w    C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 04:28    706    ----a-w    C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-12 17:32    23,904    ----a-w    C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-14 10:32    12,632    ----a-w    C:\WINDOWS\system32\lsdelete.exe
2007-11-07 09:28    723,456    ----a-w    C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:28    723,456    ------w    C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-06-29 19:12    20    ---ha-w    C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2005-05-11 21:36    12,288    ----a-w    C:\WINDOWS\Fonts\RandFont.dll
2007-02-24 17:01    61    --sh--w    C:\WINDOWS\cnerolf.dat
2006-07-09 09:51    80    --sh--r    C:\WINDOWS\system32\24B743E8C0.dll
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 20:51    316784    --a------    C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-01-31 09:08    116088    --a------    C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 20:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{FD8348AB-D74A-4C76-B2FE-926FF6D7CC40}]
@=MacDrive Volume Icons

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 12:00 15360]
"H/PC Connection Agent"="C:\Programmer\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 18:17 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05 344064]
"IntelWireless"="C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59 385024]
"Dell QuickSet"="C:\Programmer\Dell\QuickSet\quickset.exe" [2005-03-04 11:26 606208]
"Apoint"="C:\Programmer\Apoint\Apoint.exe" [2004-09-13 16:33 155648]
"ISUSScheduler"="C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"InCD"="C:\Programmer\Ahead\InCD\InCD.exe" [2006-03-23 17:06 1398272]
"DMXLauncher"="C:\Programmer\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 01:01 86016]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
"EverioService"="C:\Programmer\CyberLink\PCM4Everio\EverioService.exe" [2006-11-22 20:10 151552]
"Start WingMan Profiler"="C:\Programmer\Logitech\Gaming Software\LWEMon.exe" [2007-09-25 15:03 93208]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" [2007-08-24 22:07 51048]
"osCheck"="C:\Programmer\Norton Internet Security\osCheck.exe" [2007-08-24 21:53 714608]
"DigidesignMMERefresh"="C:\Programmer\Digidesign\Drivers\MMERefresh.exe" [2007-10-31 00:35 77824]
"{FD1C41EC-B9AC-4F08-9BDB-CC8ECC8FC1B3}"="C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe" [2007-04-18 13:27 159744]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 12:00 15360]
"Picasa Media Detector"="C:\Programmer\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Digital Line Detect.lnk - C:\Programmer\Digital Line Detect\DLG.exe [2005-10-28 01:53:53 24576]
NkbMonitor.exe.lnk - C:\Programmer\Nikon\PictureProject\NkbMonitor.exe [2007-01-23 20:27:47 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Programmer\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Programmer\Intel\Wireless\Bin\LgNotify.dll

R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-12-08 22:50]
R0 MDFSYSNT;MacDrive file system driver;C:\WINDOWS\system32\drivers\MDFSYSNT.sys [2007-04-18 16:33]
R0 MDPMGRNT;MDPMGRNT;C:\WINDOWS\system32\drivers\MDPMGRNT.sys [2007-02-28 11:15]
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2005-10-19 16:39]
R2 cpextender;Check Point SSL Network Extender;C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe [2006-09-12 18:14]
R2 DigiNet;Digidesign Ethernet Support;C:\WINDOWS\system32\DRIVERS\diginet.sys [2007-10-31 02:16]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe" [2007-08-24 22:07]
R2 MacDriveServiceD;MacDriveServiceD;"C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe" [2007-04-18 11:58]
R3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 17:27]
R3 VNA;Check Point Virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\vna.sys [2006-09-12 18:14]
S1 aiptektp;HyperPen;C:\WINDOWS\system32\DRIVERS\aiptektp.sys []
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-31 11:49]
S3 2fa048a3-7d17-41cb-bd1a-2cdde7a1ddad;2fa048a3-7d17-41cb-bd1a-2cdde7a1ddad;D:\Player\cds300.dll []
S3 dalwdmservice;dal service;C:\WINDOWS\system32\drivers\dalwdm.sys [2007-10-31 02:15]
S3 iLokDrvr;iLok;C:\WINDOWS\system32\DRIVERS\iLokDrvr.sys [2008-01-26 13:40]
S3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;C:\WINDOWS\system32\drivers\mbx2midk.sys [2006-11-13 14:37]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 17:27]
S3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;C:\WINDOWS\system32\drivers\usb22ldr.sys [2005-11-15 22:32]
S3 USBMN2X2;M-Audio USB MidiSport 2x2;C:\WINDOWS\system32\drivers\usbmn2x2.sys [2005-11-15 22:32]
S4 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 23:07]

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-22 18:29:01 C:\WINDOWS\Tasks\Norton Internet Security - Kør Fuld systemskanning - Peter Aclass.job"
- C:\Programmer\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
"2008-02-03 10:29:03 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Programmer\Symantec\LiveUpdate\NDetect.exe
"2008-02-02 12:04:34 C:\WINDOWS\Tasks\User_Feed_Synchronization-{FC920BF5-6290-44B5-A814-2AFCA0A93C70}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 11:48:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-03 11:49:22
ComboFix-quarantined-files.txt  2008-02-03 10:49:02
.
2008-01-09 18:34:54    --- E O F --- 









********************************* ROOTCHK-(28-12-07)-LOG, by ejvindh
03-02-2008 11:32:32.35

NOTICE!! Rootchk is not being updated anymore, and is thus gradually getting outdated.
Last update was made 28-12-07

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 11:32:32
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
IPC error: 2 Den angivne fil blev ikke fundet.

scanning hidden services & system hive ...
IPC error: 2 Den angivne fil blev ikke fundet.

scanning hidden registry entries ...

scanning hidden files ...
IPC error: 2 Den angivne fil blev ikke fundet.

hidden processes: 0
hidden services: 0
hidden files: 0









SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/03/2008 at 02:09 AM

Application Version : 3.7.1018

Core Rules Database Version : 3394
Trace Rules Database Version: 1386

Scan type      : Complete Scan
Total Scan Time : 01:00:40

Memory items scanned      : 196
Memory threats detected  : 0
Registry items scanned    : 8127
Registry threats detected : 0
File items scanned        : 38402
File threats detected    : 0
03. februar 2008 - 14:10 #7
Hmmm...

Prøv denne kommando for at rette fejlen:

Indsæt din WindowsXP Cd i drevet
Luk det vindue som popper op.

Gå i start - kør - skriv: sfc /scannow
Tast enter
Windows Cd skal ligge i drevet under denne kommando.
Du vil ikke få en tilbagemelding om noget er rettet.
Det mellemrum mellem sfc / skal være der.
Avatar billede a-class Nybegynder
03. februar 2008 - 15:19 #8
Det ændrede desværre ingenting.
Jeg har lige set at svchost.exe er også oppe på ca.40% cpu hvert 10.sekund. Men det er svært at fange de rpcesser der giver udslagene da det går rasende hurtigt.
Da jeg skulle køre SuperAntiSpyware var jeg jo i fejlsikret tilstand. Her var der ikke disse udslag i Joblisten. Giver det nogle flere spor at gå efter?
Jeg er meget glad for den hjælp jeg får.
Avatar billede fromsej Praktikant
03. februar 2008 - 21:43 #9
Åbn Stifinder, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

Upload denne fil hos Jotti eller Virustotal:
C:\WINDOWS\system32\24B743E8C0.dll
http://virusscan.jotti.org/ http://www.virustotal.com/
Fortæl resultatet.

Jeg vil ikke være her meget i den næste uges tid.
03. februar 2008 - 22:14 #10
* enig med <Fromsej> ... *
Avatar billede a-class Nybegynder
04. februar 2008 - 07:31 #11
JOTTI:
File:  24B743E8C0.dll 
Status:  OK 
MD5:  89116419560c453177ff66e38135df93 
Packers detected:  -
Bit9 reports:  File not found 

VIRUS TOTAL:
File 24B743E8C0.dll received on 02.04.2008 07:05:27 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


Result: 0/32 (0%)


Øv.
Jobliste ser stadig sådan ud:

http://webdisk.tdconline.dk/index.php?m=c9ae77e8&a=7d397569&r=965358696&share=LNK501047a6b084df21a
Avatar billede fromsej Praktikant
04. februar 2008 - 08:50 #12
Medmindre du bruger genskrivelige CD/DVDér, så afinstaller NeroInCD i Tilføj/fjern programmer.
---------------------------------------
Åbn et Notesblokvindue, kopiér indholdet mellem de bølgede linier ind i dokumentet, og gem indholdet i samme mappe, som Combofix ligger med navnet CFScript.txt. Når du gemmer, skal du sikre, at der under "filtyper" står "alle filer".

~~~~~~~~~~~~~~~~~~~~~~~~~~

Killall::

File::
C:\WINDOWS\system32\24B743E8C0.dll

~~~~~~~~~~~~~~~~~~~~~~~~~~
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
---------------------------------------

Vi skal se en frisk hijackthislog, samt den nye combofixlog.

Hvis det ikke hjælper, så prøv at sætte iPod-tjeneste (iPod Service) til manuel start.
Klik på Start->Kør skriv Services.msc og klik OK.
Find Tjenesten iPod-tjeneste (iPod Service) stop den hvis den kører, højreklik på den, klik på Egenskaber og vælg Starttype Manuel.
Avatar billede a-class Nybegynder
04. februar 2008 - 10:01 #13
Så får jeg beskeden:"You cannot rename ComboFix as ComboFix. Please use another name" hvorefter Combofix lukker ned?
Avatar billede fromsej Praktikant
04. februar 2008 - 13:43 #14
Prøv i fejlsikret.
Avatar billede a-class Nybegynder
04. februar 2008 - 18:55 #15
Super, det hjalp. Hvordan bliver man så klog:-)
Her er combofix loggen:

ComboFix 08-02.03.1 - Peter aclass 2008-02-04 18:27:49.2 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1030.18.1848 [GMT 1:00]
Running from: C:\Downloads\0 efter 080201\Problemløsere\ComboFix\ComboFix.exe
Command switches used :: C:\Downloads\0 efter 080201\Problemløsere\ComboFix\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\24B743E8C0.dll
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\24B743E8C0.dll

.
(((((((((((((((((((((((((  Files Created from 2008-01-04 to 2008-02-04  )))))))))))))))))))))))))))))))
.

2008-02-04 08:29 . 2005-10-19 08:34    15,872    --a------    C:\WINDOWS\system32\drivers\LaCieUSBFilter.sys
2008-02-04 08:29 . 2008-02-04 08:29    631    --a------    C:\WINDOWS\UndeviceUpd
2008-02-04 08:28 . 2008-02-04 08:28    <DIR>    d--------    C:\Programmer\LaCieTools
2008-02-04 08:28 . 2005-10-18 07:28    14,848    --a------    C:\WINDOWS\system32\drivers\LaCieFWFilter.sys
2008-02-03 15:00 . 2004-08-26 17:53    116,224    --a------    C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-02-03 15:00 . 2001-08-18 06:37    99,865    --a------    C:\WINDOWS\system32\dllcache\xlog.exe
2008-02-03 15:00 . 2001-10-04 17:07    27,648    --a------    C:\WINDOWS\system32\dllcache\xrxftplt.exe
2008-02-03 15:00 . 2001-10-04 17:07    23,040    --a------    C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2008-02-03 15:00 . 2004-08-03 22:29    19,455    --a------    C:\WINDOWS\system32\dllcache\wvchntxx.sys
2008-02-03 15:00 . 2001-10-04 17:07    17,408    --a------    C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-02-03 15:00 . 2001-08-17 20:11    16,970    --a------    C:\WINDOWS\system32\dllcache\xem336n5.sys
2008-02-03 15:00 . 2004-08-03 22:29    12,063    --a------    C:\WINDOWS\system32\dllcache\wsiintxx.sys
2008-02-03 15:00 . 2004-08-26 17:53    8,192    --a------    C:\WINDOWS\system32\dllcache\wshirda.dll
2008-02-03 15:00 . 2001-10-04 17:07    4,608    --a------    C:\WINDOWS\system32\dllcache\xrxflnch.exe
2008-02-03 14:58 . 2001-08-17 21:28    794,654    --a------    C:\WINDOWS\system32\dllcache\usr1801.sys
2008-02-03 14:57 . 2001-10-04 17:07    525,568    --a------    C:\WINDOWS\system32\dllcache\tridxp.dll
2008-02-03 14:56 . 2001-10-04 17:07    440,576    --a------    C:\WINDOWS\system32\dllcache\tridkb.dll
2008-02-03 14:55 . 2001-10-04 16:28    285,760    --a------    C:\WINDOWS\system32\dllcache\stlnata.sys
2008-02-03 14:54 . 2004-08-27 12:00    461,312    --a------    C:\WINDOWS\system32\dllcache\smtpsvc.dll
2008-02-03 14:53 . 2004-08-03 22:41    404,990    --a------    C:\WINDOWS\system32\dllcache\slntamr.sys
2008-02-03 14:52 . 2001-10-04 17:07    386,560    --a------    C:\WINDOWS\system32\dllcache\sgiul50.dll
2008-02-03 14:51 . 2001-10-04 17:06    495,616    --a------    C:\WINDOWS\system32\dllcache\sblfx.dll
2008-02-03 14:50 . 2001-10-04 16:47    899,274    --a------    C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-02-03 14:49 . 2004-08-26 17:53    363,520    --a------    C:\WINDOWS\system32\dllcache\psisdecd.dll
2008-02-03 14:48 . 2001-08-17 22:05    351,616    --a------    C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-02-03 14:47 . 2001-08-17 20:50    198,144    --a------    C:\WINDOWS\system32\dllcache\nv3.sys
2008-02-03 14:46 . 2004-08-26 17:53    1,737,856    --a------    C:\WINDOWS\system32\dllcache\mtxparhd.dll
2008-02-03 14:45 . 2001-10-04 16:34    320,384    --a------    C:\WINDOWS\system32\dllcache\mgaum.sys
2008-02-03 14:44 . 2001-08-17 21:28    802,683    --a------    C:\WINDOWS\system32\dllcache\ltsm.sys
2008-02-03 14:43 . 2001-10-04 17:07    242,176    --a------    C:\WINDOWS\system32\dllcache\kdsusd.dll
2008-02-03 14:42 . 2004-08-03 22:41    1,041,536    --a------    C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2008-02-03 14:41 . 2001-08-17 21:28    542,879    --a------    C:\WINDOWS\system32\dllcache\hsf_msft.sys
2008-02-03 14:40 . 2001-10-04 17:07    1,733,120    --a------    C:\WINDOWS\system32\dllcache\g400d.dll
2008-02-03 14:39 . 2001-10-04 16:45    629,952    --a------    C:\WINDOWS\system32\dllcache\eqn.sys
2008-02-03 14:38 . 2001-08-17 20:14    952,007    --a------    C:\WINDOWS\system32\dllcache\diwan.sys
2008-02-03 14:37 . 2001-10-04 17:07    618,525    --a------    C:\WINDOWS\system32\dllcache\digiview.exe
2008-02-03 14:36 . 2001-10-04 16:34    980,034    --a------    C:\WINDOWS\system32\dllcache\cicap.sys
2008-02-03 14:35 . 2001-08-17 21:28    871,388    --a------    C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-02-03 14:34 . 2004-08-26 17:53    870,784    --a------    C:\WINDOWS\system32\dllcache\ati3d1ag.dll
2008-02-03 14:33 . 2004-05-13 00:39    876,653    --a------    C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-02-03 00:47 . 2008-02-03 11:35    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-02-03 00:47 . 2008-02-03 00:47    <DIR>    d--------    C:\Documents and Settings\Peter aclass\Application Data\SUPERAntiSpyware.com
2008-02-03 00:47 . 2008-02-03 00:47    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-03 00:37 . 2008-02-03 00:37    <DIR>    d--------    C:\Programmer\CCleaner
2008-02-02 14:22 . 2008-02-02 14:22    <DIR>    d--------    C:\Programmer\Lavasoft
2008-02-02 14:22 . 2008-02-02 14:22    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-02 13:24 . 2008-02-02 13:24    <DIR>    d--------    C:\Documents and Settings\Peter aclass\Application Data\TrojanHunter
2008-02-02 12:19 . 2008-02-02 12:19    <DIR>    d--------    C:\Programmer\TrojanHunter 5.0
2008-01-26 13:42 . 2008-01-26 13:42    <DIR>    d--------    C:\Programmer\Mediafour
2008-01-26 13:42 .     <DIR>        C:\Programmer\Fælles filer\Mediafour
2008-01-26 13:42 . 2008-01-26 13:42    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Mediafour
2008-01-26 13:34 .     <DIR>        C:\Programmer\Fælles filer\Avid
2008-01-26 13:31 . 2007-10-31 02:12    2,545,766    --a------    C:\WINDOWS\system32\dgfwdio.dll
2008-01-26 13:31 . 2007-10-30 23:03    270,336    --a------    C:\WINDOWS\system32\DigiPlatformSupport.dll
2008-01-26 13:31 . 2006-03-29 15:11    233,472    --a------    C:\WINDOWS\system32\REX Shared Library.dll
2008-01-26 13:31 . 2007-10-31 02:15    24,080    --a------    C:\WINDOWS\system32\drivers\dgfwboot.sys
2008-01-26 13:31 . 2007-10-31 02:16    16,400    --a------    C:\WINDOWS\system32\drivers\diginet.sys
2008-01-26 13:28 . 2008-01-26 13:28    <DIR>    d--------    C:\Documents and Settings\Peter aclass\Application Data\InstallShield
2008-01-22 19:20 . 2008-01-22 19:20    <DIR>    d--------    C:\Programmer\Windows Sidebar
2008-01-22 19:18 . 2008-01-23 08:12    <DIR>    d--------    C:\Programmer\Norton Internet Security
2008-01-22 19:16 . 2008-01-23 08:03    123,952    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-22 19:16 . 2008-01-23 08:03    60,800    --a------    C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-22 19:16 . 2008-01-23 08:03    10,740    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-22 19:16 . 2008-01-23 08:03    805    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-14 19:49 . 2008-01-14 19:49    <DIR>    d--------    C:\BRKP080113
2008-01-11 23:25 . 2008-01-11 23:25    <DIR>    d--------    C:\Programmer\iTunes
2008-01-11 23:25 . 2008-01-11 23:25    <DIR>    d--------    C:\Programmer\iPod
2008-01-11 23:25 . 2008-02-04 18:40    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
2008-01-11 23:25 . 2008-01-11 23:25    1,409    --a------    C:\WINDOWS\QTFont.for
2008-01-11 23:23 . 2008-01-11 23:24    <DIR>    d--------    C:\Programmer\QuickTime

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-04 11:44    ---------    d-----w    C:\Programmer\Fælles filer\Symantec Shared
2008-02-04 10:14    ---------    d-----w    C:\Documents and Settings\Peter aclass\Application Data\Digidesign
2008-02-04 05:51    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-02 23:47    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-02-02 10:50    ---------    d-----w    C:\Documents and Settings\Peter aclass\Application Data\Lavasoft
2008-01-26 12:40    54,256    ----a-w    C:\WINDOWS\system32\drivers\iLokDrvr.sys
2008-01-26 12:34    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2008-01-26 12:31    ---------    d-----w    C:\Programmer\Digidesign
2008-01-26 07:18    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-23 07:03    ---------    d-----w    C:\Programmer\Symantec
2008-01-22 18:25    ---------    d-----w    C:\Documents and Settings\Peter aclass\Application Data\Symantec
2008-01-15 08:54    10,537    ----a-w    C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 04:28    706    ----a-w    C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-12 17:32    23,904    ----a-w    C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-06-29 19:12    20    ---ha-w    C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-02-24 17:01    61    --sh--w    C:\WINDOWS\cnerolf.dat
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
            C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
            C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [ ]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{FD8348AB-D74A-4C76-B2FE-926FF6D7CC40}]
@=MacDrive Volume Icons

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 12:00 15360]
"H/PC Connection Agent"="C:\Programmer\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 18:17 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05 344064]
"IntelWireless"="C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59 385024]
"Dell QuickSet"="C:\Programmer\Dell\QuickSet\quickset.exe" [2005-03-04 11:26 606208]
"Apoint"="C:\Programmer\Apoint\Apoint.exe" [2004-09-13 16:33 155648]
"ISUSScheduler"="C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"InCD"="C:\Programmer\Ahead\InCD\InCD.exe" [2006-03-23 17:06 1398272]
"DMXLauncher"="C:\Programmer\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 01:01 86016]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
"EverioService"="C:\Programmer\CyberLink\PCM4Everio\EverioService.exe" [2006-11-22 20:10 151552]
"Start WingMan Profiler"="C:\Programmer\Logitech\Gaming Software\LWEMon.exe" [2007-09-25 15:03 93208]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" [ ]
"osCheck"="C:\Programmer\Norton Internet Security\osCheck.exe" [2007-08-24 21:53 714608]
"DigidesignMMERefresh"="C:\Programmer\Digidesign\Drivers\MMERefresh.exe" [2007-10-31 00:35 77824]
"{FD1C41EC-B9AC-4F08-9BDB-CC8ECC8FC1B3}"="C:\Programmer\Mediafour\MacDrive 7\MacDriveD.exe" [2007-04-18 13:27 159744]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 12:00 15360]
"Picasa Media Detector"="C:\Programmer\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Digital Line Detect.lnk - C:\Programmer\Digital Line Detect\DLG.exe [2005-10-28 01:53:53 24576]
NkbMonitor.exe.lnk - C:\Programmer\Nikon\PictureProject\NkbMonitor.exe [2007-01-23 20:27:47 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Programmer\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Programmer\Intel\Wireless\Bin\LgNotify.dll

R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-12-08 22:50]
R0 MDFSYSNT;MacDrive file system driver;C:\WINDOWS\system32\drivers\MDFSYSNT.sys [2007-04-18 16:33]
R0 MDPMGRNT;MDPMGRNT;C:\WINDOWS\system32\drivers\MDPMGRNT.sys [2007-02-28 11:15]
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2005-10-19 16:39]
R2 cpextender;Check Point SSL Network Extender;C:\Programmer\CheckPoint\SSL Network Extender\slimsvc.exe [2006-09-12 18:14]
R2 DigiNet;Digidesign Ethernet Support;C:\WINDOWS\system32\DRIVERS\diginet.sys [2007-10-31 02:16]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe" []
R2 MacDriveServiceD;MacDriveServiceD;"C:\Programmer\Mediafour\MacDrive 7\MacDriveServiceD.exe" [2007-04-18 11:58]
R3 LaCieFWFilter;Silver 1394 Filter (1394 BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieFWFilter.sys [2005-10-18 07:28]
R3 LaCieUSBFilter;Silver USB Filter (USB BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieUSBFilter.sys [2005-10-19 08:34]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 17:27]
R3 VNA;Check Point Virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\vna.sys [2006-09-12 18:14]
S1 aiptektp;HyperPen;C:\WINDOWS\system32\DRIVERS\aiptektp.sys []
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-31 11:49]
S3 2fa048a3-7d17-41cb-bd1a-2cdde7a1ddad;2fa048a3-7d17-41cb-bd1a-2cdde7a1ddad;D:\Player\cds300.dll []
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 dalwdmservice;dal service;C:\WINDOWS\system32\drivers\dalwdm.sys [2007-10-31 02:15]
S3 iLokDrvr;iLok;C:\WINDOWS\system32\DRIVERS\iLokDrvr.sys [2008-01-26 13:40]
S3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;C:\WINDOWS\system32\drivers\mbx2midk.sys [2006-11-13 14:37]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 17:27]
S3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;C:\WINDOWS\system32\drivers\usb22ldr.sys []
S3 USBMN2X2;M-Audio USB MidiSport 2x2;C:\WINDOWS\system32\drivers\usbmn2x2.sys []
S4 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 23:07]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-22 18:29:01 C:\WINDOWS\Tasks\Norton Internet Security - Kør Fuld systemskanning - Peter aclass.job"
Avatar billede fromsej Praktikant
05. februar 2008 - 17:11 #16
Din log er ren, har det ændret noget ved problemet?
Avatar billede a-class Nybegynder
05. februar 2008 - 22:58 #17
De peaks der var før er der stadig med samme interval, men nu peaker de på ca.50%. Det er jo meget bedre. Jeg synes dog maskinen er blevet meget langsom til at åbne programmer og logge på/af.
En af mine venner sagde jeg kunne prøve at køre en ProcessExplorer. Da jeg gjorde det kunne jeg bedre pinpointe den svchost.exe som ser ud til at have en del med balladen at gøre. På dette link kan man se hvilke services den står for:

http://webdisk.tdconline.dk/index.php?m=c9ae77e8&a=7d397569&r=632401491&share=LNK536347a8d90e1835c

Jeg prøvede at trykke "suspend" på den og væk var de grimme peaks, men måske har jeg bare været tæt på at slukke for alt?

Problemet for mig er at jeg bruger denne computer i mit daglige arbejde for en landsdækkende radiostation og disse peaks sluger så meget kraft at jeg mister min forbindelse til ekstern hardisk (forsinket skrivning til...mislykket).
Så jeg vil stadig blive mere glad hvis der kunne vendes endnu et par sten. Dette er bestemt ikke for at være utaknemmelig. Jeg synes allerede jeg har fået mere hjælp end jeg turde håbe på.
Avatar billede fromsej Praktikant
06. februar 2008 - 07:02 #18
Højreklik på "problembarnet", vælg Properties, skift til fanebladet Services.
Så kommer listen frem, her kan du prøve at stoppe en Service af gangen, til du rammer den der laver det udsving.
Det værste der kan ske, er at maskinen genstarter.

Du kan lige prøve dette:
Klik på Start->Kør skriv SFC /scannow(bemærk mellemrum), klik OK.
Din XP-CD skal sidde i drevet.
Genstart, se om det hjalp.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester