Avatar billede tornby Nybegynder
04. juni 2008 - 15:25 Der er 6 kommentarer

Min Dell D820 er begyndt at bruge 100 % CPU

Hej Alle. Jeg er helt ny herinde så i må bære lidt over med mig. ;O). Jeg har en Dell Latitude D820 som er begyndt at bruge 100% CPU kapasitet. Det er ikke en enkelt proces der bruger hele cpu'en men flere som skifter. Jeg startede med at scanne med Norton Internet Security, men den fandt ingenting. Så scannede jeg med Ad-Aware, men den fandt heller ikke noget. Jeg var inde og kikke på flere spørgsmål her på siden men der var ikke rigtigt nogen der virkede. Jeg har vedhæftet en log så jeg håber der er nogen der kan hjælpe.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:19:44, on 04-06-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programmer\Wave Systems Corp\Common\DataServer.exe
C:\Programmer\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\RETROS~1\RETROS~1.0\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
C:\Programmer\WebDrive\wdService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\WebDrive\webdrive.exe
C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\Apoint\HidFind.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
C:\Programmer\Intel\Wireless\bin\ZCfgSvc.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programmer\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Programmer\Dell\QuickSet\Quickset.exe
C:\Programmer\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\Programmer\Fælles filer\Logitech\KHAL\KHALMNPR.EXE
C:\PROGRA~1\RETROS~1\RETROS~1.0\retrospect.exe
C:\WINDOWS\system32\taskmgr.exe
C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmer\Norton Internet Security\Norton AntiVirus\NAVW32.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\cidaemon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/hws/sb/dell-row-rel/da/side.html?channel=dk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.dk/hws/sb/dell-row-rel/da/side.html?channel=dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default.aspx?c=dk&l=da&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.dk/hws/sb/dell-row-rel/da/side.html?channel=dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.dk/ig/dell?hl=da&client=dell-row-rel&channel=dk&ibd=4070417
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programmer\BAE\BAE.dll
O3 - Toolbar: Norton-værktøjslinjen - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WebDriveTray] C:\Programmer\WebDrive\webdrive.exe /trayicon
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Programmer\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.0\RetroExpress.exe /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FÆLLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Programmer\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Document Manager] C:\Programmer\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programmer\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton Internet Security\osCheck.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [] C:\Programmer\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=da&product=SymNRT&version=2008.0.3.16&build=Symantec&a=00000082.00000049.000000b9&b=00000082.00000070.0000014c&c=00000082.00000096.000001d8
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Programmer\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Programmer\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EMBASSY Trust Suite Secure Update.lnk = C:\Programmer\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Status Monitor.lnk = C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparnord.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.geograf.com/viewer/mgaxctrl.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FÆLLES~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Programmer\Wave Systems Corp\Common\DataServer.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Retrospect Express HD Helper (RetroExp Helper) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.0\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.0\retrorun.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Programmer\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
O23 - Service: WebDrive Service (WebDriveService) - South River Technologies, LLC - C:\Programmer\WebDrive\wdService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 14008 bytes
Avatar billede nva Praktikant
04. juni 2008 - 15:52 #1
Følg denne vejledning http://www.eksperten.dk/artikler/1123

Og fix denne linie, hvis den stadig er der

O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
Avatar billede hcma Novice
04. juni 2008 - 18:41 #2
det kunne være noget så simpelt at dine *.avi filer låser og dermed tager al kraft fra din cpu
http://www.hcma.dk/tips61to70.htm#no61
Avatar billede tornby Nybegynder
05. juni 2008 - 10:25 #3
Hej NVA. Det var en ordentlig omgang med en maskine på 100%. Her er lidt resulteter.
Jeg kunne se i artiklen du henviste til, at mit spørgsmål er i den forkerte kategori?
Kan spørgsmålet flyttes eller går det aligevel?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:34:53, on 05-06-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programmer\Wave Systems Corp\Common\DataServer.exe
C:\Programmer\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\RETROS~1\RETROS~1.0\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
C:\Programmer\WebDrive\wdService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Apoint\Apoint.exe
C:\Programmer\WebDrive\webdrive.exe
C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmer\Apoint\HidFind.exe
C:\Programmer\Apoint\Apntex.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\RETROS~1\RETROS~1.0\RetroExpress.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Intel\Wireless\bin\ZCfgSvc.exe
C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programmer\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Programmer\Dell\QuickSet\Quickset.exe
C:\Programmer\Brother\ControlCenter2\brctrcen.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\Programmer\Messenger\msmsgs.exe
C:\PROGRA~1\RETROS~1\RETROS~1.0\retrospect.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\Programmer\Fælles filer\Logitech\KHAL\KHALMNPR.EXE
C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.dk/hws/sb/dell-row-rel/da/side.html?channel=dk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.dk/hws/sb/dell-row-rel/da/side.html?channel=dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default.aspx?c=dk&l=da&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.dk/hws/sb/dell-row-rel/da/side.html?channel=dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.dk/ig/dell?hl=da&client=dell-row-rel&channel=dk&ibd=4070417
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programmer\BAE\BAE.dll
O3 - Toolbar: Norton-værktøjslinjen - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WebDriveTray] C:\Programmer\WebDrive\webdrive.exe /trayicon
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Programmer\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.0\RetroExpress.exe /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FÆLLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Programmer\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Document Manager] C:\Programmer\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programmer\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programmer\Norton Internet Security\osCheck.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [] C:\Programmer\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=da&product=SymNRT&version=2008.0.3.16&build=Symantec&a=00000082.00000049.000000b9&b=00000082.00000070.0000014c&c=00000082.00000096.000001d8
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Programmer\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Programmer\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EMBASSY Trust Suite Secure Update.lnk = C:\Programmer\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Status Monitor.lnk = C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparnord.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.geograf.com/viewer/mgaxctrl.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FÆLLES~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Programmer\Wave Systems Corp\Common\DataServer.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Programmer\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Retrospect Express HD Helper (RetroExp Helper) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.0\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.0\retrorun.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FÆLLES~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Programmer\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
O23 - Service: WebDrive Service (WebDriveService) - South River Technologies, LLC - C:\Programmer\WebDrive\wdService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Programmer\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 14120 bytes


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/04/2008 at 10:19 PM

Application Version : 4.15.1000

Core Rules Database Version : 3473
Trace Rules Database Version: 1464

Scan type      : Complete Scan
Total Scan Time : 04:18:27

Memory items scanned      : 171
Memory threats detected  : 0
Registry items scanned    : 7765
Registry threats detected : 0
File items scanned        : 26468
File threats detected    : 0

ComboFix 08-06-03.1 - Jan Jakobsen 2008-06-05  8:10:33.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1030.18.1274 [GMT 2:00]
Running from: C:\Documents and Settings\Jan Jakobsen\Dokumenter\Software\norton\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Jan Jakobsen\g2mdlhlpx.exe
C:\WINDOWS\3PUPTPQWQattis\10000000099999999999.DLL
C:\WINDOWS\system32\3PUPTPQWQattis\10000000099999999999.DLL
C:\WINDOWS\winhelp.ini

.
(((((((((((((((((((((((((  Files Created from 2008-05-05 to 2008-06-05  )))))))))))))))))))))))))))))))
.

2008-06-04 13:22 . 2008-06-04 13:22    10,344    --a------    C:\WINDOWS\system32\drivers\symlcbrd.sys
2008-06-04 06:59 . 2008-06-04 06:59    <DIR>    d--------    C:\Programmer\Windows Sidebar
2008-06-04 06:58 . 2008-06-04 08:07    <DIR>    d--------    C:\Programmer\Norton Internet Security
2008-06-04 06:55 . 2008-06-04 07:23    123,952    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-04 06:55 . 2008-06-04 07:23    60,800    --a------    C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-04 06:55 . 2008-06-04 07:23    10,671    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-04 06:55 . 2008-06-04 07:23    805    --a------    C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-04 06:52 . 2008-06-04 07:23    <DIR>    d--------    C:\Programmer\Symantec
2008-06-04 06:52 . 2008-06-05 07:48    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-04 06:51 .     <DIR>        C:\Programmer\Fælles filer\Symantec Shared
2008-06-04 06:50 . 2008-06-04 07:01    <DIR>    d--------    C:\Documents and Settings\Jan Jakobsen\Application Data\Symantec
2008-06-04 06:37 . 2008-06-04 06:37    <DIR>    d--------    C:\Programmer\CCleaner
2008-06-04 03:19 . 2008-06-04 03:19    <DIR>    d--------    C:\Programmer\Trend Micro
2008-06-02 18:29 . 2008-06-02 18:29    <DIR>    d--------    C:\Documents and Settings\Jan Jakobsen\DoctorWeb
2008-06-02 17:58 . 2008-06-02 17:58    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-02 17:57 . 2008-06-04 17:51    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-06-02 17:57 . 2008-06-04 16:33    <DIR>    d--------    C:\Documents and Settings\Jan Jakobsen\Application Data\SUPERAntiSpyware.com
2008-05-29 13:28 . 2008-05-29 13:28    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
2008-05-29 13:28 . 2008-05-29 13:28    1,409    --a------    C:\WINDOWS\QTFont.for
2008-05-29 12:25 .     <DIR>        C:\Programmer\Fælles filer\PCSuite
2008-05-29 12:25 .     <DIR>        C:\Programmer\Fælles filer\Nokia
2008-05-29 12:19 . 2008-05-29 12:19    <DIR>    d--------    C:\Programmer\PC Connectivity Solution
2008-05-29 12:19 . 2007-09-17 15:53    21,632    --a------    C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-05-26 17:40 . 2003-07-07 11:20    9,196    ---------    C:\WINDOWS\system32\PNCCoupler.tlb
2008-05-26 15:20 . 2008-06-05 08:13    <DIR>    d--------    C:\WINDOWS\system32\3PUPTPQWQattis
2008-05-26 15:20 . 2008-06-05 08:13    <DIR>    d--------    C:\WINDOWS\3PUPTPQWQattis
2008-05-26 15:20 . 2008-05-26 15:20    <DIR>    d--hs----    C:\AX NF ZZ
2008-05-26 14:33 . 2008-05-26 14:33    0    --a------    C:\WINDOWS\s7alibxx.INI
2008-05-26 14:19 . 2005-06-07 15:37    70,912    --a------    C:\WINDOWS\system32\drivers\s7snsrtx.sys
2008-05-26 13:23 . 2005-08-05 12:13    114,688    --a------    C:\WINDOWS\system32\s7ncmins.dll
2008-05-26 13:10 . 2004-12-07 12:14    268,288    --a------    C:\WINDOWS\system32\drivers\dpmconv.sys
2008-05-26 13:10 . 2004-12-07 12:09    168,006    --a------    C:\WINDOWS\system32\dpc2lib.dll
2008-05-26 13:10 . 2004-12-07 12:11    155,728    --a------    C:\WINDOWS\system32\dplib.dll
2008-05-26 13:10 . 2004-12-07 12:10    139,342    --a------    C:\WINDOWS\system32\dpmc2lib.dll
2008-05-26 13:10 . 2004-12-07 12:09    131,147    --a------    C:\WINDOWS\system32\dpc1lib.dll
2008-05-26 13:10 . 2004-12-07 12:09    122,955    --a------    C:\WINDOWS\system32\dpmilib.dll
2008-05-26 13:10 . 2004-11-12 16:15    80,896    --a------    C:\WINDOWS\system32\drivers\vsnl2ada.sys
2008-05-26 13:10 . 2002-02-12 13:44    49,152    --a------    C:\WINDOWS\system32\dpmiresb.dll
2008-05-26 13:10 . 2004-12-07 12:08    49,152    --a------    C:\WINDOWS\system32\dpmiresa.dll
2008-05-26 13:09 . 2002-08-28 12:26    495,669    --a------    C:\WINDOWS\system32\S7OINTFX.dll
2008-05-26 13:09 . 2004-03-01 14:08    233,472    --a------    C:\WINDOWS\system32\s7esetdx.dll
2008-05-26 13:09 . 2002-08-28 12:20    110,645    --a------    C:\WINDOWS\system32\s7wcaotx.dll
2008-05-26 13:09 . 2002-08-28 12:22    69,685    --a------    C:\WINDOWS\system32\S7OTBLEX.dll
2008-05-26 13:09 . 2000-02-09 14:08    40,960    --a------    C:\WINDOWS\system32\MelbReg.dll
2008-05-26 13:09 . 1999-11-05 14:27    33,280    --a------    C:\WINDOWS\system32\s7erwlcx.dll
2008-05-26 13:05 . 2008-05-29 21:29    <DIR>    d--------    C:\WINDOWS\Setup
2008-05-26 13:04 . 2008-05-29 21:32    14,182    --a------    C:\WINDOWS\citamis.str
2008-05-26 12:58 . 2008-05-26 12:58    <DIR>    d--------    C:\Temp
2008-05-22 21:26 . 2008-05-22 21:26    1,964    --a------    C:\zMMPSCADA.ASC
2008-05-22 21:26 . 2008-05-22 21:26    1,601    --a------    C:\zVARLIST.CSV
2008-05-19 17:31 . 2008-05-19 17:31    32    --a------    C:\WINDOWS\Wmbbil.INI
2008-05-19 17:24 . 2003-11-06 06:08    1,076,876    ---------    C:\WINDOWS\system32\C60RUNX.DLL
2008-05-19 17:24 . 2003-11-04 17:10    89,088    ---------    C:\WINDOWS\system32\C60TPSX.DLL
2008-05-19 17:24 . 2003-11-01 14:34    62,464    ---------    C:\WINDOWS\system32\C60basx.dll
2008-05-19 17:24 . 2003-11-01 13:34    51,712    ---------    C:\WINDOWS\system32\C60ascx.dll
2008-05-19 17:24 . 2003-11-01 13:34    44,032    ---------    C:\WINDOWS\system32\C60dosx.dll
2008-05-06 09:22 . 1999-04-15 13:10    424,960    ---------    C:\WINDOWS\system32\msms001.vwp
2008-05-06 09:22 . 1999-10-30 02:36    281,600    ---------    C:\WINDOWS\system32\mvoice.vwp
2008-05-06 09:22 . 1999-10-30 02:36    278,016    ---------    C:\WINDOWS\system32\vct3216.dll
2008-05-06 09:22 . 1999-10-30 02:36    82,944    ---------    C:\WINDOWS\system32\vct3216.acm
2008-05-06 09:22 . 2000-03-16 00:56    69,632    ---------    C:\WINDOWS\system32\voxmsdec.ax
2008-05-06 09:22 . 1999-04-15 13:10    56,320    ---------    C:\WINDOWS\system32\voxmvdec.ax

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-05 05:28    ---------    d-----w    C:\Documents and Settings\Jan Jakobsen\Application Data\Wave Systems Corp
2008-06-05 05:28    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\RetroExp
2008-06-04 14:32    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-06-03 05:28    ---------    d-----w    C:\Programmer\UltraVNC
2008-05-29 10:18    ---------    d-----w    C:\Programmer\Nokia
2008-05-29 10:16    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Installations
2008-05-28 18:44    ---------    d-----w    C:\Documents and Settings\Jan Jakobsen\Application Data\U3
2008-05-21 10:39    ---------    d-----w    C:\Programmer\Microsoft Silverlight
2008-05-18 20:32    ---------    d-----w    C:\Programmer\WebDrive
2008-05-08 08:41    ---------    d--h--w    C:\Programmer\InstallShield Installation Information
2008-04-23 11:56    ---------    d-----w    C:\Programmer\Fælles filer\Adobe
2008-04-23 06:20    ---------    d-----w    C:\Programmer\IMSIDesign
2008-04-23 06:20    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\IMSIDesign
2008-04-22 21:16    ---------    d-----w    C:\Documents and Settings\Jan Jakobsen\Application Data\skypePM
2008-04-22 21:16    ---------    d-----w    C:\Documents and Settings\Jan Jakobsen\Application Data\Skype
2008-04-21 22:40    ---------    d-----w    C:\Programmer\Fælles filer\Sonic Shared
2008-04-20 21:11    ---------    d--h--w    C:\Programmer\Zenographics
2008-04-20 21:11    ---------    d-----w    C:\Programmer\Hewlett-Packard
2008-04-18 07:18    ---------    d-----w    C:\Programmer\DivX
2008-04-17 12:10    663,552    ------w    C:\WINDOWS\system32\wdResDll.dll
2008-04-17 12:09    630,784    ------w    C:\WINDOWS\system32\wdnp32.dll
2008-04-17 12:09    3,375,104    ------w    C:\WINDOWS\system32\wdHelper.dll
2008-04-17 12:09    2,228,224    ------w    C:\WINDOWS\system32\wdShellExt.dll
2008-04-17 12:08    69,632    ------w    C:\WINDOWS\system32\wdIconDll.dll
2008-04-17 12:08    237,568    ------w    C:\WINDOWS\system32\wdUIResDll.dll
2008-04-16 10:28    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-15 16:39    ---------    d-----w    C:\Programmer\Microsoft Works
2008-04-11 11:09    ---------    d-----w    C:\Documents and Settings\Jan Jakobsen\Application Data\FileZilla
2008-04-06 17:45    ---------    d-----w    C:\Documents and Settings\Jan Jakobsen\Application Data\VoipStunt
2008-04-05 17:30    ---------    d-----w    C:\Programmer\VoipStunt.com
2008-03-31 21:25    831,488    ------w    C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25    823,296    ------w    C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25    823,296    ------w    C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25    802,816    ------w    C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25    682,496    ------w    C:\WINDOWS\system32\DivX.dll
2008-03-31 21:25    161,096    ------w    C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-21 20:30    524,288    ------w    C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30    3,596,288    ------w    C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30    200,704    ------w    C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30    1,044,480    ------w    C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28    81,920    ------w    C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28    593,920    ------w    C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28    57,344    ------w    C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28    53,248    ------w    C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28    344,064    ------w    C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28    294,912    ------w    C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28    294,912    ------w    C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28    196,608    ------w    C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28    12,288    ------w    C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-20 08:09    1,845,248    ------w    C:\WINDOWS\system32\win32k.sys
2008-03-12 11:10    633,344    ------w    C:\WINDOWS\system32\gpprefcl.dll
2008-03-06 09:14    831,048    ----a-w    C:\WINDOWS\system32\WudfUpdate_01005.dll
2008-02-19 11:11    32    ----a-w    C:\Documents and Settings\All Users\Application Data\ezsid.dat
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
            C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
            C:\PROGRA~1\FÆLLES~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll" [ ]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Programmer\Fælles filer\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [ ]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\WebDrive1]
@={04466240-beb3-11d1-be1c-00aa006b77f4}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\WebDrive2]
@={37D70BD3-073C-4180-ADD9-C032EA5A7204}

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"LDM"="C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-10-30 09:47 67128]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00 15360]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 17:51 1506544]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"@"="C:\Programmer\Internet Explorer\iexplore.exe" [2008-02-29 10:54 625664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-19 09:14 7401472]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-27 13:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Apoint"="C:\Programmer\Apoint\Apoint.exe" [2005-10-07 13:13 176128]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"WebDriveTray"="C:\Programmer\WebDrive\webdrive.exe" [2008-04-17 14:10 3088384]
"TomTomHOME.exe"="C:\Programmer\TomTom HOME 2\HOMERunner.exe" [2007-10-31 11:19 378784]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
"RetroExpress"="C:\PROGRA~1\RETROS~1\RETROS~1.0\RetroExpress.exe" [2007-01-18 13:02 9371648]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"nwiz"="nwiz.exe" [2006-01-19 09:14 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-01-19 09:14 86016 C:\WINDOWS\system32\nvmctray.dll]
"NVHotkey"="nvHotkey.dll" [2006-01-19 09:14 73728 C:\WINDOWS\system32\nvhotkey.dll]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 28160 C:\WINDOWS\KHALMNPR.Exe]
"ISUSScheduler"="C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [ ]
"ISUSPM Startup"="C:\PROGRA~1\FÆLLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"IntelZeroConfig"="C:\Programmer\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 19:04 802816]
"IntelWireless"="C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 18:58 696320]
"DVDLauncher"="C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 21:29 49152]
"Document Manager"="C:\Programmer\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2006-09-08 09:32 102400]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"Dell QuickSet"="C:\Programmer\Dell\QuickSet\Quickset.exe" [2006-06-29 13:13 1032192]
"ControlCenter2.0"="C:\Programmer\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 09:34 851968]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" [ ]
"osCheck"="C:\Programmer\Norton Internet Security\osCheck.exe" [2007-08-24 22:53 714608]
"combofix"="C:\WINDOWS\system32\CF11426.exe" [2004-08-27 13:00 391168]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 13:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FÆLLES~1\MICROS~1\DW\dwtrig20.exe" [ ]
"Nokia.PCSync"="C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IETI"="C:\Programmer\Skype\Phone\IEPlugin\unins000.exe" [ ]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Digital Line Detect.lnk - C:\Programmer\Digital Line Detect\DLG.exe [2007-04-17 04:39:55 24576]
EMBASSY Trust Suite Secure Update.lnk - C:\Programmer\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe [2006-08-25 10:45:30 192512]
Logitech Desktop Messenger.lnk - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-10-30 09:47:15 67128]
Logitech SetPoint.lnk - C:\Programmer\Logitech\SetPoint\SetPoint.exe [2007-04-30 21:45:35 450560]
Status Monitor.lnk - C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe [2007-07-06 08:21:52 819200]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Programmer\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2008-06-04 17:50 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wxvault.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages    REG_MULTI_SZ      msv1_0 wvauth

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Programmer\\Retrospect\\Retrospect Express HD 2.0\\Retrospect.exe"=
"C:\\Programmer\\Retrospect\\Retrospect Express HD 2.0\\retrorun.exe"=
"C:\\Programmer\\WebDrive\\webdrive.exe"=
"C:\\Programmer\\WebDrive\\wdService.exe"=
"C:\\Programmer\\VoipStunt.com\\VoipStunt\\VoipStunt.exe"=
"C:\\Programmer\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration
"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery

R0 PBADRV;PBADRV;C:\WINDOWS\system32\drivers\pbadrv.sys [2005-12-09 16:35]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 Peakcan;Peakcan;C:\WINDOWS\system32\drivers\Peakcan.sys [2006-09-22 11:10]
R2 s7snsrtx;PROFINET IO RT-Protocol;C:\WINDOWS\system32\DRIVERS\s7snsrtx.sys [2005-06-07 15:37]
R2 WebDriveFSD;WebDrive File System Driver;C:\Programmer\WebDrive\wdfsd.sys [2008-04-16 12:19]
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-31 11:49]
S2 SNTIE;SIMATIC Industrial Ethernet (ISO);C:\WINDOWS\system32\DRIVERS\sntie.sys []
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 GT72NDISIPXP;GT 72 IP NDIS;C:\WINDOWS\system32\DRIVERS\Gt51Ip.sys [2007-07-09 14:17]
S3 GT72UBUS;GT 72 U BUS;C:\WINDOWS\system32\DRIVERS\gt72ubus.sys [2007-06-26 13:38]
S3 GTPTSER;GT PT SER;C:\WINDOWS\system32\DRIVERS\gtptser.sys [2007-03-30 13:38]
S3 htsxhci;NComputing UTMA USB Host Controller;C:\WINDOWS\system32\DRIVERS\htsxhci.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be504fc6-00c9-11dd-9cbd-001a6b3023c3}]
\Shell\AutoRun\command - E:\setup.exe AUTORUN=1

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-06-04 05:02:46 C:\WINDOWS\Tasks\Norton Internet Security - Kør Fuld systemskanning - Jan Jakobsen.job"
Avatar billede nva Praktikant
06. juni 2008 - 10:52 #4
Det er faktisk ikke noget 'snavs' at se i din log. Du kan prøve at scanne din harddisk for fejl ved at gå i 'denne computer - h-klik på drev - egenskaber - funktioner - undersøg nu' og markere at alle fejl skal rettes. Tjek også i enhedshåndtering at IDE/ATAPI IKKE står som PIO i 'nuværende overførselstilstand'
Avatar billede hcma Novice
06. juni 2008 - 11:15 #5
har du prøvet:  Kommentar: hcma    04/06-2008 18:41:47
Avatar billede tornby Nybegynder
06. juni 2008 - 22:53 #6
Hej nva. Jeg tror det var harddisken. Det hjalp at scanne disken for fejl. Nu ser det ud til at fungere igen. Tak for hjælpen. Hvordan får du poingene? Skal jeg gøre noget?

Hej hcma. Nej jeg fik ikke prøvet dit råd.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester