Avatar billede targa55 Praktikant
04. september 2008 - 21:27 Der er 10 kommentarer og
1 løsning

Check af log

Er der en der vil checke disse logs.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06:08, on 04-09-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Glocalnet\Bredbandscenter\BredbandscenterUpdater.exe
C:\Programmer\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\StartupMonitor.exe
C:\Programmer\Trust\MI-7500X Wireless Laser Mouse\Mouse32a.exe
C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programmer\Glocalnet\Bredbandscenter\Launcher.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\ClocX\ClocX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Programmer\Vista Start Menu\VistaStartMenu.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\FreeNote\FreeNote.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Jan\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\Philips\VOIP321\VOIP321.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmer\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jan\Skrivebord\HiJackThis.exe
C:\WINDOWS\System32\HPZipm12.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - :C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Programmer\Trust\MI-7500X Wireless Laser Mouse\Mouse32a.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Bredbandscenter] "C:\Programmer\Glocalnet\Bredbandscenter\Launcher.exe" /winstart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ClocX] C:\Programmer\ClocX\ClocX.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [VistaStartMenu] "C:\Programmer\Vista Start Menu\VistaStartMenu.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [FreeNote] C:\Programmer\FreeNote\FreeNote.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Jan\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VOIP321.lnk = C:\Programmer\Philips\VOIP321\VOIP321.exe
O4 - Global Startup: ~Disabled
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.danicapension.dk
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187907598203
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220538399968
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netpension.danicapension.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F9F8BC4-8D36-4DCB-99B6-55B5EDB8263F}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: BredbandscenterDownloader - Glocalnet AB - C:\Programmer\Glocalnet\Bredbandscenter\BredbandscenterUpdater.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Programmer\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe
O24 - Desktop Component 0: (no name) - http://www.avast.com/eng/images/maincn_middle.gif

--
End of file - 10328 bytes

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/04/2008 at 08:54 PM

Application Version : 4.20.1046

Core Rules Database Version : 3556
Trace Rules Database Version: 1544

Scan type      : Complete Scan
Total Scan Time : 00:41:20

Memory items scanned      : 446
Memory threats detected  : 0
Registry items scanned    : 5897
Registry threats detected : 0
File items scanned        : 31339
File threats detected    : 14

Adware.Tracking Cookie
    C:\Documents and Settings\Jan\Cookies\jan@adtech[3].txt
    C:\Documents and Settings\Jan\Cookies\jan@advertising[3].txt
    C:\Documents and Settings\Jan\Cookies\jan@track.adform[3].txt
    C:\Documents and Settings\Jan\Cookies\jan@2o7[1].txt
    C:\Documents and Settings\Jan\Cookies\jan@ad.zanox[2].txt
    C:\Documents and Settings\Jan\Cookies\jan@adtech[2].txt
    C:\Documents and Settings\Jan\Cookies\jan@advertising[2].txt
    C:\Documents and Settings\Jan\Cookies\jan@atdmt[2].txt
    C:\Documents and Settings\Jan\Cookies\jan@doubleclick[1].txt
    C:\Documents and Settings\Jan\Cookies\jan@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Jan\Cookies\jan@stat.swedbank[1].txt
    C:\Documents and Settings\Jan\Cookies\jan@track.adform[2].txt
    C:\Documents and Settings\Jan\Cookies\jan@viasatsatelliteservices.112.2o7[1].txt
    C:\Documents and Settings\Jan\Cookies\jan@www.googleadservices[1].txt


ComboFix 08-09-03.06 - Jan 2008-09-04 19:53:32.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1030.18.479 [GMT 2:00]
Running from: C:\Documents and Settings\Jan\Skrivebord\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\MSINET.oca

.
(((((((((((((((((((((((((  Files Created from 2008-08-04 to 2008-09-04  )))))))))))))))))))))))))))))))
.

2008-09-04 17:19 . 2008-09-04 17:19    <DIR>    d--------    C:\WINDOWS\system32\CatRoot2
2008-09-04 16:21 . 2008-07-18 22:09    29,896    --a------    C:\WINDOWS\system32\wuapi.dll.mui
2008-09-01 00:19 . 2008-09-02 15:17    <DIR>    d--------    C:\Programmer\FreeNote
2008-08-31 23:08 . 2008-04-14 18:05    116,224    --a--c---    C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-08-31 23:08 . 2008-04-13 20:46    19,200    --a--c---    C:\WINDOWS\system32\dllcache\wstcodec.sys
2008-08-31 23:08 . 2008-04-14 18:05    18,944    --a--c---    C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-08-31 23:08 . 2008-04-14 18:05    8,192    --a--c---    C:\WINDOWS\system32\dllcache\wshirda.dll
2008-08-31 23:07 . 2008-04-14 18:05    54,272    --a--c---    C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-08-31 23:07 . 2008-04-14 17:37    32,000    --a--c---    C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-08-31 23:07 . 2008-04-13 20:45    26,112    --a--c---    C:\WINDOWS\system32\dllcache\usbser.sys
2008-08-31 23:07 . 2008-04-13 20:45    17,152    --a--c---    C:\WINDOWS\system32\dllcache\usbohci.sys
2008-08-31 23:07 . 2008-04-13 20:36    8,832    --a--c---    C:\WINDOWS\system32\dllcache\wmiacpi.sys
2008-08-31 23:07 . 2008-04-13 20:40    5,376    --a--c---    C:\WINDOWS\system32\dllcache\viaide.sys
2008-08-31 23:06 . 2008-04-13 20:40    149,376    --a--c---    C:\WINDOWS\system32\dllcache\tffsport.sys
2008-08-31 23:06 . 2008-04-14 18:06    82,944    --a--c---    C:\WINDOWS\system32\dllcache\tp4mon.exe
2008-08-31 23:06 . 2008-04-13 20:46    15,232    --a--c---    C:\WINDOWS\system32\dllcache\streamip.sys
2008-08-31 23:05 . 2008-04-13 20:40    43,904    --a--c---    C:\WINDOWS\system32\dllcache\sbp2port.sys
2008-08-31 23:05 . 2008-04-13 20:36    16,000    --a--c---    C:\WINDOWS\system32\dllcache\smbbatt.sys
2008-08-31 23:05 . 2008-04-13 20:45    11,520    --a--c---    C:\WINDOWS\system32\dllcache\scsiscan.sys
2008-08-31 23:05 . 2008-04-13 20:46    11,136    --a--c---    C:\WINDOWS\system32\dllcache\slip.sys
2008-08-31 23:05 . 2008-04-13 20:40    7,552    --a--c---    C:\WINDOWS\system32\dllcache\sonyait.sys
2008-08-31 23:05 . 2008-04-13 20:36    6,912    --a--c---    C:\WINDOWS\system32\dllcache\smbclass.sys
2008-08-31 23:03 . 2008-04-14 17:44    2,068,480    --a--c---    C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-31 23:03 . 2008-04-13 20:46    85,248    --a--c---    C:\WINDOWS\system32\dllcache\nabtsfec.sys
2008-08-31 23:03 . 2008-04-13 20:54    28,672    --a--c---    C:\WINDOWS\system32\dllcache\nscirda.sys
2008-08-31 23:03 . 2008-04-13 20:44    27,904    --a--c---    C:\WINDOWS\system32\dllcache\perm2.sys
2008-08-31 23:03 . 2008-04-13 20:46    10,880    --a--c---    C:\WINDOWS\system32\dllcache\ndisip.sys
2008-08-31 23:02 . 2008-04-14 18:06    56,832    --a--c---    C:\WINDOWS\system32\dllcache\msdvbnp.ax
2008-08-31 23:02 . 2008-04-13 20:46    51,200    --a--c---    C:\WINDOWS\system32\dllcache\msdv.sys
2008-08-31 23:02 . 2008-04-13 20:46    49,024    --a--c---    C:\WINDOWS\system32\dllcache\mstape.sys
2008-08-31 23:02 . 2008-04-13 20:41    26,112    --a--c---    C:\WINDOWS\system32\dllcache\memstpci.sys
2008-08-31 23:02 . 2008-04-13 20:54    22,016    --a--c---    C:\WINDOWS\system32\dllcache\msircomm.sys
2008-08-31 23:02 . 2008-04-13 20:46    15,232    --a--c---    C:\WINDOWS\system32\dllcache\mpe.sys
2008-08-31 23:02 . 2008-04-13 20:39    5,504    --a--c---    C:\WINDOWS\system32\dllcache\mstee.sys
2008-08-31 23:00 . 2008-04-14 18:05    702,845    --a--c---    C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2008-08-31 23:00 . 2008-04-13 20:41    18,560    --a--c---    C:\WINDOWS\system32\dllcache\i2omp.sys
2008-08-31 23:00 . 2008-04-13 20:41    8,576    --a--c---    C:\WINDOWS\system32\dllcache\i2omgmt.sys
2008-08-31 22:59 . 2008-04-13 20:45    59,136    --a--c---    C:\WINDOWS\system32\dllcache\gckernel.sys
2008-08-31 22:59 . 2008-04-14 17:38    28,416    --a--c---    C:\WINDOWS\system32\dllcache\grserial.sys
2008-08-31 22:59 . 2008-04-13 20:36    20,352    --a--c---    C:\WINDOWS\system32\dllcache\hidbatt.sys
2008-08-31 22:59 . 2008-04-13 20:45    10,624    --a--c---    C:\WINDOWS\system32\dllcache\gameenum.sys
2008-08-31 22:58 . 2008-04-13 20:39    206,976    --a--c---    C:\WINDOWS\system32\dllcache\dot4.sys
2008-08-31 22:58 . 2008-04-14 18:06    20,992    --a--c---    C:\WINDOWS\system32\dllcache\dshowext.ax
2008-08-31 22:58 . 2008-04-13 20:40    8,320    --a--c---    C:\WINDOWS\system32\dllcache\dlttape.sys
2008-08-31 22:57 . 2008-04-14 18:05    250,880    --a--c---    C:\WINDOWS\system32\dllcache\ctmasetp.dll
2008-08-31 22:57 . 2008-04-14 18:05    121,856    --a--c---    C:\WINDOWS\system32\dllcache\camext30.dll
2008-08-31 22:57 . 2008-04-13 20:46    17,024    --a--c---    C:\WINDOWS\system32\dllcache\ccdecode.sys
2008-08-31 22:57 . 2008-04-13 20:36    13,952    --a--c---    C:\WINDOWS\system32\dllcache\cmbatt.sys
2008-08-31 22:57 . 2008-04-13 20:36    10,240    --a--c---    C:\WINDOWS\system32\dllcache\compbatt.sys
2008-08-31 22:57 . 2008-04-13 20:40    8,192    --a--c---    C:\WINDOWS\system32\dllcache\changer.sys
2008-08-31 22:56 . 2008-04-13 20:46    38,912    --a--c---    C:\WINDOWS\system32\dllcache\avc.sys
2008-08-31 22:56 . 2008-04-14 18:06    18,432    --a--c---    C:\WINDOWS\system32\dllcache\bdaplgin.ax
2008-08-31 22:56 . 2008-04-13 20:36    14,208    --a--c---    C:\WINDOWS\system32\dllcache\battc.sys
2008-08-31 22:56 . 2008-04-13 20:46    13,696    --a--c---    C:\WINDOWS\system32\dllcache\avcstrm.sys
2008-08-31 22:56 . 2008-04-13 20:46    11,776    --a--c---    C:\WINDOWS\system32\dllcache\bdasup.sys
2008-08-31 22:55 . 2008-04-14 17:45    2,191,616    --a--c---    C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-31 22:55 . 2008-04-13 20:46    48,128    --a--c---    C:\WINDOWS\system32\dllcache\61883.sys
2008-08-31 22:55 . 2008-04-13 20:40    12,288    --a--c---    C:\WINDOWS\system32\dllcache\4mmdat.sys
2008-08-31 11:12 . 2008-08-31 11:13    <DIR>    d--------    C:\Programmer\ClocX
2008-08-31 10:54 . 2008-09-01 00:07    <DIR>    d--------    C:\Programmer\KeyKeeper
2008-08-31 10:48 . 2008-08-31 10:48    <DIR>    d--------    C:\Programmer\ABF software
2008-08-31 10:48 . 2008-08-31 10:48    97    --a------    C:\WINDOWS\CSS.key
2008-08-12 22:56 . 2008-08-12 22:56    <DIR>    d--------    C:\WINDOWS\system32\da
2008-08-12 22:56 . 2008-08-12 22:56    <DIR>    d--------    C:\WINDOWS\l2schemas
2008-08-12 22:03 . 2008-04-14 18:05    1,306,624    ---------    C:\WINDOWS\system32\msxml6.dll
2008-08-09 13:25 . 2004-05-14 16:53    462,848    --a------    C:\WINDOWS\system32\ltkrn13n.dll
2008-08-09 13:25 . 2004-05-14 16:53    450,560    --a------    C:\WINDOWS\system32\ltimg13n.dll
2008-08-09 13:25 . 2004-05-14 16:53    401,408    --a------    C:\WINDOWS\system32\lfcmp13n.dll
2008-08-09 13:25 . 2004-05-14 16:53    299,008    --a------    C:\WINDOWS\system32\ltdis13n.dll
2008-08-09 13:25 . 2004-01-12 02:09    206,336    --a------    C:\WINDOWS\system32\ltefx13n.dll
2008-08-09 13:25 . 2004-05-14 16:53    163,840    --a------    C:\WINDOWS\system32\ltfil13n.dll
2008-08-09 13:25 . 2003-11-04 15:10    69,632    --a------    C:\WINDOWS\system32\lfgif13n.dll
2008-08-09 13:25 . 2004-05-14 16:53    57,344    --a------    C:\WINDOWS\system32\lfbmp13n.dll
2008-08-07 08:03 . 2008-08-07 08:03    <DIR>    d--------    C:\Programmer\iTunes
2008-08-07 08:03 . 2008-08-07 08:03    <DIR>    d--------    C:\Programmer\iPod
2008-08-07 08:03 . 2008-08-07 08:04    <DIR>    d--------    C:\Programmer\Apple Software Update
2008-08-07 08:02 . 2008-08-07 08:02    <DIR>    d--------    C:\Programmer\Bonjour
2008-08-07 07:59 . 2008-08-07 07:59    <DIR>    d--------    C:\Programmer\Safari
2008-08-07 07:58 . 2008-08-07 07:58    <DIR>    d--------    C:\Programmer\QuickTime

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-04 17:49    ---------    d-----w    C:\Documents and Settings\Jan\Application Data\Skype
2008-09-04 17:31    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-04 17:30    ---------    d-----w    C:\Programmer\Spybot - Search & Destroy
2008-09-04 15:52    ---------    d-----w    C:\Documents and Settings\Jan\Application Data\Vista Start Menu
2008-09-04 15:13    ---------    d-----w    C:\Documents and Settings\Jan\Application Data\skypePM
2008-09-04 10:16    156,713    -c--a-w    C:\WINDOWS\system32\drivers\fwdrv.err
2008-09-02 14:16    ---------    d-----w    C:\Programmer\SUPERAntiSpyware
2008-09-02 14:15    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-09-02 14:09    ---------    d-----w    C:\Documents and Settings\Jan\Application Data\MSN6
2008-08-25 22:39    ---------    d-----w    C:\Programmer\HP
2008-08-05 11:21    ---------    d-----w    C:\Documents and Settings\Jan\Application Data\Image Zone Express
2008-08-02 21:17    ---------    d-----w    C:\Programmer\Lavasoft
2008-08-02 21:08    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-24 09:19    ---------    d-----w    C:\Programmer\Yahoo!
2008-07-18 20:10    94,920    ----a-w    C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10    53,448    ----a-w    C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10    45,768    ----a-w    C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10    36,552    ----a-w    C:\WINDOWS\system32\wups.dll
2008-07-18 20:09    563,912    ----a-w    C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09    325,832    ----a-w    C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09    1,811,656    ----a-w    C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07    210,976    ----a-w    C:\WINDOWS\system32\muweb.dll
2008-07-18 12:37    ---------    d-----w    C:\Programmer\Hewlett-Packard
2008-07-18 12:22    ---------    d-----w    C:\Programmer\Fælles filer\HP
2008-07-18 10:09    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Sonic
2008-07-18 09:58    ---------    d-----w    C:\Programmer\MultiKeyboard Driver
2008-07-15 18:07    ---------    d-----w    C:\Programmer\Skype
2008-07-15 18:07    ---------    d-----w    C:\Programmer\Fælles filer\Skype
2008-07-15 18:07    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Skype
2008-07-15 17:33    ---------    d-----w    C:\Programmer\Philips
2008-07-10 08:13    5,632    ----a-w    C:\WINDOWS\system32\drivers\StarOpen.sys
2008-07-07 20:29    253,952    ----a-w    C:\WINDOWS\system32\es.dll
2008-06-24 16:44    74,240    ----a-w    C:\WINDOWS\system32\mscms.dll
2008-06-23 16:33    826,368    ----a-w    C:\WINDOWS\system32\wininet.dll
2008-06-20 17:48    246,784    ----a-w    C:\WINDOWS\system32\mswsock.dll
2007-12-10 15:27    32    ----a-w    C:\Documents and Settings\All Users\Application Data\ezsid.dat
2005-12-06 13:13    2,847,210    ----a-w    C:\Programmer\everesthome151.zip
2003-01-13 10:30    278,528    -c----w    C:\Programmer\internet explorer\plugins\PanoViewer.dll
1999-04-30 15:00    98,304    -c----w    C:\Programmer\internet explorer\plugins\UPjpeg.dll
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Gadwin PrintScreen 2.6"="C:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe" [2003-07-16 913408]
"VistaStartMenu"="C:\Programmer\Vista Start Menu\VistaStartMenu.exe" [2007-12-12 1704624]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"Skype"="C:\Programmer\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"FreeNote"="C:\Programmer\FreeNote\FreeNote.exe" [2008-02-19 1040384]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]
"Google Update"="C:\Documents and Settings\Jan\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FLMOFFICE4DMOUSE"="C:\Programmer\Trust\MI-7500X Wireless Laser Mouse\Mouse32a.exe" [2007-09-19 370176]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 7700480]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Bredbandscenter"="C:\Programmer\Glocalnet\Bredbandscenter\Launcher.exe" [2008-05-01 808104]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"ClocX"="C:\Programmer\ClocX\ClocX.exe" [2007-07-26 270336]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 C:\WINDOWS\StartupMonitor.exe]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 C:\WINDOWS\system32\ptipbmf.dll]
"nwiz"="nwiz.exe" [2006-10-22 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="C:\PROGRA~1\FLLESF~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
HP Digital Imaging Monitor.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
VOIP321.lnk - C:\Programmer\Philips\VOIP321\VOIP321.exe [2006-11-07 771072]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\~Disabled
Adobe Reader Speed Launch.lnk - C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe [2008-01-11 39792]
Adobe Reader Synchronizer.lnk - C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-05-11 738968]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages    REG_MULTI_SZ      msv1_0 nwprovau
Notification Packages    REG_MULTI_SZ      scecli scecli

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 12:22 7700480 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-09-25 02:11 132496 C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmer\\Glocalnet\\Bredbandscenter\\Bredbandscenter.exe"=
"C:\\Programmer\\Glocalnet\\Bredbandscenter\\BredbandscenterUpdater.exe"= C:\\Programmer\\Glocalnet\\Bredbandscenter\\BredbandCenterUpdater.exe
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmer\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmer\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Programmer\\Skype\\Phone\\Skype.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 302000]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 72624]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 BredbandscenterDownloader;BredbandscenterDownloader;C:\Programmer\Glocalnet\Bredbandscenter\BredbandscenterUpdater.exe [2008-05-01 1055912]
R2 NMSAccessU;NMSAccessU;C:\Programmer\CDBurnerXP\NMSAccessU.exe [2007-05-04 71360]
R2 sbbotdi;sbbotdi;C:\PROGRA~1\SPEEDB~1\sbbotdi.sys [2007-07-17 35200]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 1234480]
S3 N100;Compaq Ethernet eller Fast Ethernet NIC-driver;C:\WINDOWS\system32\DRIVERS\n100325.sys [2001-10-04 129536]
S3 NetWlan5;Driver til symbolbaseret 802.11b Wireless LAN-netværkskort;C:\WINDOWS\system32\DRIVERS\NetWlan5.sys [2004-08-27 132695]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Ulead AutoDetector - :C:\Programmer\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
HKLM-Run-Ulead Photo Express Calendar Checker - :C:\Programmer\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
HKLM-Run-HP Software Update - :C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
HKLM-Run-AppleSyncNotifier - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
HKU-Default-Run-swg - C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-HP Software Update - :C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
MSConfigStartUp-MSMSGS - :C:\Programmer\Messenger\msmsgs.exe
MSConfigStartUp-NeroFilterCheck - :C:\WINDOWS\system32\NeroCheck.exe
MSConfigStartUp-QuickTime Task - :C:\Programmer\QuickTime\qttask.exe
MSConfigStartUp-swg - C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Jan\Application Data\Mozilla\Firefox\Profiles\9bmcliqs.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.dk
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-04 20:02:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Programmer\Windows Defender\MsMpEng.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\HP\Digital Imaging\bin\hpqste08.exe
C:\Programmer\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-09-04 20:06:59 - machine was rebooted
ComboFix-quarantined-files.txt  2008-09-04 18:06:48

Pre-Run: 116,019,130,368 byte ledig
Post-Run: 116,170,178,560 byte ledig

281    --- E O F ---    2008-09-04 17:37:27
Avatar billede levich Nybegynder
05. september 2008 - 00:01 #1
Umiddelbart ser det fint ud. Jeg undrer mig lidt over din DNS-server (208.67.222.222) - er det noget du ved noget om? Desunden, hvilke problem oplever du med din computer?
Avatar billede targa55 Praktikant
05. september 2008 - 01:02 #2
Er pt. på besøg i Sverige.
Den vil ikke inst. opdateringer fra Microsoft.
05. september 2008 - 06:48 #3
Hent Dial-a-fix på dette link, og gem det på skrivebordet.
http://djlizard.net/Dial-a-fix-2006-09-19.exe


1. Dobbeltklik det blå tandhjul.
2. Klik på knappen "Flush Softwaredistribution"
3. Sæt flueben i "Fix Windows update"
4. Klik på knappen GO i nederste venstre hjørne.
5. Lad den køre færdig.
6. Genstart maskinen.

Forklaring på fixet her:  http://wiki.djlizard.net/Dial-a-fix
Avatar billede targa55 Praktikant
05. september 2008 - 13:33 #4
Det er prøvet -  blev også bedre.
Nu er det kun opdateringer til Office 2003, det er galt med.
Opgraderer nok til 2007, og ser hvad der sker.
Avatar billede targa55 Praktikant
05. september 2008 - 17:30 #5
Har opgraderet til 2007 og alt virker.
Siger tak for hjælpen, så læg venligst et svar begge to.
05. september 2008 - 18:46 #6
Ping...
Avatar billede levich Nybegynder
06. september 2008 - 11:15 #7
svar
Avatar billede targa55 Praktikant
06. september 2008 - 13:26 #8
levich --- læg lige et svar igen.
Avatar billede levich Nybegynder
06. september 2008 - 18:52 #9
targa55 -> det er for sent nu, da du har fordelt de 100 point, men bare rolig det gør ikke noget :-)
Avatar billede targa55 Praktikant
06. september 2008 - 19:05 #10
Opretter et spørgsmål i fri debat.
Tak for hjælpen.
Avatar billede vejmand Juniormester
06. september 2008 - 19:30 #11
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester