Avatar billede Slettet bruger
14. august 2010 - 18:56 Der er 35 kommentarer

Google og andre links sender mig til FALSK SIDE!

Hey eksperter

Mit problem er kort sagt at når jeg trykker på links fra google eller andre sider, selv når jeg skal logge ind her, bliver jeg mange gange sendt til siden http ://154clicks.info/go.php?p=0 (har lavet mellemrum melle http og : for at man ved fejl ikke får trykket sig ind på siden) Her står der ERROR: No P parameter.

Har prøvet følgende:

Scanne med AVG 9
Scanne med Super Anti Spyware
Scanne med ComboFiX
Scanne med TDSSKiller

Men intet har hjulpet

Håber der er nogle der kan hjælpe mig med problemet

På forhånd tak
14. august 2010 - 19:15 #1
Velkommen til E. ...

Under hvilket system:
Win98, ME, W2000, XP, Vista, Win7, OS/2, Unix, Linux, ... ?
14. august 2010 - 19:16 #2
Gennemfør denne 'pakke' i første omgang ->

Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/manual-for-installation-og-brug-af-ccleaner/
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
http://vistaguide.dk/?Artikler/CCleaner-GuideTilOptimeringAfVista/763
Lad programmet foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...

...og her er omtalte HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

Mht.: Vista/Win7 - HøjreMusseTast - "Kør som Administrator..."

------------------
Avatar billede Slettet bruger
15. august 2010 - 12:17 #3
Tusinde tak for det hurtige svar.

Har kørt alle programmerne, men bliver stadigvæk ført til andre sider, dog ikke kun 154clicks.info mere, men dette er de logs der er kommet ud af det. Håber det kan bruges til yderligere hjælp.

Malewarebytes:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4429

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

15-08-2010 11:53:02
mbam-log-2010-08-15 (11-53-02).txt

Skanningstype: Fuldstændig skanning (C:\|D:\|)
Objekter skannet: 397993
Tid gået: 3 time(e), 17 minut(ter), 49 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 3
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 4
Inficerede Filer: 300

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
C:\Users\Mathias Refnov\AppData\Roaming\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\Logs (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180 (Rogue.RegTool) -> Quarantined and deleted successfully.

Inficerede Filer:
C:\Qoobox\Quarantine\C\Users\Mathias Refnov\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp.vir (Spyware.Passwords) -> Quarantined and deleted successfully.
D:\Downloads\Programmer\embrace\Adobe.Photoshop.CS5.Extended.v12.Keygen.Only.EMBRACE-Deantjah\Keygen\keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\resultsw.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\Logs\2009-02-25 17-21-270.log (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-100.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-101.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-102.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-103.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-104.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-105.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-106.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-107.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-108.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-109.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-110.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-111.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-112.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-113.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-114.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-115.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-116.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-117.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-118.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-119.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-12.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-120.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-121.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-122.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-123.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-124.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-125.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-126.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-127.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-128.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-129.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-13.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-130.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-131.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-132.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-133.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-134.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-135.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-136.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-137.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-138.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-139.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-14.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-140.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-141.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-142.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-143.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-144.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-145.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-146.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-147.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-148.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-149.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-15.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-150.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-151.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-152.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-153.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-154.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-155.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-156.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-157.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-158.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-159.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-16.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-160.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-161.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-162.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-163.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-164.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-165.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-166.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-167.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-168.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-169.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-17.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-170.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-171.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-172.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-173.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-174.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-175.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-176.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-177.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-178.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-179.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-18.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-180.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-181.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-182.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-183.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-184.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-185.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-186.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-187.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-188.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-189.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-19.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-190.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-191.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-192.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-193.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-194.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-195.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-196.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-197.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-198.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-199.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-20.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-200.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-201.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-202.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-203.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-204.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-205.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-206.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-207.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-208.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-209.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-21.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-210.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-211.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-212.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-213.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-214.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-215.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-216.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-217.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-218.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-219.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-22.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-220.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-221.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-222.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-223.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-224.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-225.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-226.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-227.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-228.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-229.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-23.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-230.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-231.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-232.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-233.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-234.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-235.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-236.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-237.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-238.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-239.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-24.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-240.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-241.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-242.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-243.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-244.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-245.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-246.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-247.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-248.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-249.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-25.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-250.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-251.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-252.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-253.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-254.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-255.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-256.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-257.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-258.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-259.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-26.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-260.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-261.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-262.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-263.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-264.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-265.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-266.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-267.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-268.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-269.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-27.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-270.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-271.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-272.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-273.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-274.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-275.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-276.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-277.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-278.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-279.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-28.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-280.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-281.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-282.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-283.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-284.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-285.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-286.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-287.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-288.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-289.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-29.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-290.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-291.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-292.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-293.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-294.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-30.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-31.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-32.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-33.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-34.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-35.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-36.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-37.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-38.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-39.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-40.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-41.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-42.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-43.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-44.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-45.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-46.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-47.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-48.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-49.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-50.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-51.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-52.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-53.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-54.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-55.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-56.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-57.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-58.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-59.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-60.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-61.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-62.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-63.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-64.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-65.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-66.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-67.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-68.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-69.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-7.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-70.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-71.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-72.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-73.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-74.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-75.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-76.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-77.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-78.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-79.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-8.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-80.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-81.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-82.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-83.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-84.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-85.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-86.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-87.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-88.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-89.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-9.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-90.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-91.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-92.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-93.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-94.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-95.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-96.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-97.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-98.db (Rogue.RegTool) -> Quarantined and deleted successfully.
C:\Users\Mathias Refnov\AppData\Roaming\RegTool\QuarantineW\2009-02-25 17-25-180\regb-99.db (Rogue.RegTool) -> Quarantined and deleted successfully.

HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:13, on 15-08-2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Users\MATHIA~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Mathias Refnov\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - Startup: Dropbox.lnk = C:\Users\Mathias Refnov\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Indholdsfortegnelse i OneNote.onetoc2
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki ... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O15 - Trusted Zone: *.danskebank.dk
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\eNetHook.dll C:\Windows\System32\avgrsstx.dll C:\Windows\System32\acaptuser32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SuperAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Tjenesten Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - (no file)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 15556 bytes
Avatar billede johnstigers Seniormester
15. august 2010 - 13:34 #4
Jeg tror ikke jeg kan mindes at have set en maskine mere inficeret end denne...!!!

"Inficerede Filer: 300"

Har du genstartet efter denne procedure?

Hijackthis skal køres fra sin egen mappe, for når man fixer noget med dette program oprettes punkter så man kan gå tilbage til før man fixede. Derfor skal du lige lave en frisk Hijackthis log og smide herind.
Avatar billede johnstigers Seniormester
15. august 2010 - 13:36 #5
Desuden er der vist 2 x antivirus?
AVG + Norton...?

Ud med det ene.
Avatar billede it-noerden Nybegynder
15. august 2010 - 14:19 #6
Jeg har engang haft næsten samme problem det var bare med at den gik til min ip adresse og jeg ordnede det ved at bruge ccleaner + jeg opdaterede min computer :)
Avatar billede Slettet bruger
15. august 2010 - 15:06 #7
Endnu en gang tak for de hurtige svar, for det her problem
driver en til vanvid...

Ja også overrasket over de 300, troede min computer var OK sikret med de fire andre programmer, men det lader det så ikke til.

Angående de to virus programmer, så har jeg ikke Norton eller jeg kan i hvert fald ikke finde det, hverken med tilføj/fjern programmer, program oversigten eller i program mappen, ej heller når jeg søger på denne. Der var en prøveversion da jeg købte computeren, men denne har jeg slettet efter perioden var over.

Har nu lagt HijackThis over i mappen C:\Program Files\Hijackthis, ved ikke om det var det du mente med, at den skulle have sin egen mappe. Nu lægger den også logsne og program exe filen her, men ikke nogen "gendannelses" filer/punkter (men det måske heller ikke sådan programmet virker?) den dug friske log er som følgende:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:52:35, on 15-08-2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Users\MATHIA~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Hijackthis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - Startup: Dropbox.lnk = C:\Users\Mathias Refnov\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Indholdsfortegnelse i OneNote.onetoc2
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki ... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O15 - Trusted Zone: *.danskebank.dk
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\eNetHook.dll C:\Windows\System32\avgrsstx.dll C:\Windows\System32\acaptuser32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SuperAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Tjenesten Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - (no file)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 15306 bytes
Avatar billede Slettet bruger
15. august 2010 - 15:07 #8
PS: ccleaner er kørt både med reg og rens, samt fuld opdateret computer.
Avatar billede f-arn Guru
15. august 2010 - 15:36 #9
troede min computer var OK sikret med de fire andre programmer, men det lader det så ikke til

Hvis du blandt dem tæller Combofix og TDSSKiller, så sikrer de ikke mod noget som helst.

Prøv lige selv at se i den HijackThis log.
Der står meget "Symantec".
Avatar billede Slettet bruger
15. august 2010 - 15:58 #10
For mig er log's fremmedsprog, så har ingen idé om hvad "Symantec" betyder, og hvis det ikke er godt, hvad der så skal gøres ved dette. Jeg kan finde ud af at bruge standard virus/spyware programmer, og da disse ikke har hjulpet, henvender jeg mig til jer eksperter i håb om en redning i form af en løsningsvejledning eller lignende. Om der skal skrives i cmd'en, regedit eller hvad det ellers alt sammen hedder, skal jeg nok kunne klare det, bare det bliver forklaret trin for trin:)
Avatar billede Slettet bruger
15. august 2010 - 16:12 #11
Symantec = Norton fandt jeg frem til, disse er fjernet med tilføj/fjern programmer.
Avatar billede f-arn Guru
15. august 2010 - 16:15 #12
"Norton" bliver lavet af Symantec. Derfor er de mange "Symantec" i din log tegn på at "Norton" ikke er fjernet rigtigt.

Prøv lige at lave en ny Combofix-log. Læg den herind.
Avatar billede Slettet bruger
15. august 2010 - 19:43 #13
Her er så en ComboFix log:

ComboFix 10-08-12.03 - Mathias Refnov 15-08-2010  18:59:57.2.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.2045.1008 [GMT 2:00]
Kører fra: c:\users\Mathias Refnov\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Mathias Refnov\AppData\Local\VirtualStore\Windows\System32\Desktop_.ini
c:\users\Mathias Refnov\AppData\Local\Windows Server
c:\users\Mathias Refnov\AppData\Local\Windows Server\admin.txt
c:\users\Mathias Refnov\AppData\Local\Windows Server\flags.ini
c:\users\Mathias Refnov\AppData\Local\Windows Server\server.dat
c:\users\Mathias Refnov\AppData\Local\Windows Server\uses32.dat

Inficeret kopi af c:\windows\explorer.exe blev fundet og desinficeret
Genskabt kopi fra - c:\windows\ERDNT\cache\explorer.exe

Inficeret kopi af c:\windows\System32\wininit.exe blev fundet og desinficeret
Genskabt kopi fra - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-07-15 til 2010-08-15  )))))))))))))))))))))))))))))))))))
.

2010-08-15 17:16 . 2010-08-15 17:19    --------    d-----w-    c:\users\Mathias Refnov\AppData\Local\temp
2010-08-15 17:16 . 2010-08-15 17:16    --------    d-----w-    c:\users\Public\AppData\Local\temp
2010-08-15 17:16 . 2010-08-15 17:16    --------    d-----w-    c:\users\Mcx1\AppData\Local\temp
2010-08-15 17:16 . 2010-08-15 17:16    --------    d-----w-    c:\users\Default\AppData\Local\temp
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Malwarebytes
2010-08-14 18:19 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\programdata\Malwarebytes
2010-08-14 18:19 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-08-14 09:47 . 2010-08-14 15:49    --------    d-----w-    c:\users\Mathias Refnov\AppData\Local\Windows
2010-08-14 04:40 . 2010-06-21 13:37    2037760    ----a-w-    c:\windows\system32\win32k.sys
2010-08-14 04:40 . 2010-05-27 20:08    81920    ----a-w-    c:\windows\system32\iccvid.dll
2010-08-14 04:40 . 2010-06-26 06:05    916480    ----a-w-    c:\windows\system32\wininet.dll
2010-07-27 17:06 . 2010-07-30 19:57    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Be a King 2
2010-07-27 16:57 . 2010-07-27 16:57    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\PlayFirst
2010-07-27 16:57 . 2010-07-27 16:57    --------    d-----w-    c:\programdata\PlayFirst
2010-07-27 16:39 . 2010-07-27 16:39    --------    d-----w-    C:\BigFishGamesCache

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-15 17:16 . 2007-07-03 11:51    12    ----a-w-    c:\windows\bthservsdp.dat
2010-08-15 16:55 . 2007-07-03 16:18    50800    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\nvModes.dat
2010-08-15 14:53 . 2010-02-12 21:03    0    ----a-w-    c:\users\Mathias Refnov\AppData\Local\prvlcl.dat
2010-08-15 14:09 . 2007-01-23 05:30    --------    d-----w-    c:\programdata\Symantec
2010-08-15 14:09 . 2007-01-23 05:30    --------    d-----w-    c:\program files\Common Files\Symantec Shared
2010-08-14 16:07 . 2007-07-05 13:38    --------    d-----w-    c:\programdata\Microsoft Help
2010-08-14 16:02 . 2006-11-02 11:18    --------    d-----w-    c:\program files\Windows Mail
2010-08-14 14:16 . 2010-02-15 16:05    --------    d-----w-    c:\program files\CCleaner
2010-08-14 04:27 . 2009-09-05 21:33    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox
2010-08-12 17:33 . 2006-11-21 04:49    77202    ----a-w-    c:\windows\system32\perfc006.dat
2010-08-12 17:33 . 2006-11-21 04:49    463344    ----a-w-    c:\windows\system32\perfh006.dat
2010-08-10 18:41 . 2009-04-29 16:12    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\dvdcss
2010-07-31 07:26 . 2007-07-03 11:48    113472    ----a-w-    c:\users\Mathias Refnov\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-26 11:15 . 2007-07-03 18:19    --------    d-----w-    c:\program files\SuperAntiSpyware
2010-07-16 17:06 . 2009-10-21 13:07    243024    ----a-w-    c:\windows\system32\drivers\avgtdix.sys
2010-07-16 17:06 . 2010-07-16 17:06    12536    ----a-w-    c:\windows\system32\avgrsstx.dll
2010-07-16 17:05 . 2008-09-03 20:47    216400    ----a-w-    c:\windows\system32\drivers\avgldx86.sys
2010-07-16 16:52 . 2010-07-16 16:50    --------    d-----w-    c:\program files\Mobilt Bredband
2010-07-15 13:01 . 2010-07-15 13:00    --------    d-----w-    c:\programdata\FarmFrenzy2
2010-07-15 12:07 . 2010-07-15 11:58    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Microsoft Games
2010-07-15 12:06 . 2007-01-23 04:52    --------    d--h--w-    c:\program files\InstallShield Installation Information
2010-07-15 11:58 . 2010-07-15 11:58    --------    d-----w-    c:\program files\Common Files\Microsoft Games
2010-07-15 11:51 . 2010-07-15 11:51    --------    d-----w-    c:\programdata\Microsoft Games
2010-07-15 11:46 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Microsoft Games
2010-07-10 10:25 . 2007-08-24 20:44    --------    d-----w-    c:\program files\Java
2010-07-06 19:47 . 2010-07-06 19:47    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-07-06 13:48 . 2007-08-24 20:40    --------    d-----w-    c:\program files\Common Files\Java
2010-07-05 09:34 . 2010-07-05 09:21    --------    d-----w-    c:\programdata\regid.1986-12.com.adobe
2010-07-05 09:28 . 2007-10-24 19:12    --------    d-----w-    c:\program files\Common Files\Adobe
2010-07-05 09:09 . 2010-07-05 09:09    --------    d-----w-    c:\program files\Adobe Media Player
2010-07-05 09:06 . 2010-07-05 09:06    --------    d-----w-    c:\program files\Common Files\Adobe AIR
2010-06-30 10:26 . 2009-09-17 17:49    --------    d-----w-    c:\programdata\Blizzard Entertainment
2010-06-26 06:02 . 2010-08-14 04:39    71680    ----a-w-    c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-14 04:39    109056    ----a-w-    c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-14 04:39    133632    ----a-w-    c:\windows\system32\ieUnatt.exe
2010-06-18 17:31 . 2010-08-14 04:39    36864    ----a-w-    c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-14 04:39    302080    ----a-w-    c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-14 04:39    144896    ----a-w-    c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-14 04:39    905088    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2010-06-11 16:16 . 2010-08-14 04:39    274944    ----a-w-    c:\windows\system32\schannel.dll
2010-06-11 16:15 . 2010-08-14 04:39    1248768    ----a-w-    c:\windows\system32\msxml3.dll
2010-06-08 17:35 . 2010-08-14 04:39    3548040    ----a-w-    c:\windows\system32\ntoskrnl.exe
2010-06-08 17:35 . 2010-08-14 04:39    3600768    ----a-w-    c:\windows\system32\ntkrnlpa.exe
2010-06-03 17:03 . 2008-02-01 18:50    29584    ----a-w-    c:\windows\system32\drivers\avgmfx86.sys
2010-06-03 02:41 . 2010-06-03 02:41    3600384    ----a-w-    c:\windows\system32\GPhotos.scr
2010-05-26 17:06 . 2010-06-11 14:31    34304    ----a-w-    c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-11 14:31    289792    ----a-w-    c:\windows\system32\atmfd.dll
2009-05-01 21:02 . 2009-05-01 21:02    1044480    ----a-w-    c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02    200704    ----a-w-    c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-04-19 10:46 . 2008-04-19 10:15    72    --sh--w-    c:\windows\S5E90672C.tmp
2008-06-30 15:05 . 2008-06-30 08:55    2048    --sha-w-    c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-06-30 15:05 . 2008-06-30 08:55    2048    --sha-w-    c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
.

------- Sigcheck -------

  • 2009-04-11 . 1B5063720BC4DF7D622451DE252731F5 . 2926592 . . [6.0.6000.16386] . . c:\windows\explorer.exe
[7] 2009-04-11 . D07D4C3038F3578FFCE1C0237F2A1253 . 2926592 . . [6.0.6000.16386] . . c:\windows\ERDNT\cache\explorer.exe
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1119488]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-18 10:27    1119488    ----a-w-    c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"="" [?]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-24 68856]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-01-08 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 4186112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-01-02 464168]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-12-08 614400]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-30 304664]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-28 244512]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-20 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-20 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-20 81920]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-16 2065760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\users\Mathias Refnov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
Indholdsfortegnelse i OneNote.onetoc2 [2009-2-2 3656]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-20 18:36    548352    ----a-w-    c:\program files\SuperAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\eNetHook.dll c:\windows\System32\avgrsstx.dll c:\windows\System32\acaptuser32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Exif Launcher S.lnk]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Google Updater.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
??????????????e [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
??????????????e [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
2007-01-14 03:38    151552    ----a-w-    c:\acer\AcerTour\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcerOrbicamRibbon]
2006-11-28 16:43    754712    ----a-w-    c:\program files\Acer\OrbiCam10\OrbiCam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-03 16:50    1603152    ----a-w-    c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-14 16:01    644696    ----a-w-    c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29    165784    ----a-w-    c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2006-12-26 00:23    643072    ----a-w-    c:\program files\Eraser\eraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44    31072    ----a-w-    c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08    417792    ----a-w-    c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28    1233920    ----a-w-    c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-09-02 13:27    25623336    ----a-r-    c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-07-26 11:15    2403568    ----a-w-    c:\program files\SuperAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):7d,ee,23,ce,ca,40,ca,01

R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 167936]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-12-08 113664]
R3 gkmixern;gkmixern; [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 101120]
R3 SASENUM;SASENUM;c:\program files\SuperAntiSpyware\SASENUM.SYS [2010-02-19 12872]
R3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\DRIVERS\SMSCirda.sys [2006-10-18 31232]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2007-07-05 682232]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-16 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-16 243024]
S1 SASDIFSV;SASDIFSV;c:\program files\SuperAntiSpyware\SASDIFSV.SYS [2010-02-19 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SuperAntiSpyware\SASKUTIL.sys [2010-05-29 67656]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-16 308136]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-01-08 233472]
S2 SBKUPNT;SBKUPNT;c:\windows\system32\Drivers\SBKUPNT.SYS [2001-07-13 14976]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-01-08 36608]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]


--- Andre Services/Drivers i Hukommelsen ---

*NewlyCreated* - FSUSBEXDISK
*Deregistered* - Ndisprot.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs    REG_MULTI_SZ      BthServ
LocalServiceAndNoImpersonation    REG_MULTI_SZ      FontCache
.
Indhold af mappen 'Planlagte Opgaver'

2010-08-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 12:33]

2010-08-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 12:33]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: danskebank.dk
Trusted Zone: danskebank.dk\netbank
Trusted Zone: danskebank.dk\www
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\users\Mathias Refnov\AppData\Roaming\Mozilla\Firefox\Profiles\mfu7o3gq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\users\Mathias Refnov\AppData\Roaming\Mozilla\Firefox\Profiles\mfu7o3gq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLITIKKER ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - TOMME GENVEJE FJERNET - - - -

AddRemove-HijackThis - c:\users\Mathias Refnov\Desktop\HijackThis.exe



**************************************************************************
scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer:

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-891747130-3254500623-152161286-1000\Software\SecuROM\License information*]
"datasecu"=hex:f3,97,b2,6c,40,89,55,7e,92,7c,af,8c,29,ca,c7,e0,af,e0,22,63,e6,
  8c,68,18,8e,7d,7c,39,81,c4,0e,b5,6f,c9,9d,70,9a,0f,d5,d6,8f,67,33,af,2b,89,\
"rkeysecu"=hex:69,e2,59,40,d7,9b,66,ac,16,9a,78,8d,72,ca,5c,c9

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'Explorer.exe'(612)
c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\btncopy.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\windows\system32\conime.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Gennemført tid: 2010-08-15  19:32:03 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2010-08-15 17:32
ComboFix2.txt  2010-08-14 15:48

Pre-Kørsel: 12.704.821.248 byte ledig
Post-Kørsel: 12.590.358.528 byte ledig

- - End Of File - - DF570B7F2D2907E1CF5086B5308C7286
Avatar billede f-arn Guru
15. august 2010 - 20:18 #14
@karise_larry
Rent principielt:
Fortsætter du?
15. august 2010 - 22:43 #15
<f-arn>: Ta' du bare herfra ...

(Der er sandelig en del oprydning på dette 'dyr'...)
Avatar billede f-arn Guru
16. august 2010 - 22:23 #16
Avatar billede Slettet bruger
17. august 2010 - 15:26 #17
Så har jeg fulgt vejledningen, og kørt programmet som administrator, men efter meget kort tid popper en log op, og der kommer en error.

Error:
15:14:02: Unrecognized partition type 6 (0x6)!
15:16:42: Could not read system registry! Please contact the author!

Og her er loggen:

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time:        2010/08/17 15:13
Program Version:        Version 1.3.5.0
Windows Version:        Windows Vista SP2
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x9636C000    Size: 32768    File Visible: No    Signed: -
Status: -

Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x96361000    Size: 45056    File Visible: No    Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xA8B8A000    Size: 49152    File Visible: No    Signed: -
Status: -

Processes
-------------------
Path: SYSTEM
PID: 4    Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1260    Status: Locked to the Windows API!

==EOF==
Avatar billede f-arn Guru
17. august 2010 - 16:56 #18
Kør GMER efter denne vejledning:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=208&title=gmer-vejledning

Læg mærke til:
Hvis du bliver advaret om rootkit aktivitet og spørger om du vil køre en fuld scanning, så svar "NO
Avatar billede Slettet bruger
17. august 2010 - 17:57 #19
Fulgte vejledningen, men igen en fejl... Når den er sat i gang, popper windows op med: Programmet er holdt op med at fungere... Prøvede flere gange, og den stopper altid ved det samme.

\Device\VolumeShadowHarddiskCopy1
Avatar billede Slettet bruger
25. august 2010 - 19:58 #20
Nogen der kan hjælpe mig? Problemet er ikke løst endnu
Avatar billede johnstigers Seniormester
25. august 2010 - 20:09 #21
f-arn vender sikkert tilbage.
Avatar billede Slettet bruger
25. august 2010 - 21:37 #22
kørte noget der hedder browser hijack recover,og problemet lader til at være forsvundet nu... Vender tilbage hvis problemet vender tilbage inden for en uge... Tusinde tak til alle som tog sig tid til at hjælpe mig:)
Avatar billede Slettet bruger
26. august 2010 - 16:40 #23
Det var så en kortvarig løsning... Hjælp en aften, og denne aften var jeg kun inde på facebook og youtube... I dag er problemet så tilbage, uden at have været inde på nogen sider...
Avatar billede f-arn Guru
26. august 2010 - 16:54 #24
Beklager det sene svar.

Hent en ny Combofix og send en log fra den herind. Vi må prøve om vi kan slå hul med den.
Avatar billede Slettet bruger
27. august 2010 - 21:29 #25
Der intet at beklage over:) Bare mig der var lidt irriteret over mit browserproblem i og med at jeg sad og skrev på mit speciale og ikke kunne få lavet research på nogle ting... Er kun taknemlig for at der er nogen som gider tage sig tid til at hjælpe os som ikke er eksperter med computer stuff. Så undskyld for min utålmodighed...

Men ud over det, så tror jeg måske jeg har fået løst problemet "igen" ved at installere spywareblaster, uninstallere firefox, uninstallere java runtime center (kunne nemlig ikke opdatere java fandt jeg ud af) downloade den nyeste java og installeret denne, kørt browser hijack recover, installeret firefox, kørt malewarebytes, superantispyware, avg, ccleaner alle flere gange... og til sidst combofix...

Men for en sikkerhedsskyld, her er den sidste log combofix har lavet, hvis nu der skulle gemme sig noget, som programmerne ikke har taget. Har jo prøvet hvor det så ud som om det var i orden og så dagen efter var den gal igen, men her er den sidste log altså:

ComboFix 10-08-25.01 - Mathias Refnov 26-08-2010  18:44:17.3.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.2045.1154 [GMT 2:00]
Kører fra: c:\users\Mathias Refnov\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\System32\Desktop_.ini

Inficeret kopi af c:\windows\explorer.exe blev fundet og desinficeret
Genskabt kopi fra - c:\windows\ERDNT\cache\explorer.exe

Inficeret kopi af c:\windows\System32\wininit.exe blev fundet og desinficeret
Genskabt kopi fra - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe

Inficeret kopi af c:\windows\explorer.exe blev fundet og desinficeret
Genskabt kopi fra - c:\windows\ERDNT\cache\explorer.exe
.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-07-26 til 2010-08-26  )))))))))))))))))))))))))))))))))))
.

2010-08-26 17:00 . 2010-08-26 17:14    --------    d-----w-    c:\users\Mathias Refnov\AppData\Local\temp
2010-08-26 17:00 . 2010-08-26 17:00    --------    d-----w-    c:\users\Public\AppData\Local\temp
2010-08-26 17:00 . 2010-08-26 17:00    --------    d-----w-    c:\users\Mcx1\AppData\Local\temp
2010-08-26 17:00 . 2010-08-26 17:00    --------    d-----w-    c:\users\Default\AppData\Local\temp
2010-08-26 14:38 . 2010-08-26 14:43    --------    d-----w-    c:\program files\SpywareBlaster
2010-08-25 19:04 . 2010-08-26 14:27    --------    d-----w-    c:\program files\Browser Hijack Recover
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Malwarebytes
2010-08-14 18:19 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\programdata\Malwarebytes
2010-08-14 18:19 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-08-14 09:47 . 2010-08-14 15:49    --------    d-----w-    c:\users\Mathias Refnov\AppData\Local\Windows
2010-08-14 04:40 . 2010-06-21 13:37    2037760    ----a-w-    c:\windows\system32\win32k.sys
2010-08-14 04:40 . 2010-05-27 20:08    81920    ----a-w-    c:\windows\system32\iccvid.dll
2010-08-14 04:40 . 2010-06-26 06:05    916480    ----a-w-    c:\windows\system32\wininet.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 16:38 . 2010-02-12 21:03    0    ----a-w-    c:\users\Mathias Refnov\AppData\Local\prvlcl.dat
2010-08-26 16:12 . 2007-07-03 11:51    12    ----a-w-    c:\windows\bthservsdp.dat
2010-08-25 18:57 . 2010-02-15 16:05    --------    d-----w-    c:\program files\CCleaner
2010-08-22 10:48 . 2006-11-21 04:49    77202    ----a-w-    c:\windows\system32\perfc006.dat
2010-08-22 10:48 . 2006-11-21 04:49    463344    ----a-w-    c:\windows\system32\perfh006.dat
2010-08-21 05:37 . 2007-07-03 16:18    50800    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\nvModes.dat
2010-08-19 19:25 . 2007-01-23 04:52    --------    d--h--w-    c:\program files\InstallShield Installation Information
2010-08-19 19:23 . 2007-07-03 11:48    113080    ----a-w-    c:\users\Mathias Refnov\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-19 19:19 . 2010-05-29 21:34    --------    d-----w-    c:\program files\Amazonia
2010-08-15 14:09 . 2007-01-23 05:30    --------    d-----w-    c:\programdata\Symantec
2010-08-15 14:09 . 2007-01-23 05:30    --------    d-----w-    c:\program files\Common Files\Symantec Shared
2010-08-14 16:07 . 2007-07-05 13:38    --------    d-----w-    c:\programdata\Microsoft Help
2010-08-14 16:02 . 2006-11-02 11:18    --------    d-----w-    c:\program files\Windows Mail
2010-08-14 04:27 . 2009-09-05 21:33    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox
2010-08-10 18:41 . 2009-04-29 16:12    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\dvdcss
2010-07-30 19:57 . 2010-07-27 17:06    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Be a King 2
2010-07-27 16:57 . 2010-07-27 16:57    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\PlayFirst
2010-07-27 16:57 . 2010-07-27 16:57    --------    d-----w-    c:\programdata\PlayFirst
2010-07-26 11:15 . 2007-07-03 18:19    --------    d-----w-    c:\program files\SuperAntiSpyware
2010-07-16 17:06 . 2009-10-21 13:07    243024    ----a-w-    c:\windows\system32\drivers\avgtdix.sys
2010-07-16 17:06 . 2010-07-16 17:06    12536    ----a-w-    c:\windows\system32\avgrsstx.dll
2010-07-16 17:05 . 2008-09-03 20:47    216400    ----a-w-    c:\windows\system32\drivers\avgldx86.sys
2010-07-16 16:52 . 2010-07-16 16:50    --------    d-----w-    c:\program files\Mobilt Bredband
2010-07-15 13:01 . 2010-07-15 13:00    --------    d-----w-    c:\programdata\FarmFrenzy2
2010-07-15 12:07 . 2010-07-15 11:58    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Microsoft Games
2010-07-15 11:58 . 2010-07-15 11:58    --------    d-----w-    c:\program files\Common Files\Microsoft Games
2010-07-15 11:51 . 2010-07-15 11:51    --------    d-----w-    c:\programdata\Microsoft Games
2010-07-15 11:46 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Microsoft Games
2010-07-10 10:25 . 2007-08-24 20:44    --------    d-----w-    c:\program files\Java
2010-07-06 19:47 . 2010-07-06 19:47    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-07-06 13:48 . 2007-08-24 20:40    --------    d-----w-    c:\program files\Common Files\Java
2010-07-05 09:34 . 2010-07-05 09:21    --------    d-----w-    c:\programdata\regid.1986-12.com.adobe
2010-07-05 09:28 . 2007-10-24 19:12    --------    d-----w-    c:\program files\Common Files\Adobe
2010-07-05 09:09 . 2010-07-05 09:09    --------    d-----w-    c:\program files\Adobe Media Player
2010-07-05 09:06 . 2010-07-05 09:06    --------    d-----w-    c:\program files\Common Files\Adobe AIR
2010-06-30 10:26 . 2009-09-17 17:49    --------    d-----w-    c:\programdata\Blizzard Entertainment
2010-06-26 06:02 . 2010-08-14 04:39    71680    ----a-w-    c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-14 04:39    109056    ----a-w-    c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-14 04:39    133632    ----a-w-    c:\windows\system32\ieUnatt.exe
2010-06-18 17:31 . 2010-08-14 04:39    36864    ----a-w-    c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-14 04:39    302080    ----a-w-    c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-14 04:39    144896    ----a-w-    c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-14 04:39    905088    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2010-06-11 16:16 . 2010-08-14 04:39    274944    ----a-w-    c:\windows\system32\schannel.dll
2010-06-11 16:15 . 2010-08-14 04:39    1248768    ----a-w-    c:\windows\system32\msxml3.dll
2010-06-08 17:35 . 2010-08-14 04:39    3548040    ----a-w-    c:\windows\system32\ntoskrnl.exe
2010-06-08 17:35 . 2010-08-14 04:39    3600768    ----a-w-    c:\windows\system32\ntkrnlpa.exe
2010-06-03 17:03 . 2008-02-01 18:50    29584    ----a-w-    c:\windows\system32\drivers\avgmfx86.sys
2010-06-03 02:41 . 2010-06-03 02:41    3600384    ----a-w-    c:\windows\system32\GPhotos.scr
2009-05-01 21:02 . 2009-05-01 21:02    1044480    ----a-w-    c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02    200704    ----a-w-    c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-04-19 10:46 . 2008-04-19 10:15    72    --sh--w-    c:\windows\S5E90672C.tmp
2008-06-30 15:05 . 2008-06-30 08:55    2048    --sha-w-    c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-06-30 15:05 . 2008-06-30 08:55    2048    --sha-w-    c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-18 10:27    1119488    ----a-w-    c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"="" [?]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-28 244512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-20 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-20 81920]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\users\Mathias Refnov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
Indholdsfortegnelse i OneNote.onetoc2 [2009-2-2 3656]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-20 18:36    548352    ----a-w-    c:\program files\SuperAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\eNetHook.dll c:\windows\System32\avgrsstx.dll c:\windows\System32\acaptuser32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Exif Launcher S.lnk]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Google Updater.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
??????????????e [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
??????????????e [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
2007-01-14 03:38    151552    ----a-w-    c:\acer\AcerTour\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcerOrbicamRibbon]
2006-11-28 16:43    754712    ----a-w-    c:\program files\Acer\OrbiCam10\OrbiCam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-03 16:50    1603152    ----a-w-    c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-14 16:01    644696    ----a-w-    c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29    165784    ----a-w-    c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2006-12-26 00:23    643072    ----a-w-    c:\program files\Eraser\eraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44    31072    ----a-w-    c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08    417792    ----a-w-    c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28    1233920    ----a-w-    c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-09-02 13:27    25623336    ----a-r-    c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-07-26 11:15    2403568    ----a-w-    c:\program files\SuperAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):7d,ee,23,ce,ca,40,ca,01

R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 167936]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-12-08 113664]
R3 gkmixern;gkmixern; [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 101120]
R3 SASENUM;SASENUM;c:\program files\SuperAntiSpyware\SASENUM.SYS [2010-02-19 12872]
R3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\DRIVERS\SMSCirda.sys [2006-10-18 31232]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2007-07-05 682232]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-16 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-16 243024]
S1 SASDIFSV;SASDIFSV;c:\program files\SuperAntiSpyware\SASDIFSV.SYS [2010-02-19 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SuperAntiSpyware\SASKUTIL.sys [2010-05-29 67656]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-16 308136]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-01-08 233472]
S2 SBKUPNT;SBKUPNT;c:\windows\system32\Drivers\SBKUPNT.SYS [2001-07-13 14976]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-01-08 36608]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]


--- Andre Services/Drivers i Hukommelsen ---

*NewlyCreated* - FSUSBEXDISK
*Deregistered* - Ndisprot.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs    REG_MULTI_SZ      BthServ
LocalServiceAndNoImpersonation    REG_MULTI_SZ      FontCache
.
Indhold af mappen 'Planlagte Opgaver'

2010-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 12:33]

2010-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 12:33]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uDefault_Search_URL = hxxp://www.google.com/ie
mWindow Title =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: danskebank.dk\netbank
Trusted Zone: danskebank.dk\www
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\users\Mathias Refnov\AppData\Roaming\Mozilla\Firefox\Profiles\k4f1n2bf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=da&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\users\Mathias Refnov\AppData\Roaming\Mozilla\Firefox\Profiles\k4f1n2bf.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLITIKKER ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************
scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer:

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-891747130-3254500623-152161286-1000\Software\SecuROM\License information*]
"datasecu"=hex:f3,97,b2,6c,40,89,55,7e,92,7c,af,8c,29,ca,c7,e0,af,e0,22,63,e6,
  8c,68,18,8e,7d,7c,39,81,c4,0e,b5,6f,c9,9d,70,9a,0f,d5,d6,8f,67,33,af,2b,89,\
"rkeysecu"=hex:69,e2,59,40,d7,9b,66,ac,16,9a,78,8d,72,ca,5c,c9

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'Explorer.exe'(2612)
c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\btncopy.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\conime.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Gennemført tid: 2010-08-26  19:25:48 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2010-08-26 17:25
ComboFix2.txt  2010-08-15 17:32
ComboFix3.txt  2010-08-14 15:48

Pre-Kørsel: 12.390.510.592 byte ledig
Post-Kørsel: 12.272.123.904 byte ledig

- - End Of File - - 0D967D84F84F9CC6E03F2647146BDA36
Avatar billede f-arn Guru
27. august 2010 - 23:21 #26
Har du en Vista installations CD/DVD? Det kan være vi bli'r nødt til at hente en systemfil.

------

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::
Registry::
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
Driver::
gkmixern


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede Slettet bruger
28. august 2010 - 10:02 #27
Nej det har jeg desværre ikke, der fulgte ikke nogen med da jeg købte computeren... Skal jeg CFScript anyway?
Avatar billede f-arn Guru
28. august 2010 - 11:06 #28
Ja - naturligvis, jeg ville bare gerne vide det.
Avatar billede Slettet bruger
28. august 2010 - 13:50 #29
Det her loggen efter CFSript kørsel:

ComboFix 10-08-25.01 - Mathias Refnov 28-08-2010  12:59:01.4.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.2045.1152 [GMT 2:00]
Kører fra: c:\users\Mathias Refnov\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Mathias Refnov\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

Inficeret kopi af c:\windows\system32\wininit.exe blev fundet og desinficeret
Genskabt kopi fra - c:\windows\ERDNT\cache\wininit.exe

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Tjenester  )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gkmixern


(((((((((((((((((((((((((((((  Filer skabt fra 2010-07-28 til 2010-08-28  )))))))))))))))))))))))))))))))))))
.

2010-08-28 11:12 . 2010-08-28 11:31    --------    d-----w-    c:\users\Mathias Refnov\AppData\Local\temp
2010-08-28 11:12 . 2010-08-28 11:12    --------    d-----w-    c:\users\Public\AppData\Local\temp
2010-08-28 11:12 . 2010-08-28 11:12    --------    d-----w-    c:\users\Mcx1\AppData\Local\temp
2010-08-28 11:12 . 2010-08-28 11:12    --------    d-----w-    c:\users\Default\AppData\Local\temp
2010-08-27 21:24 . 2010-08-27 21:24    --------    d-----w-    c:\program files\RapidShareManager
2010-08-27 14:12 . 2010-08-27 14:10    423656    ----a-w-    c:\windows\system32\deployJava1.dll
2010-08-26 14:38 . 2010-08-27 20:05    --------    d-----w-    c:\program files\SpywareBlaster
2010-08-25 19:04 . 2010-08-26 14:27    --------    d-----w-    c:\program files\Browser Hijack Recover
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Malwarebytes
2010-08-14 18:19 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
2010-08-14 18:19 . 2010-08-14 18:19    --------    d-----w-    c:\programdata\Malwarebytes
2010-08-14 18:19 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-08-14 09:47 . 2010-08-27 20:11    --------    d-----w-    c:\users\Mathias Refnov\AppData\Local\Windows
2010-08-14 04:40 . 2010-06-21 13:37    2037760    ----a-w-    c:\windows\system32\win32k.sys
2010-08-14 04:40 . 2010-05-27 20:08    81920    ----a-w-    c:\windows\system32\iccvid.dll
2010-08-14 04:40 . 2010-06-26 06:05    916480    ----a-w-    c:\windows\system32\wininet.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-28 08:23 . 2010-02-12 21:03    0    ----a-w-    c:\users\Mathias Refnov\AppData\Local\prvlcl.dat
2010-08-28 08:01 . 2006-11-21 04:49    77202    ----a-w-    c:\windows\system32\perfc006.dat
2010-08-28 08:01 . 2006-11-21 04:49    463344    ----a-w-    c:\windows\system32\perfh006.dat
2010-08-28 07:53 . 2009-09-05 21:33    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox
2010-08-27 22:07 . 2007-07-03 11:51    12    ----a-w-    c:\windows\bthservsdp.dat
2010-08-27 14:13 . 2007-08-24 20:40    --------    d-----w-    c:\program files\Common Files\Java
2010-08-27 14:04 . 2007-08-24 20:44    --------    d-----w-    c:\program files\Java
2010-08-25 18:57 . 2010-02-15 16:05    --------    d-----w-    c:\program files\CCleaner
2010-08-21 05:37 . 2007-07-03 16:18    50800    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\nvModes.dat
2010-08-19 19:25 . 2007-01-23 04:52    --------    d--h--w-    c:\program files\InstallShield Installation Information
2010-08-19 19:23 . 2007-07-03 11:48    113080    ----a-w-    c:\users\Mathias Refnov\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-19 19:19 . 2010-05-29 21:34    --------    d-----w-    c:\program files\Amazonia
2010-08-15 14:09 . 2007-01-23 05:30    --------    d-----w-    c:\programdata\Symantec
2010-08-15 14:09 . 2007-01-23 05:30    --------    d-----w-    c:\program files\Common Files\Symantec Shared
2010-08-14 16:07 . 2007-07-05 13:38    --------    d-----w-    c:\programdata\Microsoft Help
2010-08-14 16:02 . 2006-11-02 11:18    --------    d-----w-    c:\program files\Windows Mail
2010-08-10 18:41 . 2009-04-29 16:12    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\dvdcss
2010-07-30 19:57 . 2010-07-27 17:06    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Be a King 2
2010-07-27 16:57 . 2010-07-27 16:57    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\PlayFirst
2010-07-27 16:57 . 2010-07-27 16:57    --------    d-----w-    c:\programdata\PlayFirst
2010-07-26 11:15 . 2007-07-03 18:19    --------    d-----w-    c:\program files\SuperAntiSpyware
2010-07-16 17:06 . 2009-10-21 13:07    243024    ----a-w-    c:\windows\system32\drivers\avgtdix.sys
2010-07-16 17:06 . 2010-07-16 17:06    12536    ----a-w-    c:\windows\system32\avgrsstx.dll
2010-07-16 17:05 . 2008-09-03 20:47    216400    ----a-w-    c:\windows\system32\drivers\avgldx86.sys
2010-07-16 16:52 . 2010-07-16 16:50    --------    d-----w-    c:\program files\Mobilt Bredband
2010-07-15 13:01 . 2010-07-15 13:00    --------    d-----w-    c:\programdata\FarmFrenzy2
2010-07-15 12:07 . 2010-07-15 11:58    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\Microsoft Games
2010-07-15 11:58 . 2010-07-15 11:58    --------    d-----w-    c:\program files\Common Files\Microsoft Games
2010-07-15 11:51 . 2010-07-15 11:51    --------    d-----w-    c:\programdata\Microsoft Games
2010-07-15 11:46 . 2006-11-02 12:37    --------    d-----w-    c:\program files\Microsoft Games
2010-07-06 19:47 . 2010-07-06 19:47    --------    d-----w-    c:\users\Mathias Refnov\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-07-05 09:34 . 2010-07-05 09:21    --------    d-----w-    c:\programdata\regid.1986-12.com.adobe
2010-07-05 09:28 . 2007-10-24 19:12    --------    d-----w-    c:\program files\Common Files\Adobe
2010-07-05 09:09 . 2010-07-05 09:09    --------    d-----w-    c:\program files\Adobe Media Player
2010-07-05 09:06 . 2010-07-05 09:06    --------    d-----w-    c:\program files\Common Files\Adobe AIR
2010-06-30 10:26 . 2009-09-17 17:49    --------    d-----w-    c:\programdata\Blizzard Entertainment
2010-06-26 06:02 . 2010-08-14 04:39    71680    ----a-w-    c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-14 04:39    109056    ----a-w-    c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-14 04:39    133632    ----a-w-    c:\windows\system32\ieUnatt.exe
2010-06-18 17:31 . 2010-08-14 04:39    36864    ----a-w-    c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-14 04:39    302080    ----a-w-    c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-14 04:39    144896    ----a-w-    c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-14 04:39    905088    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2010-06-11 16:16 . 2010-08-14 04:39    274944    ----a-w-    c:\windows\system32\schannel.dll
2010-06-11 16:15 . 2010-08-14 04:39    1248768    ----a-w-    c:\windows\system32\msxml3.dll
2010-06-08 17:35 . 2010-08-14 04:39    3548040    ----a-w-    c:\windows\system32\ntoskrnl.exe
2010-06-08 17:35 . 2010-08-14 04:39    3600768    ----a-w-    c:\windows\system32\ntkrnlpa.exe
2010-06-03 17:03 . 2008-02-01 18:50    29584    ----a-w-    c:\windows\system32\drivers\avgmfx86.sys
2010-06-03 02:41 . 2010-06-03 02:41    3600384    ----a-w-    c:\windows\system32\GPhotos.scr
2009-05-01 21:02 . 2009-05-01 21:02    1044480    ----a-w-    c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02    200704    ----a-w-    c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-04-19 10:46 . 2008-04-19 10:15    72    --sh--w-    c:\windows\S5E90672C.tmp
2008-06-30 15:05 . 2008-06-30 08:55    2048    --sha-w-    c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-06-30 15:05 . 2008-06-30 08:55    2048    --sha-w-    c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-18 10:27    1119488    ----a-w-    c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19    94208    ----a-w-    c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"="" [?]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-24 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-28 244512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-20 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-20 81920]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\users\Mathias Refnov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
Indholdsfortegnelse i OneNote.onetoc2 [2009-2-2 3656]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-20 18:36    548352    ----a-w-    c:\program files\SuperAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\eNetHook.dll c:\windows\System32\avgrsstx.dll c:\windows\System32\acaptuser32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Exif Launcher S.lnk]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Google Updater.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
??????????????e [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
2007-01-14 03:38    151552    ----a-w-    c:\acer\AcerTour\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcerOrbicamRibbon]
2006-11-28 16:43    754712    ----a-w-    c:\program files\Acer\OrbiCam10\OrbiCam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-03 16:50    1603152    ----a-w-    c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-14 16:01    644696    ----a-w-    c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29    165784    ----a-w-    c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2006-12-26 00:23    643072    ----a-w-    c:\program files\Eraser\eraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44    31072    ----a-w-    c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08    417792    ----a-w-    c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28    1233920    ----a-w-    c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-09-02 13:27    25623336    ----a-r-    c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-07-26 11:15    2403568    ----a-w-    c:\program files\SuperAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):7d,ee,23,ce,ca,40,ca,01

R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 167936]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-12-08 113664]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 101120]
R3 SASENUM;SASENUM;c:\program files\SuperAntiSpyware\SASENUM.SYS [2010-02-19 12872]
R3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\DRIVERS\SMSCirda.sys [2006-10-18 31232]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2007-07-05 682232]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-16 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-16 243024]
S1 SASDIFSV;SASDIFSV;c:\program files\SuperAntiSpyware\SASDIFSV.SYS [2010-02-19 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SuperAntiSpyware\SASKUTIL.sys [2010-05-29 67656]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-16 308136]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-01-08 233472]
S2 SBKUPNT;SBKUPNT;c:\windows\system32\Drivers\SBKUPNT.SYS [2001-07-13 14976]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-01-08 36608]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]


--- Andre Services/Drivers i Hukommelsen ---

*NewlyCreated* - FSUSBEXDISK
*Deregistered* - Ndisprot.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs    REG_MULTI_SZ      BthServ
LocalServiceAndNoImpersonation    REG_MULTI_SZ      FontCache
.
Indhold af mappen 'Planlagte Opgaver'

2010-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 12:33]

2010-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 12:33]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uDefault_Search_URL = hxxp://www.google.com/ie
mWindow Title =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: danskebank.dk\netbank
Trusted Zone: danskebank.dk\www
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\users\Mathias Refnov\AppData\Roaming\Mozilla\Firefox\Profiles\k4f1n2bf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=da&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\users\Mathias Refnov\AppData\Roaming\Mozilla\Firefox\Profiles\k4f1n2bf.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLITIKKER ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-28 13:31
Windows 6.0.6002 Service Pack 2 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-891747130-3254500623-152161286-1000\Software\SecuROM\License information*]
"datasecu"=hex:f3,97,b2,6c,40,89,55,7e,92,7c,af,8c,29,ca,c7,e0,af,e0,22,63,e6,
  8c,68,18,8e,7d,7c,39,81,c4,0e,b5,6f,c9,9d,70,9a,0f,d5,d6,8f,67,33,af,2b,89,\
"rkeysecu"=hex:69,e2,59,40,d7,9b,66,ac,16,9a,78,8d,72,ca,5c,c9

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'Explorer.exe'(1408)
c:\users\Mathias Refnov\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\btncopy.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\conime.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Gennemført tid: 2010-08-28  13:42:32 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2010-08-28 11:42
ComboFix2.txt  2010-08-26 17:25
ComboFix3.txt  2010-08-15 17:32
ComboFix4.txt  2010-08-14 15:48

Pre-Kørsel: 13.357.453.312 byte ledig
Post-Kørsel: 13.002.514.432 byte ledig

- - End Of File - - 68E13D8221447139797C59C5930416F8
Avatar billede f-arn Guru
28. august 2010 - 14:48 #30
Da der er sket visse fremskridt, kunne jeg godt tænke min at prøve GMER igen.

Prov at køre GMER eefter denne vejledning.
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=208&title=gmer-vejledning

Læg mærke til:

Hvis du bliver advaret om rootkit aktivitet og spørger om du vil køre en fuld scanning, så svar "NO"

PS Da dine sikkerhedsprogammer kan kan konflikte med GMER er det vigtigt at du deaktiverer dem.
Avatar billede Slettet bruger
29. august 2010 - 15:39 #31
Stopper igen ved den der shadowvolumeharddiskcopy1 hvor programmet siger det er holdt op med at fungere.
Avatar billede f-arn Guru
30. august 2010 - 14:08 #32
Jeg begynder at ane et Bootkit. Vil du godt lave en Backup af ting du ikke vil miste.
Avatar billede Slettet bruger
31. august 2010 - 11:56 #33
Puuuuuuh det er mange filer, ser lige hvad jeg kan finde ud af og vender hurtigst muligt tilbage....
Avatar billede Slettet bruger
14. september 2010 - 10:51 #34
Det tog sin tid, men jeg er tilbage igen... Det er næsten umuligt at finde plads til alle mine arbejdsfiler m.m. og må derfor sige det ikke er muligt at lave en fuld backup... Dog kører min computer nu uden beklageligheder:D

Der kan ikke lyde nok tak til f-arn for al den hjælp du har givet!! Det har sku virkelig gjort mit specialeskriveri meget nemmere!!

Tak til alle jer andre eksperter som også gjorde en indsats.
Avatar billede f-arn Guru
16. september 2010 - 20:29 #35
Jamen - så holder vi her.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester





White paper
Tidsbegrænset kampagne: Overvejer du at udskifte eller tilføje printere i din forretning? Vi kan tilbyde én eller flere maskiner gratis