Avatar billede cvan Nybegynder
17. juli 2011 - 17:25 Der er 11 kommentarer og
1 løsning

Meget langsom computer

Hej eksperter.

Jeg sidder med en computer der er blevet ekstrem langsom. Jeg har fulgt fromsej's artikel/guide og her de nedenstående logs, I meget gerne må kigge på.

-----

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7173

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

17-07-2011 16:08:02
mbam-log-2011-07-17 (16-08-02).txt

Skanningstype: Fuldstændig skanning (C:\|D:\|E:\|F:\|G:\|)
Objekter skannet: 632036
Tid gået: 1 time(e), 44 minut(ter), 35 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 1

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
d:\Games\medal of honor\Binaries\loader.dll (Riskware.Tool.CK) -> Quarantined and deleted successfully.



-------


ComboFix 11-07-17.01 - AB 17-07-2011  16:23:35.1.4 - x64
Microsoft® Windows Vista™ Ultimate  6.0.6002.2.1252.45.1030.18.4094.2527 [GMT 2:00]
Kører fra: c:\users\AB\Desktop\Virus hjµlp\ComboFix.exe
Kommandoer benyttet :: c:\users\AB\Desktop\Virus hjµlp\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Dannede nyt systemgendannelsespunkt
* Resident AV is active
.
.
.
(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\IsUn0406.exe
c:\windows\security\Database\tmp.edb
.
.
(((((((((((((((((((((((((((((  Filer skabt fra 2011-06-17 til 2011-07-17  )))))))))))))))))))))))))))))))))))
.
.
2011-07-17 14:29 . 2011-07-17 14:29    --------    d-----w-    c:\users\Default\AppData\Local\temp
2011-07-17 12:21 . 2011-07-17 12:21    --------    d-----w-    c:\users\AB\AppData\Roaming\Malwarebytes
2011-07-17 12:21 . 2011-07-06 17:52    41272    ----a-w-    c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-17 12:21 . 2011-07-17 12:21    --------    d-----w-    c:\programdata\Malwarebytes
2011-07-17 12:21 . 2011-07-17 12:21    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-17 12:21 . 2011-07-06 17:52    25912    ----a-w-    c:\windows\system32\drivers\mbam.sys
2011-07-17 12:10 . 2011-07-17 12:10    --------    d-----w-    c:\program files\CCleaner
2011-07-15 15:01 . 2011-06-07 17:10    8873296    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{7C50E1BC-1588-45E7-A512-C0272BB6A441}\mpengine.dll
2011-07-13 16:35 . 2011-06-02 13:50    2764288    ----a-w-    c:\windows\system32\win32k.sys
2011-07-13 16:35 . 2011-04-20 16:03    451072    ----a-w-    c:\windows\system32\winsrv.dll
2011-07-13 16:35 . 2011-04-20 15:58    85504    ----a-w-    c:\windows\system32\csrsrv.dll
2011-07-12 18:51 . 2011-07-12 19:06    --------    d-----w-    c:\users\AB\AppData\Local\Ubisoft Game Launcher
2011-07-06 11:42 . 2011-07-06 11:42    404640    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-06 11:42 . 2011-06-16 04:30    89048    ----a-w-    c:\program files (x86)\Mozilla Firefox\libEGL.dll
2011-07-06 11:42 . 2011-06-16 04:30    781272    ----a-w-    c:\program files (x86)\Mozilla Firefox\mozsqlite3.dll
2011-07-06 11:42 . 2011-06-16 04:30    465880    ----a-w-    c:\program files (x86)\Mozilla Firefox\libGLESv2.dll
2011-07-06 11:42 . 2011-06-16 04:30    1850328    ----a-w-    c:\program files (x86)\Mozilla Firefox\mozjs.dll
2011-07-06 11:42 . 2011-06-16 04:30    15832    ----a-w-    c:\program files (x86)\Mozilla Firefox\mozalloc.dll
2011-07-06 11:42 . 2011-06-16 04:30    142296    ----a-w-    c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2011-07-06 11:42 . 2010-01-01 08:00    1998168    ----a-w-    c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-07-06 11:42 . 2010-01-01 08:00    2106216    ----a-w-    c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-07-06 11:32 . 2011-04-29 16:15    344576    ----a-w-    c:\windows\system32\schannel.dll
2011-07-06 11:32 . 2011-04-29 15:59    276992    ----a-w-    c:\windows\SysWow64\schannel.dll
2011-07-05 15:55 . 2011-07-05 15:55    --------    d-----w-    c:\program files (x86)\Pure Networks
2011-07-05 15:55 . 2009-03-06 11:01    76184    ----a-w-    c:\windows\SysWow64\atsckernel.exe
2011-07-05 15:55 . 2009-03-06 10:59    20376    ----a-w-    c:\windows\SysWow64\atashost.exe
2011-07-05 15:55 . 2011-07-05 15:55    --------    d-----w-    c:\programdata\webex
2011-07-05 15:55 . 2011-07-05 15:55    8892928    ----a-w-    c:\programdata\atscie.msi
2011-07-05 15:53 . 2011-07-05 15:53    --------    d-----w-    c:\program files (x86)\Linksys
2011-07-05 15:53 . 2009-05-13 12:47    31536    ----a-w-    c:\windows\system32\drivers\pnarp.sys
2011-07-05 15:53 . 2009-05-13 12:47    33072    ----a-w-    c:\windows\system32\drivers\purendis.sys
2011-07-05 15:53 . 2011-07-05 15:53    --------    d-----w-    c:\program files (x86)\Common Files\Pure Networks Shared
2011-07-05 15:53 . 2011-07-05 15:53    --------    d-----w-    c:\programdata\Pure Networks
2011-07-05 15:51 . 2009-08-02 11:56    900608    ----a-w-    c:\windows\system32\drivers\netr28ux.sys
2011-06-17 23:10 . 2010-12-20 16:59    847360    ----a-w-    c:\windows\system32\oleaut32.dll
2011-06-17 23:10 . 2010-12-20 16:35    563712    ----a-w-    c:\windows\SysWow64\oleaut32.dll
2011-06-17 23:10 . 2011-04-29 13:41    176128    ----a-w-    c:\windows\system32\drivers\srv2.sys
2011-06-17 23:10 . 2011-04-29 13:40    145920    ----a-w-    c:\windows\system32\drivers\srvnet.sys
2011-06-17 23:10 . 2011-04-21 14:20    405504    ----a-w-    c:\windows\system32\drivers\afd.sys
2011-06-17 23:10 . 2011-04-29 13:39    275456    ----a-w-    c:\windows\system32\drivers\mrxsmb10.sys
2011-06-17 23:10 . 2011-04-29 13:39    135680    ----a-w-    c:\windows\system32\drivers\mrxsmb.sys
2011-06-17 23:10 . 2011-04-29 13:39    107008    ----a-w-    c:\windows\system32\drivers\mrxsmb20.sys
2011-06-17 23:08 . 2011-05-02 12:02    2409784    ----a-w-    c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-06-17 23:08 . 2011-05-02 12:01    2409784    ----a-w-    c:\program files\Windows Mail\OESpamFilter.dat
2011-06-17 23:08 . 2011-04-14 15:14    97792    ----a-w-    c:\windows\system32\drivers\dfsc.sys
2011-06-17 23:08 . 2011-05-02 17:16    739328    ----a-w-    c:\windows\SysWow64\inetcomm.dll
2011-06-17 23:08 . 2011-05-02 17:13    975360    ----a-w-    c:\windows\system32\inetcomm.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-24 17:14 . 2009-10-03 11:56    270720    ------w-    c:\windows\system32\MpSigStub.exe
2011-05-10 13:47 . 2011-05-10 13:47    161792    ----a-w-    c:\windows\SysWow64\msls31.dll
2011-05-10 13:47 . 2011-05-10 13:47    1126912    ----a-w-    c:\windows\SysWow64\wininet.dll
2011-05-10 13:47 . 2011-05-10 13:47    86528    ----a-w-    c:\windows\SysWow64\iesysprep.dll
2011-05-10 13:47 . 2011-05-10 13:47    76800    ----a-w-    c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-10 13:47 . 2011-05-10 13:47    74752    ----a-w-    c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-10 13:47 . 2011-05-10 13:47    48640    ----a-w-    c:\windows\SysWow64\mshtmler.dll
2011-05-10 13:47 . 2011-05-10 13:47    74752    ----a-w-    c:\windows\SysWow64\iesetup.dll
2011-05-10 13:47 . 2011-05-10 13:47    63488    ----a-w-    c:\windows\SysWow64\tdc.ocx
2011-05-10 13:47 . 2011-05-10 13:47    367104    ----a-w-    c:\windows\SysWow64\html.iec
2011-05-10 13:47 . 2011-05-10 13:47    23552    ----a-w-    c:\windows\SysWow64\licmgr10.dll
2011-05-10 13:47 . 2011-05-10 13:47    152064    ----a-w-    c:\windows\SysWow64\wextract.exe
2011-05-10 13:47 . 2011-05-10 13:47    150528    ----a-w-    c:\windows\SysWow64\iexpress.exe
2011-05-10 13:47 . 2011-05-10 13:47    1427456    ----a-w-    c:\windows\SysWow64\inetcpl.cpl
2011-05-10 13:47 . 2011-05-10 13:47    420864    ----a-w-    c:\windows\SysWow64\vbscript.dll
2011-05-10 13:47 . 2011-05-10 13:47    35840    ----a-w-    c:\windows\SysWow64\imgutil.dll
2011-05-10 13:47 . 2011-05-10 13:47    142848    ----a-w-    c:\windows\SysWow64\ieUnatt.exe
2011-05-10 13:47 . 2011-05-10 13:47    11776    ----a-w-    c:\windows\SysWow64\mshta.exe
2011-05-10 13:47 . 2011-05-10 13:47    101888    ----a-w-    c:\windows\SysWow64\admparse.dll
2011-05-10 13:46 . 2011-05-10 13:46    110592    ----a-w-    c:\windows\SysWow64\IEAdvpack.dll
2011-05-10 13:46 . 2011-05-10 13:46    89088    ----a-w-    c:\windows\system32\RegisterIEPKEYs.exe
2011-05-10 13:46 . 2011-05-10 13:46    222208    ----a-w-    c:\windows\system32\msls31.dll
2011-05-10 13:46 . 2011-05-10 13:46    1389056    ----a-w-    c:\windows\system32\wininet.dll
2011-05-10 13:46 . 2011-05-10 13:46    12288    ----a-w-    c:\windows\system32\mshta.exe
2011-05-10 13:46 . 2011-05-10 13:46    114176    ----a-w-    c:\windows\system32\admparse.dll
2011-05-10 13:46 . 2011-05-10 13:46    91648    ----a-w-    c:\windows\system32\SetIEInstalledDate.exe
2011-05-10 13:46 . 2011-05-10 13:46    85504    ----a-w-    c:\windows\system32\iesetup.dll
2011-05-10 13:46 . 2011-05-10 13:46    76800    ----a-w-    c:\windows\system32\tdc.ocx
2011-05-10 13:46 . 2011-05-10 13:46    49664    ----a-w-    c:\windows\system32\imgutil.dll
2011-05-10 13:46 . 2011-05-10 13:46    48640    ----a-w-    c:\windows\system32\mshtmler.dll
2011-05-10 13:46 . 2011-05-10 13:46    448512    ----a-w-    c:\windows\system32\html.iec
2011-05-10 13:46 . 2011-05-10 13:46    135168    ----a-w-    c:\windows\system32\IEAdvpack.dll
2011-05-10 13:46 . 2011-05-10 13:46    111616    ----a-w-    c:\windows\system32\iesysprep.dll
2011-05-10 13:46 . 2011-05-10 13:46    603648    ----a-w-    c:\windows\system32\vbscript.dll
2011-05-10 13:46 . 2011-05-10 13:46    30720    ----a-w-    c:\windows\system32\licmgr10.dll
2011-05-10 13:46 . 2011-05-10 13:46    173056    ----a-w-    c:\windows\system32\ieUnatt.exe
2011-05-10 13:46 . 2011-05-10 13:46    165888    ----a-w-    c:\windows\system32\iexpress.exe
2011-05-10 13:46 . 2011-05-10 13:46    160256    ----a-w-    c:\windows\system32\wextract.exe
2011-05-10 13:46 . 2011-05-10 13:46    1492992    ----a-w-    c:\windows\system32\inetcpl.cpl
2011-04-21 17:03 . 2010-06-24 09:33    18328    ----a-w-    c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-02 98304]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"nmctxth"="c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-06-18 647216]
"nmapp"="c:\program files (x86)\Pure Networks\Network Magic\nmapp.exe" [2009-06-18 472112]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-21 135664]
R3 cpuz130;cpuz130;c:\users\AB\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [x]
R3 gupdatem;Google Update Tjeneste (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-21 135664]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 atashost;WebEx Service Host for Support Center;c:\windows\SysWOW64\atashost.exe [2009-03-06 20376]
S2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2007-12-21 468224]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 netr28ux;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
.
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-21 11:16]
.
2011-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-21 11:16]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-01-13 6963232]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-10-24 1911040]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 225792]
"Linksys Wireless Manager"="c:\program files (x86)\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-07-09 1366064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.dk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&ksporter til Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\AB\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\AB\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.254
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\AB\AppData\Roaming\Mozilla\Firefox\Profiles\kvspic8j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk/
.
- - - - TOMME GENVEJE FJERNET - - - -
.
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Engelsk-Dansk Ordbog - c:\windows\IsUn0406.exe
.
.
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_USERS\S-1-5-21-3206092701-1098271699-1650808052-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:15,15,26,94,12,4f,52,d5,ba,c8,29,53,eb,d5,22,58,0e,78,b2,f6,3c,11,ce,
  75,cc,b4,33,7e,1d,d6,07,d4,f7,8b,e8,5c,03,5b,e2,0a,7b,d1,40,2b,e9,cf,df,48,\
"??"=hex:69,6f,5c,46,6a,89,f9,ee,2d,48,e0,10,87,42,1e,12
.
[HKEY_USERS\S-1-5-21-3206092701-1098271699-1650808052-1000\Software\SecuROM\License information*]
"datasecu"=hex:94,cc,65,36,e7,0f,93,3d,55,57,f1,d8,62,67,3b,a2,96,7a,d9,f6,2e,
  9a,be,bd,04,95,0b,b1,73,f6,67,3f,39,bf,73,09,0a,03,99,a0,2e,fc,c3,22,09,8c,\
"rkeysecu"=hex:cf,fd,36,ed,8f,83,8f,67,d5,d5,68,a4,04,da,e7,c7
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
.
**************************************************************************
.
Gennemført tid: 2011-07-17  16:35:17 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2011-07-17 14:35
.
Pre-Kørsel: 21.922.463.744 byte ledig
Post-Kørsel: 21.798.244.352 byte ledig
.
- - End Of File - - 6C953468D0195921EA9DFF6D3D5EBD0D


-------


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:43:05, on 17-07-2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Hjælp til logon til Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~2\TEXTware\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\AB\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\AB\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\SysWOW64\atashost.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8108 bytes


---------------------------
17. juli 2011 - 17:39 #1
... blevet ekstrem langsom...

* Under opstart
* Ved (Inter)nettet
* Programmer generelt
* Spil (hvilke)
Avatar billede cvan Nybegynder
17. juli 2011 - 17:50 #2
Opstart er nok næsten normal.

Når jeg surfer på nettet er den meget langsom
Når den åbner/anvender programmer eller spil

Altså når jeg bruger computeren i det hele taget.
Avatar billede cvan Nybegynder
17. juli 2011 - 17:58 #3
Der skal dog siges at den er blevet hurtigere efter jeg fulgte guiden. Vil bare gerne høre om der er mere jeg kan gøre.
17. juli 2011 - 19:55 #4
Hvilken browser ? version ?
Avatar billede cvan Nybegynder
17. juli 2011 - 20:32 #5
Mozilla Firefox 5.0
17. juli 2011 - 20:34 #6
Hvordan med IE ?

"Gnaver" PC'en en del på Harddisken undervejs ?
Avatar billede cvan Nybegynder
17. juli 2011 - 20:38 #7
Jamen computeren kører faktisk okay nu efter jeg fulgte guiden: "Sådan fjerner du virus og malware".

Men jeg vil bare have nogen til at kigge logs igennem og se om der er andet :)
17. juli 2011 - 21:01 #8
... det er nok mest CCleaner's oprydning der har gjort en del... resten vil jeg lade andre om at kommentere...
Avatar billede johnstigers Seniormester
22. juli 2011 - 21:32 #9
Defragmentering er altid en god ting :)
Jeg gør det 1 gang om md.
Avatar billede cvan Nybegynder
23. juli 2011 - 11:20 #10
Tak for alle de gode forslag :) Betyder det at alle logs er rene? :)
23. juli 2011 - 13:38 #11
Evt. afinstall
* QUICKfind  (Eller bruger du den meget?)
* iPod-tjeneste (iPod Service)
* Google Update ####

---

Du bør/skal opdatere din AcrobatReader ->
http://get.adobe.com/dk/reader/  (FRAKlik det der Google halløj!)

---

http://kundeservice.tdc.dk/testcenter/

---
23. juli 2011 - 13:38 #12
* Oprydning med CCleaner
* Opret et FRISK SYSTEMGENDANNELSESPUNKT
* CCleaner - værktøjer - Systemgendannelse - Slet de gamle punkter
* Defragmentering
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester