Avatar billede enriko Nybegynder
31. maj 2012 - 23:02

Virus tjek ønskes( Combofix og hijakcthis log)

Hej Eksperter

Er her ikke en kyndig person til hjælpe mig med en vista pc der var angrebet af virus?

Jeg fik fjernet nogle ved at bruge microsoft secuirty essential, derefter har jeg hentet combofix og kørte den, og helt til sidst en tur med hijackthis.

Her er det forskellige log:

                                                                   
                                                                   
                                                                   
                                           
ComboFix 12-05-31.02 - Peri 31-05-2012  21:48:45.1.2 - x86
Kører fra: c:\users\Peri\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Internet Explorer\Internet Explorer
c:\program files\Internet Explorer\Internet Explorer\Internet.ico
c:\program files\Internet Explorer\Internet Explorer\Interop.SHDocVw.DLL
c:\program files\Internet Explorer\Internet Explorer\MSHTMLSubset.dll
c:\users\Peri\AppData\Roaming\.#
c:\users\Peri\AppData\Roaming\.#\MBX@10B4@292950.###
c:\users\Peri\AppData\Roaming\.#\MBX@10B4@292980.###
c:\users\Peri\AppData\Roaming\.#\MBX@10B4@2929B0.###
c:\users\Peri\AppData\Roaming\.#\MBX@14CC@1B32950.###
c:\users\Peri\AppData\Roaming\.#\MBX@14CC@1B32980.###
c:\users\Peri\AppData\Roaming\.#\MBX@14CC@1B329B0.###
c:\users\Peri\AppData\Roaming\.#\MBX@15FC@3E2950.###
c:\users\Peri\AppData\Roaming\.#\MBX@15FC@3E2980.###
c:\users\Peri\AppData\Roaming\.#\MBX@15FC@3E29B0.###
c:\users\Peri\AppData\Roaming\.#\MBX@B28@192950.###
c:\users\Peri\AppData\Roaming\.#\MBX@B28@192980.###
c:\users\Peri\AppData\Roaming\.#\MBX@B28@1929B0.###
c:\windows\unin0406.exe
.
.
(((((((((((((((((((((((((((((  Filer skabt fra 2012-04-28 til 2012-05-31  )))))))))))))))))))))))))))))))))))
.
.
2012-05-31 20:09 . 2012-05-31 20:09    29904    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D1101283-E4C4-4385-8FFA-9C626F040BE6}\MpKsl36fc3b81.sys
2012-05-31 20:01 . 2012-05-31 20:01    --------    d-----w-    c:\users\Gæst\AppData\Local\temp
2012-05-31 20:01 . 2012-05-31 20:01    --------    d-----w-    c:\users\Default\AppData\Local\temp
2012-05-31 19:42 . 2012-05-14 23:43    6737808    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D1101283-E4C4-4385-8FFA-9C626F040BE6}\mpengine.dll
2012-05-29 22:15 . 2012-02-09 11:17    713784    ------w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C869B7A8-2022-437D-98C7-1446D45FD2EE}\gapaengine.dll
2012-05-29 22:12 . 2012-05-14 23:43    6737808    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-29 22:01 . 2012-05-29 22:01    159744    ----a-w-    c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2012-05-29 22:01 . 2012-05-29 22:01    159744    ----a-w-    c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2012-05-29 22:01 . 2012-05-29 22:01    159744    ----a-w-    c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2012-05-29 22:01 . 2012-05-29 22:01    159744    ----a-w-    c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2012-05-29 22:01 . 2012-05-29 22:01    159744    ----a-w-    c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2012-05-29 22:01 . 2012-05-29 22:01    159744    ----a-w-    c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2012-05-29 22:01 . 2012-05-29 22:01    159744    ----a-w-    c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2012-05-29 21:59 . 2012-05-29 22:01    --------    d-----w-    c:\program files\QuickTime
2012-05-29 21:51 . 2012-05-29 21:54    --------    d-----w-    c:\program files\Microsoft Security Client
2012-05-29 21:48 . 2010-04-05 20:00    221568    ----a-w-    c:\windows\system32\drivers\netio.sys
2012-05-29 21:32 . 2012-05-29 21:32    --------    d-----w-    c:\users\Gæst\AppData\Local\Secunia PSI (BETA)
2012-05-29 20:48 . 2012-05-29 20:48    --------    d-----w-    c:\users\Peri\AppData\Local\Secunia PSI (BETA)
2012-05-29 20:47 . 2012-05-29 20:47    --------    d-----w-    c:\program files\Secunia
2012-05-25 19:46 . 2012-05-08 16:40    6737808    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{5330EA23-B6DE-4654-9D59-116548DF40AF}\mpengine.dll
2012-05-14 17:44 . 2012-05-14 17:44    --------    d-----w-    c:\programdata\iMesh
2012-05-14 17:44 . 2012-05-14 17:44    --------    d-----w-    c:\program files\iMesh Applications
2012-05-14 17:44 . 2012-05-14 17:44    --------    d-----w-    c:\programdata\{4965EFCE-6978-4137-B293-4130A6875DB9}
2012-05-14 17:44 . 2012-05-14 17:44    --------    d-----w-    c:\users\Peri\AppData\Local\PackageAware
.
.
.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-29 22:32 . 2011-08-16 19:36    472808    ----a-w-    c:\windows\system32\deployJava1.dll
2012-05-29 20:05 . 2012-05-01 12:26    419488    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2012-05-29 20:05 . 2011-11-29 19:35    70304    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-18 18:56 . 2012-04-18 18:56    94208    ----a-w-    c:\windows\system32\QuickTimeVR.qtx
2012-04-18 18:56 . 2012-04-18 18:56    69632    ----a-w-    c:\windows\system32\QuickTime.qts
2012-04-03 08:16 . 2012-05-11 11:20    3602816    ----a-w-    c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16 . 2012-05-11 11:20    3550080    ----a-w-    c:\windows\system32\ntoskrnl.exe
2012-04-02 13:36 . 2012-05-11 11:20    2044928    ----a-w-    c:\windows\system32\win32k.sys
2012-03-20 18:44 . 2012-03-20 18:44    74112    ----a-w-    c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-20 18:44 . 2012-03-20 18:44    171064    ----a-w-    c:\windows\system32\drivers\MpFilter.sys
2012-03-05 13:49 . 2012-03-05 13:49    161792    ----a-w-    c:\windows\system32\msls31.dll
2012-03-05 13:49 . 2012-03-05 13:49    86528    ----a-w-    c:\windows\system32\iesysprep.dll
2012-03-05 13:49 . 2012-03-05 13:49    76800    ----a-w-    c:\windows\system32\SetIEInstalledDate.exe
2012-03-05 13:49 . 2012-03-05 13:49    74752    ----a-w-    c:\windows\system32\RegisterIEPKEYs.exe
2012-03-05 13:49 . 2012-03-05 13:49    48640    ----a-w-    c:\windows\system32\mshtmler.dll
2012-03-05 13:49 . 2012-03-05 13:49    63488    ----a-w-    c:\windows\system32\tdc.ocx
2012-03-05 13:49 . 2012-03-05 13:49    367104    ----a-w-    c:\windows\system32\html.iec
2012-03-05 13:49 . 2012-03-05 13:49    74752    ----a-w-    c:\windows\system32\iesetup.dll
2012-03-05 13:49 . 2012-03-05 13:49    420864    ----a-w-    c:\windows\system32\vbscript.dll
2012-03-05 13:49 . 2012-03-05 13:49    23552    ----a-w-    c:\windows\system32\licmgr10.dll
2012-03-05 13:49 . 2012-03-05 13:49    152064    ----a-w-    c:\windows\system32\wextract.exe
2012-03-05 13:49 . 2012-03-05 13:49    150528    ----a-w-    c:\windows\system32\iexpress.exe
2012-03-05 13:49 . 2012-03-05 13:49    35840    ----a-w-    c:\windows\system32\imgutil.dll
2012-03-05 13:49 . 2012-03-05 13:49    142848    ----a-w-    c:\windows\system32\ieUnatt.exe
2012-03-05 13:49 . 2012-03-05 13:49    11776    ----a-w-    c:\windows\system32\mshta.exe
2012-03-05 13:49 . 2012-03-05 13:49    101888    ----a-w-    c:\windows\system32\admparse.dll
2012-03-05 13:49 . 2012-03-05 13:49    110592    ----a-w-    c:\windows\system32\IEAdvpack.dll
2007-11-11 22:03 . 2007-11-11 22:03    2293712    ----a-w-    c:\program files\FLV PlayerFCSetup.exe
2007-11-11 22:03 . 2007-11-11 22:03    3928264    ----a-w-    c:\program files\FLV PlayerRCATSetup.exe
2007-11-11 22:02 . 2007-11-11 22:01    411248    ----a-w-    c:\program files\FLV PlayerRCSetup.exe
2007-03-09 08:12    27648    --sha-w-    c:\windows\System32\AVSredirect.dll
.
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12    94208    ----a-w-    c:\users\Peri\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12    94208    ----a-w-    c:\users\Peri\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12    94208    ----a-w-    c:\users\Peri\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12    94208    ----a-w-    c:\users\Peri\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-20 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-29 17148552]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-12-02 167936]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-12-04 46704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-07 44128]
.
c:\users\Peri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Peri\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-15 24246216]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2012-5-3 562232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Peri^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Screen Clipper and Launcher til OneNote 2007.lnk]
path=c:\users\Peri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk
backup=c:\windows\pss\Screen Clipper and Launcher til OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2068818888-4123811976-889618881-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000002
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-29 257696]
.
.
--- Andre Services/Drivers i Hukommelsen ---
.
*NewlyCreated* - MPKSL36FC3B81
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12    REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt    REG_MULTI_SZ      hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation    REG_MULTI_SZ      FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{42C5E519-D47F-4105-9CEC-29CC51DD953F}]
2009-04-11 06:27    73216    ----a-w-    c:\windows\System32\msiexec.exe
.
Indhold af mappen 'Planlagte Opgaver'
.
2012-05-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-01 20:05]
.
2012-05-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 13:23]
.
2012-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 13:23]
.
2010-12-17 c:\windows\Tasks\User_Feed_Synchronization-{5C0EE7B5-38BF-431D-B4C0-C0EC6EC485D8}.job
- c:\windows\system32\msfeedssync.exe [2012-03-05 13:49]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://google.dk/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=71&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: danskebank.dk
TCP: DhcpNameServer = 10.0.0.1
DPF: {5BEB08D4-5421-446C-B329-10377FC45736} - hxxp://launcher.room-3.com/room3_40/room3_50.cab
.
- - - - TOMME GENVEJE FJERNET - - - -
.
AddRemove-HijackThis - c:\users\Peri\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HB3EXPVY\HijackThis.exe
AddRemove-RBODeinstKey - c:\windows\unin0406.exe
.
.
.
**************************************************************************
scanner skjulte processer ... 
.
scanner skjulte autostarter ...
.
scanner skjulte filer ... 
.
scanning gennemført med succes
skjulte filer:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000031
.
--------------------- DLLs startet under kørende Processer ---------------------
.
- - - - - - - > 'Explorer.exe'(3604)
c:\users\Peri\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Secunia\PSI\PSIA.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLSched.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\conime.exe
c:\program files\Secunia\PSI\sua.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Google\Google Toolbar\GoogleToolbarUser_32.exe
c:\program files\Microsoft Security Client\MpCmdRun.exe
.
**************************************************************************
.
Gennemført tid: 2012-05-31  22:21:00 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2012-05-31 20:19
.
Pre-Kørsel: 48.547.467.264 byte ledig
Post-Kørsel: 47.833.194.496 byte ledig
.
- - End Of File - - 8D2F6EA3E3D539BE74804C8C39F56D08





HIJACKTHIS LOG*******************************************

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:24:22, on 31-05-2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Users\Peri\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Peri\Desktop\gt\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=71&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - Startup: Dropbox.lnk = C:\Users\Peri\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.danskebank.dk
O16 - DPF: {5BEB08D4-5421-446C-B329-10377FC45736} (Croom3_50 Object) - http://launcher.room-3.com/room3_40/room3_50.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.torstorpskole.skoleintra.dk/Li/_includes/XUpload.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Tjenesten Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files\Secunia\PSI\sua.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10483 bytes
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester