Avatar billede lonerangr Nybegynder
06. oktober 2009 - 20:01 Der er 6 kommentarer og
1 løsning

HiJack logfil

Hej Eksperter

Jeg sidder her med en Asus laptop der opfører sig underligt. Derfor lige en log fra HiJack, som jeg håber en eller anden gider kikke igennem.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:55:26, on 06-10-2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ATK Hotkey\HControlUser.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\AsScrPro.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Users\gerda\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R3KAOIVL\HiJackThis[1].exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Users\gerda\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3YNDQH52\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HControlUser] "C:\Program Files\ATK Hotkey\HcontrolUser.exe"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
O4 - HKLM\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O4 - HKUS\S-1-5-18\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'Default user')
O4 - Startup: Windows Mail.lnk = C:\Program Files\Windows Mail\WinMail.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe

--
End of file - 8866 bytes

Jeg takker og bukker på forhånd.
Avatar billede f-arn Guru
06. oktober 2009 - 20:07 #1
Hent "Malwarebytes' Anti-Malware" her: http://www.malwarebytes.org/mbam.php
Installer og start programmet, opdater, lav "Hurtig skan" under fanebladet "skanner".
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra DDS som du finder her: http://download.bleepingcomputer.com/sUBs/dds.scr

eller her: http://www.forospyware.com/sUBs/dds


Den laver to logs,(DDS.txt og Attach.txt) gem dem på skrivebordet og kopier indholdet af DDS.txt  herind.

OBS - DDS skal gemmes på computeren og ikke køres fra nettet

Mht.: Vista - Højreklik på filen - Kør som Administrator.


NB Når du opdaterer Malwarebytes, så klik på "opdater" til den skriver at der ikke er flere opdateringer.
Avatar billede lonerangr Nybegynder
06. oktober 2009 - 20:46 #2
Anti-Malware fandt ingenting.

Malwarebytes' Anti-Malware 1.41
Database version: 2916
Windows 6.0.6002 Service Pack 2

06-10-2009 20:40:10
mbam-log-2009-10-06 (20-40-10).txt

Skan type: Hurtig skanning
Objekter skannet: 156995
Tid tilbagelagt: 16 minute(s), 15 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)







DDS Logfil.


DDS (Ver_09-09-29.01) - NTFSx86 
Run by gerda at 20:41:28,75 on 06-10-2009
Internet Explorer: 8.0.6001.18813
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.1790.652 [GMT 2:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\rundll32.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Windows\System32\svchost.exe -k BullGuard
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATK Hotkey\MsgTranAgt.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
C:\Program Files\ASUS\ATK Media\GPSWATCH.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\ATK Hotkey\HControlUser.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\ACEngSvr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\AsScrPro.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\gerda\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.dk/
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [BullGuard] "c:\program files\bullguard ltd\bullguard\bullguard.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [CLMLServer] "c:\program files\cyberlink\power2go\CLMLSvc.exe"
mRun: [P2Go_Menu] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [HControlUser] "c:\program files\atk hotkey\HcontrolUser.exe"
mRun: [ATKOSD2] "c:\program files\atkosd2\ATKOSD2.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [ASUS Screen Saver Protector] c:\windows\AsScrPro.exe
mRun: [ASUS Camera ScreenSaver] c:\windows\AsScrProlog.exe
mRun: [BullGuard] "c:\program files\bullguard ltd\bullguard\bullguard.exe" -boot
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Skytel] Skytel.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
dRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
StartupFolder: c:\users\gerda\appdata\roaming\micros~1\windows\startm~1\programs\startup\window~1.lnk - c:\program files\windows mail\WinMail.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\windows\system32\BGLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL

============= SERVICES / DRIVERS ===============

R1 afw;Agnitum Firewall Driver;c:\windows\system32\drivers\afw.sys [2009-4-16 29208]
R2 BdFileSpy;BullGuard File Monitor Driver;c:\windows\system32\drivers\BdFileSpy.sys [2009-5-4 55504]
R2 BsFileScan;BullGuard File Scan Service;c:\windows\system32\svchost.exe -k BullGuard [2008-1-21 21504]
R2 BsFire;BullGuard Firewall Service;c:\windows\system32\svchost.exe -k BullGuard [2008-1-21 21504]
R2 BsMailProxy;BullGuard Email Monitoring Service;c:\windows\system32\svchost.exe -k BullGuard [2008-1-21 21504]
R3 AfwCore;Agnitum Firewall Core Driver;c:\windows\system32\drivers\AfwCore.sys [2009-5-4 305688]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-10-6 38224]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-6-25 44064]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-5-4 55264]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2008-12-8 533344]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-3-7 30192]

=============== Created Last 30 ================

2009-10-06 20:16    <DIR>    --d-----    c:\users\gerda\appdata\roaming\Malwarebytes
2009-10-06 20:15    38,224    a-------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-06 20:15    19,160    a-------    c:\windows\system32\drivers\mbam.sys
2009-10-06 20:15    <DIR>    --d-----    c:\programdata\Malwarebytes
2009-10-06 20:15    <DIR>    --d-----    c:\program files\Malwarebytes' Anti-Malware
2009-10-06 20:15    <DIR>    --d-----    c:\progra~2\Malwarebytes
2009-10-06 19:48    <DIR>    --d-----    c:\users\gerda\.housecall6.6
2009-10-05 12:21    <DIR>    --d-----    c:\program files\SkoleKom
2009-10-04 22:14    <DIR>    --d-----    c:\users\gerda\appdata\roaming\FirstClass
2009-10-04 21:48    <DIR>    --d-----    c:\users\gerda\Office Genuine Advantage
2009-10-04 16:44    32,656    a-------    c:\windows\system32\msonpmon.dll
2009-10-04 16:19    <DIR>    --d-----    c:\users\gerda\appdata\roaming\OLYMPUS
2009-10-04 16:10    <DIR>    --d-----    c:\program files\common files\MSSoap
2009-10-04 16:10    <DIR>    --d-----    c:\program files\OLYMPUS
2009-10-04 16:01    54,156    a---h---    c:\windows\QTFont.qfn
2009-10-04 16:01    1,409    a-------    c:\windows\QTFont.for
2009-10-04 16:01    86,016    a-------    c:\windows\unvise32qt.exe
2009-10-04 16:00    <DIR>    --d-----    c:\windows\system32\QuickTime
2009-10-04 16:00    <DIR>    --d-----    c:\programdata\QuickTime
2009-10-03 18:05    2,421,760    a-------    c:\windows\system32\wucltux.dll
2009-10-03 18:05    87,552    a-------    c:\windows\system32\wudriver.dll
2009-10-03 18:04    171,608    a-------    c:\windows\system32\wuwebv.dll
2009-10-03 18:04    33,792    a-------    c:\windows\system32\wuapp.exe
2009-10-02 19:39    195,440    --------    c:\windows\system32\MpSigStub.exe
2009-09-26 23:47    <DIR>    --d-----    c:\windows\system32\eu-ES
2009-09-26 23:47    <DIR>    --d-----    c:\windows\system32\ca-ES
2009-09-26 23:47    <DIR>    --d-----    c:\windows\system32\vi-VN
2009-09-26 22:41    <DIR>    --d-----    c:\windows\system32\EventProviders
2009-09-19 23:54    12,240,896    a-------    c:\windows\system32\NlsLexicons0007.dll
2009-09-19 23:54    3,408,896    a-------    c:\windows\system32\SLsvc.exe
2009-09-19 23:54    1,081,344    a-------    c:\windows\system32\SLCExt.dll
2009-09-19 23:54    2,134,528    a-------    c:\windows\system32\FunctionDiscoveryFolder.dll
2009-09-19 23:54    65,536    a-------    c:\windows\system32\DevicePairingWizard.exe
2009-09-19 23:54    2,644,480    a-------    c:\windows\system32\NlsLexicons0009.dll
2009-09-19 23:54    1,480,704    a-------    c:\windows\system32\mssrch.dll
2009-09-19 23:54    684,032    a-------    c:\windows\system32\drivers\spsys.sys
2009-09-19 23:54    1,576,960    a-------    c:\windows\system32\tquery.dll
2009-09-19 23:52    524,288    a-------    c:\windows\system32\sqlsrv32.dll
2009-09-19 23:51    306,176    a-------    c:\windows\system32\scesrv.dll
2009-09-19 23:50    265,728    a-------    c:\windows\system32\wbem\esscli.dll
2009-09-19 23:50    189,440    a-------    c:\windows\system32\wbem\mofd.dll
2009-09-19 23:50    83,968    a-------    c:\windows\system32\wbem\wmiutils.dll
2009-09-19 23:50    30,208    a-------    c:\windows\system32\wbem\wbemprox.dll
2009-09-19 23:50    744,448    a-------    c:\windows\system32\wbem\wbemcore.dll
2009-09-19 23:50    614,912    a-------    c:\windows\system32\wbem\fastprox.dll
2009-09-19 23:50    265,728    a-------    c:\windows\system32\wbem\repdrvfs.dll
2009-09-19 23:49    705,536    a-------    c:\windows\system32\SmiEngine.dll
2009-09-19 23:49    218,624    a-------    c:\windows\system32\wdscore.dll
2009-09-19 23:49    130,560    a-------    c:\windows\system32\PkgMgr.exe
2009-09-19 23:47    247,808    a-------    c:\windows\system32\drvstore.dll
2009-09-10 17:45    904,776    a-------    c:\windows\system32\drivers\tcpip.sys
2009-09-10 17:45    105,984    a-------    c:\windows\system32\netiohlp.dll
2009-09-10 17:45    30,720    a-------    c:\windows\system32\drivers\tcpipreg.sys
2009-09-10 17:44    27,136    a-------    c:\windows\system32\NETSTAT.EXE
2009-09-10 17:44    19,968    a-------    c:\windows\system32\ARP.EXE
2009-09-10 17:44    9,728    a-------    c:\windows\system32\TCPSVCS.EXE
2009-09-10 17:44    17,920    a-------    c:\windows\system32\ROUTE.EXE
2009-09-10 17:44    11,264    a-------    c:\windows\system32\MRINFO.EXE
2009-09-10 17:44    10,240    a-------    c:\windows\system32\finger.exe
2009-09-10 17:44    8,704    a-------    c:\windows\system32\HOSTNAME.EXE
2009-09-10 17:44    17,920    a-------    c:\windows\system32\netevent.dll
2009-09-08 17:58    4,710    a-------    c:\windows\system32\fc.ico
2009-09-08 17:58    2,528    a-------    c:\windows\FCIC.INI
2009-09-08 17:58    <DIR>    --d-----    c:\programdata\FirstClass
2009-09-08 17:58    <DIR>    --d-----    c:\progra~2\FirstClass
2009-09-08 17:58    <DIR>    --d-----    c:\program files\FirstClass
2009-09-07 00:21    1,696,768    a-------    c:\windows\system32\gameux.dll
2009-09-07 00:21    28,672    a-------    c:\windows\system32\Apphlpdm.dll
2009-09-07 00:21    4,240,384    a-------    c:\windows\system32\GameUXLegacyGDFs.dll

==================== Find3M  ====================

2009-10-05 19:41    463,344    a-------    c:\windows\system32\perfh006.dat
2009-10-05 19:41    77,202    a-------    c:\windows\system32\perfc006.dat
2009-10-04 19:39    45,056    a-------    c:\windows\system32\acovcnt.exe
2009-09-27 01:34    143,360    a-------    c:\windows\inf\infstrng.dat
2009-09-27 01:34    86,016    a-------    c:\windows\inf\infstor.dat
2009-09-27 01:34    51,200    a-------    c:\windows\inf\infpub.dat
2009-09-26 23:46    665,600    a-------    c:\windows\inf\drvindex.dat
2009-08-29 04:30    173,056    a-------    c:\windows\apppatch\AcXtrnal.dll
2009-08-29 04:30    458,752    a-------    c:\windows\apppatch\AcSpecfc.dll
2009-08-29 04:30    2,159,616    a-------    c:\windows\apppatch\AcGenral.dll
2009-08-29 04:30    542,720    a-------    c:\windows\apppatch\AcLayers.dll
2009-08-03 15:07    403,816    a-------    c:\windows\system32\OGACheckControl.dll
2009-08-03 15:07    322,928    a-------    c:\windows\system32\OGAAddin.dll
2009-08-03 15:07    230,768    a-------    c:\windows\system32\OGAEXEC.exe
2009-07-31 15:23    411,368    a-------    c:\windows\system32\deploytk.dll
2009-07-22 18:13    27,839    a-------    c:\programdata\nvModes.dat
2009-07-22 18:13    27,839    a-------    c:\progra~2\nvModes.dat
2009-07-21 23:52    915,456    a-------    c:\windows\system32\wininet.dll
2009-07-21 23:47    109,056    a-------    c:\windows\system32\iesysprep.dll
2009-07-21 23:47    71,680    a-------    c:\windows\system32\iesetup.dll
2009-07-21 22:13    133,632    a-------    c:\windows\system32\ieUnatt.exe
2009-07-17 15:54    71,680    a-------    c:\windows\system32\atl.dll
2009-07-15 14:40    8,147,456    a-------    c:\windows\system32\wmploc.DLL
2009-07-15 14:39    313,344    a-------    c:\windows\system32\wmpdxm.dll
2009-07-15 14:39    4,096    a-------    c:\windows\system32\dxmasf.dll
2009-07-15 14:39    7,680    a-------    c:\windows\system32\spwmp.dll
2009-07-11 21:01    513,536    a-------    c:\windows\system32\wlansvc.dll
2009-07-11 21:01    302,592    a-------    c:\windows\system32\wlansec.dll
2009-07-11 21:01    293,376    a-------    c:\windows\system32\wlanmsm.dll
2009-07-11 21:01    65,024    a-------    c:\windows\system32\wlanapi.dll
2009-07-11 19:03    127,488    a-------    c:\windows\system32\L2SecHC.dll
2008-04-29 08:07    300,302    a-------    c:\windows\inf\perflib\0406\perfi.dat
2008-04-29 08:07    300,302    a-------    c:\windows\inf\perflib\0406\perfh.dat
2008-04-29 08:07    36,364    a-------    c:\windows\inf\perflib\0406\perfd.dat
2008-04-29 08:07    36,364    a-------    c:\windows\inf\perflib\0406\perfc.dat
2008-01-21 04:43    174    a--sh---    c:\program files\desktop.ini
2006-11-02 11:20    287,440    a-------    c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 11:20    287,440    a-------    c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 11:20    30,674    a-------    c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 11:20    30,674    a-------    c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 20:43:31,12 ===============
Avatar billede f-arn Guru
07. oktober 2009 - 04:15 #3
Jeg sidder her med en Asus laptop der opfører sig underligt

Hvad gør den da?
Avatar billede lonerangr Nybegynder
07. oktober 2009 - 07:35 #4
Den mister jævnligt forbindelsen til nettet, både via kabel og trådløs. Java fungerer ikke. Når den spørger efter Flash 10, bliver den linket til en underlig side jeg ikke har set før. Bullguard har efter hvad brugeren sige, lagt sig ind únder spil.

Alt i alt noget der ikke giver mening. Overvejer en reinstallation, men kunne godt tænke mig at finde ud af hvad det egentlig er der sker forinden.
Avatar billede f-arn Guru
07. oktober 2009 - 10:32 #5
Jeg kan ikke få øje på noget malware, men jeg ved at Agnitum sommetider kan forårsage en ustabil internet forbindelse. Prøv, i første omgang, at deaktivere den.
Avatar billede lonerangr Nybegynder
07. oktober 2009 - 10:45 #6
Det vil jeg prøve. Jeg kommer ikke til PC'en før til aften, men sender en tilbagemelding når det er testet.
Avatar billede lonerangr Nybegynder
12. marts 2011 - 16:44 #7
.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester