Avatar billede rexa Nybegynder
30. november 2009 - 16:06 Der er 14 kommentarer og
1 løsning

HTJ,,,,

Hej jeg syntes min computer er blevet lidt langsom her på det sidste.

jeg ville høre om en af jeg gad og kigge min HTJ report igennem :) og se om der skulle ligge noget som ikke skulle være der


Logfile of HijackThis v1.99.1
Scan saved at 15:53:13, on 30-11-2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Creative\Shared Files\CTDevSrv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Programmer\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Stefan Rosquist\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programmer\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmer\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programmer\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Programmer\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FLLESF~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Programmer\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Programmer\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Programmer\Java\jre6\bin\jqs.exe" -service -config "C:\Programmer\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
Avatar billede f-arn Guru
30. november 2009 - 16:31 #1
Start med at opgradere HijackThis, XP og IE.
Avatar billede rexa Nybegynder
30. november 2009 - 16:52 #2
skal jeg nok ;) ... men bruger Firefox.. bruger ikke IE
Avatar billede rexa Nybegynder
30. november 2009 - 22:25 #3
jwg har opdateret WIndows og IE. men ikke Highjackthjis.. kunne ikke finde hvordan ..

men her er den nu

Logfile of HijackThis v1.99.1
Scan saved at 22:23:49, on 30-11-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Creative\Shared Files\CTDevSrv.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Programmer\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Microsoft IntelliType Pro\itype.exe
C:\Programmer\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Stefan Rosquist\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programmer\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmer\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programmer\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Programmer\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [itype] "C:\Programmer\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Programmer\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259603720109
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BD3993F-C7A4-4B13-AEEC-236B4620A7D6}: NameServer = 193.162.153.164,194.239.134.83
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FLLESF~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Programmer\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Programmer\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Programmer\Java\jre6\bin\jqs.exe" -service -config "C:\Programmer\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
30. november 2009 - 22:32 #4
...bruger ikke IE... - men det gør uønskede 'gæster' - også selvom IE 'aldrig' har været åbnet!!!

Desuden:
Husk M$ ServicePack3 til XP -> http://www.microsoft.com/downloads/details.aspx?FamilyID=5b33b5a8-5e76-401f-be08-1e1555d4f3d4&displaylang=da
samt de MANGE (=ALLE) opdateringer fra WindowsUpdate. Incl IE8 komplet !!!
Du bruger en meget GAMMEL AVG8 !!!
http://www.spywarefri.dk/artikel/computerblade-misinformerer/
Brug denne istedet -> http://www.spywarefri.dk/artikel/avg-anti-virus-free-edition-9.0-231009/

(Der er mange flere elementer, som skal ses på men ovenstående 100% først !!!)

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

Så vender vi måske tilbage til dig når du måske for fuldt op på dine tidligere spørgsmål -> http://www.eksperten.dk/list/spoergsmaal/rexa
http://www.eksperten.dk/faq#faq-8-5

(Du har vist fået det at vide før ?)
Avatar billede rexa Nybegynder
01. december 2009 - 08:17 #5
jeg har nu opdateret IE og HTJ også har jeg hentet 9'eren af AVG.
jeg har også lukket de spørgsmål jeg havde åben.
men her er den nye log fil :) håber du kan hjælpe mig :)
------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:14:29, on 01-12-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\AVG\AVG9\avgwdsvc.exe
C:\Programmer\Creative\Shared Files\CTDevSrv.exe
C:\Programmer\AVG\AVG9\avgchsvx.exe
C:\Programmer\AVG\AVG9\avgrsx.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\AVG\AVG9\avgcsrvx.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Programmer\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Microsoft IntelliType Pro\itype.exe
C:\Programmer\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Documents and Settings\Stefan Rosquist\Dokumenter\Hentede filer\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmer\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG9\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Programmer\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [itype] "C:\Programmer\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Programmer\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259603720109
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BD3993F-C7A4-4B13-AEEC-236B4620A7D6}: NameServer = 193.162.153.164,194.239.134.83
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG9\avgwdsvc.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Programmer\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Programmer\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmer\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 8601 bytes
02. januar 2010 - 22:42 #6
(Så har du vist 'vente' længe nok *S*)

Det ser fornuftigt ud - hvordan er status så nu ?
Avatar billede rexa Nybegynder
03. januar 2010 - 15:40 #7
hejsa ... ja den er stadivæk lidt lang som især på nettet.. selv om jeg har brugt cc cleaner.. men ja den er da blevet en smule hurtigere :)
03. januar 2010 - 16:15 #8
Du bruger altså IE8 ?

Tips: Disable/fjern alle unødvendig tilføjelses 'ting' i IE ->
Funktioner - Administarer tilføjelsesprogrammer ...

---

http://kundeservice.tdc.dk/testcenter/
Avatar billede rexa Nybegynder
03. januar 2010 - 18:15 #9
nej jeg bruger firefox
03. januar 2010 - 19:30 #10
Nu kender jeg ikke til diverse 'trix' i FireFox - men prøv tilsvarende i IE ...
03. januar 2010 - 19:31 #11
... evt. denne procedure -> -- Hent Combofix fra et af disse links, og gem den på dit skrivebord:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

NB: Du må ikke døbe den Combofix.exe, men eksempelvis BANAN.exe

-- Kør så combofix.exe (BANAN.exe), som du hentede tidligere, og følg anvisningerne.

Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.
Avatar billede rexa Nybegynder
04. januar 2010 - 02:49 #12
her er filen.. btw. den sagde at der ikke var nogen genopretteles konsol. er det noget jeg burde have?
-----------------------------------------------------------------
ComboFix 10-01-03.03 - Stefan Rosquist 04-01-2010  2:30.1.1 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.45.1030.18.1022.622 [GMT 1:00]
Kører fra: c:\documents and settings\Stefan Rosquist\Dokumenter\Hentede filer\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
(((((((((((((((((((((((((((((  Filer skabt fra 2009-12-04 til 2010-01-04  )))))))))))))))))))))))))))))))))))
.

2010-01-01 07:21 . 2009-12-12 07:27    2033432    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-12-28 16:37 . 2009-12-28 16:37    --------    d-----w-    c:\programmer\Fælles filer\DirectX
2009-12-28 16:28 . 2009-12-28 16:28    --------    d-----w-    c:\programmer\Codemasters
2009-12-28 15:36 . 2009-12-28 15:36    --------    d-----w-    c:\documents and settings\All Users\Application Data\HipSoft
2009-12-28 15:04 . 2009-12-28 15:04    --------    d-----w-    c:\programmer\Build A Lot 3 Passport To Europe
2009-12-28 15:03 . 2009-12-28 15:03    --------    d-----w-    c:\programmer\ReflexiveArcade
2009-12-25 12:02 . 2009-12-30 16:38    0    ----a-w-    c:\documents and settings\Stefan Rosquist\temp.dat
2009-12-25 12:02 . 2009-12-25 12:02    --------    d-----w-    c:\documents and settings\Stefan Rosquist\.oces
2009-12-25 12:00 . 2009-12-25 12:00    --------    d-----w-    c:\documents and settings\Stefan Rosquist\cbt
2009-12-23 09:24 . 2009-12-23 09:24    4043544    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-23 09:24 . 2009-12-12 07:27    3776280    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-23 09:24 . 2009-12-23 09:23    3966744    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-22 22:12 . 2009-12-22 22:12    --------    d-----w-    c:\documents and settings\Stefan Rosquist\Application Data\Birdstep Technology
2009-12-22 22:12 . 2009-12-22 22:12    --------    d-----w-    c:\documents and settings\All Users\Application Data\Birdstep Technology
2009-12-22 22:11 . 2009-09-14 18:05    621056    ----a-w-    c:\windows\system32\drivers\mod7700.sys
2009-12-22 22:11 . 2009-09-14 18:05    24448    ----a-w-    c:\windows\system32\drivers\ewdcsc.sys
2009-12-22 22:11 . 2009-09-14 18:05    112640    ----a-w-    c:\windows\system32\drivers\ewusbnet.sys
2009-12-22 22:11 . 2009-09-14 18:05    102656    ----a-w-    c:\windows\system32\drivers\ewusbfake.sys
2009-12-22 22:11 . 2009-09-14 18:05    102400    ----a-w-    c:\windows\system32\drivers\ewusbmdm.sys
2009-12-22 22:11 . 2009-12-22 22:11    --------    d-----w-    c:\programmer\Huawei Modems
2009-12-22 22:11 . 2009-12-22 22:11    71253    ----a-w-    c:\windows\Huawei ModemsUninstall.exe
2009-12-22 22:11 . 2009-09-14 19:06    10240    ----a-w-    c:\windows\system32\drivers\mdvrmng.sys
2009-12-22 22:10 . 2009-12-22 22:10    --------    d-----w-    c:\programmer\3
2009-12-19 09:00 . 2009-12-19 09:00    294656    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-19 09:00 . 2009-12-12 07:26    2352920    ----a-w-    c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-18 09:20 . 2010-01-03 13:04    --------    d-----w-    c:\documents and settings\Stefan Rosquist\Application Data\vlc
2009-12-18 09:01 . 2009-12-18 09:01    --------    d-----w-    c:\programmer\VideoLAN
2009-12-11 18:51 . 2009-12-11 18:51    --------    d-----w-    c:\programmer\TVTool
2009-12-11 16:19 . 2009-12-11 16:19    --------    d-----w-    c:\documents and settings\All Users\Application Data\TEMP
2009-12-11 16:19 . 2009-12-11 16:19    --------    d-----w-    c:\programmer\AltoMP3 Gold
2009-12-11 16:08 . 2009-12-11 16:08    --------    d-----w-    C:\Mp3 Output
2009-12-11 16:08 . 2009-12-11 16:08    --------    d-----w-    c:\programmer\Smallvideosoft
2009-12-11 16:08 . 2009-06-08 14:33    8676883    ----a-w-    c:\windows\system32\mp3Media2.dll
2009-12-10 18:28 . 2009-12-10 18:28    --------    d-----w-    c:\programmer\PFPortChecker
2009-12-10 13:24 . 2008-01-07 20:31    49904    ----a-r-    c:\windows\system32\drivers\BVRPMPR5.SYS
2009-12-10 13:23 . 2009-12-10 13:30    --------    d-----w-    C:\Netgear
2009-12-05 20:38 . 2009-12-05 20:38    --------    d-----w-    c:\programmer\Fælles filer\xing shared
2009-12-05 20:33 . 2009-12-05 20:33    402952    ----a-w-    c:\documents and settings\Stefan Rosquist\Application Data\Real\RealPlayer\setup\AU_setup11.exe

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-04 01:33 . 2004-09-17 10:37    83518    ----a-w-    c:\windows\system32\perfc006.dat
2010-01-04 01:33 . 2004-09-17 10:37    459438    ----a-w-    c:\windows\system32\perfh006.dat
2010-01-04 01:24 . 2009-07-11 19:55    --------    d-----w-    c:\documents and settings\Stefan Rosquist\Application Data\uTorrent
2009-12-31 09:11 . 2009-08-02 19:34    --------    d-----w-    c:\programmer\Fælles filer\Blizzard Entertainment
2009-12-27 10:42 . 2009-11-13 17:03    1    ----a-w-    c:\documents and settings\Stefan Rosquist\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-25 11:20 . 2009-07-17 08:44    --------    d-----w-    c:\documents and settings\Stefan Rosquist\Application Data\U3
2009-12-22 22:10 . 2006-05-07 20:58    --------    d--h--w-    c:\programmer\InstallShield Installation Information
2009-12-05 20:39 . 2009-09-01 11:36    --------    d-----w-    c:\programmer\Fælles filer\Real
2009-11-30 22:39 . 2009-07-11 20:25    12464    ----a-w-    c:\windows\system32\avgrsstx.dll
2009-11-30 22:39 . 2009-07-11 20:25    360584    ----a-w-    c:\windows\system32\drivers\avgtdix.sys
2009-11-30 22:39 . 2009-07-11 20:25    333192    ----a-w-    c:\windows\system32\drivers\avgldx86.sys
2009-11-30 22:39 . 2009-07-11 20:25    28424    ----a-w-    c:\windows\system32\drivers\avgmfx86.sys
2009-11-30 22:39 . 2009-11-30 22:39    --------    d-----w-    c:\documents and settings\All Users\Application Data\avg9
2009-11-30 22:39 . 2009-07-11 20:25    --------    d-----w-    c:\programmer\AVG
2009-11-30 19:54 . 2009-07-10 19:36    83680    ----a-w-    c:\documents and settings\Stefan Rosquist\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-11-30 19:33 . 2009-11-30 19:32    --------    d-----w-    c:\programmer\Microsoft IntelliPoint
2009-11-30 19:31 . 2009-11-30 19:30    --------    d-----w-    c:\programmer\Microsoft IntelliType Pro
2009-11-30 17:26 . 2004-09-17 10:25    86267    ----a-w-    c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-30 16:23 . 2009-11-30 15:07    --------    d-----w-    c:\documents and settings\Stefan Rosquist\Application Data\Winamp
2009-11-30 15:10 . 2009-11-30 15:07    --------    d-----w-    c:\programmer\Winamp
2009-11-30 15:10 . 2009-11-30 14:28    --------    d-----w-    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-30 14:38 . 2009-08-17 20:38    --------    d---a-w-    c:\documents and settings\All Users\Application Data\Sports Interactive
2009-11-30 14:35 . 2009-07-21 21:49    --------    d-----w-    c:\programmer\Cyanide
2009-11-30 14:31 . 2009-11-30 14:28    --------    d-----w-    c:\programmer\Spybot - Search & Destroy
2009-11-27 11:22 . 2009-11-27 11:22    --------    d-----w-    c:\programmer\CCleaner
2009-11-24 20:40 . 2009-11-23 21:48    79488    ----a-w-    c:\documents and settings\Stefan Rosquist\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-19 12:27 . 2009-07-11 12:11    --------    d-----w-    c:\programmer\Windows Live
2009-11-16 13:24 . 2009-11-16 12:33    --------    d-----w-    c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-16 13:13 . 2006-05-07 20:58    --------    d-----w-    c:\programmer\Microsoft Works
2009-11-16 12:50 . 2009-07-22 23:22    --------    d-----w-    c:\programmer\MSBuild
2009-11-16 12:45 . 2009-11-16 12:45    --------    d-----w-    c:\programmer\Microsoft.NET
2009-11-16 12:40 . 2009-11-16 12:40    --------    d-----w-    c:\programmer\Microsoft Visual Studio 8
2009-11-14 12:00 . 2009-08-17 20:38    --------    d-----w-    c:\documents and settings\Stefan Rosquist\Application Data\Sports Interactive
2009-11-13 17:01 . 2009-11-13 17:01    --------    d-----w-    c:\documents and settings\Stefan Rosquist\Application Data\OpenOffice.org
2009-11-09 08:23 . 2009-11-09 08:23    203776    ----a-w-    c:\windows\system32\clrviddc.dll
2009-11-05 10:58 . 2009-11-05 10:58    --------    d-----w-    c:\programmer\Microsoft
2009-05-01 21:02 . 2009-05-01 21:02    1044480    ----a-w-    c:\programmer\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02    200704    ----a-w-    c:\programmer\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\programmer\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"uTorrent"="c:\programmer\uTorrent\uTorrent.exe" [2009-12-17 289584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 344064]
"SynTPEnh"="c:\programmer\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1015808]
"eabconfg.cpl"="c:\programmer\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-07 409600]
"Cpqset"="c:\programmer\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"hpWirelessAssistant"="c:\programmer\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"GrooveMonitor"="c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"WinampAgent"="c:\programmer\Winamp\winampa.exe" [2009-07-01 37888]
"SynTPStart"="c:\programmer\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"itype"="c:\programmer\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"IntelliPoint"="c:\programmer\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"TkBellExe"="c:\programmer\Fælles filer\Real\Update_OB\realsched.exe" [2009-12-05 198160]
"V0400Mon.exe"="c:\windows\V0400Mon.exe" [2007-06-03 32768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-30 22:39    12464    ----a-w-    c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Stefan Rosquist^Menuen Start^Programmer^Start^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Stefan Rosquist\Menuen Start\Programmer\Start\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2009-04-24 03:16    203928    ----a-w-    c:\programmer\Alcohol Soft\Alcohol 120\AxCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Live! Cam Manager]
2007-06-07 12:01    155648    ------w-    c:\programmer\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51    691656    ----a-w-    c:\programmer\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-07-10 18:48    133104    ----atw-    c:\documents and settings\Stefan Rosquist\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44    31072    ----a-w-    c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 22:11    49152    ----a-w-    c:\programmer\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44    3883856    ----a-w-    c:\programmer\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2005-12-12 10:39    94208    ----a-w-    c:\programmer\HP\QuickPlay\QPService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard]
2005-10-11 09:23    1187840    ----a-w-    c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoftAuto.exe]
2008-08-13 03:49    405504    ----a-w-    c:\programmer\Creative\Software Update 3\SoftAuto.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-07-21 13:23    1217784    ----a-w-    c:\games\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-14 14:18    148888    ----a-w-    c:\programmer\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-12-05 20:36    198160    ----a-w-    c:\programmer\Fælles filer\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-17 16:57    289584    ----a-w-    c:\programmer\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\V0400Mon.exe]
2007-06-03 17:01    32768    ----a-w-    c:\windows\V0400Mon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"ERSvc"=2 (0x2)
"TVersityMediaServer"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\uTorrent\\uTorrent.exe"=
"c:\\games\\Sierra Entertainment\\Empire Earth III\\EE3.exe"=
"c:\\Programmer\\Mozilla Firefox\\firefox.exe"=
"c:\\gamesr\\Sports Interactive\\Football Manager 2010\\fm.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmer\\AVG\\AVG9\\avgnsx.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11-07-2009 21:25 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11-07-2009 21:25 360584]
R1 tvtool;tvtool;c:\programmer\TVTool\TVTOOL.SYS [03-04-1996 19:33 5248]
R2 avg9wd;AVG Free WatchDog;c:\programmer\AVG\AVG9\avgwdsvc.exe [30-11-2009 23:39 285392]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [22-08-2005 10:06 231424]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11-07-2009 21:44 721904]
S3 CTUPnPSv;Creative Centrale Media Server;c:\programmer\Creative\Creative Centrale\CTUPnPSv.exe [21-05-2008 12:42 64000]
S3 VF0400Afx;VF0400 Audio FX;c:\windows\system32\drivers\V0400Afx.sys [16-07-2009 04:25 142656]
S3 VF0400Vfx;VF0400 Video FX;c:\windows\system32\drivers\V0400Vfx.sys [16-07-2009 04:25 7424]
S3 VF0400Vid;Live! Cam Notebook Pro (VF0400);c:\windows\system32\drivers\V0400Vid.sys [16-07-2009 04:25 166720]
.
Indhold af mappen 'Planlagte Opgaver'

2009-11-30 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\programmer\Microsoft IntelliPoint\ipoint.exe [2008-06-10 19:56]

2009-11-30 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
- c:\programmer\Microsoft IntelliType Pro\itype.exe [2008-06-10 19:56]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.hp.com
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
IE: &Google Search - c:\programmer\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\programmer\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\programmer\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Similar Pages - c:\programmer\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\programmer\Google\GoogleToolbar1.dll/cmtrans.html
TCP: {7BD3993F-C7A4-4B13-AEEC-236B4620A7D6} = 10.0.0.1
FF - ProfilePath - c:\documents and settings\Stefan Rosquist\Application Data\Mozilla\Firefox\Profiles\uteki903.default\
FF - component: c:\programmer\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\Stefan Rosquist\Lokale indstillinger\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
- - - - TOMME GENVEJE FJERNET - - - -

WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-04 02:37
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = c:\programmer\HPQ\Default Settings\cpqset.exe???????????3?2?3?9??`???? ???B????????? ???hLC????????

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-1072710251-4249323958-1487843073-1006\Software\G*e*n*i*e*"!\FM Genie Scout 2009 XE]
"GameDir"="c:\\Documents and Settings\\Stefan Rosquist\\Dokumenter\\Sports Interactive\\Football Manager 2009\\games"
"ShortlistDir"=""
"ScreenshotsDir"="c:\\Documents and Settings\\Stefan Rosquist\\Dokumenter\\Sports Interactive\\Football Manager 2009"
"SaveDir"="c:\\Documents and Settings\\Stefan Rosquist\\Dokumenter\\Sports Interactive\\Football Manager 2009\\"
"HistoryDir"="c:\\Documents and Settings\\Stefan Rosquist\\Skrivebord\\games\\trainers\\FMGenie93\\History Points"
"LangDB"="c:\\games\\Sports Interactive\\Football Manager 2009\\data\\updates\\update-930\\db\\930\\lang_db.dat"
"LastSaveGame"="c:\\Documents and Settings\\Stefan Rosquist\\Dokumenter\\Sports Interactive\\Football Manager 2009\\games\\fck 1.fm"
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="Champions League"
"LastUpdateCheck"=dword:00000000
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000067
"UniqueID"="E6-FAD5-06C1"
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(908)
c:\windows\system32\Ati2evxx.dll
.
Gennemført tid: 2010-01-04  02:39:48
ComboFix-quarantined-files.txt  2010-01-04 01:39

Pre-Kørsel: 7.078.133.760 byte ledig
Post-Kørsel: 7.111.135.232 byte ledig

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 36D362E99A0ECECCADCF119416B4A0B6
06. januar 2010 - 21:16 #13
Afinstall
* uTorrent

Slet mappen
c:\Programmer\uTorrent\

---

Ta' en oprydning med nævnte CCleaner...

---

Brug IE istedet; hvor er status så nu ?
Avatar billede rexa Nybegynder
06. januar 2010 - 21:30 #14
hvorfor vil du ha mig til at bruge IE.. min overbevisning er at Firefox både er mere sikkert og hurtigere?
06. januar 2010 - 21:50 #15
... for at i første omgang dele problemet på 'midten' !!!
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester