Avatar billede LiseM Novice
16. januar 2010 - 20:07 Der er 10 kommentarer og
1 løsning

jucheck.exe - skal jeg være på vagt?

Har netop installeret Bullguard, som spørger om alverdens ting.

Er jucheck.exe ok eller skal jeg afvise?

Har prøvet at google, mener ikke blevet klogere ;-)
16. januar 2010 - 20:22 #1
jucheck.exe -> "Jave Update Checker"

OK - den bør/skal være der...
Avatar billede johnstigers Seniormester
16. januar 2010 - 20:43 #2
http://www.processlibrary.com

Brug den side til dem du er i tvivl om.
Avatar billede fromsej Praktikant
16. januar 2010 - 21:05 #3
Er du det mindste i tvivl om noget Bullguard spørger om, så bloker det, spørg så herinde, vi kan som regel svare. :-)
Avatar billede f-arn Guru
17. januar 2010 - 00:13 #4
Prøv lige at gøre det her;

Hent "Malwarebytes' Anti-Malware" her: http://www.besttechie.net/tools/mbam-setup.exe
Installer og start programmet, klik på fanen opdater, klik Tjek for opdatering, lav "Hurtig skan" under fanebladet "skanner"
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra DDS som du finder her: http://download.bleepingcomputer.com/sUBs/dds.scr

eller her: http://www.forospyware.com/sUBs/dds

Den laver to logs,(DDS.txt og Attach.txt) gem dem på skrivebordet og kopier indholdet af DDS.txt  herind.

OBS - DDS skal gemmes på computeren og ikke køres fra nettet

Mht.: Vista og Windows 7 - Højreklik på filen - Kør som Administrator.

NB Når du opdaterer Malwarebytes, så klik på Tjek for opdatering til den skriver at der ikke er flere opdateringer.
--------
Avatar billede LiseM Novice
17. januar 2010 - 17:30 #5
Her er så nogle logs:

Malwarebytes' Anti-Malware 1.44
Database version: 3583
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

17-01-2010 17:14:26
mbam-log-2010-01-17 (17-14-26).txt

Skan type: Hurtig skanning
Objekter skannet: 115932
Tid tilbagelagt: 6 minute(s), 32 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)





UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12-01-2010 17:34:31
System Uptime: 17-01-2010 14:45:06 (3 hours ago)

Motherboard: Quanta |  | 3637
Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 451 GiB total, 412,027 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 2,424 GiB free.
E: is CDROM ()
F: is CDROM (CDFS)
G: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 12-01-2010 17:56:51 - First_User_Boot
RP2: 13-01-2010 17:16:39 - Installationsprogram til Windows-moduler
RP3: 13-01-2010 17:18:39 - Installationsprogram til Windows-moduler
RP4: 14-01-2010 20:06:00 - Windows Update
RP5: 14-01-2010 20:29:37 - Windows Update
RP6: 15-01-2010 16:48:15 - Installed 7-Zip 4.65 (x64 edition)
RP7: 15-01-2010 17:00:55 - Windows Update
RP8: 16-01-2010 11:58:56 - Fjernelse af sprogpakke
RP9: 16-01-2010 13:36:18 - Installed 7-Zip 4.65 (x64 edition)
RP10: 16-01-2010 17:44:15 - Windows Update
RP11: 16-01-2010 20:12:14 - Windows Update
RP12: 17-01-2010 14:50:13 - Installed 7-Zip 9.10 (x64 edition)
RP13: 17-01-2010 14:55:03 - Installed Canon ScanGear Starter
RP14: 17-01-2010 15:02:32 - Installed Canon ScanGear Starter
RP15: 17-01-2010 15:11:41 - Installed Canon ScanGear Starter
RP16: 17-01-2010 16:07:09 - Installed Java(TM) 6 Update 17
RP17: 17-01-2010 16:07:56 - Installed Java Runtime Environment

==== Installed Programs ======================

2007 Microsoft Office Suite Service Pack 1 (SP1)
Acrobat.com
Activate Norton Online Backup
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1 MUI
AMD USB Filter Driver
AOL Toolbar 5.0
Atheros Driver Installation Program
Canon ScanGear Starter
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Choice Guard
CyberLink DVD Suite
Google Toolbar for Internet Explorer
HP Advisor
HP Customer Experience Enhancements
HP Games
HP MediaSmart DVD
HP MediaSmart Internet TV
HP MediaSmart Live TV
HP MediaSmart Movie Themes
HP MediaSmart Music/Photo/Video
HP MediaSmart Webcam
HP Quick Launch Buttons
HP Setup
HP Support Assistant
HP Update
HP User Guides 0154
HP Wireless Assistant
HPAsset component for HP Active Support Library
IDT Audio
Java(TM) 6 Update 17
JMicron Flash Media Controller Driver
Junk Mail filter update
Kompatibilitetspakke til Office 2007-systemet
LabelPrint
LightScribe System Software
Magic Desktop
Malwarebytes' Anti-Malware
Microsoft Office Excel MUI (Danish) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (Danish) 2007
Microsoft Office PowerPoint MUI (Danish) 2007
Microsoft Office PowerPoint Viewer 2007 (Danish)
Microsoft Office Proof (Danish) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proofing (Danish) 2007
Microsoft Office Shared MUI (Danish) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (Danish) 2007
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
Mobile Partner
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Opdatering til Microsoft Office Excel 2007 Help (KB963678)
Opdatering til Microsoft Office Powerpoint 2007 Help (KB963669)
Opdatering til Microsoft Office Word 2007 Help (KB963665)
Overførselsværktøj til Windows Live
Power2Go
PowerDirector
PowerRecover
QLBCASL
Realtek 8136 8168 8169 Ethernet Driver
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB960003)
Security Update for Microsoft Office Excel 2007 (KB959997)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Tilmeldingsassistent til Windows Live
Update for 2007 Microsoft Office System (KB967642)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Writer

==== End Of File ===========================




DDS (Ver_09-12-01.01) - NTFSX64 
Run by lise at 17:17:25,62 on 17-01-2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.45.1030.18.4092.2427 [GMT 1:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Windows\System32\svchost.exe -k BullGuard
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\taskeng.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\program files\bullguard ltd\bullguard\BullGuard.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\lise\Desktop\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.dk/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_DK&c=94&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_DK&c=94&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_DK&c=94&bd=Pavilion&pf=cnnb
mLocal Page = c:\windows\syswow64\blank.htm
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AOL Toolbar BHO: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files (x86)\aol\aol toolbar 5.0\aoltb.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files (x86)\aol\aol toolbar 5.0\aoltb.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
uRun: [HPADVISOR] c:\program files (x86)\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [LightScribe Control Panel] c:\program files (x86)\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [BullGuard] "c:\program files\bullguard ltd\bullguard\BullGuard.exe"
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [HPCam_Menu] "c:\program files (x86)\hewlett-packard\media\webcam\muitransfer\muistartmenu.exe" "c:\program files (x86)\hewlett-packard\media\webcam" updatewithcreateonce "software\hewlett-packard\media\Webcam"
mRun: [QlbCtrl.exe] c:\program files (x86)\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [NortonOnlineBackupReminder] "c:\program files (x86)\symantec\norton online backup\activation\NobuActivation.exe" UNATTENDED
mRun: [UpdatePRCShortCut] "c:\program files (x86)\hewlett-packard\recovery\muitransfer\muistartmenu.exe" "c:\program files (x86)\hewlett-packard\recovery" updatewithcreateonce "software\cyberlink\PowerRecover"
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Easybits Recovery] c:\program files (x86)\easybits for kids\ezRecover.exe
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [WirelessAssistant] c:\program files (x86)\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files (x86)\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRunOnce: [ScanGearStarter] c:\windows\twain_32\cnqsg\SGST.exe RegPushButton
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files (x86)\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
uPolicies-system: WallpaperStyle = 2
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: E&ksporter til Microsoft Excel - c:\progra~2\micros~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\program files (x86)\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Send billede til &Bluetooth-enhed... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth-enhed... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~1\office12\REFIEBAR.DLL
LSP: c:\windows\system32\BGLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - c:\windows\syswow64\EZUPBH~1.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files (x86)\common files\lightscribe\LSRunOnce.exe"
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
TB-X64: {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [SysTrayApp] c:\program files\idt\wdm\sttray64.exe
mRun-x64: [SmartMenu] c:\program files\hewlett-packard\hp mediasmart\SmartMenu.exe /background
mRun-x64: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun-x64: [BullGuard] "c:\program files\bullguard ltd\bullguard\bullguard.exe" -boot
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm

============= SERVICES / DRIVERS ===============

R1 afw;Agnitum Firewall Driver;c:\windows\system32\drivers\afw.sys [2009-3-23 31768]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 59904]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-11-21 89600]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-7-2 203264]
R2 BdFileSpy;BullGuard File Monitor Driver;c:\windows\system32\drivers\BdFileSpy.sys [2010-1-13 53840]
R2 BsFileScan;BullGuard File Scan Service;c:\windows\system32\svchost.exe -k BullGuard [2009-7-14 27136]
R2 BsFire;BullGuard Firewall Service;c:\windows\system32\svchost.exe -k BullGuard [2009-7-14 27136]
R2 BsMailProxy;BullGuard Email Monitoring Service;c:\windows\system32\svchost.exe -k BullGuard [2009-7-14 27136]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [2009-7-14 27136]
R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2009-7-8 30520]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2009-3-23 396824]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-9-6 228408]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2009-6-29 70656]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-11-21 215040]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-11-21 36408]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-11-21 35104]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x64.sys [2009-6-10 389120]

=============== Created Last 30 ================

2010-01-17 15:52:05    0    d-----w-    c:\users\lise\appdata\roaming\Malwarebytes
2010-01-17 15:51:56    22104    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-01-17 15:51:56    0    d-----w-    c:\programdata\Malwarebytes
2010-01-17 15:51:55    0    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2010-01-17 15:09:21    0    d-----w-    c:\program files\Google
2010-01-17 15:08:19    0    d-----w-    c:\programdata\Google
2010-01-17 15:07:52    149280    ----a-w-    c:\windows\syswow64\javaws.exe
2010-01-17 15:07:52    145184    ----a-w-    c:\windows\syswow64\javaw.exe
2010-01-17 15:07:52    145184    ----a-w-    c:\windows\syswow64\java.exe
2010-01-17 13:54:59    0    d-----w-    c:\program files\common files\Canon
2010-01-17 13:54:46    64000    ----a-w-    c:\windows\system32\CNCSCM60.DLL
2010-01-17 13:54:46    62976    ----a-w-    c:\windows\system32\CNCSUT60.DLL
2010-01-17 13:54:46    62464    ----a-w-    c:\windows\system32\CNCSTR60.DLL
2010-01-17 13:54:46    54784    ----a-w-    c:\windows\system32\CNCSIF60.DLL
2010-01-17 13:54:46    398    ----a-w-    c:\windows\system32\CNCMP60.INI
2010-01-17 13:54:46    389180    ----a-w-    c:\windows\syswow64\UCS32P.DLL
2010-01-17 13:54:46    109056    ----a-w-    c:\windows\system32\CNCSDO60.DLL
2010-01-17 13:54:45    49664    ----a-w-    c:\windows\system32\CNCI750.DLL
2010-01-17 13:54:45    38400    ----a-w-    c:\windows\system32\cncisco.x64.dll
2010-01-17 13:54:45    23040    ----a-w-    c:\windows\system32\CNCL750.DLL
2010-01-17 13:54:45    219136    ----a-w-    c:\windows\system32\CNCC750.DLL
2010-01-17 13:54:34    0    d--h--w-    c:\program files\CanonBJ
2010-01-16 16:29:07    0    d-----w-    c:\users\lise\Tracing
2010-01-16 15:21:18    0    d-----w-    c:\users\lise\appdata\roaming\WildTangent
2010-01-15 14:18:00    0    d-----w-    c:\program files (x86)\GPLGS
2010-01-15 14:16:53    85504    ----a-w-    c:\windows\system32\cpwmon64.dll
2010-01-15 14:16:47    0    d-----w-    c:\program files (x86)\Acro Software
2010-01-14 19:48:07    2048    ----a-w-    c:\windows\syswow64\tzres.dll
2010-01-14 19:48:07    2048    ----a-w-    c:\windows\system32\tzres.dll
2010-01-14 19:44:08    311808    ----a-w-    c:\windows\system32\msv1_0.dll
2010-01-14 19:44:08    257024    ----a-w-    c:\windows\syswow64\msv1_0.dll
2010-01-14 19:40:25    0    d-----w-    c:\program files (x86)\MSXML 4.0
2010-01-14 19:08:41    226688    ------w-    c:\windows\system32\MpSigStub.exe
2010-01-14 19:02:24    64512    ----a-w-    c:\windows\syswow64\msfeedsbs.dll
2010-01-14 19:02:24    5958656    ----a-w-    c:\windows\syswow64\mshtml.dll
2010-01-14 19:00:27    11406336    ----a-w-    c:\windows\syswow64\wmp.dll
2010-01-14 19:00:25    1975296    ----a-w-    c:\windows\system32\CertEnroll.dll
2010-01-14 19:00:25    1320960    ----a-w-    c:\windows\syswow64\CertEnroll.dll
2010-01-14 19:00:24    982600    ----a-w-    c:\windows\system32\drivers\dxgkrnl.sys
2010-01-14 19:00:23    2868224    ----a-w-    c:\windows\explorer.exe
2010-01-14 19:00:23    2613248    ----a-w-    c:\windows\syswow64\explorer.exe
2010-01-14 19:00:19    12625408    ----a-w-    c:\windows\syswow64\wmploc.DLL
2010-01-14 19:00:18    12625920    ----a-w-    c:\windows\system32\wmploc.DLL
2010-01-14 18:58:28    70656    ----a-w-    c:\windows\syswow64\fontsub.dll
2010-01-14 18:58:28    366080    ----a-w-    c:\windows\system32\atmfd.dll
2010-01-14 18:58:28    293888    ----a-w-    c:\windows\syswow64\atmfd.dll
2010-01-14 18:58:28    148480    ----a-w-    c:\windows\system32\t2embed.dll
2010-01-14 18:58:28    108544    ----a-w-    c:\windows\syswow64\t2embed.dll
2010-01-14 18:58:28    100864    ----a-w-    c:\windows\system32\fontsub.dll
2010-01-14 18:48:02    46592    ----a-w-    c:\windows\system32\msasn1.dll
2010-01-14 18:48:02    34816    ----a-w-    c:\windows\syswow64\msasn1.dll
2010-01-13 20:02:52    0    d-----w-    c:\users\lise\appdata\roaming\BullGuard
2010-01-13 17:57:59    87376    ----a-w-    c:\windows\syswow64\BGLsp.dll
2010-01-13 17:53:00    15688    ----a-w-    c:\windows\system32\client_cc.dll
2010-01-13 17:53:00    15176    ----a-w-    c:\windows\system32\lccl.dll
2010-01-13 17:52:50    23880    ----a-w-    c:\windows\system32\BgOutlookHook.dll
2010-01-13 17:48:10    0    ---ha-w-    c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-01-13 17:46:47    29696    ----a-r-    c:\windows\system32\drivers\ewdcsc.sys
2010-01-13 17:46:47    119296    ----a-w-    c:\windows\system32\drivers\ewusbnet.sys
2010-01-13 17:46:47    117120    ----a-w-    c:\windows\system32\drivers\ewusbfake.sys
2010-01-13 17:46:47    115328    ----a-r-    c:\windows\system32\drivers\ewusbmdm.sys
2010-01-13 17:46:47    1003008    ----a-w-    c:\windows\system32\drivers\mod7700.sys
2010-01-13 17:46:18    0    d-----w-    c:\program files (x86)\Mobile Partner
2010-01-13 17:41:26    0    d-----w-    c:\programdata\BullGuard
2010-01-13 17:40:58    53840    ----a-w-    c:\windows\system32\drivers\BdFileSpy.sys
2010-01-13 17:40:38    0    d-----w-    c:\program files\BullGuard Ltd
2010-01-13 16:55:31    56    ---ha-w-    c:\windows\syswow64\ezsidmv.dat
2010-01-13 16:55:27    1397248    ----a-w-    c:\windows\syswow64\win_utilman.exe
2010-01-13 13:53:46    0    d-----w-    c:\programdata\Recovery
2010-01-13 10:37:27    0    d-----w-    c:\program files (x86)\common files\Symantec Shared
2010-01-12 16:45:22    0    d-----w-    c:\program files (x86)\Microsoft
2010-01-12 16:45:06    0    d-----w-    c:\program files (x86)\Windows Live SkyDrive
2010-01-12 16:44:11    0    d-----w-    c:\program files (x86)\common files\Windows Live
2010-01-12 16:40:01    0    d-----w-    c:\program files (x86)\Microsoft Office Suite Activation Assistant
2010-01-12 16:38:48    0    d-----w-    c:\windows\PCHEALTH
2010-01-12 16:37:42    0    d-----w-    c:\program files\Microsoft Office
2010-01-12 16:37:26    0    d-----w-    c:\windows\SHELLNEW
2010-01-12 16:37:15    0    d-----w-    c:\programdata\Microsoft Help
2010-01-12 16:35:58    0    --sha-r-    c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF946BF5P_E572195-DH1_4A_I3637_SQuanta_V33.22_F.08_T091015_WU3-0_L406_M4093_J500_7AMD_8F62_92.00_#100112_N10EC8168;168C002B_(VS107EA#UUW)_XMOBILE_CN10_Z.MRK

==================== Find3M  ====================

2010-01-17 14:41:30    76742    ----a-w-    c:\windows\system32\perfc006.dat
2010-01-17 14:41:30    461276    ----a-w-    c:\windows\system32\perfh006.dat
2009-11-21 08:29:48    0    ---ha-w-    c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2009-09-06 00:27:17    39236    ----a-w-    c:\windows\inf\perflib\0406\perfd.dat
2009-09-06 00:27:17    39236    ----a-w-    c:\windows\inf\perflib\0406\perfc.dat
2009-09-06 00:27:17    306636    ----a-w-    c:\windows\inf\perflib\0406\perfi.dat
2009-09-06 00:27:17    306636    ----a-w-    c:\windows\inf\perflib\0406\perfh.dat
2009-07-14 04:54:24    174    --sha-w-    c:\program files\desktop.ini
2009-07-14 04:54:24    174    --sha-w-    c:\program files (x86)\desktop.ini
2009-07-14 01:00:34    291294    ----a-w-    c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34    291294    ----a-w-    c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32    31548    ----a-w-    c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32    31548    ----a-w-    c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08    9633792    --sha-r-    c:\windows\fonts\StaticCache.dat
2009-07-14 01:39:53    398848    --sha-w-    c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45    396800    --sha-w-    c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 17:18:06,56 ===============
Avatar billede LiseM Novice
17. januar 2010 - 17:33 #6
#5
Er der noget, som jeg med fordel kan rydde op i? Dvs. sige fjerne.. Hvis ja, hvad og hvordan.

Og god arbejdslyst :-)
Avatar billede f-arn Guru
17. januar 2010 - 18:55 #7
Jeg skulle bare sikre mig at jucheck.exe ikke stod i din opstart.
Avatar billede LiseM Novice
18. januar 2010 - 20:31 #8
Da jeg kørte Malwarebytes' Anti-Malware 1.44, fik jeg flg. meddelelse:


Inficerede Registeringsdatabase Filer:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Den blev altså slettet. Men nu er jeg kommet i tvivl om, om den skulle have været det??

Kan en af jer sige mig, om det er OK eller om jeg skal gøre et eller andet?

karise_larry: Send venligst svar.

Til I andre: Jeg opretter et nyt spørgsmål, så jeg kan tildele jer alle points. Men hvordan lavet jeg lige linket??
Avatar billede LiseM Novice
18. januar 2010 - 20:32 #9
Glemte at sige MANGE tak til alle.
18. januar 2010 - 21:15 #10
Joooo - den sletning er go' nok...

http://www.eksperten.dk/faq#faq-3-5
18. januar 2010 - 21:17 #11
Ping...
(Det var et [svar]... evt. til delning mellem flere ...)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester