Avatar billede short3 Nybegynder
27. februar 2011 - 05:56 Der er 21 kommentarer og
1 løsning

HJT-fil, pc låser og jeg er nød til at gestarte manuelt

Hej har problemer med virus. Pc'en går i sort og den er nød til at blive genstartet manuelt. Nogle gange virker musen og skærmen kan ses, men jeg kan ikke trykke på noget, please help. Internettet er lidt on and off, men virker generelt ok.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:49:54, on 22-01-2011
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Poker\Betway\Poker\MPPoker.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Lau\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fck.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files (x86)\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files (x86)\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Poker\Betway\Poker\MPPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Poker\PartyPoker\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Poker\PartyPoker\PartyPoker\RunApp.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E05C2C8-E716-4F2C-9A7B-34FA1C85F9D7}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E05C2C8-E716-4F2C-9A7B-34FA1C85F9D7}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E05C2C8-E716-4F2C-9A7B-34FA1C85F9D7}: NameServer = 156.154.70.22,156.154.71.22
O18 - Protocol: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
O20 - AppInit_DLLs:  C:\Windows\SysWOW64\guard32.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8866 bytes
Avatar billede f-arn Guru
27. februar 2011 - 06:04 #1
Hent "Malwarebytes' Anti-Malware" her

Eller her

Installer og start programmet, klik på fanen opdater, klik Tjek for opdatering, lav "Hurtig skan" under fanebladet "skanner"
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra DDS som du finder her

eller her

Den laver to logs,(DDS.txt og Attach.txt) gem dem på skrivebordet og kopier indholdet af DDS.txt  herind.

OBS - DDS skal gemmes på computeren og ikke køres fra nettet.

Mht.: Vista og Windows 7 - højreklik på filen - Kør som Administrator.

NB Når du opdaterer Malwarebytes, så klik på Tjek for opdatering til den skriver at der ikke er flere opdateringer.
Avatar billede short3 Nybegynder
27. februar 2011 - 06:15 #2
Her er AntiMalware log

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5889

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

27-02-2011 06:12:42
mbam-log-2011-02-27 (06-12-42).txt

Scan type: Quick scan
Objects scanned: 181151
Time elapsed: 2 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Avatar billede short3 Nybegynder
27. februar 2011 - 06:20 #3
Jeg kan ikke finde "kør som..." når jeg højreklikker
Avatar billede short3 Nybegynder
27. februar 2011 - 06:31 #4
Desuden går mit antivirus amok, når jeg prøver at køre filen
Avatar billede f-arn Guru
27. februar 2011 - 06:45 #5
Hvad står der når du højreklikker på DDS?

Desuden går mit antivirus amok, når jeg prøver at køre filen

Deaktiver script blocking!
Avatar billede short3 Nybegynder
27. februar 2011 - 06:59 #6
Der står når jeg højre klikker:
Test
Konfigurer
Installer
Run in comodo sandbox
Skan efter via
Flyt til karantæne
Scan with ad-aware
Submit to threadworkalliance
Del med
Skan Malware antimalware
Gendan tidl. versioner
Send til
Klip
Kopier
opret genvej
slet
omdøb
Egenskaber
Avatar billede short3 Nybegynder
27. februar 2011 - 07:14 #7
okay, nu fik jeg den til at virke

DDS (Ver_10-12-12.02) - NTFS_AMD64 
Run by Lau at  7:11:38,71 on 27-02-2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.45.1030.18.4095.2805 [GMT 1:00]

AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: COMODO Defense+ *Disabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
FW: COMODO Firewall *Disabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Lau\Desktop\dds.scr
C:\Windows\system32\conhost.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://fck.dk/
mWinlogon: Userinit=userinit.exe
BHO: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO: Hjælp til logon til Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [LogitechVideoRepair] C:\Program Files (x86)\Logitech\Video\ISStart.exe
mRun: [LogitechVideoTray] C:\Program Files (x86)\Logitech\Video\LogiTray.exe
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Føj til Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Poker\Betway\Poker\MPPoker.exe
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Poker\PartyPoker\PartyPoker\RunApp.exe
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {1E05C2C8-E716-4F2C-9A7B-34FA1C85F9D7} = 156.154.70.22,156.154.71.22
Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
AppInit_DLLs:  C:\Windows\SysWOW64\guard32.dll,C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{E33CF602-D945-461A-83F0-819F76A199F8}
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB-X64: {043C5167-00BB-4324-AF7E-62013FAEDACF} - No File
mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
AppInit_DLLs-X64:  C:\Windows\system32\guard64.dll,C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Lau\AppData\Roaming\Mozilla\Firefox\Profiles\9lch2ji1.default\
FF - prefs.js: browser.startup.homepage - hxxp://fck.dk/
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Anti-Banner: KavAntiBanner@Kaspersky.ru - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2010-12-12 69152]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2010-12-29 250008]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2010-12-29 39888]
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
R2 AVP;Kaspersky Anti-Virus-service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-7-1 352976]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-12-3 1405384]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2009-12-10 65536]
R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2011-1-10 993848]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2011-1-10 399416]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2010-9-20 86120]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-8 136176]
S3 FLASHSYS;FLASHSYS;C:\Program Files (x86)\MSI\Live Update 4\LU4\Flashsys64.sys [2010-9-20 15192]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2010-12-3 17152]
S3 MsibiosDevice;MsibiosDevice;C:\Program Files (x86)\MSI\Live Update 4\LU4\msibios64.sys [2010-9-20 33080]
S3 PSI;PSI;C:\Windows\System32\drivers\psi_mf.sys [2010-9-1 17976]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-8-19 239616]
S3 WatAdminSvc;Tjenesten Windows Aktivering;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-9-20 1255736]

=============== Created Last 30 ================

2011-02-27 01:20:01    38224    ----a-w-    C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-02-25 20:28:55    --------    d-----w-    C:\Program Files (x86)\ESET
2011-02-25 18:55:44    7947600    ----a-w-    C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{E17B6DE0-670E-474C-9DF6-6686D6883D28}\mpengine.dll
2011-02-23 22:52:10    472808    ----a-w-    C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-02-23 22:45:59    --------    d-----w-    C:\Users\Lau\AppData\Local\Secunia PSI
2011-02-23 22:45:48    --------    d-----w-    C:\Program Files (x86)\Secunia
2011-02-23 06:54:22    367104    ----a-w-    C:\Windows\System32\wcncsvc.dll
2011-02-23 06:54:22    276992    ----a-w-    C:\Windows\SysWow64\wcncsvc.dll
2011-02-23 06:09:27    662528    ----a-w-    C:\Windows\System32\XpsPrint.dll
2011-02-23 06:09:27    475648    ----a-w-    C:\Windows\System32\XpsGdiConverter.dll
2011-02-23 06:09:27    442880    ----a-w-    C:\Windows\SysWow64\XpsPrint.dll
2011-02-23 06:09:27    288256    ----a-w-    C:\Windows\SysWow64\XpsGdiConverter.dll
2011-02-22 03:03:04    109240    ----a-w-    C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
2011-02-22 03:03:02    150200    ----a-w-    C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2011-02-22 03:02:26    --------    d-----w-    C:\Program Files (x86)\Kaspersky Lab
2011-02-22 02:43:40    --------    d-----w-    C:\PROGRA~3\Kaspersky Lab Setup Files
2011-02-20 23:56:28    --------    d-----w-    C:\PROGRA~3\Kaspersky Lab
2011-02-18 23:44:32    --------    d-----w-    C:\Users\Lau\AppData\Local\{DC2A156A-DF57-424D-9666-653EC449C5C2}
2011-02-18 11:44:12    --------    d-----w-    C:\Users\Lau\AppData\Local\{16873F32-C5A1-40AD-AA83-342DD64296B3}
2011-02-17 23:14:39    --------    d-----w-    C:\Users\Lau\AppData\Local\{C664C750-0F55-405C-BE72-88BF7BC7BEA3}
2011-02-17 11:14:05    --------    d-----w-    C:\Users\Lau\AppData\Local\{E20EAE91-F2C9-475A-AF5E-090A99DA0943}
2011-02-16 15:45:51    --------    d-----w-    C:\Users\Lau\AppData\Local\{D4634294-A1F8-494F-80F6-F0D7F66739A8}
2011-02-16 00:08:01    905216    ----a-w-    C:\Windows\SysWow64\GX5050R.dll
2011-02-16 00:07:59    598288    ----a-w-    C:\Windows\SysWow64\temp.002
2011-02-16 00:07:59    204296    ----a-w-    C:\Windows\SysWow64\RICHTX32.OCX
2011-02-16 00:07:59    17920    ----a-w-    C:\Windows\SysWow64\temp.001
2011-02-16 00:07:59    164112    ----a-w-    C:\Windows\SysWow64\temp.003
2011-02-16 00:07:59    16384    ----a-w-    C:\Windows\SysWow64\temp.005
2011-02-16 00:07:59    147728    ----a-w-    C:\Windows\SysWow64\temp.004
2011-02-16 00:07:59    140288    ----a-w-    C:\Windows\SysWow64\COMDLG32.OCX
2011-02-16 00:07:59    1384448    ----a-w-    C:\Windows\SysWow64\temp.000
2011-02-16 00:07:59    1064456    ----a-w-    C:\Windows\SysWow64\MSCOMCTL.OCX
2011-02-16 00:07:49    --------    d-----w-    C:\Program Files (x86)\Databog
2011-02-15 11:50:27    --------    d-----w-    C:\Users\Lau\AppData\Local\{C184A75A-47FF-45E7-83E5-F436FD05108F}
2011-02-14 12:55:41    --------    d-----w-    C:\Users\Lau\AppData\Local\{E485A9FE-7F23-4707-B1ED-587A51F19AB1}
2011-02-13 13:28:13    --------    d-----w-    C:\Users\Lau\AppData\Local\{B83E3536-48B7-4D3F-9EC9-0E300C467A56}
2011-02-12 17:39:43    --------    d-----w-    C:\Users\Lau\AppData\Local\{A1EE9203-58FD-4D10-B8AB-481A99BBC011}
2011-02-12 13:36:09    --------    d-----w-    C:\Users\Lau\AppData\Local\{72D9ED47-769D-4537-9724-E7CFB3283B25}
2011-02-11 11:32:52    --------    d-----w-    C:\Users\Lau\AppData\Local\{4FD5E187-34CC-4721-8B37-F1D6DCCDCD08}
2011-02-10 22:51:38    --------    d-----w-    C:\Users\Lau\AppData\Local\{A35C2EC3-EDA3-4A93-A6A5-C4C0676CF3DC}
2011-02-10 11:08:41    --------    d-----w-    C:\Users\Lau\AppData\Roaming\SUPERAntiSpyware.com
2011-02-10 11:08:41    --------    d-----w-    C:\PROGRA~3\SUPERAntiSpyware.com
2011-02-10 11:08:30    --------    d-----w-    C:\Program Files\SUPERAntiSpyware
2011-02-10 10:51:03    --------    d-----w-    C:\Users\Lau\AppData\Local\{2560174D-13E1-40C4-B912-4D994A0FDE3F}
2011-02-09 16:31:12    --------    d-----w-    C:\Users\Lau\AppData\Local\{01ACBD17-B8DA-458B-80E2-36F1ED74DB02}
2011-02-09 16:26:15    --------    d-----w-    C:\Users\Lau\AppData\Local\{C3575FB2-9DE6-47BD-88C0-A6A7DAE323C2}
2011-02-08 11:40:20    --------    d-----w-    C:\Users\Lau\AppData\Local\{F4BF02C5-FB50-4DF6-97BA-F03764265BB3}
2011-02-07 23:39:44    --------    d-----w-    C:\Users\Lau\AppData\Local\{72E97142-86BC-437B-AE06-BA4E82CD411D}
2011-02-07 11:39:08    --------    d-----w-    C:\Users\Lau\AppData\Local\{BB2B4DD3-21E3-4025-835A-574F1CA55165}
2011-02-06 23:38:32    --------    d-----w-    C:\Users\Lau\AppData\Local\{4629FFDC-D5B8-4499-B918-892171023A8D}
2011-02-06 11:38:20    --------    d-----w-    C:\Users\Lau\AppData\Local\{40530597-8622-415E-92FA-F29E6EEBF8DD}
2011-02-05 12:43:46    --------    d-----w-    C:\Users\Lau\AppData\Local\{7103D706-3713-4AA4-9755-715B8279DA7B}
2011-02-04 11:04:35    --------    d-----w-    C:\Users\Lau\AppData\Local\{3DA949ED-F1B5-4B7B-9BBD-1BFD2872E392}
2011-02-03 13:00:06    --------    d-----w-    C:\Users\Lau\AppData\Local\{2C4068CC-A749-4F7D-8813-BFEB6A0FB045}
2011-02-03 12:23:24    --------    d-----w-    C:\Users\Lau\AppData\Local\{E7C5DCEE-FD9E-430E-B759-4BF509A0A1FC}
2011-02-02 15:12:28    --------    d-----w-    C:\Users\Lau\AppData\Local\{0157F438-CBF7-418A-A042-2E926CC9A683}
2011-02-01 17:33:53    --------    d-----w-    C:\Users\Lau\.oces
2011-02-01 11:34:51    --------    d-----w-    C:\Users\Lau\AppData\Local\{027B6A7D-01C8-4CCF-98DE-84A5CEAADD94}
2011-01-31 11:13:25    --------    d-----w-    C:\Users\Lau\AppData\Local\{343123B3-2672-4F05-8ED6-187200D88788}
2011-01-30 12:38:13    --------    d-----w-    C:\Users\Lau\AppData\Local\{42ADFF4E-6634-4F2C-8093-43D1A7A557BA}
2011-01-29 10:10:44    --------    d-----w-    C:\Users\Lau\AppData\Local\{6DAB57B0-7520-4DA8-8F44-7F4651CDFF84}
2011-01-28 21:13:21    --------    d-----w-    C:\Users\Lau\AppData\Local\{4C519719-5536-40B5-9915-9DFDBF5B6AE0}
2011-01-28 08:48:06    --------    d-----w-    C:\Users\Lau\AppData\Local\{C888E71E-BCF2-4C01-8115-A984F80DD2E6}
2011-01-28 08:48:06    --------    d-----w-    C:\Users\Lau\AppData\Local\{BE63F3CA-09EF-4709-8F76-5AD0B434307D}

==================== Find3M  ====================

2011-02-23 22:52:04    472808    ----a-w-    C:\Windows\SysWow64\deployJava1.dll
2011-02-08 12:55:21    16432    ----a-w-    C:\Windows\System32\lsdelete.exe
2011-02-02 16:11:20    270720    ------w-    C:\Windows\System32\MpSigStub.exe
2011-01-26 06:53:10    982912    ----a-w-    C:\Windows\System32\drivers\dxgkrnl.sys
2011-01-26 06:53:10    265088    ----a-w-    C:\Windows\System32\drivers\dxgmms1.sys
2011-01-26 06:31:20    144384    ----a-w-    C:\Windows\System32\cdd.dll
2011-01-12 01:01:39    39888    ----a-w-    C:\Windows\System32\drivers\cmdhlp.sys
2011-01-12 01:01:39    250008    ----a-w-    C:\Windows\System32\drivers\cmdGuard.sys
2011-01-12 01:01:39    14184    ----a-w-    C:\Windows\System32\drivers\cmderd.sys
2011-01-07 08:06:50    46080    ----a-w-    C:\Windows\System32\atmlib.dll
2011-01-07 07:27:11    34304    ----a-w-    C:\Windows\SysWow64\atmlib.dll
2011-01-07 05:49:20    366080    ----a-w-    C:\Windows\System32\atmfd.dll
2011-01-07 05:33:11    294400    ----a-w-    C:\Windows\SysWow64\atmfd.dll
2011-01-05 06:20:30    612352    ----a-w-    C:\Windows\System32\vbscript.dll
2011-01-05 05:37:33    428032    ----a-w-    C:\Windows\SysWow64\vbscript.dll
2011-01-05 04:00:16    3127808    ----a-w-    C:\Windows\System32\win32k.sys
2010-12-29 00:42:04    285480    ----a-w-    C:\Windows\SysWow64\guard32.dll
2010-12-29 00:42:02    362784    ----a-w-    C:\Windows\System32\guard64.dll
2010-12-21 06:16:27    97280    ----a-w-    C:\Windows\System32\wscsvc.dll
2010-12-21 06:16:27    62976    ----a-w-    C:\Windows\System32\wscapi.dll
2010-12-21 06:16:16    214016    ----a-w-    C:\Windows\System32\winsrv.dll
2010-12-21 06:16:14    442880    ----a-w-    C:\Windows\System32\winhttp.dll
2010-12-21 06:16:14    1197056    ----a-w-    C:\Windows\System32\wininet.dll
2010-12-21 06:16:09    258048    ----a-w-    C:\Windows\System32\WebClnt.dll
2010-12-21 06:15:55    264192    ----a-w-    C:\Windows\System32\upnp.dll
2010-12-21 06:15:31    15360    ----a-w-    C:\Windows\System32\slwga.dll
2010-12-21 06:13:03    2003968    ----a-w-    C:\Windows\System32\msxml6.dll
2010-12-21 06:13:03    1880576    ----a-w-    C:\Windows\System32\msxml3.dll
2010-12-21 06:10:22    100864    ----a-w-    C:\Windows\System32\davclnt.dll
2010-12-21 05:38:24    51200    ----a-w-    C:\Windows\SysWow64\wscapi.dll
2010-12-21 05:38:22    981504    ----a-w-    C:\Windows\SysWow64\wininet.dll
2010-12-21 05:38:22    350720    ----a-w-    C:\Windows\SysWow64\winhttp.dll
2010-12-21 05:38:21    204800    ----a-w-    C:\Windows\SysWow64\WebClnt.dll
2010-12-21 05:38:19    204288    ----a-w-    C:\Windows\SysWow64\upnp.dll
2010-12-21 05:38:16    14336    ----a-w-    C:\Windows\SysWow64\slwga.dll
2010-12-21 05:36:17    1389568    ----a-w-    C:\Windows\SysWow64\msxml6.dll
2010-12-21 05:36:16    1236992    ----a-w-    C:\Windows\SysWow64\msxml3.dll
2010-12-21 05:34:12    80384    ----a-w-    C:\Windows\SysWow64\davclnt.dll
2010-12-20 17:08:40    24152    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2010-12-18 06:11:41    57856    ----a-w-    C:\Windows\System32\licmgr10.dll
2010-12-18 06:11:34    714752    ----a-w-    C:\Windows\System32\kerberos.dll
2010-12-18 05:29:40    44544    ----a-w-    C:\Windows\SysWow64\licmgr10.dll
2010-12-18 05:29:31    541184    ----a-w-    C:\Windows\SysWow64\kerberos.dll
2010-12-18 04:55:03    482816    ----a-w-    C:\Windows\System32\html.iec
2010-12-18 04:20:55    386048    ----a-w-    C:\Windows\SysWow64\html.iec
2010-12-18 04:13:40    1638912    ----a-w-    C:\Windows\System32\mshtml.tlb
2010-12-18 03:47:59    1638912    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2010-12-07 09:05:00    49752    ----a-w-    C:\Windows\System32\drivers\SBREDrv.sys
2010-12-03 09:05:34    69152    ----a-w-    C:\Windows\System32\drivers\Lbd.sys

============= FINISH:  7:12:15,59 ===============
Avatar billede f-arn Guru
27. februar 2011 - 08:01 #8
Du kører med alt for mange sikkerheds programmer. Hvis du har en gældende, købt licens, til Kaspersky - behold den, og afinstaller Lavasoft og Comodo.

------

Hent og gem ComboFix på dit skrivebord.

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::
Filelook::
C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
Folder::
C:\Program Files (x86)\vShare\
DDS::
BHO: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf}
TB: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf}
Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484}


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede short3 Nybegynder
27. februar 2011 - 08:16 #9
Jeg har en ny og stærk pc, og har ikke haft problemer med funktionalitet pga flere virusprogrammer, skal jeg stadig afinstallere? Comodo er et gratisprogram, men jeg tror at den firewall har blokeret for rigtig mange viruser.
Avatar billede f-arn Guru
27. februar 2011 - 08:34 #10
har ikke haft problemer med funktionalitet pga flere virusprogrammer, skal jeg stadig afinstallere?

Ja
Avatar billede short3 Nybegynder
27. februar 2011 - 08:38 #11
okay... haha

ComboFix 11-02-26.01 - Lau 27-02-2011  8:28.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.45.1030.18.4095.2920 [GMT 1:00]
Kører fra: c:\users\Lau\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Lau\Desktop\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
FW: COMODO Firewall *Disabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
SP: COMODO Defense+ *Disabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Dannede nyt systemgendannelsespunkt
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files (x86)\vShare\
c:\program files (x86)\vShare\\configuration.xml
c:\program files (x86)\vShare\\configuration_ex.xml
c:\program files (x86)\vShare\\icon_logo.bmp
c:\program files (x86)\vShare\\images.bmp
c:\program files (x86)\vShare\\lip.exe
c:\program files (x86)\vShare\\newtab.htm
c:\program files (x86)\vShare\\radio\ajax.js
c:\program files (x86)\vShare\\radio\bg.gif
c:\program files (x86)\vShare\\radio\play.gif
c:\program files (x86)\vShare\\radio\play_hover.gif
c:\program files (x86)\vShare\\radio\radio.html
c:\program files (x86)\vShare\\radio\radio.js
c:\program files (x86)\vShare\\radio\sample_radio.jpg
c:\program files (x86)\vShare\\radio\stations.xml
c:\program files (x86)\vShare\\radio\stop.gif
c:\program files (x86)\vShare\\radio\stop_hover.gif
c:\program files (x86)\vShare\\radio\v_minus.gif
c:\program files (x86)\vShare\\radio\v_minus_1.gif
c:\program files (x86)\vShare\\radio\v_plus.gif
c:\program files (x86)\vShare\\radio\v_plus_1.gif
c:\program files (x86)\vShare\\radio\vol_line_emp.gif
c:\program files (x86)\vShare\\radio\vol_line_full.gif
c:\program files (x86)\vShare\\radio\vol_line_half.gif
c:\program files (x86)\vShare\\security_error.htm
c:\program files (x86)\vShare\\setup.bmp
c:\program files (x86)\vShare\\skin\bg.gif
c:\program files (x86)\vShare\\skin\e.gif
c:\program files (x86)\vShare\\skin\tt.gif
c:\program files (x86)\vShare\\TermsOfUse.rtf
c:\program files (x86)\vShare\\thisversion.txt
c:\program files (x86)\vShare\\Uninstall.exe
c:\program files (x86)\vShare\\UNWISE.EXE
c:\program files (x86)\vShare\\vshare_toolbar.dll

.
(((((((((((((((((((((((((((((  Filer skabt fra 2011-01-27 til 2011-02-27  )))))))))))))))))))))))))))))))))))
.

2011-02-27 06:33 . 2007-07-19 23:57    411496    ----a-w-    c:\windows\system32\xactengine2_9.dll
2011-02-27 01:20 . 2010-12-20 17:09    38224    ----a-w-    c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-02-25 18:55 . 2011-02-11 07:30    7947600    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{E17B6DE0-670E-474C-9DF6-6686D6883D28}\mpengine.dll
2011-02-23 22:52 . 2011-02-23 22:52    --------    d-----w-    c:\program files (x86)\Common Files\Java
2011-02-23 22:52 . 2011-02-23 22:52    --------    d-----w-    c:\program files (x86)\Java
2011-02-23 22:45 . 2011-02-23 22:45    --------    d-----w-    c:\users\Lau\AppData\Local\Secunia PSI
2011-02-23 22:45 . 2011-02-23 22:45    --------    d-----w-    c:\program files (x86)\Secunia
2011-02-23 06:54 . 2010-09-14 06:45    367104    ----a-w-    c:\windows\system32\wcncsvc.dll
2011-02-23 06:54 . 2010-09-14 06:07    276992    ----a-w-    c:\windows\SysWow64\wcncsvc.dll
2011-02-23 06:09 . 2011-01-07 08:07    662528    ----a-w-    c:\windows\system32\XpsPrint.dll
2011-02-23 06:09 . 2011-01-07 08:07    475648    ----a-w-    c:\windows\system32\XpsGdiConverter.dll
2011-02-23 06:09 . 2011-01-07 07:31    442880    ----a-w-    c:\windows\SysWow64\XpsPrint.dll
2011-02-23 06:09 . 2011-01-07 07:31    288256    ----a-w-    c:\windows\SysWow64\XpsGdiConverter.dll
2011-02-22 03:02 . 2011-02-22 03:02    --------    d-----w-    c:\program files (x86)\Kaspersky Lab
2011-02-22 02:43 . 2011-02-22 02:43    --------    d-----w-    c:\programdata\Kaspersky Lab Setup Files
2011-02-21 14:28 . 2011-02-21 14:28    --------    d-----w-    c:\users\Lau\AppData\Local\Mozilla
2011-02-20 23:56 . 2011-02-27 07:33    --------    d-----w-    c:\programdata\Kaspersky Lab
2011-02-18 23:44 . 2011-02-18 23:44    --------    d-----w-    c:\users\Lau\AppData\Local\{DC2A156A-DF57-424D-9666-653EC449C5C2}
2011-02-18 11:44 . 2011-02-18 11:44    --------    d-----w-    c:\users\Lau\AppData\Local\{16873F32-C5A1-40AD-AA83-342DD64296B3}
2011-02-17 23:14 . 2011-02-17 23:15    --------    d-----w-    c:\users\Lau\AppData\Local\{C664C750-0F55-405C-BE72-88BF7BC7BEA3}
2011-02-17 11:14 . 2011-02-17 11:14    --------    d-----w-    c:\users\Lau\AppData\Local\{E20EAE91-F2C9-475A-AF5E-090A99DA0943}
2011-02-16 15:45 . 2011-02-16 15:45    --------    d-----w-    c:\users\Lau\AppData\Local\{D4634294-A1F8-494F-80F6-F0D7F66739A8}
2011-02-16 00:08 . 1998-07-29 17:00    266293    ----a-w-    c:\windows\SysWow64\temp.00D
2011-02-16 00:07 . 1999-05-12 23:00    1064456    ----a-w-    c:\windows\SysWow64\MSCOMCTL.OCX
2011-02-16 00:07 . 1999-05-09 23:00    1384448    ----a-w-    c:\windows\SysWow64\temp.000
2011-02-16 00:07 . 1999-05-06 23:00    204296    ----a-w-    c:\windows\SysWow64\RICHTX32.OCX
2011-02-16 00:07 . 1999-05-06 23:00    140288    ----a-w-    c:\windows\SysWow64\COMDLG32.OCX
2011-02-16 00:07 . 1999-05-05 21:22    17920    ----a-w-    c:\windows\SysWow64\temp.001
2011-02-16 00:07 . 1999-05-05 21:22    16384    ----a-w-    c:\windows\SysWow64\temp.005
2011-02-16 00:07 . 1999-03-08 11:02    598288    ----a-w-    c:\windows\SysWow64\temp.002
2011-02-16 00:07 . 1999-03-08 11:02    164112    ----a-w-    c:\windows\SysWow64\temp.003
2011-02-16 00:07 . 1999-03-08 11:02    147728    ----a-w-    c:\windows\SysWow64\temp.004
2011-02-16 00:07 . 2011-02-16 00:09    --------    d-----w-    c:\program files (x86)\Databog
2011-02-15 11:50 . 2011-02-15 11:50    --------    d-----w-    c:\users\Lau\AppData\Local\{C184A75A-47FF-45E7-83E5-F436FD05108F}
2011-02-14 12:55 . 2011-02-14 12:55    --------    d-----w-    c:\users\Lau\AppData\Local\{E485A9FE-7F23-4707-B1ED-587A51F19AB1}
2011-02-13 13:28 . 2011-02-13 13:28    --------    d-----w-    c:\users\Lau\AppData\Local\{B83E3536-48B7-4D3F-9EC9-0E300C467A56}
2011-02-12 17:39 . 2011-02-12 17:40    --------    d-----w-    c:\users\Lau\AppData\Local\{A1EE9203-58FD-4D10-B8AB-481A99BBC011}
2011-02-12 13:36 . 2011-02-12 13:36    --------    d-----w-    c:\users\Lau\AppData\Local\{72D9ED47-769D-4537-9724-E7CFB3283B25}
2011-02-11 11:32 . 2011-02-11 23:45    --------    d-----w-    c:\users\Lau\AppData\Local\{4FD5E187-34CC-4721-8B37-F1D6DCCDCD08}
2011-02-10 22:51 . 2011-02-10 22:52    --------    d-----w-    c:\users\Lau\AppData\Local\{A35C2EC3-EDA3-4A93-A6A5-C4C0676CF3DC}
2011-02-10 11:08 . 2011-02-10 11:08    --------    d-----w-    c:\users\Lau\AppData\Roaming\SUPERAntiSpyware.com
2011-02-10 11:08 . 2011-02-10 11:08    --------    d-----w-    c:\programdata\SUPERAntiSpyware.com
2011-02-10 11:08 . 2011-02-10 11:08    --------    d-----w-    c:\program files\SUPERAntiSpyware
2011-02-10 10:54 . 2011-02-10 10:55    --------    d-----w-    c:\users\Lau1
2011-02-10 10:51 . 2011-02-10 10:51    --------    d-----w-    c:\users\Lau\AppData\Local\{2560174D-13E1-40C4-B912-4D994A0FDE3F}
2011-02-09 16:31 . 2011-02-09 16:31    --------    d-----w-    c:\users\Lau\AppData\Local\{01ACBD17-B8DA-458B-80E2-36F1ED74DB02}
2011-02-09 16:26 . 2011-02-09 16:26    --------    d-----w-    c:\users\Lau\AppData\Local\{C3575FB2-9DE6-47BD-88C0-A6A7DAE323C2}
2011-02-08 11:40 . 2011-02-08 11:40    --------    d-----w-    c:\users\Lau\AppData\Local\{F4BF02C5-FB50-4DF6-97BA-F03764265BB3}
2011-02-07 23:39 . 2011-02-07 23:40    --------    d-----w-    c:\users\Lau\AppData\Local\{72E97142-86BC-437B-AE06-BA4E82CD411D}
2011-02-07 11:39 . 2011-02-07 11:39    --------    d-----w-    c:\users\Lau\AppData\Local\{BB2B4DD3-21E3-4025-835A-574F1CA55165}
2011-02-06 23:38 . 2011-02-06 23:38    --------    d-----w-    c:\users\Lau\AppData\Local\{4629FFDC-D5B8-4499-B918-892171023A8D}
2011-02-06 11:38 . 2011-02-06 11:38    --------    d-----w-    c:\users\Lau\AppData\Local\{40530597-8622-415E-92FA-F29E6EEBF8DD}
2011-02-05 12:43 . 2011-02-05 12:43    --------    d-----w-    c:\users\Lau\AppData\Local\{7103D706-3713-4AA4-9755-715B8279DA7B}
2011-02-04 11:04 . 2011-02-04 23:05    --------    d-----w-    c:\users\Lau\AppData\Local\{3DA949ED-F1B5-4B7B-9BBD-1BFD2872E392}
2011-02-03 13:00 . 2011-02-03 13:00    --------    d-----w-    c:\users\Lau\AppData\Local\{2C4068CC-A749-4F7D-8813-BFEB6A0FB045}
2011-02-03 12:23 . 2011-02-03 12:23    --------    d-----w-    c:\users\Lau\AppData\Local\{E7C5DCEE-FD9E-430E-B759-4BF509A0A1FC}
2011-02-02 15:12 . 2011-02-02 15:12    --------    d-----w-    c:\users\Lau\AppData\Local\{0157F438-CBF7-418A-A042-2E926CC9A683}
2011-02-01 17:33 . 2011-02-01 17:33    --------    d-----w-    c:\users\Lau\.oces
2011-02-01 11:34 . 2011-02-01 11:35    --------    d-----w-    c:\users\Lau\AppData\Local\{027B6A7D-01C8-4CCF-98DE-84A5CEAADD94}
2011-01-31 11:13 . 2011-01-31 11:13    --------    d-----w-    c:\users\Lau\AppData\Local\{343123B3-2672-4F05-8ED6-187200D88788}
2011-01-30 12:38 . 2011-01-30 12:39    --------    d-----w-    c:\users\Lau\AppData\Local\{42ADFF4E-6634-4F2C-8093-43D1A7A557BA}
2011-01-29 10:10 . 2011-01-29 10:10    --------    d-----w-    c:\users\Lau\AppData\Local\{6DAB57B0-7520-4DA8-8F44-7F4651CDFF84}
2011-01-28 21:13 . 2011-01-28 21:14    --------    d-----w-    c:\users\Lau\AppData\Local\{4C519719-5536-40B5-9915-9DFDBF5B6AE0}
2011-01-28 08:48 . 2011-01-28 08:48    --------    d-----w-    c:\users\Lau\AppData\Local\{BE63F3CA-09EF-4709-8F76-5AD0B434307D}
2011-01-28 08:48 . 2011-01-28 08:48    --------    d-----w-    c:\users\Lau\AppData\Local\{C888E71E-BCF2-4C01-8115-A984F80DD2E6}

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-23 22:52 . 2010-12-12 14:57    472808    ----a-w-    c:\windows\SysWow64\deployJava1.dll
2011-02-02 16:11 . 2010-09-20 16:05    270720    ------w-    c:\windows\system32\MpSigStub.exe
2011-01-13 18:29 . 2010-12-03 04:33    335168    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-01-12 01:01 . 2010-12-29 00:41    89840    ----a-w-    c:\windows\system32\drivers\inspect.sys
2011-01-12 01:01 . 2010-12-29 00:41    39888    ----a-w-    c:\windows\system32\drivers\cmdhlp.sys
2011-01-12 01:01 . 2010-12-29 00:41    250008    ----a-w-    c:\windows\system32\drivers\cmdGuard.sys
2011-01-12 01:01 . 2010-12-29 00:41    14184    ----a-w-    c:\windows\system32\drivers\cmderd.sys
2010-12-29 00:42 . 2010-12-29 00:42    285480    ----a-w-    c:\windows\SysWow64\guard32.dll
2010-12-29 00:42 . 2010-12-29 00:42    362784    ----a-w-    c:\windows\system32\guard64.dll
2010-12-23 17:59 . 2010-12-23 17:59    335168    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-12-20 17:08 . 2010-12-10 06:16    24152    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-12-07 09:05 . 2010-12-07 09:05    49752    ----a-w-    c:\windows\system32\drivers\SBREDrv.sys
2010-12-06 22:42 . 2010-12-03 04:33    48648    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2010-12-05 00:46 . 2010-12-05 00:46    48648    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2010-12-03 09:05 . 2010-12-12 00:33    69152    ----a-w-    c:\windows\system32\drivers\Lbd.sys
.

((((((((((((((((((((((((((((((((((((((((((((  Look  )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

--- c:\program files (x86)\Veetle\plugins\npVeetle.dll ---
Company: Veetle Inc
File Description: Version 0.9.18, Copyright 2006-2009 Veetle Inc<br><a href=http://www.veetle.com/>http://www.veetle.com/</a>
File Version: 0.9.18
Product Name: Veetle TV Core
Copyright: Copyright © 2006-2009 Veetle Inc
Original Filename: npveetle.dll
File size: 667352
Created time: 2010-10-16 00:00
Modified time: 2010-10-16 00:00
MD5: C50B22C8D91A76069A993A2B5197A296
SHA1: DC2551AE1C6317BD5369F8AD86727B5605A0E39A


(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"LogitechVideoRepair"="c:\program files (x86)\Logitech\Video\ISStart.exe" [1601-01-01 0]
"LogitechVideoTray"="c:\program files (x86)\Logitech\Video\LogiTray.exe" [1601-01-01 0]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files (x86)\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2011-02-22 352976]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-1-10 291896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll c:\progra~2\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~2\KASPER~1\KASPER~1\sbhook.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages    REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-08 136176]
R3 FLASHSYS;FLASHSYS;c:\program files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys [2008-02-15 15192]
R3 MsibiosDevice;MsibiosDevice;c:\program files (x86)\MSI\Live Update 4\LU4\msibios64.sys [2008-12-10 33080]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-19 239616]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-20 1255736]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-12-03 69152]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-01-12 250008]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-01-12 39888]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11864]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 27736]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2009-12-10 65536]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-01-10 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-01-10 399416]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 22544]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-01-28 86120]

.
Indhold af mappen 'Planlagte Opgaver'

2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-08 10:08]

2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-08 10:08]
.

--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-19 8866120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll c:\progra~2\KASPER~1\KASPER~1\x64\sbhook64.dll
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://fck.dk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Føj til Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: {{4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - c:\poker\Betway\Poker\MPPoker.exe
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
TCP: {1E05C2C8-E716-4F2C-9A7B-34FA1C85F9D7} = 156.154.70.22,156.154.71.22
FF - ProfilePath - c:\users\Lau\AppData\Roaming\Mozilla\Firefox\Profiles\9lch2ji1.default\
FF - prefs.js: browser.startup.homepage - hxxp://fck.dk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
.
- - - - TOMME GENVEJE FJERNET - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-PartyPoker - c:\poker\PartyPoker\PartyPoker\Uninstall.exe
AddRemove-vShare - c:\program files (x86)\vShare\UNINSTALL.exe


.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_USERS\S-1-5-21-4109743488-1576573958-2140537889-1000\Software\SecuROM\License information*]
"datasecu"=hex:70,5b,37,8f,3f,a0,ba,67,8b,38,4e,9d,86,ca,ce,aa,37,a4,12,8a,3b,
  5b,03,40,d3,2e,fa,6b,e3,69,26,07,cc,ee,98,d0,f9,bd,42,e3,80,64,b8,fe,2e,1f,\
"rkeysecu"=hex:25,6e,26,75,92,ce,4f,64,cb,53,79,fc,02,ed,22,d1

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
.
**************************************************************************
.
Gennemført tid: 2011-02-27  08:35:28 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2011-02-27 07:35

Pre-Kørsel: 437.628.383.232 byte ledig
Post-Kørsel: 437.508.710.400 byte ledig

- - End Of File - - 1FB395B3803052326D3CCCAAEFEE9135
Avatar billede f-arn Guru
27. februar 2011 - 14:10 #12
Bortset fra, du stadig kører med både Kaspesky og Comodo, ser det fint ud.

------

Deaktiver dit antivirus-program, kør en online scanning med ESET Online Scanner:
http://www.eset.com/onlinescan/

Du skal acceptere betingelserne for brug, og klik på Start.
Efter ActiveX Control er indlæst, vil det tage et par minutter for scanneren at blive klar.
Dernæst skal du sætte flueben i følgende felter: (kun dem)

Scan archives

under advanced settings
Scan for potentialy unwanted applications
Scan for potentially unsafe applications
Enable anti-stealth technology


Klik på Start. Denne scanning kan tage et stykke tid, så vær tålmodig.
En log vil åbne, når scanningen er færdig.

(hvis ikke, skal du gå til C:\Programmer\EsetOnlineScanner\ og åbne filen Log.txt).

Kopier den herind i næste indlæg.
Avatar billede short3 Nybegynder
27. februar 2011 - 23:22 #13
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=89a868ed7509b443a49e0511c338c091
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-02-27 09:46:02
# local_time=2011-02-27 10:46:02 (+0100, Rom, normaltid)
# country="Denmark"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1024 16777215 100 0 11229117 11229117 0 0
# compatibility_mode=1280 16777215 100 0 502074 502074 0 0
# compatibility_mode=3073 16777214 0 10 7207 3419081 0 0
# compatibility_mode=5893 16776574 100 94 48020 50472070 0 0
# compatibility_mode=8192 67108863 100 0 5414 5414 0 0
# scanned=38997
# found=0
# cleaned=0
# scan_time=943
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=89a868ed7509b443a49e0511c338c091
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-02-27 10:19:43
# local_time=2011-02-27 11:19:43 (+0100, Rom, normaltid)
# country="Denmark"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1024 16777215 100 0 11230358 11230358 0 0
# compatibility_mode=1280 16777215 100 0 503315 503315 0 0
# compatibility_mode=3073 16777214 0 10 8448 3420322 0 0
# compatibility_mode=5893 16776574 100 94 49261 50473311 0 0
# compatibility_mode=8192 67108863 100 0 6655 6655 0 0
# scanned=89264
# found=0
# cleaned=0
# scan_time=1722
Avatar billede f-arn Guru
01. marts 2011 - 01:35 #14
Det ser fint ud.

Tast  <Windows> + <R> samtidig og kopier dette ind: combofix /uninstall
Tryk enter
Det vil fjerne Combofix og nulstille urets indstillinger.
Nulstille Systemgendannelsen.
Skjule filtypenavne hvis det kræves.
Skjule System/skjulte filer hvis det kræves.
Avatar billede short3 Nybegynder
03. marts 2011 - 05:25 #15
done
Avatar billede f-arn Guru
03. marts 2011 - 06:23 #16
Hvis du stadig har problemer, så afinstaller enten Kaspersky eller Comodo!!!
Avatar billede short3 Nybegynder
04. marts 2011 - 12:20 #17
Jeg har ingen problemer og computeren ser ud til fungere fint nu, men pc'en lukkede sådan en gang om ugen ca nogle gange sjældnere, så vil lige vente og se. Men er den repareret så må du få alle mine point og jeg er meget taknemmelig.
Avatar billede short3 Nybegynder
15. marts 2011 - 13:23 #18
Ingen problemer so far, så jeg tror at den er fixet.
Avatar billede short3 Nybegynder
15. marts 2011 - 13:23 #19
Hvordan giver man point?
15. marts 2011 - 13:47 #20
Avatar billede f-arn Guru
15. marts 2011 - 14:03 #21
:-)
Avatar billede short3 Nybegynder
20. april 2011 - 18:41 #22
Nu gjorde den det igen. Er i tvivl om det er en virus for den er rimelig kraftig. Der kommer en sort skærm og pc'en virker til at være lukket ned samtidig med den er tændt. Man kan se at den røde lampe ikke arbejder længere, men samtidig er tastaturlyset tændt og den giver stadig lyd fra sig. NumLock lyset kan ikke tændes og slukkes og tastaturet virker dødt. Kan det være en manufaktur fejl?
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester