Hej igen
Her er DDS log :
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Peter at 19:45:13 on 2011-12-01
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1471.913 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Programmer\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
svchost.exe
C:\Programmer\Connect it\BecHelperService.exe
C:\Programmer\Connect it\LoggerServer.exe
C:\Programmer\TeamViewer\Version6\TeamViewer_Service.exe
C:\Programmer\TeamViewer\Version6\TeamViewer.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\Mozilla Firefox\plugin-container.exe
C:\Programmer\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelperShim.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [MSC] "c:\programmer\microsoft security client\msseces.exe" -hide -runkey
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\fllesf~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\opdate~1.lnk - c:\programmer\connect it\AutoUpdateSrv.exe
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\utilit~1.lnk - c:\windows\system32\sistray.exe
IE: E&ksporter til Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmer\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269125759750DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabTCP: DhcpNameServer = 193.162.153.164 194.239.134.83
TCP: Interfaces\{D760E9E2-FF31-4A52-A7DB-7D96562BC9CA} : DhcpNameServer = 193.162.153.164 194.239.134.83
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\peter\application data\mozilla\firefox\profiles\f2esiidh.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - plugin: c:\programmer\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\programmer\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\programmer\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\programmer\google\update\1.3.21.79\npGoogleUpdate3.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 165648]
R1 MpKsl7e6c539f;MpKsl7e6c539f;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{545e9519-b2c1-443e-968b-be003cf2d8af}\MpKsl7e6c539f.sys [2011-12-1 29904]
R2 BecHelperService;BecHelperService;c:\programmer\connect it\BecHelperService.exe [2011-10-27 1762176]
R2 TeamViewer6;TeamViewer 6;c:\programmer\teamviewer\version6\TeamViewer_Service.exe [2011-8-30 2358656]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2011-10-27 70656]
S1 MpKsl0f4c40eb;MpKsl0f4c40eb;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ec381f36-67cd-4adb-9a6e-d2c26d4494ae}\mpksl0f4c40eb.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ec381f36-67cd-4adb-9a6e-d2c26d4494ae}\MpKsl0f4c40eb.sys [?]
S1 MpKsldedf2a93;MpKsldedf2a93;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bfbac365-a3a1-402d-b475-edb824d21a93}\mpksldedf2a93.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bfbac365-a3a1-402d-b475-edb824d21a93}\MpKsldedf2a93.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\programmer\google\update\GoogleUpdate.exe [2010-12-27 136176]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2011-10-27 101504]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2011-10-27 117504]
S3 gupdatem;Google Update Tjeneste (gupdatem);c:\programmer\google\update\GoogleUpdate.exe [2010-12-27 136176]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-01 17:39:58 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{545e9519-b2c1-443e-968b-be003cf2d8af}\MpKsl7e6c539f.sys
2011-12-01 17:39:55 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{545e9519-b2c1-443e-968b-be003cf2d8af}\offreg.dll
2011-12-01 12:55:14 6823496 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{545e9519-b2c1-443e-968b-be003cf2d8af}\mpengine.dll
2011-11-30 15:46:12 -------- d-----w- c:\programmer\fælles filer\Adobe
2011-11-30 13:28:44 -------- d-----w- c:\documents and settings\peter\application data\Malwarebytes
2011-11-30 13:28:18 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-30 13:28:13 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-30 13:28:13 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2011-11-29 16:53:34 -------- d-----w- c:\programmer\CCleaner
2011-11-06 21:59:23 -------- d-----w- C:\FH
.
==================== Find3M ====================
.
2011-11-22 11:56:04 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-27 20:49:46 67156 ----a-w- c:\windows\Huawei ModemsUninstall.exe
2011-10-10 14:22:51 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:47 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41:36 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41:36 21504 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:10:06 1858944 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 19:45:56,65 ===============
mvh
ronrea