Just nu i M3-nätverket
Jump to content

Seg dator som hänger sig


Linnégatan

Recommended Posts

Linnégatan

[log]DDS (Ver_10-03-17.01) - NTFSx86

Run by S at 21:56:20,39 on 2010-06-30

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1023.401 [GMT 2:00]

 

AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Creative\Shared Files\CTAudSvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program\Logitech\Logitech WebCam Software\LWS.exe

C:\WINDOWS\system32\CTHELPER.EXE

C:\Program\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program\Delade filer\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Skype\Phone\Skype.exe

svchost.exe

C:\Program\Delade filer\Logishrd\LQCVFX\COCIManager.exe

C:\Program\LSI SoftModem\agrsmsvc.exe

C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program\Cisco Systems\VPN Client\cvpnd.exe

C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program\Photodex\ProShowGold\ScsiAccess.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program\Canon\CAL\CALMAIN.exe

C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe

C:\Program\iPod\bin\iPodService.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program\Internet Explorer\iexplore.exe

C:\Program\Internet Explorer\iexplore.exe

C:\Program\Internet Explorer\iexplore.exe

C:\Documents and Settings\SL\Skrivbord\dds.scr

 

============== Pseudo HJT Report ===============

 

uInternet Settings,ProxyOverride = *.local

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users.windows\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program\norton antivirus\norton antivirus\engine\17.7.0.12\IPSBHO.DLL

BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program\ask.com\GenericAskToolbar.dll

TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program\ask.com\GenericAskToolbar.dll

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [skype] "c:\program\skype\phone\Skype.exe" /nosplash /minimized

uRun: [regsdkrl32] c:\documents and settings\SL\application data\regsdkrl32\regsdkrl48.exe

uRun: [byyvspdrv] rundll32.exe "nnklmj.dll",s

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect

mRun: [LogitechQuickCamRibbon] "c:\program\logitech\logitech webcam software\LWS.exe" /hide

mRun: [CTHelper] CTHELPER.EXE

mRun: [QuickTime Task] "c:\program\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program\delade filer\adobe\arm\1.0\AdobeARM.exe"

mRun: [hgggfesys] rundll32.exe "nnkhfg.dll",DllRegisterServer

mRun: [qonmjgdrv] rundll32.exe "nnklmj.dll",s

mRun: [TkBellExe] "c:\program\delade filer\real\update_ob\realsched.exe" -osboot

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRun: [sstromsys] rundll32.exe "nnkhfg.dll",DllRegisterServer

dRun: [gedefcdrv] rundll32.exe "nnklmj.dll",s

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\adobeg~1.lnk - c:\program\delade filer\adobe\calibration\Adobe Gamma Loader.exe

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\HARMAN~1.LNK -

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\VPNCLI~1.LNK -

IE: E&xportera till Microsoft Excel - c:\program\micros~2\office11\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program\micros~2\office11\REFIEBAR.DLL

DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\delade~1\skype\SKYPE4~1.DLL

LSA: Authentication Packages = msv1_0 nnkhfg.dll

 

============= SERVICES / DRIVERS ===============

 

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1107000.00c\symds.sys [2010-6-1 328752]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1107000.00c\symefa.sys [2010-6-1 173104]

R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\bashdefs\20100619.001\BHDrvx86.sys [2010-6-23 691248]

R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1107000.00c\cchpx86.sys [2010-6-1 501888]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1107000.00c\ironx86.sys [2010-6-1 116784]

R2 NAV;Norton AntiVirus;c:\program\norton antivirus\norton antivirus\engine\17.7.0.12\ccsvchst.exe [2010-6-1 126392]

R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]

R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]

R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\delade filer\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-31 102448]

R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\ipsdefs\20100625.001\IDSXpx86.sys [2010-6-26 331640]

R3 NAVENG;NAVENG;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20100629.002\NAVENG.SYS [2010-6-29 85552]

R3 NAVEX15;NAVEX15;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20100629.002\NAVEX15.SYS [2010-6-29 1347504]

S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\delade filer\creative labs shared\service\CTAELicensing.exe [2010-5-31 79360]

S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]

S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]

S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]

S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]

 

=============== Created Last 30 ================

 

2010-06-30 19:41:01 0 d-----w- c:\windows\system32\LogFiles

2010-06-28 16:54:25 0 d-----w- c:\program\delade filer\xing shared

2010-06-28 16:53:54 499712 ----a-w- c:\windows\system32\msvcp71.dll

2010-06-28 16:53:54 348160 ----a-w- c:\windows\system32\msvcr71.dll

2010-06-28 16:53:44 0 d-----w- c:\program\delade filer\Real

2010-06-28 16:46:48 0 d-----w- c:\windows\RegisteredPackages

2010-06-27 10:55:07 0 d-----w- c:\program\Super Internet TV

2010-06-27 10:35:44 0 d-----w- c:\program\IZArc

2010-06-27 09:16:54 0 d-----w- c:\program\VideoLAN

2010-06-27 08:29:04 7706 ----a-w- C:\ZB20100627102811001.xml

2010-06-13 20:43:16 0 d-----w- C:\Presentationer

2010-06-13 20:21:49 17624726 ----a-w- C:\fete.exe

2010-06-12 10:59:25 10751 ----a-w- C:\ZB20100612125853001.xml

2010-06-12 10:19:24 89600 ---ha-w- c:\windows\system32\nnklmj.dll

2010-06-12 10:16:32 0 d-----w- c:\program\Photodex Presenter

2010-06-12 10:16:18 0 d-----w- c:\program\Photodex

2010-06-12 10:13:34 0 d-----w- c:\docume~1\S~1\applic~1\Photodex

2010-06-12 10:13:33 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Photodex

2010-06-12 10:13:23 0 d-----w- c:\docume~1\S~1\applic~1\regsdkrl32

2010-06-12 10:13:22 69120 ---ha-w- c:\windows\system32\nnkhfg.dll

2010-06-12 10:13:22 2 ----a-w- c:\documents and settings\SL\tenmy.ini

2010-06-12 10:13:19 717671 ----a-w- c:\documents and settings\SL\regsdkrl48.exe

2010-06-12 09:24:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll

2010-06-10 20:53:31 161154 ----a-w- c:\windows\Expstudio Audio Editor FREE Uninstaller.exe

2010-06-10 20:53:20 0 d-----w- c:\windows\system32\EXP

2010-06-10 20:53:20 0 d-----w- c:\program\Expstudio

2010-06-09 20:04:14 272868 ----a-w- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr

2010-06-09 20:04:14 2561772 ----a-w- c:\windows\system32\attractaemc1200.avi

2010-06-06 16:42:34 0 d-----w- C:\spoolerlogs

2010-06-05 17:16:40 0 d-----w- c:\documents and settings\SL\OkiData

2010-06-01 20:21:41 0 d-----w- c:\windows\Internet Logs

2010-06-01 19:56:56 5220 ----a-r- c:\windows\system32\drivers\CVirtA.sys

2010-06-01 19:54:26 139604 ----a-w- c:\windows\system32\drivers\dne2000.sys

2010-06-01 19:54:26 113596 ----a-w- c:\windows\system32\dneinobj.dll

2010-06-01 19:54:24 0 d-----w- c:\program\delade filer\Deterministic Networks

2010-06-01 19:54:22 0 d-----w- c:\program\Cisco Systems

2010-06-01 19:49:38 0 d-----w- c:\program\LSI SoftModem

2010-06-01 19:01:24 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2010-06-01 19:00:47 0 d-----r- c:\program\Skype

2010-06-01 18:28:41 5632 ----a-w- c:\windows\system32\ptpusb.dll

2010-06-01 18:28:40 159232 ----a-w- c:\windows\system32\ptpusd.dll

2010-06-01 18:28:39 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys

2010-06-01 18:20:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys

2010-06-01 18:20:17 107368 ----a-w- c:\windows\system32\GEARAspi.dll

2010-06-01 18:19:38 0 d-----w- c:\program\iPod

2010-06-01 18:19:35 0 d-----w- c:\program\iTunes

2010-06-01 18:19:35 0 d-----w- c:\docume~1\alluse~1.win\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-06-01 18:18:12 41472 ----a-w- c:\windows\system32\drivers\usbaapl.sys

2010-06-01 18:18:12 3003680 ----a-w- c:\windows\system32\usbaaplrc.dll

2010-06-01 18:17:49 0 d-----w- c:\program\Bonjour

2010-06-01 18:17:39 0 d-----w- c:\program\delade filer\Apple

2010-06-01 18:11:19 0 d-----w- c:\docume~1\S~1\applic~1\Spotify

2010-06-01 17:22:27 383 ----a-w- c:\windows\ODBC.INI

2010-06-01 17:21:35 0 d-----w- c:\program\delade filer\ODBC

2010-06-01 17:13:27 0 d-----w- C:\e66cec3e1f7a842add20df881c6696

2010-06-01 17:01:54 1089883 -c----w- c:\windows\system32\dllcache\ntprint.cat

2010-05-31 21:57:12 1080 ----a-w- c:\windows\system32\settingsbkup.sfm

2010-05-31 21:57:12 1080 ----a-w- c:\windows\system32\settings.sfm

2010-05-31 21:35:20 44032 ------w- c:\windows\system32\CTSVCCDA.EXE

2010-05-31 21:35:20 25088 ------w- c:\windows\system32\CTSVCCTL.EXE

2010-05-31 21:34:42 0 d-----w- c:\program\delade filer\Creative

2010-05-31 21:34:41 0 d--h--w- c:\program\Creative Installation Information

2010-05-31 21:22:47 30888 ----a-w- c:\windows\system32\BMXStateBkp-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

2010-05-31 21:22:47 30888 ----a-w- c:\windows\system32\BMXState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

2010-05-31 21:22:47 29952 ----a-w- c:\windows\system32\BMXCtrlState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

2010-05-31 21:22:47 29952 ----a-w- c:\windows\system32\BMXBkpCtrlState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

2010-05-31 21:22:47 11564 ----a-w- c:\windows\system32\DVCState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

2010-05-31 21:22:34 4932561 ------w- c:\windows\{00000003-00000000-00000006-00001102-00000004-20051102}.BAK

2010-05-31 21:21:27 4174814 ------w- c:\windows\system32\CT4MGM.SF2

2010-05-31 21:21:22 0 d-----w- c:\windows\system32\Defaults

2010-05-31 21:20:38 4932561 ----a-w- c:\windows\{00000003-00000000-00000006-00001102-00000004-20051102}.CDF

2010-05-31 21:20:25 7062 ----a-w- c:\windows\system32\audiopid.vxd

2010-05-31 21:20:04 0 d-----w- c:\program\delade filer\Creative Labs Shared

2010-05-31 21:19:09 445016 ----a-w- c:\windows\system32\wrap_oal.dll

2010-05-31 21:19:09 109144 ----a-w- c:\windows\system32\OpenAL32.dll

2010-05-31 21:17:36 0 d-----w- c:\windows\system32\Data

2010-05-31 21:17:31 0 d-----w- c:\program\Creative

2010-05-31 21:17:22 0 d-----w- C:\f83720b3455df4548a

2010-05-31 21:15:16 0 d-----w- c:\windows\system32\XPSViewer

2010-05-31 21:14:34 117760 ------w- c:\windows\system32\prntvpt.dll

2010-05-31 21:14:33 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2010-05-31 21:14:33 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2010-05-31 21:14:33 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2010-05-31 21:14:33 575488 ------w- c:\windows\system32\xpsshhdr.dll

2010-05-31 21:14:33 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2010-05-31 21:14:33 1676288 ------w- c:\windows\system32\xpssvcs.dll

2010-05-31 21:14:32 0 d-----w- C:\628c1d721dce675620a976

2010-05-31 21:11:17 0 d-----w- c:\program\MSXML 6.0

2010-05-31 20:40:07 0 d-sh--w- c:\documents and settings\SL\PrivacIE

2010-05-31 20:15:14 0 d-sh--w- c:\documents and settings\SL\IETldCache

 

==================== Find3M ====================

 

2010-06-30 19:30:44 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs

2010-06-30 19:30:41 0 ----a-w- c:\windows\system32\drivers\logiflt.iad

2010-06-30 19:20:42 3932160 ---ha-w- c:\documents and settings\SL\NTUSER.DAT

2010-06-23 19:36:39 82854 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 19:36:39 443012 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-02 18:39:32 4771328 ----a-w- c:\program\iFunBox.exe

2010-05-30 17:48:06 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF

2010-05-30 17:48:06 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT

2010-05-30 17:48:06 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL

2010-05-30 17:48:06 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS

2010-05-30 17:32:10 21700 ----a-w- c:\windows\system32\emptyregdb.dat

2010-05-06 10:36:51 916480 ----a-w- c:\windows\system32\wininet.dll

2010-05-02 08:10:15 1851264 ----a-w- c:\windows\system32\win32k.sys

2010-04-20 05:34:53 285696 ----a-w- c:\windows\system32\atmfd.dll

2010-04-08 11:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-04-08 11:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe

2008-12-02 14:17:02 9912 ----a-w- c:\program\absokt.nfo

2008-12-02 14:05:22 429 ----a-w- c:\program\file_id.diz

2008-12-02 09:37:06 5000000 ----a-w- c:\program\aodt291.r08

 

============= FINISH: 21:56:41,85 ===============

 

==== End Of File ===========================

[/log]Hej på er!

Jag har kikat i ett par trådar för att se om jag kunde få någon vägledning men inte hittat någon som har samma typ av fel som jag upplever att jag har. Därför lämnar jag en rad här och hoppas att någon vänligt sinnad kan kika på mina problem.

 

1. Datorn är mycket slö när jag är ute på nätet. Det tar lång tid att växla mellan sidor. Ibland kommer jag inte ut på nätet överhuvudtaget.

2. När skärmsläckaren går igång händer det att hela datorn låser sig (jag har en känsla av att datorn tror att den har två olika bildskärmar). Detta gör att jag får trycka på off-knappen för att få igång datorn igen.

3. Det händer ofta att jag får starta om datorn igen efter jag startat den eftersom den startar med själva skrivbordsunderlägget bara (inga ikoner syns någonstans). Återigen tryckaer jag på off-knappen under några sekunder. Ibland kan jag starta upp datorn fyra-fem gånger.

3. Spotify hänger sig och informerar mig att någon annan är inloggad på kontot.

 

Det är väl egentligen att datorn är så seg och att det tar så himla lång tid som gör att jag lämnar ett avtryck här. Jag ska försöka klistra in min logg nedan.

 

 

 

 

 

Tack för hjälpen!

Link to comment
Share on other sites

  • Replies 53
  • Created
  • Last Reply

Avinstallera Ask Toolbar.

 

Det har kommit in många skadliga filer samtidigt som programmet Photodex installerades.

2010-06-12 10:16:18 0 d-----w- c:\program\Photodex

Är det en crackad version eller något liknande?

Det är nog bäst att du avinstallerar Photodex.

 

På sidan http://www.virustotal.com trycker du på Bläddra-knappen och klistrar in ett av följande filnamn i rutan, tryck på Öppna och sedan Skicka Fil. Vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in en länk till resultatet här. Upprepa med nästa filnamn.

c:\documents and settings\SL\application data\regsdkrl32\regsdkrl48.exe

C:\fete.exe

c:\windows\system32\nnklmj.dll

c:\windows\system32\nnkhfg.dll

c:\documents and settings\SL\regsdkrl48.exe

Link to comment
Share on other sites

Linnégatan

Avinstallera Ask Toolbar.

 

Det har kommit in många skadliga filer samtidigt som programmet Photodex installerades.

2010-06-12 10:16:18 0 d-----w- c:\program\Photodex

Är det en crackad version eller något liknande?

Det är nog bäst att du avinstallerar Photodex.

 

På sidan http://www.virustotal.com trycker du på Bläddra-knappen och klistrar in ett av följande filnamn i rutan, tryck på Öppna och sedan Skicka Fil. Vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in en länk till resultatet här. Upprepa med nästa filnamn.

c:\documents and settings\SL\application data\regsdkrl32\regsdkrl48.exe

C:\fete.exe

c:\windows\system32\nnklmj.dll

c:\windows\system32\nnkhfg.dll

c:\documents and settings\SL\regsdkrl48.exe

Link to comment
Share on other sites

Linnégatan

Trodde att jag bara hade betald programvara. Nu har jag dock pratat med den kamrat som installerade photodex för mig som sa något luddigt om att det kunde vara en fil från internet och han sa att den kan vara infekterad. :-(

 

Nåväl, jag har avinstallerat Ask toolbar och Photodex.

 

Här klistrar jag in de loggar från virustotal (jag tyckte att det var lite klurigt att hitta filerna, hoppas att jag gjort rätt, säg till annars).

 

Tack för din/er tid.

 

 

c:\documents and settings\SL\application data\regsdkrl32\regsdkrl48.exe

http://www.virustotal.com/sv/analisis/37ac8ebb6f795ac1510fbb54ae19db825e7ac24380aa0bd66c65ddc67f87bdd4-1277016488'>http://www.virustotal.com/sv/analisis/37ac8ebb6f795ac1510fbb54ae19db825e7ac24380aa0bd66c65ddc67f87bdd4-1277016488

 

c:\windows\system32\nnklmj.dll

http://www.virustotal.com/sv/analisis/f17a021009e4d259fc2fa4e71f3156bcfa27c9cd3a354b909bfe6fffd806b317-1276556517

 

c:\windows\system32\nnkhfg.dll

http://www.virustotal.com/sv/analisis/e4dca7bca211f962b2217e9843271bfa36ec5df43345c1c8d1c8f24a42a32e33-1276556520

 

c:\documents and settings\SL\regsdkrl48.exe

http://www.virustotal.com/sv/analisis/37ac8ebb6f795ac1510fbb54ae19db825e7ac24380aa0bd66c65ddc67f87bdd4-1277016488

Link to comment
Share on other sites

Tråkigt med kamrater som gör sådant :(

 

Ladda ner Malwarebytes Anti-Malware (MBAM) från en av dessa länkar:

http://www.malwarebytes.org/mbam-download.php

http://majorgeeks.com/downloadget.php?id=5756&file=15&evp=693ee0b20204960edfd909666f809b26

http://dw.com.com/redir?edId=3&siteId=4&oId=3000-8022_4-10804572&ontId=8022_4&spi=b4a0904e0f02b40bf2ae9ce030ef5c99&lop=link&tag=tdw_dltext&ltype=dl_dlnow&pid=11375988&mfgId=6290020&merId=6290020&pguid=XI3P-goPjFwAACI-g4wAAAA4&destUrl=http%3A%2F%2Fdownload.cnet.com%2F3001-8022_4-10804572.html%3Fspi%3Db4a0904e0f02b40bf2ae9ce030ef5c99

http://fileforum.betanews.com/detail/Malwarebytes-AntiMalware/1186760019/1

Dubbelklicka på mbam-setup för att installera programmet.

 

Se till i slutet av installationen att det är bockar för:

Uppdatera Malwarebytes' Anti-Malware

Starta Malwarebytes' Anti-Malware

Tryck på Slutför

Om det finns någon uppdatering så kommer den att laddas ner och installeras.

 

När programmet startar så välj "Utför snabb skanning" och tryck på Skanna.

Skanningen tar ett tag.

När den är klar så tryck på OK och sedan "Visa resultat".

Bocka för allt och tryck sedan Ta bort markerade.

När borttagningen är klar så öppnar Anteckningar med en logg.

 

Eventuellt så kommer det upp en begäran om att starta om datorn (Restart). I så fall gör det.

Om det blir ett felmeddelande Error loading... efter omstarten så starta om datorn än en gång.

Om programmet inte kommer igång efter omstarten så starta det.

 

Om loggen inte kommer upp själv i Anteckningar så hittar du loggen på fliken Loggar i MBAM.

Kopiera loggen och klistra in den i ditt svar tillsammans med en ny DDS-logg.

Link to comment
Share on other sites

Linnégatan

Hej igen,

Efter att ha varit lite arg för att jag får sitta och brottas med min dator istället för kompisen som orsakat detta har jag lugnat ner mig nu. Det är ju trots allt så att jag får hjälp härifrån. :-) Stort tack för det...

 

Hur som helst. Här kommer loggen. Jag hoppas att jag gör rätt... (klistrar in loggen i rutan).

 

 

 

 

[log]Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Databasversion: 4052

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

2010-07-01 20:06:46

mbam-log-2010-07-01 (20-06-46).txt

 

Skanningstyp: Snabbskanning

Antal skannade objekt: 166896

Förfluten tid: 11 minut(er), 19 sekund(er)

 

Infekterade minnesprocesser: 0

Infekterade minnesmoduler: 0

Infekterade registernycklar: 0

Infekterade registervärden: 7

Infekterade registerdataposter: 0

Infekterade mappar: 0

Infekterade filer: 0

 

Infekterade minnesprocesser:

(Inga illasinnade poster hittades)

 

Infekterade minnesmoduler:

(Inga illasinnade poster hittades)

 

Infekterade registernycklar:

(Inga illasinnade poster hittades)

 

Infekterade registervärden:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\byyvspdrv (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qonmjgdrv (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gedefcdrv (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gedefcdrv (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hgggfesys (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sstromsys (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sstromsys (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Infekterade registerdataposter:

(Inga illasinnade poster hittades)

 

Infekterade mappar:

(Inga illasinnade poster hittades)

 

Infekterade filer:

(Inga illasinnade poster hittades)

 

DDS (Ver_10-03-17.01) - NTFSx86

Run by SL‚n at 20:24:05,18 on 2010-07-01

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1023.318 [GMT 2:00]

 

AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Creative\Shared Files\CTAudSvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program\Logitech\Logitech WebCam Software\LWS.exe

C:\WINDOWS\system32\CTHELPER.EXE

C:\Program\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program\Delade filer\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Skype\Phone\Skype.exe

C:\Program\Delade filer\Logishrd\LQCVFX\COCIManager.exe

svchost.exe

C:\Program\LSI SoftModem\agrsmsvc.exe

C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program\Cisco Systems\VPN Client\cvpnd.exe

C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe

C:\Program\Canon\CAL\CALMAIN.exe

C:\Program\iPod\bin\iPodService.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program\Internet Explorer\iexplore.exe

C:\Program\Internet Explorer\iexplore.exe

C:\Program\Internet Explorer\iexplore.exe

C:\Documents and Settings\SLén\Skrivbord\dds.scr

 

============== Pseudo HJT Report ===============

 

uInternet Settings,ProxyOverride = *.local

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users.windows\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program\norton antivirus\norton antivirus\engine\17.7.0.12\IPSBHO.DLL

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [skype] "c:\program\skype\phone\Skype.exe" /nosplash /minimized

uRun: [regsdkrl32] c:\documents and settings\SLén\application data\regsdkrl32\regsdkrl48.exe

uRun: [xxyaxvdrv] rundll32.exe "nnklmj.dll",s

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect

mRun: [LogitechQuickCamRibbon] "c:\program\logitech\logitech webcam software\LWS.exe" /hide

mRun: [CTHelper] CTHELPER.EXE

mRun: [QuickTime Task] "c:\program\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program\delade filer\adobe\arm\1.0\AdobeARM.exe"

mRun: [TkBellExe] "c:\program\delade filer\real\update_ob\realsched.exe" -osboot

mRun: [ssqrpndrv] rundll32.exe "nnklmj.dll",s

mRun: [urroljsys] rundll32.exe "nnkhfg.dll",DllRegisterServer

mRunOnce: [Malwarebytes' Anti-Malware] c:\program\malwarebytes' anti-malware\mbamgui.exe /install /silent

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRun: [ursrsssys] rundll32.exe "nnkhfg.dll",DllRegisterServer

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\adobeg~1.lnk - c:\program\delade filer\adobe\calibration\Adobe Gamma Loader.exe

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\HARMAN~1.LNK -

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\VPNCLI~1.LNK -

IE: E&xportera till Microsoft Excel - c:\program\micros~2\office11\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program\micros~2\office11\REFIEBAR.DLL

DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\delade~1\skype\SKYPE4~1.DLL

LSA: Authentication Packages = msv1_0 nnkhfg.dll

 

============= SERVICES / DRIVERS ===============

 

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1107000.00c\symds.sys [2010-6-1 328752]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1107000.00c\symefa.sys [2010-6-1 173104]

R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\bashdefs\20100619.001\BHDrvx86.sys [2010-6-23 691248]

R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1107000.00c\cchpx86.sys [2010-6-1 501888]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1107000.00c\ironx86.sys [2010-6-1 116784]

R2 NAV;Norton AntiVirus;c:\program\norton antivirus\norton antivirus\engine\17.7.0.12\ccsvchst.exe [2010-6-1 126392]

R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]

R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]

R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\delade filer\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-31 102448]

R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\ipsdefs\20100630.006\IDSXpx86.sys [2010-7-1 331640]

R3 NAVENG;NAVENG;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20100630.041\NAVENG.SYS [2010-7-1 85552]

R3 NAVEX15;NAVEX15;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20100630.041\NAVEX15.SYS [2010-7-1 1347504]

S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\delade filer\creative labs shared\service\CTAELicensing.exe [2010-5-31 79360]

S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]

S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]

S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]

S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]

 

=============== Created Last 30 ================

 

2010-07-01 17:53:34 0 d-----w- c:\docume~1\stefan~1\applic~1\Malwarebytes

2010-07-01 17:30:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-01 17:30:58 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes

2010-07-01 17:30:57 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-01 17:30:57 0 d-----w- c:\program\Malwarebytes' Anti-Malware

2010-06-30 19:41:01 0 d-----w- c:\windows\system32\LogFiles

2010-06-28 16:54:25 0 d-----w- c:\program\delade filer\xing shared

2010-06-28 16:53:54 499712 ----a-w- c:\windows\system32\msvcp71.dll

2010-06-28 16:53:54 348160 ----a-w- c:\windows\system32\msvcr71.dll

2010-06-28 16:53:44 0 d-----w- c:\program\delade filer\Real

2010-06-28 16:46:48 0 d-----w- c:\windows\RegisteredPackages

2010-06-27 10:35:44 0 d-----w- c:\program\IZArc

2010-06-27 09:16:54 0 d-----w- c:\program\VideoLAN

2010-06-27 08:29:04 7706 ----a-w- C:\ZB20100627102811001.xml

2010-06-13 20:43:16 0 d-----w- C:\Presentationer

2010-06-13 20:21:49 17624726 ----a-w- C:\Räkfesten.exe

2010-06-12 10:59:25 10751 ----a-w- C:\ZB20100612125853001.xml

2010-06-12 10:19:24 89600 ---ha-w- c:\windows\system32\nnklmj.dll

2010-06-12 10:13:34 0 d-----w- c:\docume~1\SL~1\applic~1\Photodex

2010-06-12 10:13:33 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Photodex

2010-06-12 10:13:23 0 d-----w- c:\docume~1\SL~1\applic~1\regsdkrl32

2010-06-12 10:13:22 69120 ---ha-w- c:\windows\system32\nnkhfg.dll

2010-06-12 10:13:22 2 ----a-w- c:\documents and settings\SL\tenmy.ini

2010-06-12 10:13:19 717671 ----a-w- c:\documents and settings\SL\regsdkrl48.exe

2010-06-12 09:24:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll

2010-06-10 20:53:31 161154 ----a-w- c:\windows\Expstudio Audio Editor FREE Uninstaller.exe

2010-06-10 20:53:20 0 d-----w- c:\windows\system32\EXP

2010-06-10 20:53:20 0 d-----w- c:\program\Expstudio

2010-06-09 20:04:14 272868 ----a-w- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr

2010-06-09 20:04:14 2561772 ----a-w- c:\windows\system32\attractaemc1200.avi

2010-06-06 16:42:34 0 d-----w- C:\spoolerlogs

2010-06-05 17:16:40 0 d-----w- c:\documents and settings\SL\OkiData

2010-06-01 20:21:41 0 d-----w- c:\windows\Internet Logs

2010-06-01 19:56:56 5220 ----a-r- c:\windows\system32\drivers\CVirtA.sys

2010-06-01 19:54:26 139604 ----a-w- c:\windows\system32\drivers\dne2000.sys

2010-06-01 19:54:26 113596 ----a-w- c:\windows\system32\dneinobj.dll

2010-06-01 19:54:24 0 d-----w- c:\program\delade filer\Deterministic Networks

2010-06-01 19:54:22 0 d-----w- c:\program\Cisco Systems

2010-06-01 19:49:38 0 d-----w- c:\program\LSI SoftModem

2010-06-01 19:01:24 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2010-06-01 19:00:47 0 d-----r- c:\program\Skype

2010-06-01 18:28:41 5632 ----a-w- c:\windows\system32\ptpusb.dll

2010-06-01 18:28:40 159232 ----a-w- c:\windows\system32\ptpusd.dll

2010-06-01 18:28:39 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys

 

==================== Find3M ====================

 

2010-07-01 17:20:09 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs

2010-07-01 17:20:06 0 ----a-w- c:\windows\system32\drivers\logiflt.iad

2010-07-01 17:13:34 3932160 ---ha-w- c:\documents and settings\SLén\NTUSER.DAT

2010-06-23 19:36:39 82854 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 19:36:39 443012 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-02 18:39:32 4771328 ----a-w- c:\program\iFunBox.exe

2010-05-31 21:19:09 445016 ----a-w- c:\windows\system32\wrap_oal.dll

2010-05-31 21:19:09 109144 ----a-w- c:\windows\system32\OpenAL32.dll

2010-05-30 17:48:06 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF

2010-05-30 17:48:06 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT

2010-05-30 17:48:06 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL

2010-05-30 17:48:06 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS

2010-05-30 17:32:10 21700 ----a-w- c:\windows\system32\emptyregdb.dat

2010-05-06 10:36:51 916480 ----a-w- c:\windows\system32\wininet.dll

2010-05-02 08:10:15 1851264 ----a-w- c:\windows\system32\win32k.sys

2010-04-20 05:34:53 285696 ----a-w- c:\windows\system32\atmfd.dll

2010-04-16 06:33:36 3003680 ----a-w- c:\windows\system32\usbaaplrc.dll

2010-04-08 11:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-04-08 11:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe

2008-12-02 14:17:02 9912 ----a-w- c:\program\absokt.nfo

2008-12-02 14:05:22 429 ----a-w- c:\program\file_id.diz

2008-12-02 09:37:06 5000000 ----a-w- c:\program\aodt291.r08

 

============= FINISH: 20:24:28,15 ===============

 

 

 

 

 

 

 

 

 

 

[/log]

Link to comment
Share on other sites

Du måste uppdatera MBAM varje gång du ska skanna igenom datorn. Starta MBAM, uppdatera och skanna igenom igen. Om något hittas så klistra in den loggen och en ny DDS-logg.

Link to comment
Share on other sites

Linnégatan

[log]Databasversion: 4265

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

2010-07-01 21:13:11

mbam-log-2010-07-01 (21-13-11).txt

 

Skanningstyp: Snabbskanning

Antal skannade objekt: 179768

Förfluten tid: 11 minut(er), 54 sekund(er)

 

Infekterade minnesprocesser: 0

Infekterade minnesmoduler: 1

Infekterade registernycklar: 0

Infekterade registervärden: 5

Infekterade registerdataposter: 0

Infekterade mappar: 0

Infekterade filer: 4

 

Infekterade minnesprocesser:

(Inga illasinnade poster hittades)

 

Infekterade minnesmoduler:

C:\WINDOWS\system32\nnklmj.dll (Trojan.Agent) -> Delete on reboot.

 

Infekterade registernycklar:

(Inga illasinnade poster hittades)

 

Infekterade registervärden:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xxyaxvdrv (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\urroljsys (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssqrpndrv (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ursrsssys (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ursrsssys (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Infekterade registerdataposter:

(Inga illasinnade poster hittades)

 

Infekterade mappar:

(Inga illasinnade poster hittades)

 

Infekterade filer:

C:\WINDOWS\system32\nnklmj.dll (Trojan.Agent) -> Delete on reboot.

C:\RECYCLER\S-1-5-21-1715567821-1757981266-725345543-1005\Dc13228.jpg (Extension.Mismatch) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-1715567821-1757981266-725345543-1005\Dc4309.jpg (Extension.Mismatch) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-1715567821-1757981266-725345543-1005\Dc7662.jpg (Extension.Mismatch) -> Quarantined and deleted successfully.

[/log]Sorry, jag fixar.

Link to comment
Share on other sites

Bra! Det börjar arta sig :thumbsup:

 

Klistra in en ny DDS-logg så får vi se om det är något kvar i den.

Link to comment
Share on other sites

Linnégatan

[log]DDS (Ver_10-03-17.01) - NTFSx86

Run by S L‚n at 22:40:48,12 on 2010-07-01

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.1023.277 [GMT 2:00]

 

AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Creative\Shared Files\CTAudSvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program\Logitech\Logitech WebCam Software\LWS.exe

C:\WINDOWS\system32\CTHELPER.EXE

C:\WINDOWS\system32\rundll32.exe

C:\Program\iTunes\iTunesHelper.exe

C:\Program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe

C:\Program\Delade filer\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Delade filer\Logishrd\LQCVFX\COCIManager.exe

svchost.exe

C:\Program\LSI SoftModem\agrsmsvc.exe

C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program\Cisco Systems\VPN Client\cvpnd.exe

C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program\Canon\CAL\CALMAIN.exe

C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe

C:\Program\iPod\bin\iPodService.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program\Internet Explorer\iexplore.exe

C:\Program\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program\Internet Explorer\iexplore.exe

C:\Program\Internet Explorer\iexplore.exe

C:\Documents and Settings\S Lén\Skrivbord\dds.scr

 

============== Pseudo HJT Report ===============

 

uInternet Settings,ProxyOverride = *.local

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users.windows\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program\norton antivirus\norton antivirus\engine\17.7.0.12\IPSBHO.DLL

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [skype] "c:\program\skype\phone\Skype.exe" /nosplash /minimized

uRun: [regsdkrl32] c:\documents and settings\S Lén\application data\regsdkrl32\regsdkrl48.exe

uRun: [hgdedbdrv] rundll32.exe "nnklmj.dll",s

uRun: [byvspmdrv] rundll32.exe "tuvurp.dll",s

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect

mRun: [LogitechQuickCamRibbon] "c:\program\logitech\logitech webcam software\LWS.exe" /hide

mRun: [CTHelper] CTHELPER.EXE

mRun: [QuickTime Task] "c:\program\quicktime\qttask.exe" -atboottime

mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program\delade filer\adobe\arm\1.0\AdobeARM.exe"

mRun: [TkBellExe] "c:\program\delade filer\real\update_ob\realsched.exe" -osboot

mRun: [wvvurpdrv] rundll32.exe "nnklmj.dll",s

mRun: [yaxusssys] rundll32.exe "nnkhfg.dll",DllRegisterServer

mRun: [wvvwwtdrv] rundll32.exe "tuvurp.dll",s

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRun: [ljklklsys] rundll32.exe "nnkhfg.dll",DllRegisterServer

dRun: [efcayadrv] rundll32.exe "nnklmj.dll",s

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\adobeg~1.lnk - c:\program\delade filer\adobe\calibration\Adobe Gamma Loader.exe

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\HARMAN~1.LNK -

StartupFolder: c:\docume~1\alluse~1.win\start-~1\program\autost~1\VPNCLI~1.LNK -

IE: E&xportera till Microsoft Excel - c:\program\micros~2\office11\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\program\micros~2\office11\REFIEBAR.DLL

DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\delade~1\skype\SKYPE4~1.DLL

LSA: Authentication Packages = msv1_0 nnkhfg.dll

 

============= SERVICES / DRIVERS ===============

 

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1107000.00c\symds.sys [2010-6-1 328752]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1107000.00c\symefa.sys [2010-6-1 173104]

R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\bashdefs\20100619.001\BHDrvx86.sys [2010-6-23 691248]

R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1107000.00c\cchpx86.sys [2010-6-1 501888]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1107000.00c\ironx86.sys [2010-6-1 116784]

R2 NAV;Norton AntiVirus;c:\program\norton antivirus\norton antivirus\engine\17.7.0.12\ccsvchst.exe [2010-6-1 126392]

R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]

R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]

R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\delade filer\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-31 102448]

R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\ipsdefs\20100630.006\IDSXpx86.sys [2010-7-1 331640]

R3 NAVENG;NAVENG;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20100630.041\NAVENG.SYS [2010-7-1 85552]

R3 NAVEX15;NAVEX15;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.6.0.32\definitions\virusdefs\20100630.041\NAVEX15.SYS [2010-7-1 1347504]

S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program\delade filer\creative labs shared\service\CTAELicensing.exe [2010-5-31 79360]

S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]

S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]

S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]

S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]

 

=============== Created Last 30 ================

 

2010-07-01 19:24:26 95232 ---ha-w- c:\windows\system32\tuvurp.dll

2010-07-01 17:53:34 0 d-----w- c:\docume~1\S~1\applic~1\Malwarebytes

2010-07-01 17:30:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-01 17:30:58 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes

2010-07-01 17:30:57 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-01 17:30:57 0 d-----w- c:\program\Malwarebytes' Anti-Malware

2010-06-30 19:41:01 0 d-----w- c:\windows\system32\LogFiles

2010-06-28 16:54:25 0 d-----w- c:\program\delade filer\xing shared

2010-06-28 16:53:54 499712 ----a-w- c:\windows\system32\msvcp71.dll

2010-06-28 16:53:54 348160 ----a-w- c:\windows\system32\msvcr71.dll

2010-06-28 16:53:44 0 d-----w- c:\program\delade filer\Real

2010-06-28 16:46:48 0 d-----w- c:\windows\RegisteredPackages

2010-06-27 10:35:44 0 d-----w- c:\program\IZArc

2010-06-27 09:16:54 0 d-----w- c:\program\VideoLAN

2010-06-27 08:29:04 7706 ----a-w- C:\ZB20100627102811001.xml

2010-06-13 20:43:16 0 d-----w- C:\Presentationer

2010-06-13 20:21:49 17624726 ----a-w- C:\Räkfesten.exe

2010-06-12 10:59:25 10751 ----a-w- C:\ZB20100612125853001.xml

2010-06-12 10:13:34 0 d-----w- c:\docume~1\S~1\applic~1\Photodex

2010-06-12 10:13:33 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Photodex

2010-06-12 10:13:23 0 d-----w- c:\docume~1\S~1\applic~1\regsdkrl32

2010-06-12 10:13:22 69120 ---ha-w- c:\windows\system32\nnkhfg.dll

2010-06-12 10:13:22 2 ----a-w- c:\documents and settings\S Lén\tenmy.ini

2010-06-12 10:13:19 717671 ----a-w- c:\documents and settings\S Lén\regsdkrl48.exe

2010-06-12 09:24:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll

2010-06-10 20:53:31 161154 ----a-w- c:\windows\Expstudio Audio Editor FREE Uninstaller.exe

2010-06-10 20:53:20 0 d-----w- c:\windows\system32\EXP

2010-06-10 20:53:20 0 d-----w- c:\program\Expstudio

2010-06-09 20:04:14 272868 ----a-w- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr

2010-06-09 20:04:14 2561772 ----a-w- c:\windows\system32\attractaemc1200.avi

2010-06-06 16:42:34 0 d-----w- C:\spoolerlogs

2010-06-05 17:16:40 0 d-----w- c:\documents and settings\S Lén\OkiData

2010-06-02 19:14:06 0 d-----w- c:\docume~1\S~1\applic~1\uTorrent

 

==================== Find3M ====================

 

2010-07-01 19:19:20 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs

2010-07-01 19:19:17 0 ----a-w- c:\windows\system32\drivers\logiflt.iad

2010-07-01 19:18:24 3932160 ---ha-w- c:\documents and settings\S Lén\NTUSER.DAT

2010-06-23 19:36:39 82854 ----a-w- c:\windows\system32\perfc01D.dat

2010-06-23 19:36:39 443012 ----a-w- c:\windows\system32\perfh01D.dat

2010-06-02 18:39:32 4771328 ----a-w- c:\program\iFunBox.exe

2010-05-31 21:19:09 445016 ----a-w- c:\windows\system32\wrap_oal.dll

2010-05-31 21:19:09 109144 ----a-w- c:\windows\system32\OpenAL32.dll

2010-05-30 17:48:06 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF

2010-05-30 17:48:06 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT

2010-05-30 17:48:06 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL

2010-05-30 17:48:06 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS

2010-05-30 17:32:10 21700 ----a-w- c:\windows\system32\emptyregdb.dat

2010-05-06 10:36:51 916480 ----a-w- c:\windows\system32\wininet.dll

2010-05-02 08:10:15 1851264 ----a-w- c:\windows\system32\win32k.sys

2010-04-20 05:34:53 285696 ----a-w- c:\windows\system32\atmfd.dll

2010-04-16 06:33:36 3003680 ----a-w- c:\windows\system32\usbaaplrc.dll

2010-04-08 11:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-04-08 11:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe

2008-12-02 14:17:02 9912 ----a-w- c:\program\absokt.nfo

2008-12-02 14:05:22 429 ----a-w- c:\program\file_id.diz

2008-12-02 09:37:06 5000000 ----a-w- c:\program\aodt291.r08

 

============= FINISH: 22:41:19,82 ===============

[/log]Det känns tryggt att du säger det.

Här kommer det du kallar DDS:en.

Link to comment
Share on other sites

Spara ComboFix på Skrivbordet:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram men lämna brandväggen på.

Hur? Se http://www.bleepingcomputer.com/forums/topic114351.html

Kör ComboFix och följ anvisningarna som visas.

Om det kommer upp en fråga om du vill installera återställningskonsolen så svara ja.

 

VIKTIGT! Klicka inte på ComboFix-fönstret med musen när den körs annars kan den hänga upp sig.

 

När den är färdig så ska en logg komma upp, klistra in den i ditt svar. Kontrollera att antivirusprogram mm är igång innan du ansluter till internet.

 

Om du får problem med att komma ut på internet:

Kontrollpanelen - Nätverksanslutningar

högerklicka på din internetanslutning och välj Reparera och/eller starta om datorn.

 

Varning! ComboFix förhindrar automatisk körning av CD, disketter och USB-enheter för att göra det lättare att rensa datorn och skydda datorn mot infektioner i framtiden. Det kan bli problem t ex om datorn har internet via ett USB-modem eller USB-nätverkskort. Säg då till i stället för att köra ComboFix.

Link to comment
Share on other sites

Spara RKill av Grinler på Skrivbordet. Ladda ner det från den första av dessa länkar:

http://download.bleepingcomputer.com/grinler/rkill.com

http://download.bleepingcomputer.com/grinler/rkill.pif

http://download.bleepingcomputer.com/grinler/rkill.scr

http://download.bleepingcomputer.com/grinler/rkill.exe

 

Starta Rkill (i Vista och Windows 7 genom att högerklicka på filen och välj Kör som administratör om det valet finns).

Det blir ett svart fönster/ruta en stund om programmet lyckades köra.

Om det inte blev något svart fönster/ruta så ta bort den RKill-varianten och upprepa med nästa RKill.

 

Om du får ett meddelande om att RKill är skadligt så bry dig inte om det. Det är det skadliga programmen som inte vill bli stoppat. Lämna kvar varningen på skärmen och kör RKill en gång till.

 

Kör RKill några gånger efter varandra. Pröva sedan med ComboFix igen.

 

Om det inte heller hjälper så pröva med att ta bort den ComboFix du har och så spara ned den på nytt. Men denna gång byter du namn på filen, t ex till LinneCF, i samband med sparandet.

 

Om inte det heller hjälper starta om datorn i felsäkert läge med nätverk (tryck F8 upprepade gånger under uppstarten och välj felsäkert läge med nätverk i menyn) och pröva med den omdöpta ComboFix.

Link to comment
Share on other sites

Linnégatan

Det går sådär... Har testat att göra som du säger med alla filerna. Ganska många gånger efter varandra men utan att det såg ut som att programmet lyckades göra någoning alls. Det kom en logg som informerade om att programmet tagit bort rkill...

 

Har testat i felsäkert läge också.

 

När jag inte hade felsäkert läge bockade jag av Norton Antivirusprogrammet som du sa.

 

Har också testat att installera om Combofix (med nytt namn) och köra det i felsäkert läge, men utan att lyckas... "Combofix har stött på ett problem och måste avslutas heter det."

 

Illa, men skam den som ger sig (som jag ska gnälla på kompisen i morgon när jag träffar honom).

 

Nu går jag och lägger mig. Fortsätter i morgon igen. Tack för din assistans än så länge.

Link to comment
Share on other sites

Då tar vi ett annat program i stället. Spara OTL på Skrivbordet. http://oldtimer.geekstogo.com/OTL.exe

Stäng alla program.

Kör OTL (i Vista och Windows 7 högerklicka och Kör som administratör).

Under Output högt upp så välj Minimal Output.

Under Standard Registry välj All.

 

I rutan Custom scan's and fixes klistra in följande rader (kolla att du verkligen får med alla raderna):

%SYSTEMDRIVE%\*.*
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\System32\config\*.sav
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles

 

Bocka för LOP Check och Purity Check.

Tryck på Run Scan och låt programmet köra ostört.

 

När det är klart så skapas två loggfiler på Skrivbordet, OTL.txt och Extras.txt. I ditt svar klistrar du in loggen OTL.txt. Medan du bifogar Extras.txt som en fil.

Link to comment
Share on other sites

Linnégatan

[log]OTL logfile created on: 2010-07-02 23:20:34 - Run 1

OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\S L \Skrivbord

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

1 023,00 Mb Total Physical Memory | 321,00 Mb Available Physical Memory | 31,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 79,00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program

Drive C: | 698,63 Gb Total Space | 642,67 Gb Free Space | 91,99% Space Free | Partition Type: NTFS

Drive D: | 465,76 Gb Total Space | 347,03 Gb Free Space | 74,51% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

Drive H: | 195,47 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

I: Drive not present or media not loaded

 

Computer Name: Sov

Current User Name: S L

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\S L \Skrivbord\OTL.exe (OldTimer Tools)

PRC - C:\Program\Delade filer\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

PRC - C:\Program\Opera\opera.exe (Opera Software)

PRC - C:\Program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

PRC - C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)

PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)

PRC - C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)

PRC - C:\Program\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)

PRC - C:\Program\Logitech\Logitech WebCam Software\LWS.exe ()

PRC - C:\Program\Delade filer\LogiShrd\LQCVFX\COCIManager.exe ()

PRC - C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)

PRC - C:\Program\LSI SoftModem\agrsmsvc.exe (LSI Corporation)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Program\Canon\CAL\CALMAIN.exe (Canon Inc.)

PRC - C:\Program\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\S L \Skrivbord\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)

MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)

MOD - C:\WINDOWS\system32\nview.dll (NVIDIA Corporation)

MOD - C:\WINDOWS\system32\nvwimg.dll (NVIDIA Corporation)

MOD - C:\WINDOWS\system32\nvwrssv.dll (NVIDIA Corporation)

MOD - C:\WINDOWS\system32\nvwddi.dll (NVIDIA Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (Creative Audio Engine Licensing Service) -- C:\Program\Delade filer\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)

SRV - (Apple Mobile Device) -- C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)

SRV - (NAV) -- C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)

SRV - (CTAudSvcService) -- C:\Program\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)

SRV - (LVPrcSrv) -- C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)

SRV - (AgereModemAudio) -- C:\Program\LSI SoftModem\agrsmsvc.exe (LSI Corporation)

SRV - (CCALib8) -- C:\Program\Canon\CAL\CALMAIN.exe (Canon Inc.)

SRV - (IDriverT) -- C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)

SRV - (CVPND) -- C:\Program\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)

SRV - (ose) -- C:\Program\Delade filer\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

 

 

========== Driver Services (SafeList) ==========

 

DRV - (NAVEX15) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20100702.003\NAVEX15.SYS (Symantec Corporation)

DRV - (NAVENG) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20100702.003\NAVENG.SYS (Symantec Corporation)

DRV - (eeCtrl) -- C:\Program\Delade filer\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)

DRV - (EraserUtilRebootDrv) -- C:\Program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)

DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)

DRV - (IDSxpx86) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20100701.001\IDSXpx86.sys (Symantec Corporation)

DRV - (BHDrvx86) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20100619.001\BHDrvx86.sys (Symantec Corporation)

DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SYMTDI.SYS (Symantec Corporation)

DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\Ironx86.SYS (Symantec Corporation)

DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMEFA.SYS (Symantec Corporation)

DRV - (SRTSP) -- C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SRTSP.SYS (Symantec Corporation)

DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\SRTSPX.SYS (Symantec Corporation)

DRV - (hap17v2k) -- C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)

DRV - (hap16v2k) -- C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)

DRV - (ha10kx2k) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)

DRV - (emupia) -- C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)

DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)

DRV - (ctprxy2k) -- C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)

DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)

DRV - (ctdvda2k) -- C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)

DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)

DRV - (ctac32k) -- C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)

DRV - (CTERFXFX.SYS) -- C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)

DRV - (CTERFXFX) -- C:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)

DRV - (CTSBLFX.SYS) -- C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)

DRV - (CTSBLFX) -- C:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)

DRV - (CTAUDFX.SYS) -- C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)

DRV - (CTAUDFX) -- C:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)

DRV - (COMMONFX.SYS) -- C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)

DRV - (COMMONFX) -- C:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)

DRV - (ccHP) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\ccHPx86.sys (Symantec Corporation)

DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMDS.SYS (Symantec Corporation)

DRV - (FilterService) -- C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)

DRV - (LVUVC) Logitech Webcam 300(UVC) -- C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)

DRV - (LVRS) -- C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)

DRV - (lvpopflt) -- C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)

DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()

DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (LSI Corporation)

DRV - (usbaudio) USB-ljuddrivrutiner (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)

DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)

DRV - (CVPNDRVA) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)

DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)

DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)

DRV - (CVirtA) -- C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)

 

 

========== Standard Registry (All) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

 

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2010-06-01 22:11:34 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2010-06-01 19:13:21 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-06-28 18:55:04 | 000,000,000 | ---D | M]

 

 

O1 HOSTS File: ([2004-08-04 14:00:00 | 000,000,710 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)

O3 - HKCU\..\Toolbar\WebBrowser: (&Adress) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKCU\..\Toolbar\WebBrowser: (&Länkar) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O4 - HKLM..\Run: [Adobe ARM] C:\Program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)

O4 - HKLM..\Run: [iTunesHelper] C:\Program\iTunes\iTunesHelper.exe (Apple Inc.)

O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program\Logitech\Logitech WebCam Software\LWS.exe ()

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)

O4 - HKLM..\Run: [QuickTime Task] C:\Program\QuickTime\qttask.exe (Apple Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Program\Delade filer\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [wvvurpdrv] File not found

O4 - HKLM..\Run: [wvvwwtdrv] C:\WINDOWS\System32\tuvurp.dll ()

O4 - HKLM..\Run: [yaxusssys] C:\WINDOWS\System32\nnkhfg.dll ()

O4 - HKCU..\Run: [byvspmdrv] C:\WINDOWS\System32\tuvurp.dll ()

O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKCU..\Run: [hgdedbdrv] File not found

O4 - HKCU..\Run: [regsdkrl32] C:\Documents and Settings\S L \Application Data\regsdkrl32\regsdkrl48.exe ()

O4 - HKCU..\Run: [skype] C:\Program\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\Harman Kardon TC 30 Remote.lnk = File not found

O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\VPN Client.lnk = File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xportera till Microsoft Excel - C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab (Creative Software AutoUpdate Support Package)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program\Delade filer\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\Delade filer\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program\Delade filer\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (Min aktuella startsida) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\S L \Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\S L \Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (nnkhfg.dll) - C:\WINDOWS\System32\nnkhfg.dll ()

O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010-05-30 19:35:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2004-05-11 00:50:00 | 000,043,559 | R--- | M] () - H:\autorun.apm -- [ CDFS ]

O32 - AutoRun File - [2004-05-11 00:50:00 | 000,536,576 | R--- | M] (Indigo Rose Corporation) - H:\autorun.exe -- [ CDFS ]

O32 - AutoRun File - [2004-05-11 00:50:00 | 000,000,029 | R--- | M] () - H:\autorun.inf -- [ CDFS ]

O33 - MountPoints2\{4ff7f11d-6c1c-11df-b74b-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{4ff7f11d-6c1c-11df-b74b-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll -- [2008-06-17 21:02:58 | 008,468,992 | ---- | M] (Microsoft Corporation)

O33 - MountPoints2\{4ff7f121-6c1c-11df-b74b-0011d8db49f9}\Shell\AutoRun\command - "" = M:\setupSNK.exe -- File not found

O33 - MountPoints2\F\Shell - "" = AutoRun

O33 - MountPoints2\F\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll -- [2008-06-17 21:02:58 | 008,468,992 | ---- | M] (Microsoft Corporation)

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

CREATERESTOREPOINT

Restore point Set: OTL Restore Point (56027075282206720)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2010-07-02 23:16:02 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\S L \Skrivbord\OTL.exe

[2010-07-01 23:37:30 | 004,614,888 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\S L \Skrivbord\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[2010-07-01 19:53:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Malwarebytes

[2010-07-01 19:30:59 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010-07-01 19:30:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes

[2010-07-01 19:30:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2010-07-01 19:30:57 | 000,000,000 | ---D | C] -- C:\Program\Malwarebytes' Anti-Malware

[2010-07-01 19:29:22 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\S L \Skrivbord\mbam-setup.exe

[2010-06-30 21:41:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles

[2010-06-28 18:54:52 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll

[2010-06-28 18:54:37 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll

[2010-06-28 18:54:36 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll

[2010-06-28 18:54:25 | 000,000,000 | ---D | C] -- C:\Program\Delade filer\xing shared

[2010-06-28 18:53:54 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll

[2010-06-28 18:53:54 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll

[2010-06-28 18:53:54 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll

[2010-06-28 18:53:44 | 000,000,000 | ---D | C] -- C:\Program\Delade filer\Real

[2010-06-28 18:53:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Real

[2010-06-28 18:53:42 | 000,000,000 | ---D | C] -- C:\Program\Real

[2010-06-28 18:52:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Real

[2010-06-28 18:49:05 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dokument\Mina videoklipp

[2010-06-28 18:46:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\RegisteredPackages

[2010-06-28 18:45:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage

[2010-06-27 12:55:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Lokala inställningar\Application Data\Super Internet TV

[2010-06-27 12:52:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Mina dokument\Unzipped

[2010-06-27 12:48:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Mina dokument\My WinZip Files

[2010-06-27 12:39:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip

[2010-06-27 12:39:44 | 000,000,000 | ---D | C] -- C:\Program\WinZip

[2010-06-27 12:35:44 | 000,000,000 | ---D | C] -- C:\Program\IZArc

[2010-06-27 12:35:06 | 004,172,430 | ---- | C] (Ivan Zahariev ) -- C:\Documents and Settings\S L \Skrivbord\IZArc4.1.exe

[2010-06-27 11:17:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\vlc

[2010-06-27 11:16:54 | 000,000,000 | ---D | C] -- C:\Program\VideoLAN

[2010-06-13 22:43:16 | 000,000,000 | ---D | C] -- C:\Presentationer

[2010-06-12 12:16:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Netscape

[2010-06-12 12:13:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Photodex

[2010-06-12 12:13:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex

[2010-06-12 12:13:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\regsdkrl32

[2010-06-12 11:24:23 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll

[2010-06-10 22:53:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Mina dokument\Expstudio Audio Editor

[2010-06-10 22:53:20 | 000,000,000 | ---D | C] -- C:\Program\Expstudio

[2010-06-10 22:53:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\EXP

[2010-06-06 18:42:34 | 000,000,000 | ---D | C] -- C:\spoolerlogs

[2010-06-05 19:16:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \OkiData

[2010-06-05 19:12:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Lokala inställningar\Application Data\Adobe

[2010-06-05 19:11:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe

[2010-03-18 19:18:32 | 000,010,752 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2010-07-02 23:16:05 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\S L \Skrivbord\OTL.exe

[2010-07-02 22:50:40 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-07-02 22:50:38 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010-07-02 22:50:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2010-07-02 22:50:30 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs

[2010-07-02 22:50:27 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad

[2010-07-02 14:07:19 | 000,030,888 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-02 14:07:19 | 000,030,888 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-02 14:07:19 | 000,029,952 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-02 14:07:19 | 000,029,952 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-02 14:07:19 | 000,011,564 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-02 14:06:54 | 003,932,160 | -H-- | M] () -- C:\Documents and Settings\S L \NTUSER.DAT

[2010-07-02 14:06:54 | 000,000,192 | -HS- | M] () -- C:\Documents and Settings\S L \ntuser.ini

[2010-07-02 14:06:33 | 003,242,190 | -H-- | M] () -- C:\Documents and Settings\S L \Lokala inställningar\Application Data\IconCache.db

[2010-07-02 00:01:38 | 003,725,496 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\SLCF.exe

[2010-07-02 00:00:05 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\rkill.com

[2010-07-01 23:58:54 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\rkill.scr

[2010-07-01 23:48:57 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-07-01 23:37:34 | 004,614,888 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\S L \Skrivbord\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[2010-07-01 23:18:51 | 003,725,496 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\ComboFix.exe

[2010-07-01 21:24:27 | 000,095,232 | -H-- | M] () -- C:\WINDOWS\System32\tuvurp.dll

[2010-07-01 21:00:28 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Malwarebytes' Anti-Malware.lnk

[2010-07-01 19:29:22 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\S L \Skrivbord\mbam-setup.exe

[2010-06-30 21:55:45 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\dds.scr

[2010-06-29 23:08:06 | 000,002,111 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\iTunes.lnk

[2010-06-28 21:54:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml

[2010-06-28 21:46:26 | 000,002,409 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\VPN Client.lnk

[2010-06-28 18:55:05 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\RealPlayer SP.lnk

[2010-06-28 18:54:52 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll

[2010-06-28 18:54:37 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll

[2010-06-28 18:54:36 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll

[2010-06-28 18:53:54 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll

[2010-06-28 18:53:54 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll

[2010-06-28 18:53:54 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll

[2010-06-28 18:49:02 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\S L \Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

[2010-06-28 18:47:39 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb

[2010-06-28 18:47:39 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb

[2010-06-28 18:47:08 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx

[2010-06-28 18:45:57 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2010-06-27 12:35:06 | 004,172,430 | ---- | M] (Ivan Zahariev ) -- C:\Documents and Settings\S L \Skrivbord\IZArc4.1.exe

[2010-06-27 11:17:26 | 000,000,689 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\VLC media player.lnk

[2010-06-27 10:38:36 | 000,006,144 | ---- | M] () -- C:\Documents and Settings\S L \Lokala inställningar\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010-06-27 10:29:16 | 000,002,176 | -H-- | M] () -- C:\Documents and Settings\S L \Mina dokument\ZbThumbnail.info

[2010-06-27 10:29:04 | 000,007,706 | ---- | M] () -- C:\ZB20100627102811001.xml

[2010-06-23 21:36:39 | 000,443,012 | ---- | M] () -- C:\WINDOWS\System32\perfh01D.dat

[2010-06-23 21:36:39 | 000,082,854 | ---- | M] () -- C:\WINDOWS\System32\perfc01D.dat

[2010-06-23 21:36:38 | 001,010,350 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010-06-23 21:36:38 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2010-06-23 21:36:38 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2010-06-23 19:43:43 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\S L \Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2010-06-23 19:43:43 | 000,000,574 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Opera.lnk

[2010-06-20 09:03:31 | 000,002,227 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Skype.lnk

[2010-06-19 22:23:57 | 000,176,640 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\FotbollsVM2010[1].xls

[2010-06-18 21:23:14 | 004,932,561 | ---- | M] () -- C:\WINDOWS\{00000003-00000000-00000006-00001102-00000004-20051102}.CDF

[2010-06-18 21:23:14 | 004,932,561 | ---- | M] () -- C:\WINDOWS\{00000003-00000000-00000006-00001102-00000004-20051102}.BAK

[2010-06-17 21:47:04 | 000,001,711 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Adobe Reader 9.lnk

[2010-06-14 20:51:35 | 000,038,096 | ---- | M] () -- C:\Documents and Settings\S L \Mina dokument\Framgångsfaktorer.jpg

[2010-06-14 18:36:20 | 001,163,264 | ---- | M] () -- C:\Documents and Settings\S L \Mina dokument\TS.doc

[2010-06-13 22:21:51 | 017,624,726 | ---- | M] () -- C:\Räkfesten.exe

[2010-06-12 22:40:08 | 000,129,784 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010-06-12 13:46:50 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2010-06-12 12:59:25 | 000,010,751 | ---- | M] () -- C:\ZB20100612125853001.xml

[2010-06-12 12:37:33 | 000,002,437 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\Harman Kardon TC 30 Remote.lnk

[2010-06-12 12:13:22 | 000,069,120 | -H-- | M] () -- C:\WINDOWS\System32\nnkhfg.dll

[2010-06-12 12:13:22 | 000,000,002 | ---- | M] () -- C:\Documents and Settings\S L \tenmy.ini

[2010-06-12 12:13:20 | 000,717,671 | ---- | M] () -- C:\Documents and Settings\S L \regsdkrl48.exe

[2010-06-10 23:15:44 | 004,245,003 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\johanne1.mp2

[2010-06-10 23:14:50 | 002,830,420 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\johannes.mp2

[2010-06-10 22:53:46 | 000,161,154 | ---- | M] () -- C:\WINDOWS\Expstudio Audio Editor FREE Uninstaller.exe

[2010-06-09 22:04:32 | 000,000,070 | ---- | M] () -- C:\WINDOWS\control.ini

[2010-06-09 22:04:15 | 002,561,772 | ---- | M] () -- C:\WINDOWS\System32\attractaemc1200.avi

[2010-06-09 22:04:14 | 000,272,868 | ---- | M] () -- C:\WINDOWS\System32\Windows XP Media Center Edition Screen Saver.scr

[2010-06-09 21:28:15 | 000,000,608 | ---- | M] () -- C:\Documents and Settings\S L \Skrivbord\opera.lnk

[2010-06-06 18:42:36 | 028,615,025 | ---- | M] () -- C:\Documents and Settings\S L \Mina dokument\Hellström.psd

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2010-07-02 00:01:31 | 003,725,496 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\SLCF.exe

[2010-07-02 00:00:03 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\rkill.com

[2010-07-01 23:58:52 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\rkill.scr

[2010-07-01 23:17:20 | 003,725,496 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\ComboFix.exe

[2010-07-01 21:24:26 | 000,095,232 | -H-- | C] () -- C:\WINDOWS\System32\tuvurp.dll

[2010-07-01 19:31:02 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Malwarebytes' Anti-Malware.lnk

[2010-06-30 21:55:39 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\dds.scr

[2010-06-28 18:55:06 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-06-28 18:55:05 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\RealPlayer SP.lnk

[2010-06-28 18:55:05 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-06-27 11:30:22 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\Canal Plus Action.bat

[2010-06-27 11:17:26 | 000,000,689 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\VLC media player.lnk

[2010-06-27 10:29:07 | 000,002,176 | -H-- | C] () -- C:\Documents and Settings\S L \Mina dokument\ZbThumbnail.info

[2010-06-27 10:29:04 | 000,007,706 | ---- | C] () -- C:\ZB20100627102811001.xml

[2010-06-19 22:20:47 | 000,176,640 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\FotbollsVM2010[1].xls

[2010-06-14 20:51:34 | 000,038,096 | ---- | C] () -- C:\Documents and Settings\S L \Mina dokument\Framgångsfaktorer.jpg

[2010-06-14 18:36:20 | 001,163,264 | ---- | C] () -- C:\Documents and Settings\S L \Mina dokument\TS.doc

[2010-06-13 23:55:44 | 000,000,339 | ---- | C] () -- C:\Documents and Settings\S L \proshow-burn.log

[2010-06-13 23:11:56 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\S L \Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

[2010-06-13 22:21:49 | 017,624,726 | ---- | C] () -- C:\Räkfesten.exe

[2010-06-12 12:59:25 | 000,010,751 | ---- | C] () -- C:\ZB20100612125853001.xml

[2010-06-12 12:13:22 | 000,069,120 | -H-- | C] () -- C:\WINDOWS\System32\nnkhfg.dll

[2010-06-12 12:13:22 | 000,000,002 | ---- | C] () -- C:\Documents and Settings\S L \tenmy.ini

[2010-06-12 12:13:19 | 000,717,671 | ---- | C] () -- C:\Documents and Settings\S L \regsdkrl48.exe

[2010-06-10 23:15:31 | 004,245,003 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\johanne1.mp2

[2010-06-10 23:14:37 | 002,830,420 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\johannes.mp2

[2010-06-10 22:53:31 | 000,161,154 | ---- | C] () -- C:\WINDOWS\Expstudio Audio Editor FREE Uninstaller.exe

[2010-06-09 22:04:14 | 002,561,772 | ---- | C] () -- C:\WINDOWS\System32\attractaemc1200.avi

[2010-06-09 22:04:14 | 000,272,868 | ---- | C] () -- C:\WINDOWS\System32\Windows XP Media Center Edition Screen Saver.scr

[2010-06-09 21:27:48 | 000,000,608 | ---- | C] () -- C:\Documents and Settings\S L \Skrivbord\opera.lnk

[2010-06-06 18:38:12 | 028,615,025 | ---- | C] () -- C:\Documents and Settings\S L \Mina dokument\Hellström.psd

[2010-06-05 19:11:43 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Adobe Reader 9.lnk

[2010-06-01 19:22:27 | 000,000,383 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2010-05-30 20:25:05 | 000,000,148 | ---- | C] () -- C:\WINDOWS\OPHG.INI

[2010-05-30 20:18:20 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini

[2010-05-30 19:36:41 | 000,000,996 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2010-03-18 19:59:54 | 000,050,439 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini

[2010-03-18 19:59:50 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini

[2010-03-18 19:19:58 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CTBurst.dll

[2009-10-07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys

[2009-10-07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll

[2009-07-08 15:10:56 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\kill.ini

[2007-11-14 19:42:27 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2007-11-09 13:01:59 | 000,000,164 | ---- | C] () -- C:\WINDOWS\System32\psyswin32.dll

[2007-08-13 20:45:02 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ctmmactl.dll

[2004-08-27 10:34:50 | 000,143,384 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll

[2004-08-27 10:25:14 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll

[2003-04-08 11:35:24 | 000,005,414 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

 

========== LOP Check ==========

 

[2010-05-30 19:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PCSettings

[2010-06-12 12:16:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex

[2010-06-27 12:40:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip

[2010-06-01 20:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

[2010-05-30 20:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L \Application Data\Leadertech

[2010-06-12 12:16:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L \Application Data\Netscape

[2010-06-01 22:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L \Application Data\Opera

[2010-06-12 12:13:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L \Application Data\Photodex

[2010-06-12 12:13:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L \Application Data\regsdkrl32

[2010-06-29 23:06:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L \Application Data\Spotify

[2010-06-28 23:31:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L \Application Data\uTorrent

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

 

< %SYSTEMDRIVE%\*.* >

[2005-07-06 19:52:00 | 000,006,101 | ---- | M] () -- C:\Advanced.tv_

[2010-05-30 19:35:03 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2010-05-30 19:29:25 | 000,000,211 | -HS- | M] () -- C:\boot.ini

[2004-08-04 14:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin

[2005-07-06 19:52:00 | 000,005,661 | ---- | M] () -- C:\CAD.tv_

[2010-05-30 19:35:03 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2005-07-06 19:52:00 | 004,821,962 | ---- | M] () -- C:\data1.cab

[2005-07-06 19:52:00 | 000,029,096 | ---- | M] () -- C:\data1.hdr

[2005-07-06 19:52:00 | 000,000,512 | ---- | M] () -- C:\data2.cab

[2005-07-06 19:52:00 | 000,005,857 | ---- | M] () -- C:\DCC.tv_

[2005-07-06 19:52:00 | 000,010,222 | ---- | M] () -- C:\default.tv_

[2005-07-06 19:52:00 | 000,459,544 | ---- | M] () -- C:\engine32.cab

[2005-07-06 19:52:00 | 000,006,144 | ---- | M] () -- C:\Finance.tv_

[2005-07-06 19:52:00 | 000,005,822 | ---- | M] () -- C:\generic.tv_

[2005-08-22 14:03:40 | 000,073,728 | ---- | M] () -- C:\HP Display Installer.exe

[2005-08-22 14:38:52 | 000,079,872 | -H-- | M] () -- C:\hpinsx64.exe

[2010-05-30 19:35:03 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2005-07-06 19:52:00 | 000,198,759 | ---- | M] () -- C:\keystone.ex_

[2005-07-06 19:52:00 | 000,000,510 | ---- | M] () -- C:\layout.bin

[2005-07-06 19:52:00 | 000,022,004 | ---- | M] () -- C:\modes.txt

[2010-05-30 19:35:03 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2004-08-04 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2010-05-28 00:28:41 | 000,250,560 | RHS- | M] () -- C:\ntldr

[2005-07-06 19:52:00 | 002,141,562 | ---- | M] () -- C:\nv4_disp.dl_

[2005-07-06 19:52:00 | 001,720,475 | ---- | M] () -- C:\nv4_mini.sy_

[2005-07-06 19:52:00 | 000,204,592 | ---- | M] () -- C:\nvappbar.ex_

[2005-07-06 19:52:00 | 000,006,933 | ---- | M] () -- C:\NvApps.xm_

[2005-07-06 19:52:00 | 000,021,819 | ---- | M] () -- C:\nvcod.dl_

[2005-07-06 19:52:00 | 000,168,113 | ---- | M] () -- C:\NVCPDE.HL_

[2005-07-06 19:52:00 | 000,159,955 | ---- | M] () -- C:\NVCPES.HL_

[2005-07-06 19:52:00 | 000,160,944 | ---- | M] () -- C:\NVCPFR.HL_

[2005-07-06 19:52:00 | 000,152,285 | ---- | M] () -- C:\NVCPIT.HL_

[2005-07-06 19:52:00 | 000,154,097 | ---- | M] () -- C:\NVCPJA.HL_

[2005-07-06 19:52:00 | 000,138,367 | ---- | M] () -- C:\NVCPKO.HL_

[2005-07-06 19:52:00 | 004,859,837 | ---- | M] () -- C:\NvCpl.dl_

[2005-07-06 19:52:00 | 000,147,596 | ---- | M] () -- C:\NVCPL.HL_

[2005-07-06 19:52:00 | 000,161,067 | ---- | M] () -- C:\NVCPPTB.HL_

[2005-07-06 19:52:00 | 000,148,097 | ---- | M] () -- C:\NVCPTH.HL_

[2005-07-06 19:52:00 | 000,147,513 | ---- | M] () -- C:\NVCPZHC.HL_

[2005-07-06 19:52:00 | 000,147,580 | ---- | M] () -- C:\NVCPZHT.HL_

[2005-07-06 19:52:00 | 000,014,757 | ---- | M] () -- C:\NVDisp.nvu

[2005-07-14 16:21:08 | 000,014,357 | ---- | M] () -- C:\nvdm.cat

[2005-07-06 19:52:00 | 000,045,994 | ---- | M] () -- C:\NVDM.INF

[2005-07-06 19:52:00 | 000,468,522 | ---- | M] () -- C:\nvdspsch.ex_

[2005-07-06 19:52:00 | 000,650,121 | ---- | M] () -- C:\nview.dl_

[2005-07-06 19:52:00 | 000,044,072 | ---- | M] () -- C:\NvMCTray.dl_

[2005-07-06 19:52:00 | 002,628,587 | ---- | M] () -- C:\nvoglnt.dl_

[2005-07-06 19:52:00 | 000,079,346 | ---- | M] () -- C:\NVRSDE.dl_

[2005-07-06 19:52:00 | 000,077,671 | ---- | M] () -- C:\NVRSES.dl_

[2005-07-06 19:52:00 | 000,077,872 | ---- | M] () -- C:\NVRSFR.dl_

[2005-07-06 19:52:00 | 000,076,825 | ---- | M] () -- C:\NVRSIT.dl_

[2005-07-06 19:52:00 | 000,095,562 | ---- | M] () -- C:\NVRSJA.dl_

[2005-07-06 19:52:00 | 000,094,428 | ---- | M] () -- C:\NVRSKO.dl_

[2005-07-06 19:52:00 | 000,074,880 | ---- | M] () -- C:\NVRSPTB.dl_

[2005-07-06 19:52:00 | 000,088,678 | ---- | M] () -- C:\NVRSZHC.dl_

[2005-07-06 19:52:00 | 000,053,651 | ---- | M] () -- C:\NVRSZHT.dl_

[2005-07-06 19:52:00 | 000,199,839 | ---- | M] () -- C:\nvshell.dl_

[2005-07-06 19:52:00 | 000,074,899 | ---- | M] () -- C:\nvsvc32.ex_

[2005-07-06 19:52:00 | 000,035,238 | ---- | M] () -- C:\nvtuicpl.cp_

[2005-07-06 19:52:00 | 000,176,128 | ---- | M] (NVIDIA Corporation) -- C:\nvudisp.exe

[2005-07-06 19:52:00 | 000,043,454 | ---- | M] () -- C:\nvwcpde.hl_

[2005-07-06 19:52:00 | 000,039,558 | ---- | M] () -- C:\nvwcpes.hl_

[2005-07-06 19:52:00 | 000,042,140 | ---- | M] () -- C:\nvwcpfr.hl_

[2005-07-06 19:52:00 | 000,039,750 | ---- | M] () -- C:\nvwcpit.hl_

[2005-07-06 19:52:00 | 000,039,572 | ---- | M] () -- C:\nvwcpja.hl_

[2005-07-06 19:52:00 | 000,040,980 | ---- | M] () -- C:\nvwcpko.hl_

[2005-07-06 19:52:00 | 000,037,359 | ---- | M] () -- C:\nvwcplen.hl_

[2005-07-06 19:52:00 | 000,041,415 | ---- | M] () -- C:\nvwcpptb.hl_

[2005-07-06 19:52:00 | 000,036,005 | ---- | M] () -- C:\nvwcpth.hl_

[2005-07-06 19:52:00 | 000,033,585 | ---- | M] () -- C:\nvwcpzhc.hl_

[2005-07-06 19:52:00 | 000,032,242 | ---- | M] () -- C:\nvwcpzht.hl_

[2005-07-06 19:52:00 | 000,048,454 | ---- | M] () -- C:\nvwddi.dl_

[2005-07-06 19:52:00 | 000,862,034 | ---- | M] () -- C:\nvwdmcpl.dl_

[2005-07-06 19:52:00 | 000,336,369 | ---- | M] () -- C:\nvwimg.dl_

[2005-07-06 19:52:00 | 000,090,090 | ---- | M] () -- C:\nvwrsde.dl_

[2005-07-06 19:52:00 | 000,092,509 | ---- | M] () -- C:\nvwrses.dl_

[2005-07-06 19:52:00 | 000,090,969 | ---- | M] () -- C:\nvwrsfr.dl_

[2005-07-06 19:52:00 | 000,089,560 | ---- | M] () -- C:\nvwrsit.dl_

[2005-07-06 19:52:00 | 000,073,243 | ---- | M] () -- C:\nvwrsja.dl_

[2005-07-06 19:52:00 | 000,069,681 | ---- | M] () -- C:\nvwrsko.dl_

[2005-07-06 19:52:00 | 000,089,507 | ---- | M] () -- C:\nvwrsptb.dl_

[2005-07-06 19:52:00 | 000,065,203 | ---- | M] () -- C:\nvwrszhc.dl_

[2005-07-06 19:52:00 | 000,066,221 | ---- | M] () -- C:\nvwrszht.dl_

[2005-07-06 19:52:00 | 000,009,347 | ---- | M] () -- C:\NvwsApps.xm_

[2005-07-06 19:52:00 | 000,643,494 | ---- | M] () -- C:\nwiz.ex_

[2010-07-02 22:50:27 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys

[2005-11-04 13:02:08 | 000,011,207 | ---- | M] () -- C:\Readme.txt

[2010-07-02 00:00:24 | 000,000,385 | ---- | M] () -- C:\rkill.log

[2010-06-13 22:21:51 | 017,624,726 | ---- | M] () -- C:\Räkfesten.exe

[2005-07-06 19:52:00 | 000,176,760 | ---- | M] () -- C:\setup.bmp

[2005-07-06 19:52:00 | 000,116,880 | ---- | M] (InstallShield Software Corporation) -- C:\setup.exe

[2005-07-06 19:52:00 | 000,435,969 | ---- | M] () -- C:\setup.ibt

[2005-07-06 19:52:00 | 000,000,878 | ---- | M] () -- C:\setup.ini

[2005-07-06 19:52:00 | 000,225,828 | ---- | M] () -- C:\setup.inx

[2005-07-06 19:52:00 | 000,000,431 | ---- | M] () -- C:\setup.iss

[2005-07-06 19:52:00 | 000,068,593 | ---- | M] () -- C:\setup.skin

[2005-11-04 13:02:36 | 000,001,249 | ---- | M] () -- C:\SP31599.cva

[2010-06-12 12:59:25 | 000,010,751 | ---- | M] () -- C:\ZB20100612125853001.xml

[2010-06-27 10:29:04 | 000,007,706 | ---- | M] () -- C:\ZB20100627102811001.xml

 

 

< MD5 for: AGP440.SYS >

[2004-08-04 14:00:00 | 018,778,343 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys

[2010-06-01 21:58:46 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys

[2010-06-01 21:58:46 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys

[2008-04-13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys

[2008-04-13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

 

< MD5 for: ATAPI.SYS >

[2004-08-04 14:00:00 | 018,778,343 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys

[2010-06-01 21:58:46 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys

[2010-06-01 21:58:46 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys

[2008-04-13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys

[2008-04-13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

[2004-08-04 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

 

< MD5 for: EVENTLOG.DLL >

[2008-04-14 18:04:38 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=0A6DF967AE8E836D053DB46398F603E5 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll

[2008-04-14 18:04:38 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=0A6DF967AE8E836D053DB46398F603E5 -- C:\WINDOWS\system32\eventlog.dll

[2004-08-04 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=264DBC116901E89565B830B0CC20F922 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

 

< MD5 for: IASTOR.SYS >

[2004-09-26 15:24:54 | 000,477,952 | ---- | M] (Intel Corporation) MD5=DD19FDD8BB262F64A11C50CC23FC6F70 -- C:\WINDOWS\OEM\iaStor\iaStor.sys

 

< MD5 for: NETLOGON.DLL >

[2009-02-06 20:47:22 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=132A5BBF7FB14BAE44D8803A34E73A96 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll

[2009-02-06 20:47:22 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=132A5BBF7FB14BAE44D8803A34E73A96 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll

[2008-04-14 18:04:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=4F4A16EAEB932AE413E48923E6A400E0 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll

[2008-04-14 18:04:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=4F4A16EAEB932AE413E48923E6A400E0 -- C:\WINDOWS\system32\netlogon.dll

[2004-08-04 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=A6FD3341EC1A98A31B044C6E0DAF8F26 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

 

< MD5 for: NVATABUS.SYS >

[2004-09-02 09:24:38 | 000,082,816 | ---- | M] (NVIDIA Corporation) MD5=EEABD98AA887DD923546F20D400B2907 -- C:\WINDOWS\OEM\nvatabus\nvatabus.sys

 

< MD5 for: SCECLI.DLL >

[2004-08-04 14:00:00 | 000,183,808 | ---- | M] (Microsoft Corporation) MD5=24BADA1C3795CB877C67E0F2F8BBAD1F -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll

[2008-04-14 18:04:47 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=3B50B494647E60CE6AC516E3F5C82B25 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll

[2008-04-14 18:04:47 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=3B50B494647E60CE6AC516E3F5C82B25 -- C:\WINDOWS\system32\scecli.dll

 

< MD5 for: VIAMRAID.SYS >

[2004-05-18 15:55:26 | 000,074,112 | ---- | M] (VIA Technologies inc,.ltd) MD5=F199939205DCCC7836AE5AB8B5DD5E83 -- C:\WINDOWS\OEM\viapdsk\viamraid.sys

 

< %systemroot%\*. /mp /s >

 

< %systemroot%\System32\config\*.sav >

[2010-05-30 21:22:25 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav

[2010-05-30 21:22:25 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav

[2010-05-30 21:22:25 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

 

< %systemroot%\system32\*.dll /lockedfiles >

[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

 

< %systemroot%\Tasks\*.job /lockedfiles >

< End of report >

[/log]Hej igen

Detta sätt fungerade bättre.

 

Här kommer loggen...

Extras.Txt

Link to comment
Share on other sites

Har du själv installerat Harman Kardon TC 30 Remote Software?

 

Är Netscape något du använder eller är det något som följde med Photodex?

[2010-06-12 12:16:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Netscape

 

Vet du vad det är för xml-filer som ligger i C:\?

[2010-06-12 12:59:25 | 000,010,751 | ---- | M] () -- C:\ZB20100612125853001.xml

[2010-06-27 10:29:04 | 000,007,706 | ---- | M] () -- C:\ZB20100627102811001.xml

 

På sidan http://www.virustotal.com trycker du på Bläddra-knappen och klistrar in ett av följande filnamn i rutan, tryck på Öppna och sedan Skicka Fil. Vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in en länk till resultatet här.

C:\WINDOWS\System32\psyswin32.dll

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram så att de inte krockar med OTL.

Hur? Se http://www.bleepingcomputer.com/forums/topic114351.html

 

Starta programmet OTL (i Vista/Windows7 högerklicka och välj Kör som administratör).

Kopiera alla raderna i rutan:

:OTL
O4 - HKLM..\Run: [wvvurpdrv] File not found
O4 - HKLM..\Run: [wvvwwtdrv] C:\WINDOWS\System32\tuvurp.dll ()
O4 - HKLM..\Run: [yaxusssys] C:\WINDOWS\System32\nnkhfg.dll ()
O4 - HKCU..\Run: [byvspmdrv] C:\WINDOWS\System32\tuvurp.dll ()
O4 - HKCU..\Run: [hgdedbdrv] File not found
O4 - HKCU..\Run: [regsdkrl32] C:\Documents and Settings\S L \Application Data\regsdkrl32\regsdkrl48.exe ()
[2010-06-12 12:13:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Photodex
[2010-06-12 12:13:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex
[2010-06-12 12:13:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\regsdkrl32
[2010-06-12 12:13:22 | 000,069,120 | -H-- | M] () -- C:\WINDOWS\System32\nnkhfg.dll
[2010-06-12 12:13:22 | 000,000,002 | ---- | M] () -- C:\Documents and Settings\S L \tenmy.ini
[2010-06-12 12:13:20 | 000,717,671 | ---- | M] () -- C:\Documents and Settings\S L \regsdkrl48.exe
:Reg
:Files
:Commands
[CREATERESTOREPOINT]
[emptytemp]
[Reboot]

Klistra in dem i rutan Custom Scans/Fixes.

Tryck på Run Fix.

Om du blir tillfrågad om att starta om datorn så gör det.

Det kommer upp en logg i Anteckningar. Kopiera den och klistra in i ditt svar.

 

Om den inte kommer automatiskt så hittar du den i mappen c:\_OTL\Moved Files med ett namn som innehåller dagens datum och klockslaget för körningen.

 

Se till att aktivera antivirusprogram mm innan du ansluter datorn till internet.

Link to comment
Share on other sites

Linnégatan

Har du själv installerat Harman Kardon TC 30 Remote Software?

 

Ja, det har jag.

 

Är Netscape något du använder eller är det något som följde med Photodex?

[2010-06-12 12:16:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Netscape

 

Jag har inte installerat något Netscape.

 

Vet du vad det är för xml-filer som ligger i C:\?

[2010-06-12 12:59:25 | 000,010,751 | ---- | M] () -- C:\ZB20100612125853001.xml

[2010-06-27 10:29:04 | 000,007,706 | ---- | M] () -- C:\ZB20100627102811001.xml

 

Nej, jag vet inte vad det är för filer.

 

På sidan http://www.virustotal.com trycker du på Bläddra-knappen och klistrar in ett av följande filnamn i rutan, tryck på Öppna och sedan Skicka Fil. Vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in en länk till resultatet här.

 

Jag klistrar in länken till sidan på Virus Total här...

C:\WINDOWS\System32\psyswin32.dll

http://www.virustotal.com/sv/analisis/27b103fa60ccd8defc978f630740a9b00887068af2808f8ef9e194b0caa5558b-1273994141

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram så att de inte krockar med OTL.

Hur? Se http://www.bleepingcomputer.com/forums/topic114351.html

 

Starta programmet OTL (i Vista/Windows7 högerklicka och välj Kör som administratör).

Kopiera alla raderna i rutan:

:OTL
O4 - HKLM..\Run: [wvvurpdrv] File not found
O4 - HKLM..\Run: [wvvwwtdrv] C:\WINDOWS\System32\tuvurp.dll ()
O4 - HKLM..\Run: [yaxusssys] C:\WINDOWS\System32\nnkhfg.dll ()
O4 - HKCU..\Run: [byvspmdrv] C:\WINDOWS\System32\tuvurp.dll ()
O4 - HKCU..\Run: [hgdedbdrv] File not found
O4 - HKCU..\Run: [regsdkrl32] C:\Documents and Settings\S L \Application Data\regsdkrl32\regsdkrl48.exe ()
[2010-06-12 12:13:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\Photodex
[2010-06-12 12:13:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex
[2010-06-12 12:13:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L \Application Data\regsdkrl32
[2010-06-12 12:13:22 | 000,069,120 | -H-- | M] () -- C:\WINDOWS\System32\nnkhfg.dll
[2010-06-12 12:13:22 | 000,000,002 | ---- | M] () -- C:\Documents and Settings\S L \tenmy.ini
[2010-06-12 12:13:20 | 000,717,671 | ---- | M] () -- C:\Documents and Settings\S L \regsdkrl48.exe
:Reg
:Files
:Commands
[CREATERESTOREPOINT]
[emptytemp]
[Reboot]

Klistra in dem i rutan Custom Scans/Fixes.

Tryck på Run Fix.

Om du blir tillfrågad om att starta om datorn så gör det.

Det kommer upp en logg i Anteckningar. Kopiera den och klistra in i ditt svar.

 

Om den inte kommer automatiskt så hittar du den i mappen c:\_OTL\Moved Files med ett namn som innehåller dagens datum och klockslaget för körningen.

 

Se till att aktivera antivirusprogram mm innan du ansluter datorn till internet.

 

En annan sak är att när datorn startar kommer två rutor upp, felmeddelanden med kors på rutan. Jag bifogar den ena som bilaga.

post-69277-1278134656_thumb.jpg

Link to comment
Share on other sites

Linnégatan

[log]All processes killed

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\wvvurpdrv deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\wvvwwtdrv deleted successfully.

C:\WINDOWS\system32\tuvurp.dll moved successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yaxusssys deleted successfully.

C:\WINDOWS\system32\nnkhfg.dll moved successfully.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\byvspmdrv deleted successfully.

File C:\WINDOWS\System32\tuvurp.dll not found.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hgdedbdrv deleted successfully.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\regsdkrl32 deleted successfully.

c:\Documents and Settings\S L\regsdkrl48.exe moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex\ProShow Gold\download\packages folder moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex\ProShow Gold\download\menus folder moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex\ProShow Gold\download\content\borders folder moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex\ProShow Gold\download\content\backgrounds folder moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex\ProShow Gold\download\content folder moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex\ProShow Gold\download folder moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex\ProShow Gold folder moved successfully.

C:\Documents and Settings\S L\Application Data\Photodex folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow Gold\Menu Layouts folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow Gold folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Triptych.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Triptych Still.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Swap Still.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Swap Right 1.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Swap Left 2.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Still Photo White.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Still Photo Black.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Spin and Shrink.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Single Snapshot Still.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Scrolling Credits.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Photo Stack 2 Still.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Photo Stack 2 Expanding.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Photo Stack 1 Still.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\No Style.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Display of Nine Still.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Display of Five.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Display of Five Still.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Colorize Sepia Antiqued.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\Colorize Grayscale.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\A Photo Border.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache\A Moving Backdrop.installed folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles\Cache folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow\Styles folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex\ProShow folder moved successfully.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Photodex folder moved successfully.

C:\Documents and Settings\S L\Application Data\regsdkrl32 folder moved successfully.

File move failed. C:\WINDOWS\system32\nnkhfg.dll scheduled to be moved on reboot.

C:\Documents and Settings\S L\tenmy.ini moved successfully.

File C:\Documents and Settings\S L\regsdkrl48.exe not found.

Error: Unable to interpret <:Reg:Files:Commands> in the current context!

Error: Unable to interpret <[CREATERESTOREPOINT]> in the current context!

Error: Unable to interpret <[emptytemp]> in the current context!

Error: Unable to interpret <[Reboot]> in the current context!

 

OTL by OldTimer - Version 3.2.7.0 log created on 07032010_092016

 

Files\Folders moved on Reboot...

C:\WINDOWS\system32\nnkhfg.dll moved successfully.[/log]Här kommer ytterligare en logg... Stort tack för ditt idoga arbete med att läsa bland raderna.

 

Som upplysning kan nämnas att när jag nyss startade om datorn kom inte rutorna upp som jag nyss beskrev.

Link to comment
Share on other sites

Felmeddelanderutorna vid uppstart berodde på att de skadliga filerna som står i rutorna var borttagna men referenserna till dem i registret var fortfarande kvar.

 

Då kan du ta bort mappen C:\Documents and Settings\S L \Application Data\Netscape

 

Du kan antingen byta namn på filerna

[2010-06-12 12:59:25 | 000,010,751 | ---- | M] () -- C:\ZB20100612125853001.xml

[2010-06-27 10:29:04 | 000,007,706 | ---- | M] () -- C:\ZB20100627102811001.xml

eller flytta dem till skrivbordet. Om det inte är något program som klagar på att de saknas så kan du ta bort dem efter någon vecka eller så.

 

Det ser ut som att OTL har gjort sitt jobb men klistra in en ny OTL-logg för kontroll.

Link to comment
Share on other sites

Linnégatan

[log]OTL logfile created on: 2010-07-03 11:30:32 - Run 5

OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\S L\Skrivbord

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

1 023,00 Mb Total Physical Memory | 552,00 Mb Available Physical Memory | 54,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 87,00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program

Drive C: | 698,63 Gb Total Space | 643,22 Gb Free Space | 92,07% Space Free | Partition Type: NTFS

Drive D: | 465,76 Gb Total Space | 347,03 Gb Free Space | 74,51% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

Drive H: | 195,47 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

I: Drive not present or media not loaded

 

Computer Name: SOV

Current User Name: S L

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\S L\Skrivbord\OTL.exe (OldTimer Tools)

PRC - C:\Program\Delade filer\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

PRC - C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)

PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)

PRC - C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)

PRC - C:\Program\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)

PRC - C:\Program\Logitech\Logitech WebCam Software\LWS.exe ()

PRC - C:\Program\Delade filer\LogiShrd\LQCVFX\COCIManager.exe ()

PRC - C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)

PRC - C:\Program\LSI SoftModem\agrsmsvc.exe (LSI Corporation)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Program\Canon\CAL\CALMAIN.exe (Canon Inc.)

PRC - C:\Program\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\S L\Skrivbord\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)

MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)

MOD - C:\WINDOWS\system32\nview.dll (NVIDIA Corporation)

MOD - C:\WINDOWS\system32\nvwimg.dll (NVIDIA Corporation)

MOD - C:\WINDOWS\system32\nvwrssv.dll (NVIDIA Corporation)

MOD - C:\WINDOWS\system32\nvwddi.dll (NVIDIA Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (Creative Audio Engine Licensing Service) -- C:\Program\Delade filer\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)

SRV - (Apple Mobile Device) -- C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)

SRV - (NAV) -- C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)

SRV - (CTAudSvcService) -- C:\Program\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)

SRV - (LVPrcSrv) -- C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)

SRV - (AgereModemAudio) -- C:\Program\LSI SoftModem\agrsmsvc.exe (LSI Corporation)

SRV - (CCALib8) -- C:\Program\Canon\CAL\CALMAIN.exe (Canon Inc.)

SRV - (IDriverT) -- C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)

SRV - (CVPND) -- C:\Program\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)

SRV - (ose) -- C:\Program\Delade filer\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

 

 

========== Driver Services (SafeList) ==========

 

DRV - (NAVEX15) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20100702.036\NAVEX15.SYS (Symantec Corporation)

DRV - (NAVENG) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20100702.036\NAVENG.SYS (Symantec Corporation)

DRV - (eeCtrl) -- C:\Program\Delade filer\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)

DRV - (EraserUtilRebootDrv) -- C:\Program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)

DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)

DRV - (IDSxpx86) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20100702.001\IDSXpx86.sys (Symantec Corporation)

DRV - (BHDrvx86) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20100619.001\BHDrvx86.sys (Symantec Corporation)

DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SYMTDI.SYS (Symantec Corporation)

DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\Ironx86.SYS (Symantec Corporation)

DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMEFA.SYS (Symantec Corporation)

DRV - (SRTSP) -- C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SRTSP.SYS (Symantec Corporation)

DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\SRTSPX.SYS (Symantec Corporation)

DRV - (hap17v2k) -- C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)

DRV - (hap16v2k) -- C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)

DRV - (ha10kx2k) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)

DRV - (emupia) -- C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)

DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)

DRV - (ctprxy2k) -- C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)

DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)

DRV - (ctdvda2k) -- C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)

DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)

DRV - (ctac32k) -- C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)

DRV - (CTERFXFX.SYS) -- C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)

DRV - (CTERFXFX) -- C:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)

DRV - (CTSBLFX.SYS) -- C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)

DRV - (CTSBLFX) -- C:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)

DRV - (CTAUDFX.SYS) -- C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)

DRV - (CTAUDFX) -- C:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)

DRV - (COMMONFX.SYS) -- C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)

DRV - (COMMONFX) -- C:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)

DRV - (ccHP) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\ccHPx86.sys (Symantec Corporation)

DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMDS.SYS (Symantec Corporation)

DRV - (FilterService) -- C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)

DRV - (LVUVC) Logitech Webcam 300(UVC) -- C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)

DRV - (LVRS) -- C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)

DRV - (lvpopflt) -- C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)

DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()

DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (LSI Corporation)

DRV - (usbaudio) USB-ljuddrivrutiner (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)

DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)

DRV - (CVPNDRVA) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)

DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)

DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)

DRV - (CVirtA) -- C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)

 

 

========== Standard Registry (All) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

 

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2010-06-01 22:11:34 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2010-06-01 19:13:21 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-06-28 18:55:04 | 000,000,000 | ---D | M]

 

 

O1 HOSTS File: ([2004-08-04 14:00:00 | 000,000,710 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\Norton AntiVirus\Norton AntiVirus\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)

O3 - HKCU\..\Toolbar\WebBrowser: (&Adress) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKCU\..\Toolbar\WebBrowser: (&Länkar) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O4 - HKLM..\Run: [Adobe ARM] C:\Program\Delade filer\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [bywwussys] C:\WINDOWS\System32\nnkhfg.dll ()

O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)

O4 - HKLM..\Run: [iTunesHelper] C:\Program\iTunes\iTunesHelper.exe (Apple Inc.)

O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program\Logitech\Logitech WebCam Software\LWS.exe ()

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)

O4 - HKLM..\Run: [QuickTime Task] C:\Program\QuickTime\qttask.exe (Apple Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Program\Delade filer\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [yaabbcdrv] C:\WINDOWS\System32\tuvurp.dll ()

O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKCU..\Run: [effeeedrv] C:\WINDOWS\System32\tuvurp.dll ()

O4 - HKCU..\Run: [skype] C:\Program\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\Harman Kardon TC 30 Remote.lnk = File not found

O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\VPN Client.lnk = File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xportera till Microsoft Excel - C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab (Creative Software AutoUpdate Support Package)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program\Delade filer\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\Delade filer\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program\Delade filer\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (Min aktuella startsida) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\S L\Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\S L\Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (nnkhfg.dll) - C:\WINDOWS\System32\nnkhfg.dll ()

O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010-05-30 19:35:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2004-05-11 00:50:00 | 000,043,559 | R--- | M] () - H:\autorun.apm -- [ CDFS ]

O32 - AutoRun File - [2004-05-11 00:50:00 | 000,536,576 | R--- | M] (Indigo Rose Corporation) - H:\autorun.exe -- [ CDFS ]

O32 - AutoRun File - [2004-05-11 00:50:00 | 000,000,029 | R--- | M] () - H:\autorun.inf -- [ CDFS ]

O33 - MountPoints2\{232b1efe-6c1f-11df-9ccc-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{232b1efe-6c1f-11df-9ccc-806d6172696f}\Shell\AutoRun\command - "" = H:\autorun.exe -- [2004-05-11 00:50:00 | 000,536,576 | R--- | M] (Indigo Rose Corporation)

O33 - MountPoints2\{4ff7f11d-6c1c-11df-b74b-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{4ff7f11d-6c1c-11df-b74b-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll -- [2008-06-17 21:02:58 | 008,468,992 | ---- | M] (Microsoft Corporation)

O33 - MountPoints2\{4ff7f121-6c1c-11df-b74b-0011d8db49f9}\Shell\AutoRun\command - "" = M:\setupSNK.exe -- File not found

O33 - MountPoints2\F\Shell - "" = AutoRun

O33 - MountPoints2\F\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll -- [2008-06-17 21:02:58 | 008,468,992 | ---- | M] (Microsoft Corporation)

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2010-07-03 07:54:02 | 000,000,000 | ---D | C] -- C:\_OTL

[2010-07-02 23:16:02 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\S L\Skrivbord\OTL.exe

[2010-07-01 23:37:30 | 004,614,888 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\S L\Skrivbord\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[2010-07-01 19:53:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\Application Data\Malwarebytes

[2010-07-01 19:30:59 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010-07-01 19:30:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes

[2010-07-01 19:30:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2010-07-01 19:30:57 | 000,000,000 | ---D | C] -- C:\Program\Malwarebytes' Anti-Malware

[2010-07-01 19:29:22 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\S L\Skrivbord\mbam-setup.exe

[2010-06-30 21:41:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles

[2010-06-28 18:54:52 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll

[2010-06-28 18:54:37 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll

[2010-06-28 18:54:36 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll

[2010-06-28 18:54:25 | 000,000,000 | ---D | C] -- C:\Program\Delade filer\xing shared

[2010-06-28 18:53:54 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll

[2010-06-28 18:53:54 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll

[2010-06-28 18:53:54 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll

[2010-06-28 18:53:44 | 000,000,000 | ---D | C] -- C:\Program\Delade filer\Real

[2010-06-28 18:53:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Real

[2010-06-28 18:53:42 | 000,000,000 | ---D | C] -- C:\Program\Real

[2010-06-28 18:52:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\Application Data\Real

[2010-06-28 18:49:05 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dokument\Mina videoklipp

[2010-06-28 18:46:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\RegisteredPackages

[2010-06-28 18:45:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage

[2010-06-27 12:52:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\Mina dokument\Unzipped

[2010-06-27 12:48:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\Mina dokument\My WinZip Files

[2010-06-27 12:39:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip

[2010-06-27 12:39:44 | 000,000,000 | ---D | C] -- C:\Program\WinZip

[2010-06-27 12:35:44 | 000,000,000 | ---D | C] -- C:\Program\IZArc

[2010-06-27 12:35:06 | 004,172,430 | ---- | C] (Ivan Zahariev ) -- C:\Documents and Settings\S L\Skrivbord\IZArc4.1.exe

[2010-06-27 11:17:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\Application Data\vlc

[2010-06-27 11:16:54 | 000,000,000 | ---D | C] -- C:\Program\VideoLAN

[2010-06-13 22:43:16 | 000,000,000 | ---D | C] -- C:\Presentationer

[2010-06-12 11:24:23 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll

[2010-06-10 22:53:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\Mina dokument\Expstudio Audio Editor

[2010-06-10 22:53:20 | 000,000,000 | ---D | C] -- C:\Program\Expstudio

[2010-06-10 22:53:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\EXP

[2010-06-06 18:42:34 | 000,000,000 | ---D | C] -- C:\spoolerlogs

[2010-06-05 19:16:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\OkiData

[2010-06-05 19:12:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S L\Lokala inställningar\Application Data\Adobe

[2010-06-05 19:11:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe

[2010-03-18 19:18:32 | 000,010,752 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2010-07-03 11:29:55 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-07-03 11:29:54 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-07-03 11:26:42 | 003,932,160 | -H-- | M] () -- C:\Documents and Settings\S L\NTUSER.DAT

[2010-07-03 10:17:39 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010-07-03 10:17:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2010-07-03 10:17:30 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs

[2010-07-03 10:17:28 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad

[2010-07-03 10:16:44 | 000,000,192 | -HS- | M] () -- C:\Documents and Settings\S L\ntuser.ini

[2010-07-03 09:21:43 | 000,069,120 | -H-- | M] () -- C:\WINDOWS\System32\nnkhfg.dll

[2010-07-03 09:20:48 | 000,030,888 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-03 09:20:48 | 000,030,888 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-03 09:20:48 | 000,029,952 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-03 09:20:48 | 000,029,952 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-03 09:20:48 | 000,011,564 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000003-00000000-00000006-00001102-00000004-20051102}.rfx

[2010-07-03 09:20:17 | 000,095,232 | -H-- | M] () -- C:\WINDOWS\System32\tuvurp.dll

[2010-07-03 08:07:28 | 003,772,236 | -H-- | M] () -- C:\Documents and Settings\S L\Lokala inställningar\Application Data\IconCache.db

[2010-07-03 07:24:04 | 000,009,742 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\bild på ruta.JPG

[2010-07-02 23:28:21 | 000,002,111 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\iTunes.lnk

[2010-07-02 23:16:05 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\S L\Skrivbord\OTL.exe

[2010-07-02 00:01:38 | 003,725,496 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\SLCF.exe

[2010-07-02 00:00:05 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\rkill.com

[2010-07-01 23:58:54 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\rkill.scr

[2010-07-01 23:37:34 | 004,614,888 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\S L\Skrivbord\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[2010-07-01 23:18:51 | 003,725,496 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\ComboFix.exe

[2010-07-01 21:00:28 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Malwarebytes' Anti-Malware.lnk

[2010-07-01 19:29:22 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\S L\Skrivbord\mbam-setup.exe

[2010-06-30 21:55:45 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\dds.scr

[2010-06-28 21:54:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml

[2010-06-28 21:46:26 | 000,002,409 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\VPN Client.lnk

[2010-06-28 18:55:05 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\RealPlayer SP.lnk

[2010-06-28 18:54:52 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll

[2010-06-28 18:54:37 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll

[2010-06-28 18:54:36 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll

[2010-06-28 18:53:54 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll

[2010-06-28 18:53:54 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll

[2010-06-28 18:53:54 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll

[2010-06-28 18:49:02 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\S L\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

[2010-06-28 18:47:39 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb

[2010-06-28 18:47:39 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb

[2010-06-28 18:47:08 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx

[2010-06-28 18:45:57 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2010-06-27 12:35:06 | 004,172,430 | ---- | M] (Ivan Zahariev ) -- C:\Documents and Settings\S L\Skrivbord\IZArc4.1.exe

[2010-06-27 11:17:26 | 000,000,689 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\VLC media player.lnk

[2010-06-27 10:38:36 | 000,006,144 | ---- | M] () -- C:\Documents and Settings\S L\Lokala inställningar\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010-06-27 10:29:16 | 000,002,176 | -H-- | M] () -- C:\Documents and Settings\S L\Mina dokument\ZbThumbnail.info

[2010-06-27 10:29:04 | 000,007,706 | ---- | M] () -- C:\Sture.xml

[2010-06-23 21:36:39 | 000,443,012 | ---- | M] () -- C:\WINDOWS\System32\perfh01D.dat

[2010-06-23 21:36:39 | 000,082,854 | ---- | M] () -- C:\WINDOWS\System32\perfc01D.dat

[2010-06-23 21:36:38 | 001,010,350 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010-06-23 21:36:38 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2010-06-23 21:36:38 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2010-06-23 19:43:43 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\S L\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2010-06-23 19:43:43 | 000,000,574 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Opera.lnk

[2010-06-20 09:03:31 | 000,002,227 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Skype.lnk

[2010-06-19 22:23:57 | 000,176,640 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\FotbollsVM2010[1].xls

[2010-06-18 21:23:14 | 004,932,561 | ---- | M] () -- C:\WINDOWS\{00000003-00000000-00000006-00001102-00000004-20051102}.CDF

[2010-06-18 21:23:14 | 004,932,561 | ---- | M] () -- C:\WINDOWS\{00000003-00000000-00000006-00001102-00000004-20051102}.BAK

[2010-06-17 21:47:04 | 000,001,711 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Adobe Reader 9.lnk

[2010-06-14 20:51:35 | 000,038,096 | ---- | M] () -- C:\Documents and Settings\S L\Mina dokument\Framgångsfaktorer.jpg

[2010-06-14 18:36:20 | 001,163,264 | ---- | M] () -- C:\Documents and Settings\S L\Mina dokument\TS.doc

[2010-06-13 22:21:51 | 017,624,726 | ---- | M] () -- C:\Räkfesten.exe

[2010-06-12 22:40:08 | 000,129,784 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010-06-12 13:46:50 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2010-06-12 12:59:25 | 000,010,751 | ---- | M] () -- C:\Sture1.xml

[2010-06-12 12:37:33 | 000,002,437 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start-meny\Program\Autostart\Harman Kardon TC 30 Remote.lnk

[2010-06-10 23:15:44 | 004,245,003 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\johanne1.mp2

[2010-06-10 23:14:50 | 002,830,420 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\johannes.mp2

[2010-06-10 22:53:46 | 000,161,154 | ---- | M] () -- C:\WINDOWS\Expstudio Audio Editor FREE Uninstaller.exe

[2010-06-09 22:04:32 | 000,000,070 | ---- | M] () -- C:\WINDOWS\control.ini

[2010-06-09 22:04:15 | 002,561,772 | ---- | M] () -- C:\WINDOWS\System32\attractaemc1200.avi

[2010-06-09 22:04:14 | 000,272,868 | ---- | M] () -- C:\WINDOWS\System32\Windows XP Media Center Edition Screen Saver.scr

[2010-06-09 21:28:15 | 000,000,608 | ---- | M] () -- C:\Documents and Settings\S L\Skrivbord\opera.lnk

[2010-06-06 18:42:36 | 028,615,025 | ---- | M] () -- C:\Documents and Settings\S L\Mina dokument\Hellström.psd

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2010-07-03 07:24:04 | 000,009,742 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\bild på ruta.JPG

[2010-07-02 00:01:31 | 003,725,496 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\SLCF.exe

[2010-07-02 00:00:03 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\rkill.com

[2010-07-01 23:58:52 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\rkill.scr

[2010-07-01 23:17:20 | 003,725,496 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\ComboFix.exe

[2010-07-01 21:24:26 | 000,095,232 | -H-- | C] () -- C:\WINDOWS\System32\tuvurp.dll

[2010-07-01 19:31:02 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Malwarebytes' Anti-Malware.lnk

[2010-06-30 21:55:39 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\dds.scr

[2010-06-28 18:55:06 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-06-28 18:55:05 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\RealPlayer SP.lnk

[2010-06-28 18:55:05 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1715567821-1757981266-725345543-1005.job

[2010-06-27 11:30:22 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\Canal Plus Action.bat

[2010-06-27 11:17:26 | 000,000,689 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\VLC media player.lnk

[2010-06-27 10:29:07 | 000,002,176 | -H-- | C] () -- C:\Documents and Settings\S L\Mina dokument\ZbThumbnail.info

[2010-06-27 10:29:04 | 000,007,706 | ---- | C] () -- C:\Sture.xml

[2010-06-19 22:20:47 | 000,176,640 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\FotbollsVM2010[1].xls

[2010-06-14 20:51:34 | 000,038,096 | ---- | C] () -- C:\Documents and Settings\S L\Mina dokument\Framgångsfaktorer.jpg

[2010-06-14 18:36:20 | 001,163,264 | ---- | C] () -- C:\Documents and Settings\S L\Mina dokument\TS.doc

[2010-06-13 23:55:44 | 000,000,339 | ---- | C] () -- C:\Documents and Settings\S L\proshow-burn.log

[2010-06-13 23:11:56 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\S L\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

[2010-06-13 22:21:49 | 017,624,726 | ---- | C] () -- C:\Räkfesten.exe

[2010-06-12 12:59:25 | 000,010,751 | ---- | C] () -- C:\Sture1.xml

[2010-06-12 12:13:22 | 000,069,120 | -H-- | C] () -- C:\WINDOWS\System32\nnkhfg.dll

[2010-06-10 23:15:31 | 004,245,003 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\johanne1.mp2

[2010-06-10 23:14:37 | 002,830,420 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\johannes.mp2

[2010-06-10 22:53:31 | 000,161,154 | ---- | C] () -- C:\WINDOWS\Expstudio Audio Editor FREE Uninstaller.exe

[2010-06-09 22:04:14 | 002,561,772 | ---- | C] () -- C:\WINDOWS\System32\attractaemc1200.avi

[2010-06-09 22:04:14 | 000,272,868 | ---- | C] () -- C:\WINDOWS\System32\Windows XP Media Center Edition Screen Saver.scr

[2010-06-09 21:27:48 | 000,000,608 | ---- | C] () -- C:\Documents and Settings\S L\Skrivbord\opera.lnk

[2010-06-06 18:38:12 | 028,615,025 | ---- | C] () -- C:\Documents and Settings\S L\Mina dokument\Hellström.psd

[2010-06-05 19:11:43 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Skrivbord\Adobe Reader 9.lnk

[2010-06-01 19:22:27 | 000,000,383 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2010-05-30 20:25:05 | 000,000,148 | ---- | C] () -- C:\WINDOWS\OPHG.INI

[2010-05-30 20:18:20 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini

[2010-05-30 19:36:41 | 000,000,996 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2010-03-18 19:59:54 | 000,050,439 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini

[2010-03-18 19:59:50 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini

[2010-03-18 19:19:58 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CTBurst.dll

[2009-10-07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys

[2009-10-07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll

[2009-07-08 15:10:56 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\kill.ini

[2007-11-14 19:42:27 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2007-11-09 13:01:59 | 000,000,164 | ---- | C] () -- C:\WINDOWS\System32\psyswin32.dll

[2007-08-13 20:45:02 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ctmmactl.dll

[2004-08-27 10:34:50 | 000,143,384 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll

[2004-08-27 10:25:14 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll

[2003-04-08 11:35:24 | 000,005,414 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

 

========== LOP Check ==========

 

[2010-05-30 19:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PCSettings

[2010-06-27 12:40:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip

[2010-06-01 20:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

[2010-05-30 20:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L\Application Data\Leadertech

[2010-06-01 22:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L\Application Data\Opera

[2010-06-29 23:06:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L\Application Data\Spotify

[2010-06-28 23:31:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S L\Application Data\uTorrent

 

========== Purity Check ==========

 

 

< End of report >

[/log]Nu har jag gjort som du skrev (vilket du säkert ser i loggen. :-))

Link to comment
Share on other sites

Lite oroväckande att filer verkar ha dykt upp efter OTL-körningen på fm, men vi gör ett försök till.

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram så att de inte krockar med OTL.

 

Starta programmet OTL (i Vista/Windows7 högerklicka och välj Kör som administratör).

Kopiera alla raderna i rutan:

:OTL
O4 - HKLM..\Run: [bywwussys] C:\WINDOWS\System32\nnkhfg.dll ()
O4 - HKLM..\Run: [yaabbcdrv] C:\WINDOWS\System32\tuvurp.dll ()
O4 - HKCU..\Run: [effeeedrv] C:\WINDOWS\System32\tuvurp.dll ()
O30 - LSA: Authentication Packages - (nnkhfg.dll) - C:\WINDOWS\System32\nnkhfg.dll ()
[2010-07-03 09:21:43 | 000,069,120 | -H-- | M] () -- C:\WINDOWS\System32\nnkhfg.dll
[2010-07-03 09:20:17 | 000,095,232 | -H-- | M] () -- C:\WINDOWS\System32\tuvurp.dll
[CREATERESTOREPOINT]
[emptytemp]
[Reboot]

Klistra in dem i rutan Custom Scans/Fixes.

Tryck på Run Fix.

Om du blir tillfrågad om att starta om datorn så gör det.

Det kommer upp en logg i Anteckningar. Kopiera den och klistra in i ditt svar. Skicka svaret också innan du fortsätter.

 

Om den inte kommer automatiskt så hittar du den i mappen c:\_OTL\Moved Files med ett namn som innehåller dagens datum och klockslaget för körningen.

 

Se till att aktivera antivirusprogram mm innan du ansluter datorn till internet.

 

Starta MBAM och uppdatera programmet innan du låter det skanna igenom datorn. Klistra in loggen.

 

Spara Gmer på Skrivbordet från:

http://www2.gmer.net/download.php

Den har ett slumpmässigt namn så notera vad programmet sparas som.

 

Dra ur internetanslutningen.

Stäng alla program, även antivirusprogram och brandvägg.

Starta det nedladdade programmet.

En första snabbskanning startar.

Om det kommer upp en WARNING som nämner ROOTKIT och frågar om "fully scan" så välj Nej/No. Spara loggen och klistra in i ditt svar. Gör inte mer.

 

Om frågan inte kommer så välj fliken Rootkit/Malware, kontrollera att allt är förbockat till höger utom Show All och andra partitioner än C:\. Tryck på Scan. Låt datorn stå ifred medan Gmer håller på.

Tryck på Save och spara resultatet på Skrivbordet.

Sätt igång antivirusprogram och brandvägg innan du ansluter till internet.

Klistra in resultatet i ditt svar.

Link to comment
Share on other sites

Linnégatan

[log]All processes killed

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\bywwussys deleted successfully.

C:\WINDOWS\system32\nnkhfg.dll moved successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yaabbcdrv deleted successfully.

C:\WINDOWS\system32\tuvurp.dll moved successfully.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\effeeedrv deleted successfully.

File C:\WINDOWS\System32\tuvurp.dll not found.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:nnkhfg.dll deleted successfully.

File C:\WINDOWS\System32\nnkhfg.dll not found.

File C:\WINDOWS\System32\nnkhfg.dll not found.

File C:\WINDOWS\System32\tuvurp.dll not found.

File EATERESTOREPOINT] not found.

File ptytemp] not found.

File boot] not found.

 

OTL by OldTimer - Version 3.2.7.0 log created on 07032010_133131

 

Files\Folders moved on Reboot...

 

Registry entries deleted on Reboot...

[/log]Svårt att veta hur jag ska göra. Det står att jag ska skicka svar innan jag fortsätter efter OTL så jag gör väl så...

 

MBAM-logg är på G.

Link to comment
Share on other sites

Linnégatan

[log]Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Databasversion: 4269

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

2010-07-03 13:55:01

mbam-log-2010-07-03 (13-55-01).txt

 

Skanningstyp: Snabbskanning

Antal skannade objekt: 188451

Förfluten tid: 11 minut(er), 28 sekund(er)

 

Infekterade minnesprocesser: 0

Infekterade minnesmoduler: 0

Infekterade registernycklar: 0

Infekterade registervärden: 7

Infekterade registerdataposter: 0

Infekterade mappar: 0

Infekterade filer: 0

 

Infekterade minnesprocesser:

(Inga illasinnade poster hittades)

 

Infekterade minnesmoduler:

(Inga illasinnade poster hittades)

 

Infekterade registernycklar:

(Inga illasinnade poster hittades)

 

Infekterade registervärden:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vttutrdrv (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cbbawwsys (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\fcbawtdrv (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wvtrqnsys (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\geecyvdrv (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wvtrqnsys (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\geecyvdrv (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Infekterade registerdataposter:

(Inga illasinnade poster hittades)

 

Infekterade mappar:

(Inga illasinnade poster hittades)

 

Infekterade filer:

(Inga illasinnade poster hittades)

[/log]

 

Ska jag fortsätta med Gmer?

Link to comment
Share on other sites

Ja, gör det för det dyker upp nya filer hela tiden så det är något som inte syns i OTL-loggen.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.




×
×
  • Create New...