Just nu i M3-nätverket
Gå till innehåll

Pop-up annonser på webbsidor


kelby

Rekommendera Poster

Här kommer textfil och bif.

OTL Extras logfile created on: 2013-01-07 19:53:25 - Run 1

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Per karlsson\Desktop

Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

3,00 Gb Total Physical Memory | 1,86 Gb Available Physical Memory | 62,13% Memory free

5,99 Gb Paging File | 4,44 Gb Available in Paging File | 74,01% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 450,68 Gb Total Space | 252,95 Gb Free Space | 56,13% Space Free | Partition Type: NTFS

Drive D: | 15,00 Gb Total Space | 7,54 Gb Free Space | 50,29% Space Free | Partition Type: NTFS

Drive J: | 698,64 Gb Total Space | 501,21 Gb Free Space | 71,74% Space Free | Partition Type: NTFS

 

Computer Name: PERSDATOR | User Name: Per karlsson | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)

.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

 

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

.js [@ = jsfile] -- C:\Program Files\Adobe\Adobe Dreamweaver CS5.5\Dreamweaver.exe (Adobe Systems, Inc.)

.txt [@ = txtfile] -- Reg Error: Key error. File not found

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)

https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = Reg Error: Unknown registry data type -- File not found

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

 

========== Authorized Applications List ==========

 

 

========== Vista Active Open Ports Exception List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{5B4BB660-20E4-421E-94EC-3DD7CD0EB1C8}" = lport=139 | protocol=6 | dir=in | app=system |

"{695766DB-E504-471E-9BE0-BBFDDCB87B26}" = rport=445 | protocol=6 | dir=out | app=system |

"{6D6A4D4D-5F79-4F8A-ABC0-432E7293092E}" = rport=137 | protocol=17 | dir=out | app=system |

"{6D9DB51D-A74B-4E7E-B899-6D7595FB8A8D}" = lport=445 | protocol=6 | dir=in | app=system |

"{7F2B1CE6-D8D9-4B7D-9D98-434D13EF99BF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{86AF5D8B-978F-4A88-98F4-CC24AD646747}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

"{88204687-4D3D-4BCE-9387-EAF04125A6CC}" = lport=138 | protocol=17 | dir=in | app=system |

"{8B5E7C25-6C63-4374-AAD8-2C572910EA12}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{9D910796-D946-4058-9D18-DA054183DCF0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{9E92D7C1-1CF5-4134-85A3-2307FF6E379C}" = rport=138 | protocol=17 | dir=out | app=system |

"{A6BFCEC4-33EF-4B11-9455-9866DE494ADD}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{A6CEA1A5-808A-4139-938E-C411907241E0}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |

"{D6DD388D-95E4-42BA-81A9-6FC16DD0BCF2}" = rport=139 | protocol=6 | dir=out | app=system |

"{DB16003C-5658-4676-94D0-0ACA1E772DA3}" = lport=137 | protocol=17 | dir=in | app=system |

"{F6EC4FCA-6C4D-4692-8E15-5E14EDEF9C9F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

 

========== Vista Active Application Exception List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{00EAE794-F72B-4AAC-810D-8D1A90E350CE}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |

"{06A90A72-F7E7-4D91-938B-89538D37D56E}" = dir=in | app=c:\program files\itunes\itunes.exe |

"{0CF887A6-6101-4A03-A3C4-91220610AC8B}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe |

"{0F487295-54E1-46A5-BE6C-D390ADC6A5CF}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |

"{1172D906-BCC9-4A81-A1C8-E3CFC10272FF}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe |

"{120213CD-CECD-4369-AFBB-F291DD280A56}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"{127E3D15-A0D7-4FDD-A3C9-AD899CBE248C}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |

"{1AE5A0A3-92EC-453B-B142-C4BFA22FC086}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |

"{1D8DD37C-09E7-4D7D-83CD-52EC8761854D}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |

"{1DA462E1-F50A-4B21-BAC3-CAEF30672625}" = dir=in | app=c:\program files\voddler\service\voddler.exe |

"{209DD7B2-9E8D-4410-881F-B0952B89E404}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe |

"{2EC1BED5-9C78-40E3-90A7-AD402FB4DEC3}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |

"{30CC8744-8C1B-438A-A26A-F3292E03395B}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |

"{3F321694-9B63-4BA8-86CC-643DEEEE2DF9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

"{417C9578-4D75-4FF6-830E-D66FB1EE554C}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |

"{4857380A-C66E-4444-AF3C-C3B32ED1C7BF}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |

"{5B072393-B7EC-4026-BDFD-877FB6576FC0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{5F5B801B-6249-4C7E-B9F0-FC530C4A1302}" = dir=in | app=c:\users\per karlsson\appdata\local\microsoft\skydrive\skydrive.exe |

"{697A80A4-5D34-4C81-B48C-22C8A8B0D957}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |

"{6A006F68-35AE-45B5-BE0B-5A6109E33D56}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |

"{8D35994A-C0DD-4B76-A621-11CE420F151F}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |

"{9F680CA7-33D6-473A-A71F-B98DF1DEA935}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{A45F0844-25A8-4AB7-988C-171BC32FE349}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |

"{A7D1DD89-F9F5-407D-B613-9612590EA949}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{A803B013-DC05-4233-9273-820B7AF3B443}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |

"{BC2B4551-E094-47CC-8941-00249F1A558A}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |

"{BE76898E-2478-4F28-BA6F-2BEB8EE0D21A}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |

"{D4039C32-CD1C-4D0B-B318-333F84366F75}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

"{DB3FBA9C-626D-4D17-94BF-965B7149F2C9}" = protocol=17 | dir=in | app=c:\program files\voddler\service\voddler.exe |

"{EDAB20DD-6324-4E63-A235-5836EF8FDB62}" = protocol=6 | dir=in | app=c:\program files\voddler\service\voddler.exe |

"{F8E43148-0AE0-41EC-8605-4729CC448CC9}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |

"{FBE0BD1E-3135-4EB4-B227-B30AE8CDCD1D}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe |

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{0215A652-E081-4B09-9333-DC85AAB67FFA}" = Adobe Dreamweaver CS5.5

"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86

"{03D45A4B-D7F5-C03E-1650-885756303D13}" = CCC Help Norwegian

"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4

"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86

"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler

"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup

"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86

"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4

"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu-kontroll

"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4600_series" = Canon iP4600 series Printer Driver

"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4807" = CanoScan LiDE 200 Scanner Driver

"{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker

"{14ECAABB-C8B9-4A09-92F7-CDF1A45B6DDE}" = Google Drive

"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5

"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update

"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86

"{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack

"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9

"{284E9E9A-D8BE-3588-D0BA-E9BB61970A1D}" = CCC Help Hungarian

"{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common

"{2A5AD94D-B4C4-4D5C-9B8A-74A1396B7BCF}" = 3DVIA for Photoshop CS5 Plug-in

"{30E18A93-982E-AF1B-D646-E8C5DAECA390}" = CCC Help French

"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery

"{341F5F12-62D7-4BA7-B7BC-562D200D5ACB}" = Microsoft Camera Codec Pack

"{34610DE0-3C13-42CA-8E32-01FFA38AB6E8}" = PC Connectivity Solution

"{35004C1E-8651-9FFC-7D17-CE73EEE36EE8}" = ZoomEx

"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4

"{3BEF9769-BA52-18F7-1D02-2362F6A27E38}" = Adobe Media Player

"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile

"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin

"{4021F8B5-E8BB-D0F9-AF28-4970013FAE3D}" = Catalyst Control Center

"{41EDFD08-81C5-A1AD-B469-B7938250D244}" = AMD Drag and Drop Transcoding

"{4394DC3A-5DAC-4C80-A86E-FF462D0AD653}" = Windows 7 Upgrade Advisor Beta

"{459699C3-9430-4381-964B-4248D87B49F9}" = Apple Mobile Device Support

"{470D66DF-B597-124E-EDCE-8B966AA5F230}" = CCC Help Portuguese

"{47558092-6F3C-E0AF-49C2-F1795CCF20C2}" = svBuilder

"{483924A6-52C5-9169-0280-14272D5FBA70}" = CCC Help Chinese Standard

"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials

"{4A382258-EF01-40B9-85E7-1687D8506EEB}" = SPORTident Config

"{4EBD8EA6-3216-4B79-8C89-6EF694529946}" = Jalbum

"{53820F89-063F-10D7-7457-06C201F4CBF0}" =

"{57AE1BE1-24E8-4169-D52C-ABE31BD91562}" = CCC Help Finnish

"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth

"{5B5745F7-23EF-9E5E-6689-512C9FA08222}" = CCC Help English

"{625031C9-E249-2A53-C282-C1E9872B211E}" = CCC Help Turkish

"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86

"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4

"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support

"{655E0B5A-7ADF-A052-587F-64F0E59B58E7}" = CCC Help Dutch

"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR

"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK

"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

"{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{71B6C9B6-CDF1-516E-EDBD-F3F8EBF7A0C7}" = Adobe Support Advisor

"{74437563-D720-0307-90FC-1C351B1041D7}" = Catalyst Control Center Localization All

"{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6

"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies

"{76E2A1A0-CE72-48A0-8D8E-767A1B0C2191}" = PhotoFrame 4.6.3 Free

"{789A4D10-821B-3FA5-52B0-F0FAEEDED9F4}" = CCC Help Czech

"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour

"{7BA14A92-C229-5E00-3ADE-8D22F81B849E}" = CCC Help German

"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver

"{80A5B901-C7BD-D300-17BA-9E02F18EAB77}" = CCC Help Danish

"{82F505E6-5879-B30A-12B7-7795969D3BBB}" = CCC Help Polish

"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4

"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform

"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4

"{8476003F-6927-8393-C6F4-FAF47D61D00B}" = CCC Help Korean

"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver

"{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery

"{89A2D79E-B3AD-A83A-795F-5645EFF922D3}" = CCC Help Greek

"{89C0F58F-9E5B-2B45-D9DF-7988A54BECA8}" = CCC Help Italian

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8A7163DF-2116-4B48-A628-4FCD7E06B1B2}" = Voddler

"{8B91D776-792D-F02B-DE43-BF398549C729}" = CCC Help Spanish

"{8C0CAA7A-3272-4991-A808-2C7559DE3409}" = Win7codecs

"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

"{8E7C5578-1985-141E-4D5E-1FDEA31265C9}" = ccc-utility

"{8F272838-BDD6-B433-D650-25E231AEFA8A}" = Catalyst Control Center InstallProxy

"{90120000-0016-041D-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Swedish) 2007

"{90120000-0018-041D-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Swedish) 2007

"{90120000-001B-041D-0000-0000000FF1CE}" = Microsoft Office Word MUI (Swedish) 2007

"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2007

"{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2007

"{90120000-006E-041D-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Swedish) 2007

"{90120000-00A1-041D-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Swedish) 2007

"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In

"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007

"{912B04B3-7C7C-4929-AE68-EC2A4CCB4E73}" = Microsoft Mouse and Keyboard Center

"{929E7499-4B50-4C7A-8F15-D21E4061E046}" = BankID säkerhetsprogram

"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86

"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker

"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster

"{983BE967-28E9-5C78-8851-638DAC4AF66E}" = CCC Help Swedish

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail

"{9DCF4B1A-58AD-4BB0-93F1-418055801BFD}" = Document Express DjVu Plug-in

"{A1249D34-EF3A-8FD7-CB9D-8215EE83D835}" = AMD Accelerated Video Transcoding

"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help

"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime

"{A2C726E9-C3A0-4850-82C7-5D01FE0E4EB8}" = Manual CanoScan LiDE 50

"{A707240D-18D3-07F4-AE2E-6AE76C220192}" = CCC Help Japanese

"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer

"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch

"{AC76BA86-7AD7-1053-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Svenska

"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9

"{AED93BE1-9C37-483E-9133-D1820271B353}" = Adobe Photoshop Lightroom 4.3

"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime

"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter

"{B0261E53-B6F1-474A-864B-E7C3CBF468E0}" = iTunes

"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0

"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect

"{B4076407-9640-451E-B815-7971D7E8B092}" = jAlbum

"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4

"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86

"{B8D92680-34AC-4B76-8D95-7E95B11B5121}" = Perfect Effects 3 Free

"{B95AC87D-630B-603F-3F12-AA22B3BBA69C}" = CCC Help Chinese Traditional

"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module

"{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser

"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6

"{C5DA59CF-2BB8-48D5-8E5B-17F2E0F0FEE4}" = System Requirements Lab for Intel

"{C6096116-A875-4067-A70F-76C71C1FC7F9}" = SPCS Bokföring

"{C60AAF4C-A72C-36E0-8CA4-41FF753D74F6}" = Microsoft .NET Framework 4 Client Profile SVE Language Pack

"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant

"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw

"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple-programstöd

"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones

"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86

"{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail

"{D426BEEC-E288-4022-8C68-C3D0252EADAA}" = Playkanaler

"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86

"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding

"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4

"{EB1C554C-5343-9A69-1B8C-666AF192CA19}" = CCC Help Russian

"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial

"{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}" = PL-2303 Vista Driver Installer

"{EF4F8650-7710-4CA0-831D-4AA9C1CF6D87}" = SpeedMaxPc

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio

"{F32D24DD-D787-10F9-D21E-BC3FAB3064CB}" = Catalyst Control Center Graphics Previews Common

"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)

"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01

"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5

"{F5A29695-BDAD-E83E-E364-330D3029B642}" = AMD Media Foundation Decoders

"{F7D86F1C-90C5-4E5E-88E0-FCCFD1F567DA}" = OLA

"{F8D90583-7BB5-75A9-B23F-A353AD4674BC}" = CCC Help Thai

"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4

"504244733D18C8F63FF584AEB290E3904E791693" = Windows-drivrutinspaket - Nokia pccsmcfd (08/22/2008 7.0.0.0)

"7-Zip" = 7-Zip 4.65

"8461-7759-5462-8226" = Vuze

"AbacastNode:11" = Abacast Distributed On-Demand

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4

"AdobeSupportAdvisor.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Support Advisor

"aignesamdeadlink_is1" = AM-DeadLink 4.4

"AVG Secure Search" = AVG Security Toolbar

"Calibrize_is1" = Calibrize 2.0

"Canon iP4600 series användarregistrering" = Canon iP4600 series användarregistrering

"CANONIJINBOXADDON200" = Canon Inkjet Printer Driver Add-On Module V2.00

"CanonMyPrinter" = Canon Utilities My Printer

"CanonSolutionMenu" = Canon Utilities Solution Menu

"CCleaner" = CCleaner

"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help

"com.adobe.amp.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Media Player

"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant

"com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser

"Digital Editions" = Adobe Digital Editions

"DMX5_is1" = DriverMax 6

"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX

"FileZilla Client" = FileZilla Client 3.6.0.2

"Fujidirekt Fotoservice_is1" = Fujidirekt Fotoservice 2.6

"Google Chrome" = Google Chrome

"GPS Photo Tagger" = GPS Photo Tagger V1.2.4

"Inkscape" = Inkscape 0.47

"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies

"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio

"jAlbum_0" = jAlbum 9.3

"MediaNavigation.CDLabelPrint" = CD-LabelPrint

"MeOS" = MeOS 2.5

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Microsoft .NET Framework 4 Client Profile SVE Language Pack" = Microsoft .NET Framework 4 Client Profile Language Pack - SVE

"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center

"Mozilla Firefox 9.0.1 (x86 sv-SE)" = Mozilla Firefox 9.0.1 (x86 sv-SE)

"Mozilla Thunderbird 9.0.1 (x86 sv-SE)" = Mozilla Thunderbird 9.0.1 (x86 sv-SE)

"MP Navigator EX 2.0" = Canon MP Navigator EX 2.0

"NIS" = Norton Internet Security

"OCAD 10 CS_is1" = OCAD 10 CS Service Update CS

"OE2003 Edition Sverige" = OE2003 Edition Sverige V.10.3

"OE2010" = SportSoftware OE2010 V.11.0

"PrivitizeVPN" = PrivitizeVPN

"SiConfig" = SiConfig 2.0.9

"SIVCCOMM&10C4&800A" = SPORTident USB to UART Bridge (Driver Removal)

"SoftwareUpdUtility" = Download Updater (AOL LLC)

"SP_d5b5d47e" =

"svBuilder" = svBuilder

"TPTEST5_is1" = TPTEST 5.0.2

"WinLiveSuite" = Windows Live Essentials

"ZoomEx" =

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Abacast Distributed Live" = Abacast Distributed Live

"MyFreeCodec" = MyFreeCodec

"SkyDriveSetup.exe" = Microsoft SkyDrive

"Spotify" = Spotify

 

========== Last 20 Event Log Errors ==========

 

[ Application Events ]

Error - 2013-01-07 07:58:37 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: Continuously busy for more than a second

 

Error - 2013-01-07 07:58:37 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: m->NextScheduledEvent 10140

 

Error - 2013-01-07 07:58:37 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: m->NextScheduledSPRetry 10140

 

Error - 2013-01-07 07:58:38 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: Continuously busy for more than a second

 

Error - 2013-01-07 07:58:38 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: m->NextScheduledEvent 11138

 

Error - 2013-01-07 07:58:38 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: m->NextScheduledSPRetry 11138

 

Error - 2013-01-07 07:58:39 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: Continuously busy for more than a second

 

Error - 2013-01-07 07:58:39 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: m->NextScheduledEvent 12137

 

Error - 2013-01-07 07:58:39 | Computer Name = Persdator | Source = Bonjour Service | ID = 100

Description = Task Scheduling Error: m->NextScheduledSPRetry 12137

 

Error - 2013-01-07 08:35:53 | Computer Name = Persdator | Source = Application Error | ID = 1000

Description = Felet uppstod i programmet med namn: chrome.exe, version 23.0.1271.97,

tidsstämpel 0x50be88d8 , felet uppstod i modulen med namn: chrome.dll, version 23.0.1271.97,

tidsstämpel 0x50be8882 Undantagskod: 0x80000003 Felförskjutning: 0x0056f383 Process-ID:

0x1198 Programmets starttid: 0x01cdecc458347496 Sökväg till program: C:\Program Files\Google\Chrome\Application\chrome.exe

Sökväg

till modul: C:\Program Files\Google\Chrome\Application\23.0.1271.97\chrome.dll Rapport-ID:

c6452970-58c6-11e2-99aa-0024e80d8022

 

[ OSession Events ]

Error - 2011-06-02 06:53:27 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 19

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-02 06:53:49 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 8

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-02 06:54:14 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 10

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-02 09:37:00 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 13

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-02 09:37:30 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 8

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-03 06:55:32 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 0, Application Name: Microsoft Office Word, Application Version:

12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-03 13:08:59 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 8

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-03 13:12:06 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 9

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-06-03 13:13:33 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 9

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 2011-12-09 14:17:50 | Computer Name = Persdator | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:

12.0.6611.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2

seconds with 0 seconds of active time. This session ended with a crash.

 

[ System Events ]

Error - 2013-01-03 08:03:54 | Computer Name = Persdator | Source = Service Control Manager | ID = 7026

Description = Följande start- eller systemstartdrivrutin(er) avbröts på grund av

fel under start: Lbd

 

Error - 2013-01-04 04:03:04 | Computer Name = Persdator | Source = Service Control Manager | ID = 7026

Description = Följande start- eller systemstartdrivrutin(er) avbröts på grund av

fel under start: Lbd

 

Error - 2013-01-05 04:06:01 | Computer Name = Persdator | Source = Service Control Manager | ID = 7026

Description = Följande start- eller systemstartdrivrutin(er) avbröts på grund av

fel under start: Lbd

 

Error - 2013-01-06 04:51:59 | Computer Name = Persdator | Source = Service Control Manager | ID = 7026

Description = Följande start- eller systemstartdrivrutin(er) avbröts på grund av

fel under start: Lbd

 

Error - 2013-01-06 13:40:09 | Computer Name = Persdator | Source = Service Control Manager | ID = 7026

Description = Följande start- eller systemstartdrivrutin(er) avbröts på grund av

fel under start: Lbd

 

Error - 2013-01-06 13:40:26 | Computer Name = Persdator | Source = Service Control Manager | ID = 7024

Description = Tjänsten Windows Search avbröts med det tjänstspecifika felet %%-1073473535.

 

Error - 2013-01-06 13:40:26 | Computer Name = Persdator | Source = Service Control Manager | ID = 7031

Description = Tjänsten Windows Search avslutades oväntat. Den har gjort detta 1

gång(er). Följande åtgärd kommer att utföras om 30000 millisekunder: Starta om tjänsten.

 

Error - 2013-01-06 13:40:56 | Computer Name = Persdator | Source = Service Control Manager | ID = 7032

Description = Tjänsthanteraren försökte utföra en korrigeringsåtgärd (Starta om

tjänsten) efter att tjänsten Windows Search avslutats oväntat, men denna åtgärd

misslyckades med följande fel: %%1056

 

Error - 2013-01-07 02:35:56 | Computer Name = Persdator | Source = Service Control Manager | ID = 7026

Description = Följande start- eller systemstartdrivrutin(er) avbröts på grund av

fel under start: Lbd

 

Error - 2013-01-07 11:35:53 | Computer Name = Persdator | Source = DCOM | ID = 10016

Description =

 

 

< End of report >

Länk till kommentar
Dela på andra webbplatser

Du har klistrat in och bifogat samma fil.

 

Men börja med att avinstallera ZoomEx i Kontrollpanelen - Program och funktioner. Kontrollera också att den sedan försvinner som tillägg i Google Chrome och Firefox. Fast Firefox ska du antingen avinstallera eller uppdatera för version 9 är full av kända säkerhetshål och direkt olämplig att surfa med.

 

Starta sedan om datorn och kör OTL igen. Klistra in innehållet i OTL.txt i ditt svar så får vi se om allt försvann.

Länk till kommentar
Dela på andra webbplatser

Uppdatering av Firefox, avinst. ZoomEx. Här är OTL.txt efter detta. Bifogar filen eftersom jag får upp ett meddelande att inlägget är för långt?

OTL.Txt

Länk till kommentar
Dela på andra webbplatser

Avinstallera AVG Security Toolbar pga http://www.systemlookup.com/CLSID/73582-AVG_Secure_Search_toolbar_dll.html

 

Se http://www.systemlookup.com/Startup/25435-PrivitizeVPN_exe.html så avinstallera det också.

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram så att de inte krockar med OTL.

Hur? Se http://www.bleepingcomputer.com/forums/topic114351.html

 

Starta programmet OTL (i Vista/Windows7 högerklicka och välj Kör som administratör).

Kopiera alla raderna i rutan:

:OTL
DRV - File not found [File_System | Boot | Stopped] -- system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys -- (Lavasoft Kernexplorer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\PERKAR~1\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=65d6e4b6-2cf0-11e2-95ff-0024e80d8022
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = ${SEARCH_URL}{searchTerms}
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{51F12D2A-ACDA-4E99-9F8B-9D6D7680E001}: "URL" = http://isearch.avg.com/search?cid={DC3AF283-D054-4F0E-8684-AD00B96545F9}&mid=c1664e65629c47d18d47d16daee969d1-0b5d089b86a4b1e37df903fb95c8e1453c34698d&lang=en&ds=is015&pr=sa&d=2012-11-29 08:26:10&v=13.2.0.4&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://searchab.com/?aff=7&uid=65d6e4b6-2cf0-11e2-95ff-0024e80d8022&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=SE&ver=20&locale=sv_SE&gct=kwd&qsrc=2869
FF - prefs.js..browser.startup.homepage: "http://searchab.com/?aff=7&uid=65d6e4b6-2cf0-11e2-95ff-0024e80d8022"
FF - prefs.js..extensions.enabledAddons: %7Bba14329e-9550-4989-b3f2-9732e92d17cc%7D:3.16.0.100
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: ""
[2013-01-07 19:22:18 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2012-08-28 18:06:52 | 000,000,000 | ---D | M] (Bcool) -- C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\5038d87b16d42@5038d87b16d80.info
[2013-01-02 22:55:06 | 000,000,000 | ---D | M] (Zoomex) -- C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\50e445df9fc67@50e445df9fca2.com
[2011-04-01 09:20:24 | 000,000,879 | ---- | M] () -- C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\conduit.xml
[2012-08-25 14:53:16 | 000,002,203 | ---- | M] () -- C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\MyStart Search.xml
[2012-10-30 10:06:44 | 000,002,482 | ---- | M] () -- C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\safesearch.xml
[2013-01-02 15:16:03 | 000,002,090 | ---- | M] () -- C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\Searchab.xml
[2012-06-23 11:45:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [NPSStartup]  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2013-01-02 15:16:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Zoomex
:Files
C:\Program Files\AskBarDis
:Commands
[CREATERESTOREPOINT]
[REBOOT]

Klistra in dem i rutan Custom Scans/Fixes. Kontrollera att det ser exakt likadant ut, t ex när det gäller radbrytningar.

Tryck på Run Fix.

Om du blir tillfrågad om att starta om datorn så gör det.

Det kommer upp en logg i Anteckningar. Kopiera den och klistra in i ditt svar.

 

Om den inte kommer automatiskt så hittar du den i mappen c:\_OTL\Moved Files med ett namn som innehåller dagens datum och klockslaget för körningen.

 

Se till att aktivera antivirusprogram mm innan du ansluter datorn till internet.

Länk till kommentar
Dela på andra webbplatser

Här kommer log-filen.

 

========== OTL ==========

Service Lbd stopped successfully!

Service Lbd deleted successfully!

File system32\DRIVERS\Lbd.sys not found.

Service Lavasoft Kernexplorer stopped successfully!

Service Lavasoft Kernexplorer deleted successfully!

File C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys not found.

Service cpuz132 stopped successfully!

Service cpuz132 deleted successfully!

File C:\Users\PERKAR~1\AppData\Local\Temp\cpuz132\cpuz132_x32.sys not found.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ not found.

Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{51F12D2A-ACDA-4E99-9F8B-9D6D7680E001}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{51F12D2A-ACDA-4E99-9F8B-9D6D7680E001}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.

Prefs.js: "http://searchab.com/?aff=7&uid=65d6e4b6-2cf0-11e2-95ff-0024e80d8022" removed from browser.startup.homepage

Prefs.js: %7Bba14329e-9550-4989-b3f2-9732e92d17cc%7D:3.16.0.100 removed from extensions.enabledAddons

Prefs.js: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33 removed from extensions.enabledAddons

Prefs.js: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 removed from extensions.enabledItems

Prefs.js: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 removed from extensions.enabledItems

Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q="FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "" removed from keyword.URL

Prefs.js: "" removed from sweetim.toolbar.previous.browser.search.selectedEngine

Prefs.js: "" removed from sweetim.toolbar.previous.keyword.URL

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\searchplugin folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\Plugins folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\modules folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\META-INF folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\defaults folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\chrome folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc} folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\5038d87b16d42@5038d87b16d80.info\content folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\5038d87b16d42@5038d87b16d80.info folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\50e445df9fc67@50e445df9fca2.com\content folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\Firefox\Profiles\w88opuag.default\extensions\50e445df9fc67@50e445df9fca2.com folder moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\conduit.xml moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\MyStart Search.xml moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\safesearch.xml moved successfully.

C:\Users\Per karlsson\AppData\Roaming\mozilla\firefox\profiles\w88opuag.default\searchplugins\Searchab.xml moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\locale folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome\content folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\chrome folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} folder moved successfully.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.

C:\Program Files\AskBarDis\bar\bin\askBar.dll moved successfully.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.

File C:\Program Files\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}\ deleted successfully.

File C:\Program Files\AskBarDis\bar\bin\askBar.dll not found.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98}\ not found.

File C:\Program Files\AskBarDis\bar\bin\askBar.dll not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NPSStartup deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

C:\ProgramData\Zoomex folder moved successfully.

========== COMMANDS ==========

Restore point Set: OTL Restore Point

 

OTL by OldTimer - Version 3.2.69.0 log created on 01082013_173034

Länk till kommentar
Dela på andra webbplatser

Det verkar ju ha gått bra.

 

Kör OTL igen och klistra in (eller bifoga om den fortfarande är för stor) OTL.txt (Extras.txt kommer inte att skapas på nytt).

 

Skanna datorn online på http://www.eset.com/onlinescan/

För att inte skannern ska ta för lång tid på sig stäng av ditt antivirusprogram under tiden.

 

Avbocka alternativet Remove found threats

Bocka för Scan Archives

 

Klicka på Advanced Settings

Bocka för:

Scan for potentially unwanted applications

Scan for potentially unsafe applications

Enable Anti-Stealth Technology

 

Klicka på Scan

 

När skanningen är klar kopiera resultatet och klistra sedan in det i ditt svar.

Länk till kommentar
Dela på andra webbplatser

Ny dag med fortsättning på Pop Up.

Har kört OTL igen och bif resultatet.

Betr onlinescanning stängde jag av antivirusprogrammet, öppnade programmet där jag klickade på scanningsknappen och fick då upp en ny ruta där man skall acceptera "Terms of Use" klickade i rutan och sedan "Start" En ny ruta kom upp som bara var grå och inget mer hände?

OTL.Txt

Länk till kommentar
Dela på andra webbplatser

Kan du själv ta bort mappen C:\Program Files\AskBarDis?

 

Ska Privitize VPN vara kvar?

Jag ser att den finns med i Firefox när det gäller sökningar.

 

Kan du i Firefox - Verktyg - Tillägg - Insticksmoduler avinstallera Java ... 6 ..., där 6 är versionsnumret (till skillnad från version 7 som ska vara kvar)?

 

Skriv följande i addressfältet i Firefox:

 

about:config

 

Leta upp raden: keyworkd.URL

Högerklicka på den och välj Återställ.

 

Leta upp de två rader som börjar med "sweetim". Går det att ta bort de två raderna?

 

Avsluta about:config.

 

Du får pröva med någon annan online-skanner då.

http://www.f-secure.com/sv/web/home_se/protection/free-online-tools/free-online-tools

Om något hittas så spara resultatet och klistra in i ditt svar.

Länk till kommentar
Dela på andra webbplatser

Gick bra att ta bort Ask-mappen, Privitize VPN finns inte kvar trots att jag såg i loggen att den fanns som sökmotor,

Java 6 finns inte kvar (endast 7), keyword.URL är gråad på "Återställ" (är inte klickbar), i "about:config" finns inga rader som börjar med "sweetime".

Eftersom jag har Norton tycker jag inte att jag behöver blanda in F-secure eller...?

Länk till kommentar
Dela på andra webbplatser

Eftersom ett antivirusprogram inte hittar alla skadliga filer så är det bra att låta en annat program gå igenom datorn. Prövade du att använda Esets online-skanner med flera av dina webbläsare?

 

Stäng av alla program du ser inklusive antivirusprogram och antispionprogram så att de inte krockar med OTL.

 

Starta programmet OTL (i Vista/Windows7 högerklicka och välj Kör som administratör).

Kopiera alla raderna i rutan:

:OTL
PRC - [2009-04-02 11:47:04 | 000,234,888 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
PRC - [2009-04-02 11:47:02 | 000,464,264 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\AskService.exe
SRV - [2009-04-02 11:47:04 | 000,234,888 | ---- | M] () [Auto | Running] -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade)
SRV - [2009-04-02 11:47:02 | 000,464,264 | ---- | M] () [Auto | Running] -- C:\Program Files\AskBarDis\bar\bin\AskService.exe -- (ASKService)
FF - prefs.js..browser.search.defaultengine: "Privitize VPN"
FF - prefs.js..browser.search.defaultenginename: "Privitize VPN"
FF - prefs.js..browser.search.defaultenginename,S: S", ""
FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "Privitize VPN"
FF - prefs.js..browser.search.order.1,S: S", ""
FF - prefs.js..browser.search.selectedEngine: "Privitize VPN"
FF - prefs.js..browser.search.selectedEngine,S: S", ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
:Commands
[CREATERESTOREPOINT]
[REBOOT]

Klistra in dem i rutan Custom Scans/Fixes. Kontrollera att det ser exakt likadant ut, t ex när det gäller radbrytningar.

Tryck på Run Fix.

Om du blir tillfrågad om att starta om datorn så gör det.

Det kommer upp en logg i Anteckningar. Kopiera den och klistra in i ditt svar.

 

Om den inte kommer automatiskt så hittar du den i mappen c:\_OTL\Moved Files med ett namn som innehåller dagens datum och klockslaget för körningen.

 

Se till att aktivera antivirusprogram mm innan du ansluter datorn till internet.

Länk till kommentar
Dela på andra webbplatser

Ny dag, nya tag med PopUp.

ESET fungerade med Chrome, men efter 4tim15min och bara 30% scannat avbröt jag och fick dessa oönskade filer:

C:\Program Files\Vuze\.install4j\i4j_extf_32_5p83tu.dll a variant of Win32/Bunndle application

C:\Program Files\Vuze\Adobe Illustrator CS4\Activation & Instructions\Activation Blocker.cmd BAT/HostsChanger.A application

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\WxwFLkkj.ini2.vir Win32/Adware.Virtumonde.NEO application

Körde sedan OTL med följande resultatlog:

========== OTL ==========

No active process named ASKUpgrade.exe was found!

No active process named AskService.exe was found!

Error: No service named ASKUpgrade was found to stop!

Service\Driver key ASKUpgrade not found.

File C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe not found.

Error: No service named ASKService was found to stop!

Service\Driver key ASKService not found.

File C:\Program Files\AskBarDis\bar\bin\AskService.exe not found.

Prefs.js: "Privitize VPN" removed from browser.search.defaultengine

Prefs.js: "Privitize VPN" removed from browser.search.defaultenginename

Prefs.js: S", "" removed from browser.search.defaultenginename,S

Prefs.js: "Web Search" removed from browser.search.defaultthis.engineName

Prefs.js: "" removed from browser.search.defaulturl

Prefs.js: "Privitize VPN" removed from browser.search.order.1

Prefs.js: S", "" removed from browser.search.order.1,S

Prefs.js: "Privitize VPN" removed from browser.search.selectedEngine

Prefs.js: S", "" removed from browser.search.selectedEngine,S

Prefs.js: true removed from browser.search.useDBForOrder

Prefs.js: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 removed from extensions.enabledItems

Prefs.js: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 removed from extensions.enabledItems

Prefs.js: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 removed from extensions.enabledItems

Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q=" removed from keyword.URL

Prefs.js: "" removed from sweetim.toolbar.previous.browser.search.defaultenginename

Prefs.js: "" removed from sweetim.toolbar.previous.browser.search.selectedEngine

========== COMMANDS ==========

Restore point Set: OTL Restore Point

 

OTL by OldTimer - Version 3.2.69.0 log created on 01102013_131834

Länk till kommentar
Dela på andra webbplatser

Eset hittade en fil som låg i ComboFix karantän (Qoobox), men då är det väl från en körning med ComboFix vid ett tidigare tillfälle.

 

Fungerar allt bra med datorn nu så det är dags för avinstallation av OTL mm?

Några frågor eller funderingar innan dess?

Länk till kommentar
Dela på andra webbplatser

Vad jag kan se finns inga konstiga "länkar" när jag är inne på websidor oavsett jag använder Explorer, Firefox eller Chrome, så det verkar som rensning har fungerat.

Tack för din insats som har varit engagerad.

(Kan inte OTL vara kvar för framtida bruk?)

Länk till kommentar
Dela på andra webbplatser

Det är bäst att ta bort ComboFix, OTL och andra program eftersom de uppdateras rätt ofta och därför måste du i alla fall ladda ner dem på nytt utifall att datorn blir infekterad igen. Dessutom hoppas jag förstås att du är rädd om datorn och inte låter den bli infekterad igen.

 

1. Spara ComboFix på Skrivbordet: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Tryck Windows-tangenten + R

Kopiera och klistra in denna rad:

ComboFix /Uninstall

 

Observera att det är ett mellanrum före /

Klicka på OK.

 

2. Starta OTL.

Tryck på knappen CleanUp! och DDS m.fl. rensningsprogram kommer att avinstalleras efter en omstart av datorn. Om något sådant program är kvar efter det så fråga hur du ska ta bort det. Ta bort eventuella loggar.

 

3. Byt alla lösenord som du använder i datorn och på internet eftersom dessa kan ha kommit i orätta händer.

http://mnin.blogspot.com/2009/02/why-i-enjoyed-tiggersyzor.html beskriver ett skadligt program som spionerar genom att ta skärmbilder, logga tangentbordsnedtryckningar och läsa lösenord som är lagrade i webbläsare, epostprogram etc.

 

4. Förbättra skyddet i datorn, se mina Råd för en säkrare dator: http://ceciliasec.wordpress.com/rad/

Det är mycket viktigt att hålla alla småprogram i datorn uppdaterade, gamla versioner av t ex Flash, Java och Adobe Reader innehåller kända säkerhetshål, vilka kan användas av en webbsida för att infektera datorn. Jag tycker att Secunias program (länk på min webbsida) är en bra hjälp för att kontrollera hur det står till med säkerhetshål i datorn och ange vad som behöver åtgärdas.

Länk till kommentar
Dela på andra webbplatser

Arkiverat

Det här ämnet är nu arkiverat och är stängt för ytterligare svar.

×
×
  • Skapa nytt...