Gammel sløv computer
  jansler
Antal indlæg: 31

Hej

Jeg har prøvet jer før med et godt resultat og håber I kan hjælpe mig igen grin Jeg har en gammel computer, som er blevet utrolig sløv i særdeleshed, når jeg skal åbne fx Word (den scanner filen i laaaaang tid) og næsten umulig at lukke filen. Jeg kan ikke have to Internetsider åbnet på samme tid, så går alt helt i stå/eller total langsomt.

Her i weeekenden har jeg været forbi kandu. Også utrolig dejlige hjælpsomme mennesker der. Sidste anbefaling var jer grinForslag derfra var, at jeg skal i gang med en geninstallering. Det vil jeg jo gerne undgå, da jeg ikke er nogen ørn wink

Fakta:
Officepakken 2003
Windows XP
228 GB/147 GB ledig plads
I Egenskaber for System står der: Dell Dimension DXP=51, Pentium (R) CPU 3,00 GGz, 2,99 GHz 2,00 GB Ram.
Processer: 75 - CPU-brug: 0 - 23% skifter hele tiden.
Allkokeret hukommelse 101 1M/

Jeg har (i weekenden) købt og kørt SlowPC Fighter. Den rettede 2.054 fejl
Har kørt Ccleaner.
Kørt Malwarecheck, den siger: No unnecessary startups found.

Har også foretaget en defragmentering, men det har heller ikke hjulpet.

For 2 måneder siden kørte den fint. Har I et godt råd til hvad jeg kan gøre?

På forhånd tak.

De bedste hilsner
Jansler

Administrator
Avatar
Antal indlæg: 29177

Hej   wink


Lad os se hvad der kører på computeren ->


Vi er nødt til at se hvad der kører på systemet ->

Hent DDS og gem programmet på dit Skrivebord:
Her
Dobbeltklik på DDS.scr og tillad programmet at køre.
Når programmet er færdig vil det åbne to logs/tekst-filer.
Gem begge filer på dit Skrivebord og kopier indholdet af txt filerne herind i dit næste indlæg.

Da de er forholdsvis lange, kan du blive nødt til at sende dem i flere indlæg.


Før du sender logfilerne, beder vi dig om at fjerne enhvert P2P/fildelings program, hvis du har nogen, og dette inkluderer Torrent software, før vi renser computeren.

  jansler
Antal indlæg: 31

Herlig godmorgen

Her kommer ATTACH.txt 1. del


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 14-06-2006 17:03:44
System Uptime: 22-03-2010 06:16:46 (1 hours ago)

Motherboard: Dell Inc.        |  | 0FJ030
Processor:          Intel(R) Pentium(R) D CPU 3.00GHz | Microprocessor | 2992/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 228 GiB total, 164,563 GiB free.
D: is CDROM ()
E: is CDROM ()
I: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP190: 22-12-2009 08:32:43 - Avg8 Update
RP191: 23-12-2009 11:29:11 - Systemkontrolpunkt
RP192: 26-12-2009 12:28:38 - Systemkontrolpunkt
RP193: 27-12-2009 12:52:51 - Systemkontrolpunkt
RP194: 28-12-2009 15:37:35 - Systemkontrolpunkt
RP195: 29-12-2009 08:04:38 - Avg8 Update
RP196: 31-12-2009 13:56:31 - Systemkontrolpunkt
RP197: 02-01-2010 08:31:12 - Systemkontrolpunkt
RP198: 03-01-2010 10:31:13 - Systemkontrolpunkt
RP199: 04-01-2010 16:22:29 - Systemkontrolpunkt
RP200: 04-01-2010 18:21:59 - Installed Battlefield 2 Patch v1.41
RP201: 04-01-2010 19:30:19 - Installed Battlefield 2 Patch
RP202: 05-01-2010 09:33:38 - Avg8 Update
RP203: 06-01-2010 12:22:24 - Systemkontrolpunkt
RP204: 08-01-2010 06:29:50 - Systemkontrolpunkt
RP205: 09-01-2010 08:48:44 - Systemkontrolpunkt
RP206: 10-01-2010 09:55:34 - Systemkontrolpunkt
RP207: 11-01-2010 09:58:58 - Systemkontrolpunkt
RP208: 12-01-2010 11:16:04 - Systemkontrolpunkt
RP209: 13-01-2010 09:40:54 - Software Distribution Service 3.0
RP210: 14-01-2010 16:29:07 - Systemkontrolpunkt
RP211: 15-01-2010 17:34:15 - Systemkontrolpunkt
RP212: 17-01-2010 18:02:21 - Systemkontrolpunkt
RP213: 19-01-2010 12:29:21 - Systemkontrolpunkt
RP214: 20-01-2010 10:00:17 - Software Distribution Service 3.0
RP215: 22-01-2010 09:49:28 - Systemkontrolpunkt
RP216: 22-01-2010 10:00:16 - Software Distribution Service 3.0
RP217: 23-01-2010 14:17:49 - Systemkontrolpunkt
RP218: 23-01-2010 19:51:22 - Installed DirectX
RP219: 25-01-2010 09:27:18 - Systemkontrolpunkt
RP220: 26-01-2010 10:57:45 - Systemkontrolpunkt
RP221: 27-01-2010 11:01:23 - Systemkontrolpunkt
RP222: 28-01-2010 13:08:37 - Systemkontrolpunkt
RP223: 29-01-2010 13:39:59 - Systemkontrolpunkt
RP224: 29-01-2010 18:06:43 - Installed Windows XP KB954708.
RP225: 29-01-2010 18:07:17 - Installed DirectX
RP226: 30-01-2010 10:00:18 - Software Distribution Service 3.0
RP227: 31-01-2010 10:34:03 - Systemkontrolpunkt
RP228: 31-01-2010 12:10:20 - Installed HP Print Diagnostic Utility
RP229: 31-01-2010 14:16:25 - Installed Microsoft Fix it 50126
RP230: 01-02-2010 19:12:28 - Systemkontrolpunkt
RP231: 03-02-2010 09:59:57 - Avg8 Update
RP232: 04-02-2010 12:10:05 - Systemkontrolpunkt
RP233: 06-02-2010 07:35:12 - Systemkontrolpunkt
RP234: 08-02-2010 11:27:03 - Systemkontrolpunkt
RP235: 09-02-2010 13:50:01 - Systemkontrolpunkt
RP236: 10-02-2010 16:00:58 - Systemkontrolpunkt
RP237: 11-02-2010 10:00:28 - Software Distribution Service 3.0
RP238: 12-02-2010 12:12:32 - Systemkontrolpunkt
RP239: 13-02-2010 13:19:58 - Systemkontrolpunkt
RP240: 14-02-2010 17:20:06 - Installed Stronghold
RP241: 15-02-2010 18:49:51 - Systemkontrolpunkt
RP242: 16-02-2010 19:44:16 - Systemkontrolpunkt
RP243: 18-02-2010 13:46:45 - Systemkontrolpunkt
RP244: 19-02-2010 19:22:05 - Systemkontrolpunkt
RP245: 22-02-2010 10:34:29 - Systemkontrolpunkt
RP246: 24-02-2010 10:00:18 - Software Distribution Service 3.0
RP247: 25-02-2010 10:11:51 - Systemkontrolpunkt
RP248: 26-02-2010 12:05:31 - Systemkontrolpunkt
RP249: 28-02-2010 12:57:04 - Systemkontrolpunkt
RP250: 03-03-2010 08:55:28 - Systemkontrolpunkt
RP251: 04-03-2010 13:21:40 - Systemkontrolpunkt
RP252: 05-03-2010 10:00:18 - Software Distribution Service 3.0
RP253: 06-03-2010 10:48:12 - Systemkontrolpunkt
RP254: 07-03-2010 16:32:47 - Systemkontrolpunkt
RP255: 08-03-2010 19:00:56 - Systemkontrolpunkt
RP256: 09-03-2010 09:07:38 - Avg8 Update
RP257: 09-03-2010 14:45:45 - Installed Java(TM) 6 Update 18
RP258: 10-03-2010 10:00:32 - Software Distribution Service 3.0
RP259: 12-03-2010 11:38:52 - Systemkontrolpunkt
RP260: 13-03-2010 11:58:08 - Systemkontrolpunkt
RP261: 14-03-2010 12:00:29 - Systemkontrolpunkt
RP262: 15-03-2010 12:07:43 - Systemkontrolpunkt
RP263: 15-03-2010 15:07:48 - Printerdriveren Microsoft Office Document Image er installeret
RP264: 16-03-2010 05:49:47 - Registreringsdatabasen er renset med Windows Live OneCare-sikkerhedsscanner
RP265: 17-03-2010 07:44:55 - Systemkontrolpunkt
RP266: 17-03-2010 20:12:45 - Software Distribution Service 3.0
RP267: 19-03-2010 09:14:11 - Avg8 Update
RP268: 19-03-2010 09:15:00 - Avg8 Update
RP269: 20-03-2010 11:11:27 - Systemkontrolpunkt
RP270: 20-03-2010 16:14:59 - Installed SLOW-PCfighter.
RP271: 20-03-2010 16:19:59 - Installed SPAMfighter
RP272: 20-03-2010 16:36:01 - SLOW-PCfighter Backup
RP273: 20-03-2010 16:38:48 - SLOW-PCfighter Backup
RP274: 20-03-2010 16:46:22 - Removed FirstClass
RP275: 20-03-2010 16:50:56 - Removed Marvel(TM) - Ultimate Alliance
RP276: 20-03-2010 17:35:53 - SLOW-PCfighter Backup
RP277: 20-03-2010 17:38:32 - SLOW-PCfighter Backup
RP278: 20-03-2010 17:42:08 - SLOW-PCfighter Backup
RP279: 20-03-2010 18:12:03 - SLOW-PCfighter Backup
RP280: 20-03-2010 19:05:15 - Printerdriveren Microsoft Office Document Image er installeret

==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Acrobat 7.0 Professional - Dansk, Nederlands
Adobe Acrobat 7.1.0 Professional - Dansk, Nederlands
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
Adobe Photoshop 7.0
Adobe Reader 8.1.0
Adobe Shockwave Player
Adobe® Photoshop® Album Starter Edition 3.0
AiO_Scan
AiOSoftware
Andrea VoiceCenter
ANYCOM USB-200/250 Bluetooth Software
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AutoUpdate
avast! Antivirus
AVG Free 8.5
Azureus Vuze
Battlefield 1942
Battlefield 2(TM)
Battlefield Heroes
Bonjour
BufferChm
CCleaner
CDBurnerXP
Color LaserJet 2600n
Copy
CP_AtenaShokunin1Config
CP_CalendarTemplates1
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
Creative MediaSource
Critical Update for Windows Media Player 11 (KB959772)
CueTour
CustomerResearchQFolder
danish.ilsc Toolbar
Dell CinePlayer
Dell Driver Reset Tool
Dell System Restore
Destination Component
Det gode program
DeviceDiscovery
DeviceFunctionQFolder
DeviceManagementQFolder
Digital Signatur
DivX Player
DivX Pro Trial
DJ_AIO_03_F4200_ProductContext
DJ_AIO_03_F4200_Software
DJ_AIO_03_F4200_Software_Min
DNA
DocProc
DocumentViewer
DocumentViewerQFolder
E-Julemærket 2008 til Outlook 2002-2007
EAX Unified
ESPNMotion
eSupportQFolder
F4200
F4200_Help
Fax
Filzip 3.06
Flash 1.0
For-a-perfect-image PrintDesigner
FullDPAppQFolder
GamersGate Downloader
GameSpy Arcade
GdiplusUpgrade
GemMaster Mystic
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
GPBaseService
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
HP Customer Participation Program 10.0
HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3
HP Document Viewer 5.3
HP Image Zone 5.3
HP Imaging Device Functions 10.0
HP Photosmart Essential
HP Photosmart Essential 2.5
HP Print Diagnostic Utility
HP PSC & OfficeJet 5.3.B
HP Smart Web Printing
HP Solution Center 10.0
HP Update
HPProductAssistant
HPSSupply
InstantShareDevices
Intel Matrix Storage Manager
Intel(R) PRO Network Connections Drivers
Intel(R) PROSet for Wired Connections
Intel(R) Quick Resume Technology Drivers
Intel® Viiv™
Ipswitch WS_FTP Professional 2006
ISO Recorder

  jansler
Antal indlæg: 31

ATTACH.txt 2 del

ISO Recorder
iTunes
Java Auto Updater
Java DB 10.4.1.3
Java(TM) 6 Update 18
Java(TM) 6 Update 6
Java(TM) 6 Update 7
Java(TM) SE Development Kit 6 Update 13
Java(TM) SE Runtime Environment 6 Update 1
JavaFX(TM) 1.1 SDK
JavaScript Plus! 6.5 - Trial Version
Junk Mail filter update
Kane and Lynch Dead Men Demo
Kompatibilitetspakke til Office 2007-systemet
Localization Pack for Microsoft Windows XP Media Center Edition
Logitech Desktop Messenger
Logitech QuickCam-software
Logitech® Camera-driver
Magic ISO Maker v5.4 (build 0251)
Malwarebytes’ Anti-Malware
MarketResearch
MCU
MediaSPace
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Danish Language Pack
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.3
Microsoft Office Standard Edition 2003
Microsoft Office XP Professional med FrontPage
Microsoft Publisher 2002
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
Mozilla Firefox (3.0.11)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML4 Parser
NewCopy
Nokia Connectivity Cable Driver
Nokia Lifeblog 2.1
Nokia MTP driver
Nokia N73 highlights
Nokia Nseries Skin for Microsoft Windows Media Player
Nokia PC Connectivity Solution
Nokia PC Suite
Nokia themes for your device
Norton Security Scan
NVIDIA Drivers
OpenOffice.org Installer 1.0
Otto
Overførselsværktøj til Windows Live
PhotoGallery
PowerArchiver 2009
PSSWCORE
PunkBuster Services
QuickTime
RandMap
Readme
RedOrchestra
RegSupreme
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Scan
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
Segoe UI
Shop for HP Supplies
SkinsHP1
Skype™ 3.8
SLOW-PCfighter
SmartFTP Client
SmartWebPrintingOC
SolutionCenter
Sonic Activation Module
Sonic Advanced Decoder
Sonic Encoders
Sonic Update Manager
Sonic_PrimoSDK
Sound Blaster Audigy ADVANCED MB
Sound Blaster Audigy ADVANCED MB Product Registration
SPAMfighter
SPAMfighter Client
Status
Stronghold
SWFBanner
TeamSpeak 2 RC2
TeamViewer 5
Tilmeldingsassistent til Windows Live
Titan Quest
Toolbox
TrayApp
Unity Web Player
Unload
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Victoria
VideoToolkit01
WebFldrs XP
WebReg
Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sync
Windows Live Toolbar
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
WinZip 12.0
XP Codec Pack

==== End Of File ===========================

  jansler
Antal indlæg: 31

DDS.TXT 1. del


DDS (Ver_10-03-17.01) - NTFSx86
Run by Annegrethe Jansler at 7:26:42,79 on 22-03-2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1033.18.2046.1169 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)  {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: avast! antivirus 4.8.1368 [VPS 100321-1] *On-access scanning enabled* (Updated)  {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\ANYCOM\Blue USB-200-250\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Fighters\SPAMfighter\sfus.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fighters\SPAMfighter\sfagent.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ANYCOM\Blue USB-200-250\BTTray.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Annegrethe Jansler\My Documents\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.janslerbooking.dk/
uDefault_Page_URL = hxxp://www.opasia.dk/start
uSearch Bar = hxxp://www.opasia.dk/msie_search.html
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: danish.ilsc Toolbar: {2b733a82-1062-47d4-a310-4de03404dc15} - c:\program files\danish.ilsc\tbdan1.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows

live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: danish.ilsc Toolbar: {2b733a82-1062-47d4-a310-4de03404dc15} - c:\program files\danish.ilsc\tbdan1.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {A171924A-D394-41EC-8B3B-B943844F01F5} - No File
uRun: [Skype] “c:\program files\skype\phone\Skype.exe” /nosplash /minimized
uRun: [SetDefaultMIDI] MIDIDef.exe
uRun: [PcSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
uRun: [Creative Detector] “c:\program files\creative\mediasource\detector\CTDetect.exe” /R
uRun: [BitTorrent DNA] “c:\program files\dna\btdna.exe”
uRun: [Google Update] “c:\documents and settings\annegrethe jansler\local settings\application data\google\update\GoogleUpdate.exe” /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] “c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe”
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [iTunesHelper] “c:\program files\itunes\iTunesHelper.exe”
mRun: [sfagent] c:\program files\fighters\spamfighter\sfagent.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

  jansler
Antal indlæg: 31

DDS.TXT 2. del

dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\anycom\blue usb-200-250\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: Google Sidewiki ... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send til &Bluetooth;-enhed… - c:\program files\anycom\blue usb-200-250\btsendto_ie_ctx.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\anycom\blue usb-200-250\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Trusted Zone: danid.dk
Trusted Zone: danskebank.dk
DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} - hxxp://downol.dr.dk/download/netradio/Rawflow.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {11818680-FCF6-11D0-9808-0800092A4865} - hxxp://www.kps.dk/Codebase/FormCtl.cab
DPF: {1469FF24-47F6-11D2-8805-006008C537E3} - hxxp://www.kps.dk/codebase/ffmail.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} - hxxp://iloapp.cvjob.dk/gallery/executable/IlosoftMultipleImageUpload.dll
DPF: {1E69721D-9104-11D3-82D3-D06650C10000} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/Dafolo.cab
DPF: {224F7DEA-B7C1-11D3-AB40-00902712A5C9} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/plsspeller.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://express.foto.com/ImageUploader5.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {92EB6641-286A-11D2-A68E-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfsignature.cab
DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {AD90E8D1-3B47-11D2-A696-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfcrypto.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} - hxxp://www.kps.dk/codebase/scriptobject.cab
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
DPF: {EF2FB80F-0975-408E-A871-B00CC863478A} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/fontinstaller.cab
DPF: {F4F6546F-FBA9-11D1-8AFB-080009ECFDC5} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/listbox.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\annegr~1\applic~1\mozilla\firefox\profiles\487kbviw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.janslerbooking.dk/
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows

presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-3 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-2 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-8-2 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-2 108552]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-3 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-3 138680]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-2 297752]
R2 Common Toolkit Service;Common Toolkit Service;c:\program files\common files\common toolkit suite\FighterSuiteService.exe [2010-2-18 684680]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-1-29 54752]
R2 IAANTMon;Intel(R) Matrix Storage Event Monitor;c:\program files\intel\intel matrix storage manager\IAANTMon.exe [2006-6-7 86140]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\fighters\spamfighter\sfus.exe [2010-2-18 189064]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-3 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-3 352920]
S2 gupdate;Tjenesten Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-4 135664]
S3 fsssvc;Windows Live-tjenesten Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 jfdcd;jfdcd;\??\c:\docume~1\annegr~1\locals~1\temp\jfdcd.sys—> c:\docume~1\annegr~1\locals~1\temp\jfdcd.sys [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2009-10-31 40448]

=============== Created Last 30 ================

2010-03-21 04:12:12   3244   ——a-w-  c:\windows\system32\wbem\Outlook_01cac8acaef35756.mof
2010-03-20 16:00:22   0   d——-w-  c:\docume~1\annegr~1\applic~1\Common Toolkit Suite
2010-03-20 15:21:21   0   d——-w-  c:\docume~1\alluse~1\applic~1\Common Toolkit Suite
2010-03-20 15:20:31   0   d——-w-  c:\program files\common files\Common Toolkit Suite
2010-03-20 15:19:08   0   dc-h—w-  c:\docume~1\alluse~1\applic~1\{E434619C-846F-4697-8739-15F436DE9B2F}
2010-03-20 15:17:31   0   d——-w-  c:\docume~1\annegr~1\applic~1\Fighters
2010-03-20 15:15:19   0   d——-w-  c:\docume~1\alluse~1\applic~1\Fighters
2010-03-20 15:15:02   0   d——-w-  c:\program files\Fighters
2010-03-20 14:44:54   0   d——-w-  c:\docume~1\annegr~1\applic~1\Uniblue
2010-03-17 17:37:51   293376   ———w-  c:\windows\system32\browserchoice.exe
2010-03-15 19:52:48   3244   ——a-w-  c:\windows\system32\wbem\Outlook_01cac479169148ec.mof
2010-03-10 11:42:19   3244   ——a-w-  c:\windows\system32\wbem\Outlook_01cac046bdce04f2.mof
2010-03-10 05:32:48   3558912   ———w-  c:\windows\system32\dllcache\moviemk.exe
2010-02-20 18:33:28   43520   ——a-w-  c:\windows\system32\CmdLineExt03.dll

==================== Find3M ====================

2010-03-01 19:36:50   139456   ——a-w-  c:\windows\system32\drivers\PnkBstrK.sys
2010-03-01 19:36:29   190160   ——a-w-  c:\windows\system32\PnkBstrB.exe
2009-12-31 16:50:03   353792   ———w-  c:\windows\system32\dllcache\srv.sys
2009-12-22 17:47:29   107888   ——a-w-  c:\windows\system32\CmdLineExt.dll
2006-06-17 08:42:53   88   -csh—r-  c:\windows\system32\526FE2B864.sys
2007-11-24 19:47:16   56   -csh—r-  c:\windows\system32\64B8E26F52.sys
2007-11-24 19:47:16   1682   -csha-w-  c:\windows\system32\KGyGaAvL.sys
2008-05-27 12:48:24   32768   -csha-w-  c:\windows\system32\config\systemprofile\local

settings\history\history.ie5\mshist012008052720080528\index.dat

============= FINISH:  7:27:46,89 ===============

  jansler
Antal indlæg: 31

Hej igen - og hvor herligt med så hurtigt en tilbagemelding grin

Nu er der vist mere plads til spørgsmål.

Du skrev: Før du sender logfilerne, beder vi dig om at fjerne enhvert P2P/fildelings program, hvis du har nogen, og dette inkluderer Torrent software, før vi renser computeren. 

Hvad er ovennævnte?

De bedste hilsner
Jansler

Administrator
Avatar
Antal indlæg: 29177

Ja, spørg endelig   grin

Du skrev: Før du sender logfilerne, beder vi dig om at fjerne enhvert P2P/fildelings program, hvis du har nogen, og dette inkluderer Torrent software, før vi renser computeren. 

Hvad er ovennævnte?


Det er bl.a Bittorrent, som du godt må fjerne mens jeg kigger loggen igennem.
BitTorrent DNA] “c:\program files\dna\btdna.exe”

Det kan sandsynligvis fjernes fra tilføj/fjern programmer i kontrolpanel.

Administrator
Avatar
Antal indlæg: 29177

Hent Combofix, og gem den på dit skrivebord, som alg.exe:
ComboFix


Åben Notesblok og kopier følgende (tekst med fed skrift) ind - og gem tekst-filen som CFScript samme sted som du har ComboFix:


…………………………………………………………………….


Killall::
Snapshot::
DDS::
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File


Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du “giver slip” med musen. Som vist her ->

http://www.fromsej.saknet.dk/billeder/swfcombo.gif


Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Læg den nye ComboFix log herind. Den kan findes her - C:\combofix Txt

  jansler
Antal indlæg: 31

Hej igen

Straks fjernet direkte fra Kontrolpanalet. Så er vi da fri for den grin

  jansler
Antal indlæg: 31

Hej igen

Det tog lidt tid, men den er forhåbentlig givet godt ud grin

ComboFix 10-03-21.02 - Annegrethe Jansler 22-03-2010   8:09.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1033.18.2046.1449 [GMT 1:00]
Kører fra: c:\documents and settings\Annegrethe Jansler\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Annegrethe Jansler\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100321-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Dannede nyt systemgendannelsespunkt

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk
c:\windows\system32\ccdcf1_g.dll
c:\windows\system32\Data

.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-02-22 til 2010-03-22 )))))))))))))))))))))))))))))))))))
.

2010-03-20 16:00 . 2010-03-20 16:00   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Common Toolkit Suite
2010-03-20 15:21 . 2010-03-20 15:21   ————  d——-w-  c:\documents and settings\All Users\Application Data\Common Toolkit Suite
2010-03-20 15:20 . 2010-03-22 07:21   ————  d——-w-  c:\program files\Common Files\Common Toolkit Suite
2010-03-20 15:19 . 2010-03-20 15:21   ————  dc-h—w-  c:\documents and settings\All Users\Application Data\{E434619C-846F-4697-8739-15F436DE9B2F}
2010-03-20 15:17 . 2010-03-20 15:17   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Fighters
2010-03-20 15:17 . 2010-03-20 15:17   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\PackageAware
2010-03-20 15:15 . 2010-03-20 15:15   ————  d——-w-  c:\documents and settings\All Users\Application Data\Fighters
2010-03-20 15:15 . 2010-03-20 15:20   ————  d——-w-  c:\program files\Fighters
2010-03-20 14:44 . 2010-03-20 14:44   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Uniblue
2010-03-17 17:37 . 2010-02-12 10:03   293376   ———w-  c:\windows\system32\browserchoice.exe
2010-03-15 14:21 . 2010-03-20 12:26   ————  d——-w-  c:\program files\Windows Live Safety Center
2010-03-10 05:32 . 2009-10-23 15:28   3558912   ———w-  c:\windows\system32\dllcache\moviemk.exe
2010-02-22 12:22 . 2010-03-18 12:32   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Temp
2010-02-20 18:33 . 2010-02-20 18:40   43520   ——a-w-  c:\windows\system32\CmdLineExt03.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-22 07:31 . 2008-06-21 10:46   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Skype
2010-03-21 09:07 . 2009-08-03 15:49   0   -c—a-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\prvlcl.dat
2010-03-21 04:09 . 2006-06-14 15:37   87352   ——a-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-20 17:39 . 2009-06-03 07:35   ————  d——-w-  c:\program files\Malwarebytes’ Anti-Malware
2010-03-20 16:33 . 2009-06-01 11:00   ————  d——-w-  c:\program files\CCleaner
2010-03-20 16:27 . 2007-11-21 22:02   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Azureus
2010-03-20 16:05 . 2006-06-07 08:23   ————  d—h—w-  c:\program files\InstallShield Installation Information
2010-03-20 15:50 . 2010-01-23 18:46   ————  d——-w-  c:\program files\Kalypso
2010-03-20 15:49 . 2006-08-11 15:27   ————  d——-w-  c:\program files\GSC Game World
2010-03-20 15:47 . 2006-07-30 16:26   ————  d——-w-  c:\program files\UBISOFT
2010-03-20 15:46 . 2006-09-24 18:20   ————  d——-w-  c:\program files\FirstClass
2010-03-19 15:22 . 2006-10-03 16:09   ————  d——-w-  c:\program files\Common Files\Symantec Shared
2010-03-09 13:46 . 2006-06-07 08:18   ————  d——-w-  c:\program files\Common Files\Java
2010-03-09 13:46 . 2010-03-09 13:46   503808   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-42752881-n\msvcp71.dll
2010-03-09 13:46 . 2010-03-09 13:46   499712   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-42752881-n\jmc.dll
2010-03-09 13:46 . 2010-03-09 13:46   348160   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-42752881-n\msvcr71.dll
2010-03-09 13:46 . 2010-03-09 13:46   61440   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6431798d-n\decora-sse.dll
2010-03-09 13:46 . 2010-03-09 13:46   12800   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6431798d-n\decora-d3d.dll
2010-03-09 13:46 . 2006-06-07 08:18   ————  d——-w-  c:\program files\Java
2010-03-01 19:36 . 2007-08-25 18:05   139456   ——a-w-  c:\windows\system32\drivers\PnkBstrK.sys
2010-03-01 19:36 . 2007-08-25 18:05   190160   ——a-w-  c:\windows\system32\PnkBstrB.exe
2010-02-18 10:39 . 2010-03-20 15:21   3253480   -c—a-w-  c:\documents and settings\All Users\Application Data\{E434619C-846F-4697-8739-15F436DE9B2F}\SPAMfighter_Client.exe
2010-02-14 16:47 . 2008-04-23 14:39   ————  d——-w-  c:\program files\Firefly Studios
2010-02-08 13:38 . 2006-06-14 15:28   ————  d——-w-  c:\program files\HP
2010-02-04 06:56 . 2007-02-12 09:43   ————  d——-w-  c:\program files\Google
2010-01-31 11:10 . 2010-01-31 11:10   45056   ——a-r-  c:\documents and settings\Annegrethe Jansler\Application Data\Microsoft\Installer\{E14B8A08-42B3-4676-9E91-1D39F8158DA1}\NewShortcut2_E14B8A0842B346769E911D39F8158DA1.exe
2010-01-31 11:10 . 2010-01-31 11:10   45056   ——a-r-  c:\documents and settings\Annegrethe Jansler\Application Data\Microsoft\Installer\{E14B8A08-42B3-4676-9E91-1D39F8158DA1}\NewShortcut1_E14B8A0842B346769E911D39F8158DA1.exe
2010-01-30 09:14 . 2010-01-30 09:14   14069760   ——a-w-  c:\documents and settings\Annegrethe Jansler\ntuser.dat.tmp
2010-01-30 09:14 . 2010-01-30 09:14   245760   ——a-w-  c:\documents and settings\LocalService\NTUSER.DAT.tmp
2010-01-30 09:14 . 2010-01-30 09:14   241664   ——a-w-  c:\documents and settings\NetworkService\NTUSER.DAT.tmp
2010-01-30 09:06 . 2010-01-30 09:03   ————  d——-w-  c:\program files\RegSupreme
2010-01-29 17:08 . 2010-01-29 17:02   ————  d——-w-  c:\program files\Windows Live
2010-01-29 17:08 . 2010-01-29 17:08   ————  d——-w-  c:\program files\Microsoft Sync Framework
2010-01-29 17:07 . 2010-01-29 17:07   ————  d——-w-  c:\program files\Microsoft SQL Server Compact Edition
2010-01-29 17:03 . 2010-01-29 17:03   ————  d——-w-  c:\program files\Microsoft
2010-01-29 17:02 . 2010-01-29 17:02   ————  d——-w-  c:\program files\Windows Live SkyDrive
2010-01-07 15:07 . 2009-06-03 07:35   38224   ——a-w-  c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-06-03 07:35   19160   ——a-w-  c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2006-06-07 08:03   353792   ——a-w-  c:\windows\system32\drivers\srv.sys
2009-12-22 17:47 . 2006-07-30 17:36   107888   ——a-w-  c:\windows\system32\CmdLineExt.dll
2006-06-17 08:42 . 2006-06-17 07:01   88   -csh—r-  c:\windows\system32\526FE2B864.sys
2007-11-24 19:47 . 2007-11-24 19:47   56   -csh—r-  c:\windows\system32\64B8E26F52.sys
2007-11-24 19:47 . 2006-06-17 07:01   1682   -csha-w-  c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
“{A3BC75A2-1F87-4686-AA43-5347D756017C}”= “c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll” [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2b733a82-1062-47d4-a310-4de03404dc15}]
2010-03-02 09:26   2349080   ——a-w-  c:\program files\danish.ilsc\tbdan1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 07:55   1090816   ——a-w-  c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
“{2b733a82-1062-47d4-a310-4de03404dc15}”= “c:\program files\danish.ilsc\tbdan1.dll” [2010-03-02 2349080]
“{CCC7A320-B3CA-4199-B1A6-9F516DD69829}”= “c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll” [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{2b733a82-1062-47d4-a310-4de03404dc15}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
“{2B733A82-1062-47D4-A310-4DE03404DC15}”= “c:\program files\danish.ilsc\tbdan1.dll” [2010-03-02 2349080]
“{CCC7A320-B3CA-4199-B1A6-9F516DD69829}”= “c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll” [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{2b733a82-1062-47d4-a310-4de03404dc15}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Skype”=“c:\program files\Skype\Phone\Skype.exe” [2008-06-03 21718312]
“SetDefaultMIDI”=“MIDIDef.exe” [2004-12-22 24576]
“PcSync”=“c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe” [2006-06-27 1449984]
“Creative Detector”=“c:\program files\Creative\MediaSource\Detector\CTDetect.exe” [2004-12-02 102400]
“Google Update”=“c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe” [2010-02-04 135664]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2009-08-05 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“hpqSRMon”=“c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe” [2007-08-22 80896]
“avast!”=“c:\progra~1\ALWILS~1\Avast4\ashDisp.exe” [2009-11-24 81000]
“AVG8_TRAY”=“c:\progra~1\AVG\AVG8\avgtray.exe” [2010-03-19 2046816]
“iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe” [2009-10-28 141600]
“sfagent”=“c:\program files\Fighters\SPAMfighter\sfagent.exe” [2010-02-18 386696]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2005-12-14 7323648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“RunNarrator”=“Narrator.exe” [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\ANYCOM\Blue USB-200-250\BTTray.exe [2006-8-18 561213]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
HP Image Zone Hurtig start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-11 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-02 21:31   11952   ——a-w-  c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVSCHED32
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 01:06   40048   -c—a-w-  c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-09-15 08:47   57344   ———w-  c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 02:12   94208   ——a-w-  c:\program files\Dell\Media Experience\DMXLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-14 19:17   49152   ——a-w-  c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
2005-06-08 12:44   196608   ——a-w-  c:\program files\Logitech\Video\ManifestEngine.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 00:54   417792   ——a-w-  c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefaultMIDI]
2004-12-22 16:40   24576   ——a-w-  c:\windows\MIDIDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 00:00   90112   ———w-  c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
2005-09-19 06:42   1159168   ———w-  c:\program files\Creative\VoiceCenter\AndreaVC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusOverride”=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\\system32\\sessmgr.exe”=
“c:\\Program Files\\Messenger\\msmsgs.exe”=
“c:\\WINDOWS\\system32\\dpvsetup.exe”=
“c:\\WINDOWS\\system32\\dpnsvr.exe”=
“c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe”=
“c:\\Program Files\\GameSpy Arcade\\Aphex.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.10.6448-enGB-downloader.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe”=
“c:\\Program Files\\WS_FTP\\WS_FTP95.exe”=
“c:\\Program Files\\Azureus\\Azureus.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“c:\\Program Files\\SmartFTP Client\\SmartFTP.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enGB-patch-downloader.exe”=
“c:\\WINDOWS\\system32\\mmc.exe”=
“c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe”=
“c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe”=
“c:\\WINDOWS\\system32\\PnkBstrA.exe”=
“c:\\WINDOWS\\system32\\PnkBstrB.exe”=
“c:\\Program Files\\AVG\\AVG8\\avgupd.exe”=
“c:\\Program Files\\AVG\\AVG8\\avgnsx.exe”=
“c:\\Program Files\\Bonjour\\mDNSResponder.exe”=
“c:\\Program Files\\iTunes\\iTunes.exe”=
“c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe”=
“c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe”=
“c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe”=
“c:\\Program Files\\Firefly Studios\\Stronghold Crusader\\Stronghold Crusader.exe”=
“c:\\Program Files\\Skype\\Phone\\Skype.exe”=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“3724:TCP”= 3724:TCP:Blizzard Downloader: 3724
“53:TCP”= 53:TCP:websrvx

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27-12-2007 21:52 715248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [03-06-2009 09:00 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [02-08-2009 22:31 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [02-08-2009 22:31 108552]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [03-06-2009 09:00 20560]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [02-08-2009 22:30 297752]
R2 Common Toolkit Service;Common Toolkit Service;c:\program files\Common Files\Common Toolkit Suite\FighterSuiteService.exe [18-02-2010 11:38 684680]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [18-02-2010 11:38 189064]
S2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04-02-2010 07:57 135664]
S3 jfdcd;jfdcd;\??\c:\docume~1\ANNEGR~1\LOCALS~1\Temp\jfdcd.sys—> c:\docume~1\ANNEGR~1\LOCALS~1\Temp\jfdcd.sys [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [31-10-2009 17:12 40448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ     Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ     hpqcxs08 hpqddsvc
.
Indhold af mappen ‘Planlagte Opgaver’

2010-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 06:56]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 06:56]

2010-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326295475-2065508634-3725981300-1005Core.job
- c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-22 06:56]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326295475-2065508634-3725981300-1005UA.job
- c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-22 06:56]

2010-03-19 c:\windows\Tasks\Norton Security Scan for Annegrethe Jansler.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-13 11:50]

2010-03-22 c:\windows\Tasks\SLOW-PCfighter-Annegrethe Jansler-Startup.job
- c:\program files\Fighters\SLOW-PCfighter\SLOW-PCfighter.exe [2010-03-10 14:33]

2010-03-22 c:\windows\Tasks\User_Feed_Synchronization-{377361DA-5D6E-45F0-A401-A5E0D02987BD}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
———- Yderligere scanning———-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.janslerbooking.dk/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki ... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send til &Bluetooth;-enhed… - c:\program files\ANYCOM\Blue USB-200-250\btsendto_ie_ctx.htm
Trusted Zone: danid.dk
Trusted Zone: danskebank.dk
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {1469FF24-47F6-11D2-8805-006008C537E3} - hxxp://www.kps.dk/codebase/ffmail.cab
DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} - hxxp://iloapp.cvjob.dk/gallery/executable/IlosoftMultipleImageUpload.dll
DPF: {1E69721D-9104-11D3-82D3-D06650C10000} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/Dafolo.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
DPF: {92EB6641-286A-11D2-A68E-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfsignature.cab
DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {AD90E8D1-3B47-11D2-A696-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfcrypto.cab
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
DPF: {F4F6546F-FBA9-11D1-8AFB-080009ECFDC5} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/listbox.cab
FF - ProfilePath - c:\documents and settings\Annegrethe Jansler\Application Data\Mozilla\Firefox\Profiles\487kbviw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.janslerbooking.dk/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - TOMME GENVEJE FJERNET - - - -

URLSearchHooks-*{2b733a82-1062-47d4-a310-4de03404dc15} - (no file)
WebBrowser-{A171924A-D394-41EC-8B3B-B943844F01F5} - (no file)
MSConfigStartUp-CTFMON - (no file)

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-22 08:28
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys prosync1.sys hal.dll sfsync04.sys sfsync02.sys iastor.sys spwf.sys >>UNKNOWN [0x8A940944]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9e69cb8
\Driver\atapi -> sfsync04.sys @ 0xb9e41a7c
\Driver\iaStor -> prosync1.sys @ 0xba5b0661
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel(R) PRO/1000 PL Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xb9bf7bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9c04a21
SendHandler -> NDIS.sys @ 0xb9be287b
user & kernel MBR OK

**************************************************************************
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EA20B5D7-213B-BF6A-A687F1F5E27AC26F}\{EEE35091-0AEA-CF92-BEFE1061EF739928}\{47B248DC-A6E0-641B-BA973614FEEFC865}*]
“NRDFOBLVNAUE2QOGEQXAH1Y2DD1”=hex:01,00,01,00,00,00,00,00,b0,0a,ac,41,7a,16,04,
  de,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
——————————- DLLs startet under kørende Processer——————————-

- - - - - - - > ‘explorer.exe’(2916)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\system32\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_dan.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\SmartFTP Client\smarthook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
————————————Andre kørende processer————————————
.
c:\program files\ANYCOM\Blue USB-200-250\bin\btwdins.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\dllhost.exe
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\windows\system32\msiexec.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Gennemført tid: 2010-03-22 08:36:19 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-03-22 07:36
ComboFix2.txt 2009-06-03 07:33

Pre-Kørsel: 176.589.545.472 bytes free
Post-Kørsel: 176.585.814.016 byte ledig

Current=5 Default=5 Failed=4 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - B53296EDC6BB400F81E0D97672AB8E9B

Administrator
Avatar
Antal indlæg: 29177

Ja, så langt så godt   grin


Du har 2 antivirus programmer kørende. Det duer ikke da de vil konflikte, og være med til at sløve computeren.

Jeg vil anbefale at droppe AVG8, den er intet værd mere.
Hent dette værktøj:
http://www.avg.com/download-tools
Hent Ccleaner her:
http://www.ccleaner.com/download/builds/downloading-slim
Installer Ccleaner, det skal ikke køres endnu.

Afbryd netforbindelsen, kør værktøjet fra AVG, genstart.
Start Ccleaner, fjern fluebenet i cookies.
Klik på kør Cleaner og lad den fjerne hvad den finder.
Klik så på Register ovre i venstre side (den blå terning), klik på Skan efter problemer, når den er færdig, klik på Udbedre valgte problemer, lav evt. en backup af registreringsdatabasen, klik så på udbedre alle valgte problemer.
Klik på OK, klik på Luk når den er færdig.

Genstart.

Send så en ny combofix log herind, og fortæl lidt om hvordan tingene kører nu ?

  jansler
Antal indlæg: 31

Hej igen

Hvordan laver jeg en backup af registreringsdatabasen?

Skal jeg starte forfra nu hvor jeg er på nettet igen?

pft
Jansler

Administrator
Avatar
Antal indlæg: 29177

Hvordan laver jeg en backup af registreringsdatabasen?


Det spørger Ccleaner dig om, der siger du bare ja 2 gange.


Og nej, der skulle ikke være grund til at starte forfra, for jeg går ud fra at AVG8 er fjernet med afinstallations programmet. Så bare fortsæt vejledningen.

  jansler
Antal indlæg: 31

Hej igen

Desværre der er ingen forskel. Lige så langsom som før.

Når jeg fx åbner Word, så kommer menuer til frem fornuftigt hurtigt, men det er selv indholdet i den gemte fil, som tager uendelig lang tid. At lukke selv uden ændringer stager måske 2 minutter.

Her kommer den nye ComboFix

Men inden den blev færdig kom DEV.EXE has encounterede a problem….... den kom ved stage 48

—-

ComboFix 10-03-21.04 - Annegrethe Jansler 22-03-2010 13:27:36.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1033.18.2046.1545 [GMT 1:00]
Kører fra: c:\documents and settings\Annegrethe Jansler\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Annegrethe Jansler\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100321-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((  Filer skabt fra 2010-02-22 til 2010-03-22 )))))))))))))))))))))))))))))))))))
.

2010-03-22 11:11 . 2010-03-22 11:11   ————  d——-w-  c:\documents and settings\All Users\Application Data\ReviverSoft
2010-03-20 16:00 . 2010-03-20 16:00   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Common Toolkit Suite
2010-03-20 15:21 . 2010-03-20 15:21   ————  d——-w-  c:\documents and settings\All Users\Application Data\Common Toolkit Suite
2010-03-20 15:20 . 2010-03-22 12:37   ————  d——-w-  c:\program files\Common Files\Common Toolkit Suite
2010-03-20 15:19 . 2010-03-20 15:21   ————  dc-h—w-  c:\documents and settings\All Users\Application Data\{E434619C-846F-4697-8739-15F436DE9B2F}
2010-03-20 15:17 . 2010-03-20 15:17   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Fighters
2010-03-20 15:17 . 2010-03-20 15:17   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\PackageAware
2010-03-20 15:15 . 2010-03-20 15:15   ————  d——-w-  c:\documents and settings\All Users\Application Data\Fighters
2010-03-20 15:15 . 2010-03-20 15:20   ————  d——-w-  c:\program files\Fighters
2010-03-20 14:44 . 2010-03-20 14:44   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Uniblue
2010-03-17 17:37 . 2010-02-12 10:03   293376   ———w-  c:\windows\system32\browserchoice.exe
2010-03-15 14:21 . 2010-03-20 12:26   ————  d——-w-  c:\program files\Windows Live Safety Center
2010-03-10 05:32 . 2009-10-23 15:28   3558912   ———w-  c:\windows\system32\dllcache\moviemk.exe
2010-02-22 12:22 . 2010-03-18 12:32   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Temp
2010-02-20 18:33 . 2010-02-20 18:40   43520   ——a-w-  c:\windows\system32\CmdLineExt03.dll

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-22 12:39 . 2008-06-21 10:46   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Skype
2010-03-22 09:07 . 2009-08-03 15:49   0   -c—a-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\prvlcl.dat
2010-03-21 04:09 . 2006-06-14 15:37   87352   ——a-w-  c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-20 17:39 . 2009-06-03 07:35   ————  d——-w-  c:\program files\Malwarebytes’ Anti-Malware
2010-03-20 16:33 . 2009-06-01 11:00   ————  d——-w-  c:\program files\CCleaner
2010-03-20 16:27 . 2007-11-21 22:02   ————  d——-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Azureus
2010-03-20 16:05 . 2006-06-07 08:23   ————  d—h—w-  c:\program files\InstallShield Installation Information
2010-03-20 15:50 . 2010-01-23 18:46   ————  d——-w-  c:\program files\Kalypso
2010-03-20 15:49 . 2006-08-11 15:27   ————  d——-w-  c:\program files\GSC Game World
2010-03-20 15:47 . 2006-07-30 16:26   ————  d——-w-  c:\program files\UBISOFT
2010-03-20 15:46 . 2006-09-24 18:20   ————  d——-w-  c:\program files\FirstClass
2010-03-19 15:22 . 2006-10-03 16:09   ————  d——-w-  c:\program files\Common Files\Symantec Shared
2010-03-09 13:46 . 2006-06-07 08:18   ————  d——-w-  c:\program files\Common Files\Java
2010-03-09 13:46 . 2010-03-09 13:46   503808   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-42752881-n\msvcp71.dll
2010-03-09 13:46 . 2010-03-09 13:46   499712   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-42752881-n\jmc.dll
2010-03-09 13:46 . 2010-03-09 13:46   348160   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-42752881-n\msvcr71.dll
2010-03-09 13:46 . 2010-03-09 13:46   61440   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6431798d-n\decora-sse.dll
2010-03-09 13:46 . 2010-03-09 13:46   12800   ——a-w-  c:\documents and settings\Annegrethe Jansler\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6431798d-n\decora-d3d.dll
2010-03-09 13:46 . 2006-06-07 08:18   ————  d——-w-  c:\program files\Java
2010-03-01 19:36 . 2007-08-25 18:05   139456   ——a-w-  c:\windows\system32\drivers\PnkBstrK.sys
2010-03-01 19:36 . 2007-08-25 18:05   190160   ——a-w-  c:\windows\system32\PnkBstrB.exe
2010-02-18 10:39 . 2010-03-20 15:21   3253480   -c—a-w-  c:\documents and settings\All Users\Application Data\{E434619C-846F-4697-8739-15F436DE9B2F}\SPAMfighter_Client.exe
2010-02-14 16:47 . 2008-04-23 14:39   ————  d——-w-  c:\program files\Firefly Studios
2010-02-08 13:38 . 2006-06-14 15:28   ————  d——-w-  c:\program files\HP
2010-02-04 06:56 . 2007-02-12 09:43   ————  d——-w-  c:\program files\Google
2010-01-31 11:10 . 2010-01-31 11:10   45056   ——a-r-  c:\documents and settings\Annegrethe Jansler\Application Data\Microsoft\Installer\{E14B8A08-42B3-4676-9E91-1D39F8158DA1}\NewShortcut2_E14B8A0842B346769E911D39F8158DA1.exe
2010-01-31 11:10 . 2010-01-31 11:10   45056   ——a-r-  c:\documents and settings\Annegrethe Jansler\Application Data\Microsoft\Installer\{E14B8A08-42B3-4676-9E91-1D39F8158DA1}\NewShortcut1_E14B8A0842B346769E911D39F8158DA1.exe
2010-01-30 09:14 . 2010-01-30 09:14   14069760   ——a-w-  c:\documents and settings\Annegrethe Jansler\ntuser.dat.tmp
2010-01-30 09:14 . 2010-01-30 09:14   245760   ——a-w-  c:\documents and settings\LocalService\NTUSER.DAT.tmp
2010-01-30 09:14 . 2010-01-30 09:14   241664   ——a-w-  c:\documents and settings\NetworkService\NTUSER.DAT.tmp
2010-01-30 09:06 . 2010-01-30 09:03   ————  d——-w-  c:\program files\RegSupreme
2010-01-29 17:08 . 2010-01-29 17:02   ————  d——-w-  c:\program files\Windows Live
2010-01-29 17:08 . 2010-01-29 17:08   ————  d——-w-  c:\program files\Microsoft Sync Framework
2010-01-29 17:07 . 2010-01-29 17:07   ————  d——-w-  c:\program files\Microsoft SQL Server Compact Edition
2010-01-29 17:03 . 2010-01-29 17:03   ————  d——-w-  c:\program files\Microsoft
2010-01-29 17:02 . 2010-01-29 17:02   ————  d——-w-  c:\program files\Windows Live SkyDrive
2010-01-07 15:07 . 2009-06-03 07:35   38224   ——a-w-  c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-06-03 07:35   19160   ——a-w-  c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2006-06-07 08:03   353792   ——a-w-  c:\windows\system32\drivers\srv.sys
2009-12-22 17:47 . 2006-07-30 17:36   107888   ——a-w-  c:\windows\system32\CmdLineExt.dll
2006-06-17 08:42 . 2006-06-17 07:01   88   -csh—r-  c:\windows\system32\526FE2B864.sys
2007-11-24 19:47 . 2007-11-24 19:47   56   -csh—r-  c:\windows\system32\64B8E26F52.sys
2007-11-24 19:47 . 2006-06-17 07:01   1682   -csha-w-  c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2b733a82-1062-47d4-a310-4de03404dc15}]
2010-03-02 09:26   2349080   ——a-w-  c:\program files\danish.ilsc\tbdan1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
“{2b733a82-1062-47d4-a310-4de03404dc15}”= “c:\program files\danish.ilsc\tbdan1.dll” [2010-03-02 2349080]

[HKEY_CLASSES_ROOT\clsid\{2b733a82-1062-47d4-a310-4de03404dc15}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
“{2B733A82-1062-47D4-A310-4DE03404DC15}”= “c:\program files\danish.ilsc\tbdan1.dll” [2010-03-02 2349080]

[HKEY_CLASSES_ROOT\clsid\{2b733a82-1062-47d4-a310-4de03404dc15}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Skype”=“c:\program files\Skype\Phone\Skype.exe” [2008-06-03 21718312]
“SetDefaultMIDI”=“MIDIDef.exe” [2004-12-22 24576]
“PcSync”=“c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe” [2006-06-27 1449984]
“Creative Detector”=“c:\program files\Creative\MediaSource\Detector\CTDetect.exe” [2004-12-02 102400]
“Google Update”=“c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe” [2010-02-04 135664]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2009-08-05 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“hpqSRMon”=“c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe” [2007-08-22 80896]
“avast!”=“c:\progra~1\ALWILS~1\Avast4\ashDisp.exe” [2009-11-24 81000]
“iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe” [2009-10-28 141600]
“sfagent”=“c:\program files\Fighters\SPAMfighter\sfagent.exe” [2010-02-18 386696]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2005-12-14 7323648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“RunNarrator”=“Narrator.exe” [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\ANYCOM\Blue USB-200-250\BTTray.exe [2006-8-18 561213]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
HP Image Zone Hurtig start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-11 73728]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 01:06   40048   -c—a-w-  c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-09-15 08:47   57344   ———w-  c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 02:12   94208   ——a-w-  c:\program files\Dell\Media Experience\DMXLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-14 19:17   49152   ——a-w-  c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
2005-06-08 12:44   196608   ——a-w-  c:\program files\Logitech\Video\ManifestEngine.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 00:54   417792   ——a-w-  c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefaultMIDI]
2004-12-22 16:40   24576   ——a-w-  c:\windows\MIDIDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 00:00   90112   ———w-  c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
2005-09-19 06:42   1159168   ———w-  c:\program files\Creative\VoiceCenter\AndreaVC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusOverride”=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\\system32\\sessmgr.exe”=
“c:\\Program Files\\Messenger\\msmsgs.exe”=
“c:\\WINDOWS\\system32\\dpvsetup.exe”=
“c:\\WINDOWS\\system32\\dpnsvr.exe”=
“c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe”=
“c:\\Program Files\\GameSpy Arcade\\Aphex.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.10.6448-enGB-downloader.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe”=
“c:\\Program Files\\WS_FTP\\WS_FTP95.exe”=
“c:\\Program Files\\Azureus\\Azureus.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“c:\\Program Files\\SmartFTP Client\\SmartFTP.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe”=
“c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enGB-patch-downloader.exe”=
“c:\\WINDOWS\\system32\\mmc.exe”=
“c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe”=
“c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe”=
“c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe”=
“c:\\WINDOWS\\system32\\PnkBstrA.exe”=
“c:\\WINDOWS\\system32\\PnkBstrB.exe”=
“c:\\Program Files\\Bonjour\\mDNSResponder.exe”=
“c:\\Program Files\\iTunes\\iTunes.exe”=
“c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe”=
“c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe”=
“c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe”=
“c:\\Program Files\\Firefly Studios\\Stronghold Crusader\\Stronghold Crusader.exe”=
“c:\\Program Files\\Skype\\Phone\\Skype.exe”=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“3724:TCP”= 3724:TCP:Blizzard Downloader: 3724
“53:TCP”= 53:TCP:websrvx

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27-12-2007 21:52 715248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [03-06-2009 09:00 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [03-06-2009 09:00 20560]
R2 Common Toolkit Service;Common Toolkit Service;c:\program files\Common Files\Common Toolkit Suite\FighterSuiteService.exe [18-02-2010 11:38 684680]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [18-02-2010 11:38 189064]
S2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04-02-2010 07:57 135664]
S3 jfdcd;jfdcd;\??\c:\docume~1\ANNEGR~1\LOCALS~1\Temp\jfdcd.sys—> c:\docume~1\ANNEGR~1\LOCALS~1\Temp\jfdcd.sys [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [31-10-2009 17:12 40448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ     Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ     hpqcxs08 hpqddsvc
.
Indhold af mappen ‘Planlagte Opgaver’

2010-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 06:56]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 06:56]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326295475-2065508634-3725981300-1005Core.job
- c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-22 06:56]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326295475-2065508634-3725981300-1005UA.job
- c:\documents and settings\Annegrethe Jansler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-22 06:56]

2010-03-19 c:\windows\Tasks\Norton Security Scan for Annegrethe Jansler.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-13 11:50]

2010-03-22 c:\windows\Tasks\SLOW-PCfighter-Annegrethe Jansler-Startup.job
- c:\program files\Fighters\SLOW-PCfighter\SLOW-PCfighter.exe [2010-03-10 14:33]

2010-03-22 c:\windows\Tasks\User_Feed_Synchronization-{377361DA-5D6E-45F0-A401-A5E0D02987BD}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
———- Yderligere scanning———-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.janslerbooking.dk/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki ... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send til &Bluetooth;-enhed… - c:\program files\ANYCOM\Blue USB-200-250\btsendto_ie_ctx.htm
Trusted Zone: danid.dk
Trusted Zone: danskebank.dk
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {1469FF24-47F6-11D2-8805-006008C537E3} - hxxp://www.kps.dk/codebase/ffmail.cab
DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} - hxxp://iloapp.cvjob.dk/gallery/executable/IlosoftMultipleImageUpload.dll
DPF: {1E69721D-9104-11D3-82D3-D06650C10000} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/Dafolo.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
DPF: {92EB6641-286A-11D2-A68E-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfsignature.cab
DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {AD90E8D1-3B47-11D2-A696-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfcrypto.cab
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
DPF: {F4F6546F-FBA9-11D1-8AFB-080009ECFDC5} - hxxp://www.diaform.dk/menu/config/version5_ny/codebase/listbox.cab
FF - ProfilePath - c:\documents and settings\Annegrethe Jansler\Application Data\Mozilla\Firefox\Profiles\487kbviw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.janslerbooking.dk/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - TOMME GENVEJE FJERNET - - - -

Notify-avgrsstarter - avgrsstx.dll

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-22 13:38
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 

scanning gennemført med succes
skjulte filer: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys prosync1.sys hal.dll sfsync04.sys sfsync02.sys iastor.sys spho.sys >>UNKNOWN [0x8A940944]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9e69cb8
\Driver\atapi -> sfsync04.sys @ 0xb9e41a7c
\Driver\iaStor -> prosync1.sys @ 0xba5b0661
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel(R) PRO/1000 PL Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xb9bf7bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9c04a21
SendHandler -> NDIS.sys @ 0xb9be287b
user & kernel MBR OK

**************************************************************************
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EA20B5D7-213B-BF6A-A687F1F5E27AC26F}\{EEE35091-0AEA-CF92-BEFE1061EF739928}\{47B248DC-A6E0-641B-BA973614FEEFC865}*]
“NRDFOBLVNAUE2QOGEQXAH1Y2DD1”=hex:01,00,01,00,00,00,00,00,b0,0a,ac,41,7a,16,04,
  de,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
——————————- DLLs startet under kørende Processer——————————-

- - - - - - - > ‘winlogon.exe’(520)
c:\windows\System32\dimsntfy.dll

- - - - - - - > ‘explorer.exe’(3596)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\system32\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_dan.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\SmartFTP Client\smarthook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
————————————Andre kørende processer————————————
.
c:\program files\ANYCOM\Blue USB-200-250\bin\btwdins.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\dllhost.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Gennemført tid: 2010-03-22 13:45:44 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-03-22 12:45
ComboFix2.txt 2010-03-22 07:36
ComboFix3.txt 2009-06-03 07:33

Pre-Kørsel: 176.878.342.144 bytes free
Post-Kørsel: 176.832.262.144 byte ledig

Current=5 Default=5 Failed=4 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - D386B169209A97387B0E6FA241503E2C


—-

Spændt på at høre, hvad du finder ud af grin

Og mange tak, fordi du bruger så megt tid på mig og min computer. Det er meget påskønnet.
grin Jansler

Administrator
Avatar
Antal indlæg: 29177

Åben Notesblok og kopier følgende (tekst med fed skrift) ind - og gem tekst-filen som CFScript samme sted som du har ComboFix:


…………………………………………………………………….


Killall::
Snapshot::
Folder::
c:\documents and settings\Annegrethe Jansler\Application Data\Azureus
File::
c:\windows\system32\526FE2B864.sys
c:\windows\system32\64B8E26F52.sys
c:\docume~1\ANNEGR~1\LOCALS~1\Temp\jfdcd.sys
Filelook::
c:\windows\system32\drivers\etc\hosts
Driver::
jfdcd
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“53:TCP”=-

………………………………………………………………………..


Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du “giver slip” med musen. Som vist her ->

http://www.fromsej.saknet.dk/billeder/swfcombo.gif


Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.


Læg den nye ComboFix log herind. Den kan findes her - C:\combofix Txt