systemgendannelse
  twi
Antal indlæg: 58

Jeg har fået lavet et eller andet på min bærbar pc, den er blevet langsom, står som om at den arbejder konstant med et eller andet, og vil ikke lukke internetsiderne ned (først efter laaang tid)

Jeg kunne godt tænke mig at lave en systemgendannelse men kan ikke komme langt nok tilbage når jeg prøver det. Jeg ved at min pc var perfekt sidst i november og kunne godt tænke mig at stille den tilbage dertil. Men min systemgendannelse kommer kun frem med mulige datoer i december og januar…. Er der noget jeg kan gøre her??

Administrator
Avatar
Antal indlæg: 29619

Hej           wink

Narh, November kan ikke lade sig gøre, men vi kan tjekke computeren, og se om vi kan få den tilbage til normal hastighed ?


Hent DDS og gem programmet på dit Skrivebord:
Her
Dobbeltklik på DDS.scr og tillad programmet at køre.
Når programmet er færdig vil det åbne to logs/tekst-filer.
Gem begge filer på dit Skrivebord og kopier indholdet af txt filerne herind i dit næste indlæg.

Da de er forholdsvis lange, kan du blive nødt til at sende dem i flere indlæg.

  twi
Antal indlæg: 58

er der mon et andet sted jeg kan hente dette program, min pc vil nemlig ikke åbne dit link mad

Administrator
Avatar
Antal indlæg: 29619

Så prøver vi noget andet.


Download OTL af Oldtimer, gem den på dit skrivebord: http://oldtimer.geekstogo.com/OTL.exe
Luk alle åbne vinduer.
Klik på OTL ikonet (for Vista/win7, skal du højreklikke på ikonet og Kør som Administrator) for at starte programmet.
Når vinduet vises, under Output i toppen skift til Minimal Output.

Marker felterne ud for LOP check og Purity Check.

Klik så på Quick Scan.

Det vil give to (2) logfiler på skrivebordet, en kaldet OTL.txt, den anden vil blive navngivet Extras.txt.Husk, hvor du har gemt disse 2 filer.

Da de er forholdsvis lange, kan du blive nødt til at sende dem i flere indlæg.

  twi
Antal indlæg: 58

der er vist noget helt galt. Den side får jeg heller ikke lov at åbne grrr 
Hvad gør vi nu??

Jeg har fra en tidligere rensning nogle programmer liggende, men ved ikke om de kan bruges.
Malwarebytes - HiJack This - CCleaner

Administrator
Avatar
Antal indlæg: 29619

Hvorfor kan du ikke åbne siderne ?


Kør en tur med Ccleaner. Opdater malwarebyte og kør en komplet scan.


Send så malwarebyte loggen herind, sammen med en hijackthis log.

  twi
Antal indlæg: 58

Jeg kunne ikke åbne siderne du gave mig, der skete bare ingenting
Nu har jeg kørt de 3 ting du bad mig om, og nu kan jeg slet ikke bruge internettet på pc’en mere.
Jeg skriver fra en anden computer.
Når jeg prøver at åbne internettet, fortæller den mig:
iexplore.exe programfejl
Instruktion ve 0x77c46fa3 referede hukommelse ved 0x0039d000 hukommelsen kunne ikke written

Jeg har her de 2 logfiler du bad om

  twi
Antal indlæg: 58

Malwarebytes Anti-Malware 1.60.0.1800
http://www.malwarebytes.org

Database version: v2012.01.09.05

Windows XP Service Pack 2 x86 NTFS
Internet Explorer 7.0.5730.13
twillads :: TWILLADS-LT [administrator]

09-01-2012 15:49:11
mbam-log-2012-01-09 (15-49-11).txt

Skanningstype: Fuldstændig skanning
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 356237
Tid gået: 1 time(e), 8 minut(ter), 37 sekund(er)

Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret: 1
HKCU\Software\qni8hj710fdl (Malware.Trace) -> Sat i karantæne og slettet succesfuldt.

Registreringsdatabaseværdier Inficeret: 0
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)

Inficerede Mapper: 0
(Ingen skadelige objekter blev fundet)

Inficerede Filer: 0
(Ingen skadelige objekter blev fundet)

(færdig)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:10:34, on 09-01-2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Arm_Apps\PCS_Service\pcs_service.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\notepad.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] “C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe”
O4 - HKLM\..\Run: [IntelWireless] “C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [McAfeeUpdaterUI] “C:\Program Files\McAfee\Common Framework\UdaterUI.exe” /StartedFromRunKey
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [CloneCDTray] “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s
O4 - HKLM\..\Run: [gemstrmw] C:\WINDOWS\system32\gemstrmw.exe /r
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKLM\..\Run: [AVG_TRAY] “C:\Program Files\AVG\AVG2012\avgtray.exe”
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Program Files\Common Files\Java\Java Update\jusched.exe”
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra ‘Tools’ menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra ‘Tools’ menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra ‘Tools’ menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O17 - HKLM\Software\..\Telephony: DomainName = europe.armstrong.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{956A7058-DD19-4270-8EB1-0051C087D46E}: NameServer = 10.80.16.61,10.80.16.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: AWI_Services - Unknown owner - C:\WINDOWS\system32\awiservices.exs
O23 - Service: Bonjour tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - Unknown owner - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: PCS Service (PCS_service) - Armstrong World Industries - C:\Arm_Apps\PCS_Service\pcs_service.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SMServer - SMServer - C:\WINDOWS\system32\snmvtsvc.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


End of file - 11661 bytes

Administrator
Avatar
Antal indlæg: 29619

Det ligner en firma/arbejds computer ?


Hvis det er tilfældet, så beklager jeg, men vi ordner kun privat computere.

  twi
Antal indlæg: 58

Det er ikke en firmacomputer, men har engang været.
Jeg har købt den til privat brug.
Glemte at sige det til dig.

Administrator
Avatar
Antal indlæg: 29619

Ok, fair nok.


Kør en scanning med Hijackthis, så du kan se alle filer.Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Nu må du fixe. Klik på Fix checked. Det er disse, som skal fixes:

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] “C:\Program Files\McAfee\Common Framework\UdaterUI.exe” /StartedFromRunKey
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [CloneCDTray] “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s
O4 - HKLM\..\Run: [gemstrmw] C:\WINDOWS\system32\gemstrmw.exe /r
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Program Files\Common Files\Java\Java Update\jusched.exe”
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe


Genstart, send en ny hijackthis log herind. Hvis du kan køre OTL eller DDS, så send også logfilerne fra èt af programmerne.

  twi
Antal indlæg: 58

Her kommer en ny logfil fra Hijackthis

Desværre kan OTL eller DDS stadig ikke køres, da jeg stadig ikke kan åbne internettet mad

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:52:44, on 10-01-2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Arm_Apps\PCS_Service\pcs_service.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [IntelZeroConfig] “C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe”
O4 - HKLM\..\Run: [IntelWireless] “C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [AVG_TRAY] “C:\Program Files\AVG\AVG2012\avgtray.exe”
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra ‘Tools’ menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra ‘Tools’ menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra ‘Tools’ menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O17 - HKLM\Software\..\Telephony: DomainName = europe.armstrong.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{956A7058-DD19-4270-8EB1-0051C087D46E}: NameServer = 10.80.16.61,10.80.16.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: AWI_Services - Unknown owner - C:\WINDOWS\system32\awiservices.exs
O23 - Service: Bonjour tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - Unknown owner - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: PCS Service (PCS_service) - Armstrong World Industries - C:\Arm_Apps\PCS_Service\pcs_service.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SMServer - SMServer - C:\WINDOWS\system32\snmvtsvc.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


End of file - 9438 bytes

Administrator
Avatar
Antal indlæg: 29619

Fortæl helt nøjagtigt hvad der sker når du vil på nettet ?


Hent HostsXpert, og udpak den til egen mappe.

http://www.funkytoad.com/download/HostsXpert.zip
Så åbner du HostsXpert, og klikker på – Restore MS Hosts File

Genstart, og fortæl hvordan tingene ser ud nu ?

  twi
Antal indlæg: 58

Når jeg prøver at åbne internettet sker følgende:
Startsiden åbnes med adressen som den prøver at åbne, men siden forbliver blank.
En fejlmeddelelse kommer frem på skærmen:
CiceroUIWndFrame: iexplore.exe - Programfejl
Instruktion ved “0x3ed122ef” refererede hukommelse ved “0x0006fc18”. Hukommelsen kunne ikke “read”.
Klik på OK for at afslutte programmet
Klik på Annuller for at udføre fejlfinding i programmet.

En ny boks fra Internet Explorer åbner derefter:
Internet Explorer har fundet en fejl og afsluttes. Vi beklager ulejligheden.
Informer Microsoft om fejlen….osv

Det var efter at jeg kørte Malwarebyte at den total nægter at åbne internetsider, men der var jo noget galt allerede inden.

Kan jeg mon slette internettet og læse det ind igen?

HostXpert kan jeg desværre ikke komme ind på, da internettet ikke åbner op.

  twi
Antal indlæg: 58

Jeg har nu slettet mit virusprogram AVG free edition, fordi jeg havde en fornemmelse af at det gav problemer. Men det har ikke hjulpet. Der sker nu det at når jeg åbner internettet kommer den hurtig frem med URL adressen foroven og en blank side, men pc’en lukker selv hurtigt siden ned igen som om intet var sket. Fejlmeddelelsen kommer ikke frem længere efter jeg slettede AVG.

Funkytoad kunne jeg kopiere til en USB stick og har nu kørt den på min syge computer.

Herefter er det det samme som sker når internettet forsøges (åbner op med blank side og lukker hurtigt igen)

  twi
Antal indlæg: 58

Jeg har nu fundet ud af at lægge OTL på en USB stick grin så her kommer de 2 logfiler:

OTL logfile created on: 11-01-2012 09:04:07 - Run 1
OTL by OldTimer - Version 3.2.31.0   Folder = C:\Documents and Settings\twillads.EUROPE\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000406 | Country: Denmark | Language: DAN | Date Format: dd-MM-yyyy

1,24 Gb Total Physical Memory | 0,83 Gb Available Physical Memory | 66,98% Memory free
2,57 Gb Paging File | 2,31 Gb Available in Paging File | 89,90% Paging File free
Paging file location(s): C:\pagefile.sys 1512 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 58,59 Gb Total Space | 32,82 Gb Free Space | 56,01% Space Free | Partition Type: NTFS
Drive E: | 34,56 Gb Total Space | 27,84 Gb Free Space | 80,56% Space Free | Partition Type: NTFS
Drive F: | 488,48 Mb Total Space | 395,25 Mb Free Space | 80,91% Space Free | Partition Type: FAT

Computer Name: TWILLADS-LT | User Name: twillads | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\twillads.EUROPE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Arm_Apps\PCS_Service\pcs_service.exe (Armstrong World Industries)
PRC - C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel(R) Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\bcm1xsup.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\acAuth.dll ()


========== Win32 Services (SafeList) ==========

SRV - (DWMRCS)—C:\WINDOWS\System32\DWRCS.EXE ()
SRV - (SMServer)—C:\WINDOWS\System32\snmvtsvc.exe (SMServer)
SRV - (McAfeeFramework)—C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (PCS_service)—C:\Arm_Apps\PCS_Service\pcs_service.exe (Armstrong World Industries)
SRV - (CcmExec)—C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (Wuser32)—C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe (Microsoft Corporation)
SRV - (WLANKEEPER) Intel(R)—C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel(R) Corporation)
SRV - (Lotus Notes Single Logon)—C:\WINDOWS\system32\nslsvice.exe (IBM Corp)
SRV - (AWI_Services)—C:\WINDOWS\system32\AWIServices.exs ()
SRV - (ExtranetAccess)—C:\Program Files\Nortel Networks\Extranet_serv.exe (Nortel Networks NA, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SndTVideo)—C:\WINDOWS\system32\drivers\SndTVideo.sys (Windows (R) 2000 DDK provider)
DRV - (SndTAudio)—C:\WINDOWS\system32\drivers\SndTAudio.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (s117obex)—C:\WINDOWS\system32\drivers\s117obex.sys (MCCI Corporation)
DRV - (s117mdm)—C:\WINDOWS\system32\drivers\s117mdm.sys (MCCI Corporation)
DRV - (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM)—C:\WINDOWS\system32\drivers\s117mgmt.sys (MCCI Corporation)
DRV - (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM)—C:\WINDOWS\system32\drivers\s117unic.sys (MCCI Corporation)
DRV - (s117mdfl)—C:\WINDOWS\system32\drivers\s117mdfl.sys (MCCI Corporation)
DRV - (s117bus) Sony Ericsson Device 117 driver (WDM)—C:\WINDOWS\system32\drivers\s117bus.sys (MCCI Corporation)
DRV - (prepdrvr)—C:\WINDOWS\system32\CCM\PrepDrv.sys (Microsoft Corporation)
DRV - (s24trans)—C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (ElbyCDFL)—C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (w29n51) Intel(R)—C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (b57w2k)—C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (GTIPCI21)—C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (NWADI)—C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (kbstuff)—C:\WINDOWS\system32\drivers\kbstuff5.sys (Microsoft Corporation)
DRV - (idisw2km)—C:\WINDOWS\system32\drivers\idisw2km.sys (Microsoft Corporation)
DRV - (HSF_DPV)—C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH)—C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf)—C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97)—C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (GTwinUSB)—C:\WINDOWS\system32\drivers\GTwinUSB.sys (Gemplus)
DRV - (Eacfilt)—C:\WINDOWS\system32\drivers\eacfilt.sys (Nortel Networks)
DRV - (IPSECSHM)—C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks)
DRV - (IPSECEXT)—C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks)
DRV - (OMCI)—C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (GEMPC430)—C:\WINDOWS\system32\drivers\grclass.sys (Gemplus)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = <local>;*.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: “http://google.dk/”
FF - prefs.js..extensions.enabledItems: .:1.0
FF - prefs.js..network.proxy.ftp: “bieas001”
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher: “bieas001”
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: “bieas001”
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: “10.*,*.europe.armstrong.com,*.americas.armstrong.com,*.pacrim.armstrong.com,intra.armstrong.com,localhost,127.0.0.1”
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: “bieas001”
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl: “bieas001”
FF - prefs.js..network.proxy.ssl_port: 80

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)


[2011-11-01 17:31:03 | 000,003,674 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Application Data\Mozilla\Firefox\Profiles\qhl0np61.default\searchplugins\avg-secure-search.xml

O1 HOSTS File: ([2012-01-11 08:48:43 | 000,000,698 |——| M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuNetworkPlaces = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra ‘Tools’ menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra ‘Tools’ menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra ‘Tools’ menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.80.12.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{26B97A4A-0666-4FFB-87FF-D5108064136F}: DhcpNameServer = 10.80.12.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5B171258-283A-4B9F-A7A7-461D357D1E5B}: DhcpNameServer = 193.162.153.164 194.239.134.83
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{956A7058-DD19-4270-8EB1-0051C087D46E}: NameServer = 10.80.16.61,10.80.16.62
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\Controls\SAPHTMLP.DLL File not found
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\Controls\SAPHTMLP.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Min aktuelle startside) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\twillads.EUROPE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\twillads.EUROPE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007-11-09 14:39:45 | 000,000,000 |——| M] () - C:\AUTOEXEC.BAT—[ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open]—“%1” %*
O35 - HKLM\..exefile [open]—“%1” %*
O37 - HKLM\...com [@ = ComFile]—“%1” %*
O37 - HKLM\...exe [@ = exefile]—“%1” %*

========== Files/Folders - Created Within 30 Days ==========

[2012-01-11 09:02:19 | 000,584,192 |——| C] (OldTimer Tools)—C:\Documents and Settings\twillads.EUROPE\Desktop\OTL.exe
[2012-01-09 13:23:51 | 000,000,000 | RH-D | C]—C:\Documents and Settings\twillads.EUROPE\Recent
[2011-12-28 21:24:28 | 000,000,000 |—-D | C]—C:\Program Files\Common Files\Java
[2011-12-25 09:44:11 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2011-12-24 15:42:56 | 000,000,000 |—-D | C]—C:\QUARANTINE
[2011-12-24 15:42:56 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\McAfee
[2011-12-24 15:42:45 | 000,000,000 |—-D | C]—C:\Program Files\McAfee
[2011-12-24 15:41:30 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\Lotus Applications
[2011-12-12 15:25:49 | 000,000,000 |—-D | C]—C:\Program Files\Microsoft Visual Studio 8
[2011-12-12 15:22:19 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Microsoft Help

========== Files - Modified Within 30 Days ==========

[2012-01-11 09:02:20 | 000,584,192 |——| M] (OldTimer Tools)—C:\Documents and Settings\twillads.EUROPE\Desktop\OTL.exe
[2012-01-11 08:52:25 | 000,000,455 |——| M] ()—C:\WINDOWS\SMSCFG.ini
[2012-01-11 08:50:30 | 000,002,048 |—S- | M] ()—C:\WINDOWS\bootstat.dat
[2012-01-11 08:46:12 | 000,000,273 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Desktop\Genvej til HostsXpert.lnk
[2012-01-10 16:56:58 | 000,002,497 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Desktop\Microsoft Office Word 2003.lnk
[2012-01-09 13:27:03 | 000,000,784 |——| M] ()—C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012-01-09 08:41:15 | 000,000,177 |——| M] ()—C:\WINDOWS\hpbafd.ini
[2012-01-09 08:34:39 | 000,002,206 |——| M] ()—C:\WINDOWS\System32\wpa.dbl
[2012-01-07 15:27:48 | 000,000,664 |——| M] ()—C:\WINDOWS\System32\d3d9caps.dat
[2011-12-24 15:46:51 | 000,265,416 |——| M] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2011-12-24 15:12:12 | 000,000,412 | -H—| M] ()—C:\WINDOWS\tasks\MP Scheduled Signature Update.job
[2011-12-24 15:12:11 | 000,000,430 | -H—| M] ()—C:\WINDOWS\tasks\MP Scheduled Quick Scan.job
[2011-12-24 15:12:09 | 000,000,406 | -H—| M] ()—C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011-12-24 13:37:22 | 000,214,016 |——| M] ()—C:\WINDOWS\System32\DWRCS.EXE
[2011-12-12 11:19:34 | 000,120,832 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Application Data\fin.zup
[2011-12-12 10:06:17 | 000,000,284 |——| M] ()—C:\WINDOWS\tasks\AppleSoftwareUpdate.job

========== Files Created - No Company Name ==========

[2012-01-11 08:46:12 | 000,000,273 |——| C] ()—C:\Documents and Settings\twillads.EUROPE\Desktop\Genvej til HostsXpert.lnk
[2012-01-09 13:27:03 | 000,000,784 |——| C] ()—C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2009-11-01 21:01:21 | 000,000,552 |——| C] ()—C:\WINDOWS\System32\d3d8caps.dat
[2009-11-01 20:39:48 | 000,000,664 |——| C] ()—C:\WINDOWS\System32\d3d9caps.dat
[2009-07-08 14:08:14 | 000,005,120 |——| C] ()—C:\Documents and Settings\twillads.EUROPE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-01-21 11:28:47 | 000,000,000 |——| C] ()—C:\WINDOWS\nsreg.dat
[2008-11-12 10:44:26 | 000,183,310 |——| C] ()—C:\WINDOWS\hpoins21.dat
[2008-11-12 10:44:26 | 000,007,262 |——| C] ()—C:\WINDOWS\hpomdl21.dat
[2008-04-15 12:43:59 | 000,000,455 |——| C] ()—C:\WINDOWS\SMSCFG.ini
[2007-11-14 10:58:14 | 000,120,832 |——| C] ()—C:\Documents and Settings\twillads.EUROPE\Application Data\fin.zup
[2007-11-12 15:02:14 | 000,214,016 |——| C] ()—C:\WINDOWS\System32\DWRCS.EXE
[2007-11-12 14:40:50 | 000,000,177 |——| C] ()—C:\WINDOWS\hpbafd.ini
[2007-11-12 09:14:14 | 000,001,558 | R—- | C] ()—C:\WINDOWS\saplogon.ini
[2007-11-12 09:12:40 | 000,045,132 |——| C] ()—C:\WINDOWS\System32\libsapu16.dll
[2007-11-12 09:12:34 | 000,081,920 |——| C] ()—C:\WINDOWS\System32\nlsxdsgn.dll
[2007-11-12 09:12:32 | 003,203,072 |——| C] ()—C:\WINDOWS\System32\lcppn201.dll
[2007-11-12 09:07:31 | 000,175,616 |——| C] ()—C:\WINDOWS\System32\h5menu32.dll
[2007-11-12 09:07:31 | 000,095,744 |——| C] ()—C:\WINDOWS\System32\h5rtf32.dll
[2007-11-12 09:07:31 | 000,051,200 |——| C] ()—C:\WINDOWS\System32\h5tool32.dll
[2007-11-12 09:07:30 | 001,064,960 |——| C] ()—C:\WINDOWS\System32\h5krnl32.dll
[2007-11-12 09:07:29 | 000,188,928 |——| C] ()—C:\WINDOWS\System32\h5icon32.dll
[2007-11-12 09:07:12 | 000,015,872 |——| C] ()—C:\WINDOWS\System32\vtssm32.dll
[2007-11-12 08:56:36 | 000,000,104 |——| C] ()—C:\WINDOWS\notesnsd.ini
[2007-11-11 08:56:23 | 000,000,376 |——| C] ()—C:\WINDOWS\ODBC.INI
[2007-11-09 18:04:45 | 000,192,512 |——| C] ()—C:\WINDOWS\System32\stac97co.dll
[2007-11-09 16:22:14 | 000,086,016 |——| C] ()—C:\WINDOWS\System32\preflib.dll
[2007-11-09 16:22:13 | 000,757,760 |——| C] ()—C:\WINDOWS\System32\bcm1xsup.dll
[2007-11-09 16:22:13 | 000,020,480 |——| C] ()—C:\WINDOWS\System32\WLTRYSVC.EXE
[2007-11-09 15:27:32 | 000,004,161 |——| C] ()—C:\WINDOWS\ODBCINST.INI
[2007-11-09 15:26:23 | 000,265,416 |——| C] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2007-11-09 14:42:47 | 000,002,048 |—S- | C] ()—C:\WINDOWS\bootstat.dat
[2007-11-09 14:36:33 | 000,021,640 |——| C] ()—C:\WINDOWS\System32\emptyregdb.dat
[2005-10-14 15:09:48 | 000,051,304 |——| C] ()—C:\WINDOWS\System32\drivers\atnt40k.sys
[2005-03-22 02:48:05 | 013,107,200 |——| C] ()—C:\WINDOWS\System32\oembios.bin
[2005-03-22 02:48:05 | 000,004,627 |——| C] ()—C:\WINDOWS\System32\oembios.dat
[2004-08-04 13:00:00 | 000,673,088 |——| C] ()—C:\WINDOWS\System32\mlang.dat
[2004-08-04 13:00:00 | 000,486,792 |——| C] ()—C:\WINDOWS\System32\perfh009.dat
[2004-08-04 13:00:00 | 000,272,128 |——| C] ()—C:\WINDOWS\System32\perfi009.dat
[2004-08-04 13:00:00 | 000,218,003 |——| C] ()—C:\WINDOWS\System32\dssec.dat
[2004-08-04 13:00:00 | 000,086,472 |——| C] ()—C:\WINDOWS\System32\perfc009.dat
[2004-08-04 13:00:00 | 000,046,258 |——| C] ()—C:\WINDOWS\System32\mib.bin
[2004-08-04 13:00:00 | 000,028,626 |——| C] ()—C:\WINDOWS\System32\perfd009.dat
[2004-08-04 13:00:00 | 000,004,569 |——| C] ()—C:\WINDOWS\System32\secupd.dat
[2004-08-04 13:00:00 | 000,001,788 |——| C] ()—C:\WINDOWS\System32\Dcache.bin
[2004-08-04 13:00:00 | 000,000,741 |——| C] ()—C:\WINDOWS\System32\noise.dat
[2003-01-07 15:05:08 | 000,002,695 |——| C] ()—C:\WINDOWS\System32\OUTLPERF.INI
[2000-12-14 05:26:30 | 000,057,344 |——| C] ()—C:\WINDOWS\System32\adssecurity.dll
[1999-12-02 20:53:44 | 000,080,896 |——| C] ()—C:\WINDOWS\System32\DUMPEL.EXE
[1999-12-02 19:54:58 | 000,091,648 |——| C] ()—C:\WINDOWS\System32\XCACLS.EXE
[1999-10-25 04:39:16 | 000,015,872 |——| C] ()—C:\WINDOWS\System32\wwiolib.dll
[1997-04-30 21:43:42 | 000,016,896 |——| C] ()—C:\WINDOWS\System32\witzsrch.dll

========== LOP Check ==========

[2011-12-08 09:00:27 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012-01-11 08:40:22 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\AVG2012
[2011-05-16 12:20:25 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\Common Files
[2007-12-17 15:37:44 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\e-Safekey
[2012-01-11 08:39:25 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\MFAData
[2008-10-22 09:38:16 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2008-12-04 20:37:00 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Network Associates
[2007-11-09 18:08:11 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2007-12-26 22:32:15 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\SlySoft
[2009-10-30 21:05:00 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010-04-29 17:35:48 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011-11-01 17:29:30 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\AVG2012
[2008-10-27 08:31:16 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\ieSpell
[2008-11-19 13:13:55 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\Productivity Tools
[2009-11-02 14:35:35 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\Sports Interactive
[2008-11-19 13:59:21 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\Webex
[2011-12-24 15:12:11 | 000,000,430 | -H—| M] ()—C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
[2011-12-24 15:12:09 | 000,000,406 | -H—| M] ()—C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011-12-24 15:12:12 | 000,000,412 | -H—| M] ()—C:\WINDOWS\Tasks\MP Scheduled Signature Update.job

========== Purity Check ==========

< End of report >