Min computer (Win7 x64) er ramt af nogle forskellige vira. Mit Antivirusprogram F-Secure har fundet to objekter: ét er et program mplayer.exe og det andet er en .exe fil jeg selv har lavet ud fra en batch fil jeg skrev for noget tid siden. Jeg ville dog gerne tjekke dette og er således begyndt på guiden.
I går kørte jeg
- F-Secure
- Malwarebytes Anti-Malware (Glemte dog at gemme loggen, så jeg vil køre det efter ESET)
I dag:
- Ccleaner (Bruger det ofte)
- Er nu i gang med ESET online scanner, der i skrivende stund har fundet en trussel.
Jeg glemte lige at skrive at jeg mister internetforbindelsen ret ofte lige nu. Jeg ved dog ikke om det skyldes vira eller om det skyldes min router, da den har drillet mig tidligere.
Godt, ESET er stadig i gang har har nu fundet 5 trusler, men hvad gør jeg ved dem? Fjerner ESET dem? Jeg synes det står så klart i vejledningen.
urup11 - 08.04.2012 18:57:56
Godt, ESET er stadig i gang har har nu fundet 5 trusler, men hvad gør jeg ved dem? Fjerner ESET dem? Jeg synes det står så klart i vejledningen.
Jeg har lige opdaget en skrivefejl. Jeg synes “IKKE” det står så klart i vejledningen. Jeg håber der er en venlig sjæl, som vil hjælpe mig fordi jeg er ikke så sikker på hvordan jeg for fjernet alt skidtet
urup11 - 08.04.2012 17:10:33
Jeg glemte lige at skrive at jeg mister internetforbindelsen ret ofte lige nu. Jeg ved dog ikke om det skyldes vira eller om det skyldes min router, da den har drillet mig tidligere.
Internetforbindelsen ryger ca. hvert 33. minut, sådan at der kommer en lille advarselstrekant nede ved internetikonet i proceslinjen. Jeg kan genetablere forbindelsen hvis jeg slukker min router et øjeblik, men det virkelig interessante her er at hvis jeg pinger min router får jeg svar tilbage.
Er der en venlig sjæl, som vil fortælle mig hvordan jeg bruger de logs jeg får ud af mine scanninger?
Administrator
Antal indlæg: 55502
Velkommen til Spywarefri.
Lad os se de logs du har, så tager vi den derfra.
Signatur
qui potest, obligatur
Nierne bomaye - You’ll never walk alone
Kaffen er drukket
Kassen er lukket
Støtten gør mere nytte
Hos de små og forknytte
Børns vilkår
Hospitalsklovne
Mange tak!
Jamen nu har jeg ESET og Malwarebytes Anti-Malware
ESET log:
C:\multiAVCHD\tools\process.exe Win32/PrcView application
C:\Users\Michael\Downloads\cdbxp_setup_4.3.8.2560.exe Win32/OpenCandy application
G:\PDFCreator-1_3_1_setup.exe Win32/OpenCandy application
G:\Installations Filer x64\CrystalDiskInfo3_10_0-en.exe Win32/OpenCandy application
G:\Installatons filer x86\Hirens.BootCD.13.1.zip Win32/PSWTool.KonBoot.A application
G:\Installatons filer x86\Hirens.BootCD.13.1\DK Patched Hiren’s.BootCD.13.1.iso Win32/PSWTool.KonBoot.A application
G:\Installatons filer x86\Hirens.BootCD.13.1\Hirens.BootCD.13.1.zip Win32/PSWTool.KonBoot.A application
G:\Installatons filer x86\Hirens.BootCD.13.1\mappe\Hiren’s.BootCD.13.1.iso Win32/PSWTool.KonBoot.A application
G:\Programmer\Miro_Installer.exe Win32/Toolbar.Zugo application
Malwarebytes’ log:
Malwarebytes Anti-Malware 1.60.1.1000
http://www.malwarebytes.org
Database version: v2012.04.08.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Michael :: MICHAEL-PC [administrator]
08-04-2012 20:04:05
mbam-log-2012-04-08 (21-09-10).txt
Skanningstype: Fuldstændig skanning
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 524153
Tid gået: 1 time(e), 3 minut(ter), 39 sekund(er)
Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabaseværdier Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)
Inficerede Mapper: 0
(Ingen skadelige objekter blev fundet)
Inficerede Filer: 2
G:\Michael\Adobe CS4 Master Collection\Adobe CS4 Master Collection\adobe-master-cs4-keygen.exe (Trojan.Downloader) -> Ingen handling valgt.
G:\Michael\Adobe CS4 Master Collection\Photoshop Crack\Adobe CS4 Master Collection Keygen.exe (Trojan.Downloader) -> Ingen handling valgt.
(færdig)
Jeg har installeret og påbegyndt scanning med SuperAntiSpyware programmet. Vil det ikke være en god idé hvis jeg slette alle de installationsfiler jeg har fået, som lægger på G-drevet?
SuperAntiSpyware finder ikke noget:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Genereret 04/08/2012 at 10:21 PM
Applikation Version : 5.0.1146
Kerne Regler Database Version : 8424
Spore Regler Database Version: 6236
Scan type : Komplet Skan
Total skanningstid : 00:53:52
Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User
Skannet poster i hukommelse : 656
Trusler i hukommelse fundet : 0
Registrerings poster skannet : 73245
Registrerings trusler fundet : 0
Fil poster skannet : 116421
Fil trusler fundet : 0
Administrator
Antal indlæg: 55502
Alt hvad der hedder cracks og andre former for illegale ting, skal væk.
Det gælder også Hiren´s boot-CD, der er ting på den, hvor licenserne ikke er i orden.
De værktøjer, man typisk har brug for, ligger på Ultimate Boot CD.
http://www.ultimatebootcd.com/
Hent Combofix, og gem den i en mappe:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Åbn mappen med Combofix, højreklik et tomt sted i mappen, vælg Ny->tekstdokument, åbn tekstdokumentet, kopier følgende ind:
Killall::
Snapshot::
File::
G:\Installatons filer x86\Hirens.BootCD.13.1.zip
Folder::
G:\Michael\Adobe CS4 Master Collection
G:\Installatons filer x86\Hirens.BootCD.13.1
klik på Filer->Gem som, navngiv den CFScript, luk tekstdokumentet.
Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du “giver slip” med musen.
http://www.fromsej.saknet.dk/billeder/swfcombo.gif
Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Kopier den fremkomne log herind.
Får du noget der ligner denne fejl.
Der blev forsøgt en ugyldig handling på en registreringsdatabasenøgle, som er blevet mærket til sletning
Så genstart, en gang mere, det burde løse det.
Signatur
qui potest, obligatur
Nierne bomaye - You’ll never walk alone
Kaffen er drukket
Kassen er lukket
Støtten gør mere nytte
Hos de små og forknytte
Børns vilkår
Hospitalsklovne
Eftersom Anti-Malware fandt noget i CS4 mappen slettede jeg den igår, måske ikke lige det klogeste?
Jeg har ikke haft cracket software installeret på computeren. Det er udelukkende selve installationsfilerne, som jeg har fået af en kammerat
ComboFix log (del 1)
ComboFix 12-04-08.02 - Michael 09-04-2012 12:30:04.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.45.1030.18.4023.2100 [GMT 2:00]
Kører fra: c:\users\Michael\Desktop\combo\ComboFix.exe
Kommandoer benyttet :: c:\users\Michael\Desktop\combo\CFScript.txt
AV: F-Secure Internet Security 2011 10.51 *Disabled/Updated* {15414183-282E-D62C-CA37-EF24860A2F17}
FW: F-Secure Internet Security 2011 10.51 *Enabled* {2D7AC0A6-6241-D774-E168-461178D9686C}
SP: F-Secure Internet Security 2011 10.51 *Disabled/Updated* {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
“g:\installatons filer x86\Hirens.BootCD.13.1.zip”
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
g:\installatons filer x86\Hirens.BootCD.13.1
g:\installatons filer x86\Hirens.BootCD.13.1.zip
g:\installatons filer x86\Hirens.BootCD.13.1\BurnCDCC.exe
g:\installatons filer x86\Hirens.BootCD.13.1\BurnToCD.cmd
g:\installatons filer x86\Hirens.BootCD.13.1\data.dat
g:\installatons filer x86\Hirens.BootCD.13.1\DefaultKeyboardPatch.zip
g:\installatons filer x86\Hirens.BootCD.13.1\DK Patched Hiren’s.BootCD.13.1.iso
g:\installatons filer x86\Hirens.BootCD.13.1\HBCD.txt
g:\installatons filer x86\Hirens.BootCD.13.1\Hirens.BootCD.13.1.zip
g:\installatons filer x86\Hirens.BootCD.13.1\mappe\BurnCDCC.exe
g:\installatons filer x86\Hirens.BootCD.13.1\mappe\BurnToCD.cmd
g:\installatons filer x86\Hirens.BootCD.13.1\mappe\DefaultKeyboardPatch.zip
g:\installatons filer x86\Hirens.BootCD.13.1\mappe\HBCD.txt
g:\installatons filer x86\Hirens.BootCD.13.1\mappe\Hiren’s.BootCD.13.1.iso
g:\installatons filer x86\Hirens.BootCD.13.1\Patch.cmd
g:\installatons filer x86\Hirens.BootCD.13.1\PatchInfo.txt
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2012-03-09 til 2012-04-09 )))))))))))))))))))))))))))))))))))
.
.
2012-04-09 10:41 . 2012-04-09 10:41 ———— d——-w- c:\users\UpdatusUser\AppData\Local\temp
2012-04-09 10:41 . 2012-04-09 10:41 ———— d——-w- c:\users\Default\AppData\Local\temp
2012-04-08 21:16 . 2012-04-08 21:16 283200 ——a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-04-08 21:16 . 2012-04-08 21:16 ———— d——-w- c:\program files (x86)\DAEMON Tools Lite
2012-04-08 20:53 . 2012-04-08 20:54 ———— d——-w- c:\program files (x86)\LibreOffice 3.4
2012-04-08 19:26 . 2012-04-08 19:26 ———— d——-w- c:\users\Michael\AppData\Roaming\SUPERAntiSpyware.com
2012-04-08 19:26 . 2012-04-08 19:26 ———— d——-w- c:\program files\SUPERAntiSpyware
2012-04-08 19:26 . 2012-04-08 19:26 ———— d——-w- c:\programdata\SUPERAntiSpyware.com
2012-04-08 18:00 . 2010-04-29 13:39 38224 ——a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2012-04-08 18:00 . 2011-12-10 13:24 23152 ——a-w- c:\windows\system32\drivers\mbam.sys
2012-04-08 18:00 . 2012-04-08 18:02 ———— d——-w- c:\program files (x86)\Malwarebytes’ Anti-Malware
2012-04-08 14:03 . 2012-04-08 14:03 ———— d——-w- c:\program files (x86)\ESET
2012-04-06 22:52 . 2012-04-06 22:52 ———— d——-w- c:\program files (x86)\COOL.STF
2012-04-06 20:27 . 2012-04-06 20:27 ———— d——-w- c:\users\Michael\AppData\Roaming\MPEG Streamclip
2012-04-01 15:27 . 2012-04-09 10:04 ———— d——-w- c:\program files (x86)\Skolekom
2012-04-01 15:27 . 2012-04-01 15:27 ———— d——-w- c:\programdata\FirstClass
2012-03-31 11:02 . 2012-03-31 11:02 ———— d——-w- c:\program files\iPod
2012-03-31 11:02 . 2012-03-31 11:02 ———— d——-w- c:\program files\iTunes
2012-03-31 11:02 . 2012-03-31 11:02 ———— d——-w- c:\program files (x86)\iTunes
2012-03-31 10:33 . 2012-03-31 10:33 ———— d——-w- C:\found.000
2012-03-31 10:02 . 2012-03-31 10:03 ———— d——-w- c:\program files (x86)\Google
2012-03-31 09:07 . 2012-03-31 09:08 418464 ——a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-31 09:00 . 2012-03-31 09:00 ———— d——-w- c:\program files (x86)\Heimdal
2012-03-31 09:00 . 2012-03-31 09:00 ———— d——-w- c:\programdata\CSIS
2012-03-31 08:52 . 2012-03-31 08:52 ———— d——-w- c:\users\buildbot
2012-03-24 11:46 . 2012-03-24 11:46 ———— d——-w- c:\users\Michael\AppData\Roaming\pdfforge
2012-03-24 11:46 . 2012-03-14 16:23 65024 ——a-w- c:\windows\system32\pdfcmon.dll
2012-03-24 11:46 . 1998-06-23 23:00 137000 ——a-w- c:\windows\SysWow64\MSMAPI32.OCX
2012-03-24 11:45 . 1998-07-05 23:00 23552 ——a-w- c:\windows\SysWow64\MSMPIDE.DLL
2012-03-24 11:45 . 2012-03-24 11:46 ———— d——-w- c:\program files (x86)\PDFCreator
2012-03-14 10:59 . 2011-11-19 15:20 5559152 ——a-w- c:\windows\system32\ntoskrnl.exe
2012-03-14 10:59 . 2011-11-19 14:50 3968368 ——a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 10:59 . 2011-11-19 14:50 3913584 ——a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 09:42 . 2012-02-03 04:34 3145728 ——a-w- c:\windows\system32\win32k.sys
2012-03-14 09:42 . 2012-02-10 06:36 1544192 ——a-w- c:\windows\system32\DWrite.dll
2012-03-14 09:42 . 2012-02-10 05:38 1077248 ——a-w- c:\windows\SysWow64\DWrite.dll
2012-03-14 09:32 . 2012-01-25 06:38 77312 ——a-w- c:\windows\system32\rdpwsx.dll
2012-03-14 09:32 . 2012-01-25 06:38 149504 ——a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-14 09:32 . 2012-01-25 06:33 9216 ——a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-14 09:32 . 2012-02-17 06:38 1031680 ——a-w- c:\windows\system32\rdpcore.dll
2012-03-14 09:32 . 2012-02-17 05:34 826880 ——a-w- c:\windows\SysWow64\rdpcore.dll
2012-03-14 09:32 . 2012-02-17 04:58 210944 ——a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-14 09:32 . 2012-02-17 04:57 23552 ——a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-10 22:31 . 2012-03-10 22:31 ———— d——-w- c:\users\Michael\AppData\Roaming\Tobit
2012-03-10 22:31 . 2012-03-10 22:31 ———— d——-w- c:\program files (x86)\Tobit Radio.fx
2012-03-10 22:31 . 2012-03-10 22:31 ———— d——-w- c:\program files (x86)\Common Files\Tobit
2012-03-10 22:31 . 2011-07-05 15:53 3528024 ——a-w- c:\windows\RXCUnins.exe
2012-03-10 22:31 . 2011-07-05 15:53 3528024 ——a-w- c:\windows\RXSUnins.exe
2012-03-10 22:31 . 2010-01-20 10:49 554496 ——a-w- c:\windows\SysWow64\dvmsg.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-09 10:43 . 2011-05-20 16:15 29 ——a-w- c:\windows\SysWow64\TempWmicBatchFile.bat
2012-03-31 09:08 . 2011-05-19 20:45 70304 ——a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-03 20:39 . 2011-06-14 12:05 48648 ——a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-03-03 20:33 . 2012-03-03 20:33 162664 ——a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
2012-02-21 23:33 . 2011-07-11 13:20 472808 ——a-w- c:\windows\SysWow64\deployJava1.dll
2012-02-07 08:21 . 2011-06-21 11:00 48648 ——a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
“{1392b8d2-5c05-419f-a8f6-b9f15a596612}”= “c:\program files (x86)\Freecorder\prxtbFre2.dll” [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
2011-05-09 09:49 176936 ——a-w- c:\program files (x86)\Freecorder\prxtbFre2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
“{1392b8d2-5c05-419f-a8f6-b9f15a596612}”= “c:\program files (x86)\Freecorder\prxtbFre2.dll” [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@=”{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ——a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@=”{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ——a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@=”{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ——a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SUPERAntiSpyware”=“c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2012-03-07 4785536]
“DAEMON Tools Lite”=“c:\program files (x86)\DAEMON Tools Lite\DTLite.exe” [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
“HPCam_Menu”=“c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe” [2009-05-19 222504]
“QlbCtrl.exe”=“c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe” [2009-08-20 322104]
“Easybits Recovery”=“c:\program files (x86)\EasyBits For Kids\ezRecover.exe” [2009-09-02 60464]
“WirelessAssistant”=“c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe” [2009-07-23 498744]
“Freecorder FLV Service”=“c:\program files (x86)\Freecorder\FLVSrvc.exe” [2011-03-24 167936]
“F-Secure Manager”=“c:\program files (x86)\F-Secure\Common\FSM32.EXE” [2011-08-14 201384]
“F-Secure TNB”=“c:\program files (x86)\F-Secure\FSGUI\TNBUtil.exe” [2011-08-14 1655464]
“HP Software Update”=“c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe” [2008-12-08 54576]
“APSDaemon”=“c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe” [2012-02-20 59240]
“QuickTime Task”=“c:\program files (x86)\QuickTime\QTTask.exe” [2011-10-24 421888]
“Adobe ARM”=“c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2012-01-03 843712]
“SunJavaUpdateSched”=“c:\program files (x86)\Common Files\Java\Java Update\jusched.exe” [2012-01-18 254696]
“iTunesHelper”=“c:\program files (x86)\iTunes\iTunesHelper.exe” [2012-03-27 421736]
.
c:\users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-15 24246216]
Skærmklipper og startprogram til OneNote 2010.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 1081632]
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“ConsentPromptBehaviorAdmin”= 5 (0x5)
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableUIADesktopToggle”= 0 (0x0)
“HideFastUserSwitching”= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
“aux2”=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=”“
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Tjeneste (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-31 136176]
R2 HeimdalSecureDNS;Heimdal Secure DNS Service;c:\program files (x86)\Heimdal\HeimdalSecureDNS\DnsService.exe [2011-11-24 79976]
R2 HeimdalService;Heimdal Service;c:\program files (x86)\Heimdal\Service\HeimdalAgentService.exe [2011-11-24 106088]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 253600]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys [x]
R3 gupdatem;Google Update Tjeneste (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-31 136176]
R3 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
R3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [x]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files (x86)\F-Secure\HIPS\drivers\fshs.sys [2011-08-14 61960]
S1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys [x]
S1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [x]
S1 fsvista;F-Secure Vista Support Driver;c:\program files (x86)\F-Secure\Anti-Virus\minifilter\fsvista.sys [2011-08-14 15016]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-03-02 89600]
S2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2011-02-15 19968]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-25 92216]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 Radio.fx;Radio.fx Server;c:\program files (x86)\Tobit Radio.fx\Server\rfx-server.exe [2011-11-18 3673944]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-04-19 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-04-19 399416]
S2 TVService;TVService;c:\program files (x86)\Team MediaPortal\MediaPortal TV Server\TVService.exe [2011-12-20 212992]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files (x86)\F-Secure\Anti-Virus\minifilter\fsgk.sys [2011-09-08 198808]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files (x86)\F-Secure\ORSP Client\fsorsp.exe [2011-08-14 61088]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
. —- Andre Services/Drivers i Hukommelsen—-
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ——a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen ‘Planlagte Opgaver’
.
2012-04-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 09:08]
.
2012-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-31 10:02]
.
2012-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-31 10:02]
.
2012-04-09 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~2\F-Secure\ANTI-V~1\fsav.exe [2011-08-14 16:04]
.
. ————- x86-64—————-
ComboFix log del 2:
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@=”{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ——a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@=”{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ——a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@=”{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ——a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@=”{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}”
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ——a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SysTrayApp”=“c:\program files\IDT\WDM\sttray64.exe” [2010-03-23 487424]
“SmartMenu”=“c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe” [2009-08-25 610872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
“LoadAppInit_DLLs”=0x0
. ———- Yderligere scanning———-
.
uStart Page = hxxp://google.dk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter; til Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: S&end; til OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Send billede til &Bluetooth;-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth;-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files (x86)\F-Secure\FSPS\program\FSLSP.DLL
Trusted Zone: uv.local\muleserv01.uvg
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\dgna65kq.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - about:home
.
- - - - TOMME GENVEJE FJERNET - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
SafeBoot-SolutoService
WebBrowser-{1392B8D2-5C05-419F-A8F6-B9F15A596612} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
.
.
. ——————————- LÅSTE REGISTRERINGS NØGLER——————————-
.
[HKEY_USERS\S-1-5-21-534576203-4222654756-1074100371-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-534576203-4222654756-1074100371-1000)
@Denied: (2) (LocalSystem)
“Progid”=“Outlook.File.eml.14”
.
[HKEY_USERS\S-1-5-21-534576203-4222654756-1074100371-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-534576203-4222654756-1074100371-1000)
@Denied: (2) (LocalSystem)
“Progid”=“Outlook.File.vcf.14”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=”@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
“Enabled”=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@=“Shockwave Flash Object”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx”
“ThreadingModel”=“Apartment”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@=“0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@=“ShockwaveFlash.ShockwaveFlash.11”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@=”{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@=“ShockwaveFlash.ShockwaveFlash”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@=“Macromedia Flash Factory Object”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx”
“ThreadingModel”=“Apartment”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@=“FlashFactory.FlashFactory.1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@=”{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@=“FlashFactory.FlashFactory”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker4”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@=”{00020424-0000-0000-C000-000000000046}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
“Solution”=”{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
“Key”=“ActionsPane3”
“Location”=“c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd”
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
. ————————————Andre kørende processer————————————
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\F-Secure\Anti-Virus\fsgk32st.exe
c:\program files (x86)\F-Secure\Common\FSMA32.EXE
c:\program files (x86)\F-Secure\Anti-Virus\FSGK32.EXE
c:\program files (x86)\F-Secure\Common\FSHDLL32.EXE
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\windows\SysWOW64\IoctlSvc.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\F-Secure\Anti-Virus\fssm32.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
c:\program files (x86)\F-Secure\Anti-Virus\fsav32.exe
.
**************************************************************************
.
Gennemført tid: 2012-04-09 13:00:14 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2012-04-09 11:00
.
Pre-Kørsel: 220.650.602.496 byte ledig
Post-Kørsel: 218.862.055.424 byte ledig
.
- - End Of File - - 4E827798E919E0F3827C60B952366E87
Nu frøs min computer. Jeg synes den er begyndt at opføre sig ret underligt
Administrator
Antal indlæg: 55502
Der er ikke noget i loggen.
Fryser den stadig?
Signatur
qui potest, obligatur
Nierne bomaye - You’ll never walk alone
Kaffen er drukket
Kassen er lukket
Støtten gør mere nytte
Hos de små og forknytte
Børns vilkår
Hospitalsklovne
Jeg tror, at jeg vil tilskrive oplevelsen med, at den fryser som en engangsoplevelse. Jeg har brugt min computer det meste af dagen, og den har været tændt og slukket et par gange uden, at der er kommet flere problemer. Jeg tror, endvidere at en reset af min router og modem løste mit internetproblem i går aftes.
Det sidste jeg egenligt gerne vil vide er hvilken kombination af gratis anti-virus, -malware, -spyware programmer som du vil foreslå at jeg skal bruge. Min nuværende licens til F-Secure udløber om en lille månedstid, så jeg skal finde noget andet i stedet for det program.