Langsom computer og måske en der prøver at få adgang via port
Antal indlæg: 34

I følge min router er der en der prøver at få adgang til min PC igennem porte. Dette er ikke problemet jeg håber at i kan fikse, men hvis der er noget mystisk i min log der pejer på dette, så sig endeligt til. smile


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:34:45, on 17/06/2012
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Users\Rasmus\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Rasmus\AppData\Roaming\Hyperdesktop\hyperdesktop.exe
C:\Users\Rasmus\Local Settings\Apps\F.lux\flux.exe
C:\Users\Rasmus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Rasmus\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Razer\Tarantula\razerhid.exe
C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\V0220Mon.exe
C:\Program Files (x86)\Razer\Lachesis\OSD.exe
C:\Program Files (x86)\Razer\Lachesis\razertra.exe
C:\Program Files (x86)\Razer\Lachesis\razerofa.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Rasmus\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=501f52120000000000001c6f65c3537d
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Hjælp til logon til Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O4 - HKLM\..\Run: [Tarantula] C:\Program Files (x86)\Razer\Tarantula\razerhid.exe
O4 - HKLM\..\Run: [StartCCC] “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
O4 - HKLM\..\Run: [Lachesis] C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
O4 - HKLM\..\Run: [ISUSScheduler] “C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe” -start
O4 - HKLM\..\Run: [V0220Mon.exe] C:\Windows\V0220Mon.exe
O4 - HKLM\..\Run: [V0220Cfg.exe] V0220Cfg.exe /d:2
O4 - HKLM\..\Run: [LifeCam] “C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe”
O4 - HKCU\..\Run: [Google Update] “C:\Users\Rasmus\AppData\Local\Google\Update\GoogleUpdate.exe” /c
O4 - HKCU\..\Run: [Hyperdesktop] C:\Users\Rasmus\AppData\Roaming\Hyperdesktop\hyperdesktop.exe
O4 - HKCU\..\Run: [F.lux] “C:\Users\Rasmus\Local Settings\Apps\F.lux\flux.exe” /noshow
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~3\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe
O4 - HKCU\..\Run: [Spotify Web Helper] “C:\Users\Rasmus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe”
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOKAL TJENESTE’)
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User ‘LOKAL TJENESTE’)
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETVÆRKSTJENESTE’)
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User ‘NETVÆRKSTJENESTE’)
O4 - HKUS\S-1-5-21-1675125441-859493970-4196966945-1011\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘UpdatusUser’)
O4 - HKUS\S-1-5-21-1675125441-859493970-4196966945-1011\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User ‘UpdatusUser’)
O4 - Startup: Dropbox.lnk = Rasmus\AppData\Roaming\Dropbox\bin\Dropbox.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra ‘Tools’ menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~3\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{88419CA0-4432-4DD6-B7B0-7ACEBE2B43C5}: NameServer = 184.106.242.193,67.23.7.56
O17 - HKLM\System\CCS\Services\Tcpip\..\{A927DE71-C653-40BD-9E9B-3F0D36FD1FF8}: NameServer = 80.251.201.177 80.251.201.178
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~3\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: HWDeviceService64.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService64.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mobile Partner. OUC (Mobile Partner. RunOuc) - Unknown owner - C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)


End of file - 12085 bytes

Mange tak!

Antal indlæg: 34

Lad mig ændre min åbningssætning til:
“Der er nogle (eller noget), der spammer vores router med port tjek, hvilket får den til ikke at fungere. Så vidt jeg kan se, så kommer det fra en PC i huset, så jeg regner med at det er et program der er noget galt med, ellers ligger der en backdoor et eller andet sted”

Administrator
Antal indlæg: 7131

Hej smile

La’ os tjekke den PC du skriver fra.

Hent “Malwarebytes’ Anti-Malware” her

eller her

Installer og start programmet, klik på fanen opdater, klik Tjek for opdatering, lav “Fuld system skan” under fanebladet “skanner”
Bagefter klik på “vis resultater”, tryk på “Fjern det valgte” gem loggen og send den herind sammen med logs fra DDS.

Den laver to logs,(DDS.txt og Attach.txt) gem dem på skrivebordet og kopier indholdet af begge herind.

OBS - DDS skal gemmes på computeren og ikke køres fra nettet.

Mht.: Vista og Windows 7 - Højreklik på filen - Kør som Administrator.

NB Når du opdaterer Malwarebytes, så klik på Tjek for opdatering til den skriver at der ikke er flere opdateringer.

Jeg vil gerne se: (Lavet i den rækkefølge)

1. Log fra Malwarebytes. (Opdateret)

2. Logs fra DDS. (DDS.txt og Attach.txt)

Signatur

Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !

Antal indlæg: 34

Ugh, den Malware Bytes scanning tog en del tid, men her er det hele i rækkefølge! smile

Malwarebytes Anti-Malware 1.61.0.1400
http://www.malwarebytes.org

Database version: v2012.06.18.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rasmus :: RASMUS-PC [administrator]

18/06/2012 19:35:23
mbam-log-2012-06-18 (19-35-23).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 859508
Time elapsed: 4 hour(s), 12 minute(s), 8 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

 

 

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_31
Run by Rasmus at 19:40:25 on 2012-06-18
Microsoft Windows 7 Enterprise   6.1.7601.1.1252.45.1030.18.4079.1748 [GMT 2:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
C:\ProgramData\DatacardService\HWDeviceService64.exe
C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\Rasmus\AppData\Roaming\Hyperdesktop\hyperdesktop.exe
C:\Users\Rasmus\Local Settings\Apps\F.lux\flux.exe
C:\Users\Rasmus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Rasmus\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Razer\Tarantula\razerhid.exe
C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\V0220Mon.exe
C:\Program Files (x86)\Razer\Lachesis\OSD.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Razer\Lachesis\razertra.exe
C:\Program Files (x86)\Razer\Lachesis\razerofa.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Rasmus\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Malwarebytes’ Anti-Malware\mbam.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\SoftwareDistribution\Download\Install\AM_Delta_Patch_1.127.2172.0.exe
C:\Windows\system32\MpSigStub.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uStart Page = hxxp://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=501f52120000000000001c6f65c3537d
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Hjælp til logon til Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [Google Update] “C:\Users\Rasmus\AppData\Local\Google\Update\GoogleUpdate.exe” /c
uRun: [Hyperdesktop] C:\Users\Rasmus\AppData\Roaming\Hyperdesktop\hyperdesktop.exe
uRun: [F.lux] “C:\Users\Rasmus\Local Settings\Apps\F.lux\flux.exe” /noshow
uRun: [ISUSPM Startup] C:\PROGRA~3\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
uRun: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe
uRun: [Spotify Web Helper] “C:\Users\Rasmus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe”
mRun: [Tarantula] C:\Program Files (x86)\Razer\Tarantula\razerhid.exe
mRun: [StartCCC] “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun: [Lachesis] C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
mRun: [ISUSScheduler] “C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe” -start
mRun: [V0220Mon.exe] C:\Windows\V0220Mon.exe
mRun: [V0220Cfg.exe] V0220Cfg.exe /d:2
mRun: [LifeCam] “C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe”
mRun: [Adobe Reader Speed Launcher] “C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”
mRun: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes’ Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\Rasmus\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Rasmus\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~3\MICROS~2\OFFICE11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 193.162.153.164 194.239.134.83
TCP: Interfaces\{4A53967F-A54E-4FD6-88C3-A6A55F942394} : DhcpNameServer = 193.162.153.164 192.168.3.200
TCP: Interfaces\{88419CA0-4432-4DD6-B7B0-7ACEBE2B43C5} : NameServer = 184.106.242.193,67.23.7.56
TCP: Interfaces\{88419CA0-4432-4DD6-B7B0-7ACEBE2B43C5} : DhcpNameServer = 193.162.153.164 194.239.134.83
TCP: Interfaces\{A927DE71-C653-40BD-9E9B-3F0D36FD1FF8} : NameServer = 80.251.201.177 80.251.201.178
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~3\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: IDMIEHlprObj Class: {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO-X64:    IDM Helper - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64:    AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Hj‘lp til logon til Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64:    SkypeIEPluginBHO - No File
BHO-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64:    Ask Toolbar BHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
mRun-x64: [Tarantula] C:\Program Files (x86)\Razer\Tarantula\razerhid.exe
mRun-x64: [StartCCC] “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun-x64: [Lachesis] C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
mRun-x64: [ISUSScheduler] “C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe” -start
mRun-x64: [V0220Mon.exe] C:\Windows\V0220Mon.exe
mRun-x64: [V0220Cfg.exe] V0220Cfg.exe /d:2
mRun-x64: [LifeCam] “C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe”
mRun-x64: [Adobe Reader Speed Launcher] “C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”
mRun-x64: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRunOnce-x64: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes’ Anti-Malware\mbamgui.exe /install /silent
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Rasmus\AppData\Roaming\Mozilla\Firefox\Profiles\oe19v151.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.teefury.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?hl=en-GB&q=
FF - component: C:\Users\Rasmus\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\Rasmus\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Rasmus\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Users\Rasmus\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Rasmus\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
——FIREFOX POLICIES——
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109989
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 501f52120000000000001c6f65c3537d
FF - user.js: extensions.BabylonToolbar_i.hardId - 501f52120000000000001c6f65c3537d
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15392
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1719:29:11
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys—> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys—> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\system32\DRIVERS\vrtaucbl.sys—> C:\Windows\system32\DRIVERS\vrtaucbl.sys [?]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\system32\DRIVERS\ew_jubusenum.sys—> C:\Windows\system32\DRIVERS\ew_jubusenum.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys—> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys—> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys—> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 VaneFltr;Lachesis Mouse Driver;C:\Windows\system32\drivers\Lachesis.sys—> C:\Windows\system32\drivers\Lachesis.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-5 257696]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys—> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys—> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe—> system32\AppleChargerSrv.exe [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys—> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 ew_usbenumfilter;huawei_CompositeFilter;C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys—> C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys—> C:\Windows\system32\DRIVERS\ewusbnet.sys [?]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2011-7-7 30528]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys—> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\system32\Drivers\nx6000.sys—> C:\Windows\system32\Drivers\nx6000.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys—> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys—> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 TarFltr;Razer Tarantula USB Keyboard;C:\Windows\system32\drivers\UsbFltr.sys—> C:\Windows\system32\drivers\UsbFltr.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys—> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys—> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 V0220Dev;Live! Cam Video IM;C:\Windows\system32\DRIVERS\V0220Dev.sys—> C:\Windows\system32\DRIVERS\V0220Dev.sys [?]
S3 V0220Vfx;V0220VFX;C:\Windows\system32\DRIVERS\V0220Vfx.sys—> C:\Windows\system32\DRIVERS\V0220Vfx.sys [?]
S3 WSDPrintDevice;Support til WSD-udskrivning via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys—> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S3 WSDScan;WSD-scanningssupport via UMB;C:\Windows\system32\DRIVERS\WSDScan.sys—> C:\Windows\system32\DRIVERS\WSDScan.sys [?]
S3 yukonw7;NDIS6.2-miniportdriver til Marvell Yukon Ethernet-controller;C:\Windows\system32\DRIVERS\yk62x64.sys—> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe—> C:\Windows\system32\atiesrxx.exe [?]
S4 DES2 Service;DES2 Service for Energy Saving.;C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2011-7-6 68136]
SUnknown tsusbhub;tsusbhub; [x]
.
=============== Created Last 30 ================
.
2012-06-18 17:38:56   8955792   ——a-w-  C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9CFF0471-DA87-4636-A970-AB6F0FAFEFB9}\mpengine.dll
2012-06-18 17:36:42   69000   ——a-w-  C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0DF36AE7-70A4-4660-BAAB-B2CE1A24F579}\offreg.dll
2012-06-17 15:43:22   8955792   ———w-  C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0DF36AE7-70A4-4660-BAAB-B2CE1A24F579}\mpengine.dll
2012-06-16 00:05:34   ————  d——-w-  C:\Users\Rasmus\AppData\Local\SIX_Projects
2012-06-15 21:23:50   ————  d——-w-  C:\Users\Rasmus\AppData\Roaming\six-zsync
2012-06-15 21:23:50   ————  d——-w-  C:\Users\Rasmus\AppData\Roaming\six-updater
2012-06-15 21:22:58   ————  d——-w-  C:\Program Files (x86)\SIX Projects
2012-06-15 12:13:25   8955792   ———w-  C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-14 20:03:59   117248   ——a-w-  C:\Windows\System32\drivers\ew_hwusbdev.sys
2012-06-14 20:03:44   ————  d——-w-  C:\Program Files (x86)\Mobile Partner
2012-06-14 20:03:26   ————  d——-w-  C:\ProgramData\DatacardService
2012-06-13 10:40:58   3216384   ——a-w-  C:\Windows\System32\msi.dll
2012-06-13 10:40:58   2342400   ——a-w-  C:\Windows\SysWow64\msi.dll
2012-06-13 10:40:52   1462272   ——a-w-  C:\Windows\System32\crypt32.dll
2012-06-13 10:40:51   1158656   ——a-w-  C:\Windows\SysWow64\crypt32.dll
2012-06-13 10:40:50   184320   ——a-w-  C:\Windows\System32\cryptsvc.dll
2012-06-13 10:40:50   140288   ——a-w-  C:\Windows\SysWow64\cryptsvc.dll
2012-06-13 10:40:50   140288   ——a-w-  C:\Windows\System32\cryptnet.dll
2012-06-13 10:40:50   103936   ——a-w-  C:\Windows\SysWow64\cryptnet.dll
2012-06-12 13:53:25   927800   ———w-  C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6C8DEBFA-4DD8-412A-9674-51914626B888}\gapaengine.dll
2012-05-31 11:41:41   ————  d——-w-  C:\Program Files (x86)\Grinding Gear Games
2012-05-29 11:14:02   ————  d——-w-  C:\Users\Rasmus\AppData\Local\ArmA 2 OA
2012-05-29 11:10:14   ————  d——-w-  C:\Users\Rasmus\AppData\Local\ArmA 2
2012-05-28 22:26:07   ————  d——-w-  C:\Users\Rasmus\AppData\Roaming\Stardock
2012-05-28 22:25:52   ————  dc-h—w-  C:\ProgramData\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
2012-05-28 22:25:50   ————  d——-w-  C:\Program Files (x86)\Stardock
2012-05-28 22:25:39   ————  d——-w-  C:\Users\Rasmus\AppData\Local\PackageAware
.
==================== Find3M ====================
.
2012-06-18 15:31:16   25640   ——a-w-  C:\Windows\gdrv.sys
2012-06-14 20:03:50   999936   ——a-w-  C:\Windows\System32\drivers\mod7700.sys
2012-06-14 20:03:50   93696   ——a-w-  C:\Windows\System32\drivers\ew_jucdcacm.sys
2012-06-14 20:03:50   85504   ——a-w-  C:\Windows\System32\drivers\ew_jubusenum.sys
2012-06-14 20:03:50   55296   ——a-w-  C:\Windows\System32\drivers\ew_jucdcecm.sys
2012-06-14 20:03:50   32768   ——a-w-  C:\Windows\System32\drivers\ewdcsc.sys
2012-06-14 20:03:50   29184   ——a-w-  C:\Windows\System32\drivers\ew_juextctrl.sys
2012-06-14 20:03:50   256000   ——a-w-  C:\Windows\System32\drivers\ewusbnet.sys
2012-06-14 20:03:50   196608   ——a-w-  C:\Windows\System32\drivers\ew_juwwanecm.sys
2012-06-14 20:03:50   1490656   ——a-w-  C:\Windows\System32\WdfCoInstaller01007.dll
2012-06-14 20:03:50   1490656   ——a-w-  C:\Windows\System32\drivers\WdfCoInstaller01007.dll
2012-06-14 20:03:50   13952   ——a-w-  C:\Windows\System32\drivers\ew_usbenumfilter.sys
2012-06-14 20:03:50   121600   ——a-w-  C:\Windows\System32\drivers\ewusbmdm.sys
2012-05-15 04:01:31   1188864   ——a-w-  C:\Windows\System32\wininet.dll
2012-05-15 03:03:54   981504   ——a-w-  C:\Windows\SysWow64\wininet.dll
2012-05-15 01:32:33   3146752   ——a-w-  C:\Windows\System32\win32k.sys
2012-05-05 18:17:39   419488   ——a-w-  C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 18:17:38   70304   ——a-w-  C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 18:17:12   8744608   ——a-w-  C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-05-04 11:06:22   5559664   ——a-w-  C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53   3968368   ——a-w-  C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50   3913072   ——a-w-  C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20   209920   ——a-w-  C:\Windows\System32\profsvc.dll
2012-04-28 05:32:05   1112064   ——a-w-  C:\Windows\System32\rdpcorets.dll
2012-04-28 03:55:21   210944   ——a-w-  C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56   77312   ——a-w-  C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55   149504   ——a-w-  C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27   9216   ——a-w-  C:\Windows\System32\rdrmemptylst.exe
2012-04-20 03:45:41   1638912   ——a-w-  C:\Windows\System32\mshtml.tlb
2012-04-20 03:16:44   1638912   ——a-w-  C:\Windows\SysWow64\mshtml.tlb
2012-04-06 20:46:33   283416   ——a-w-  C:\Windows\SysWow64\PnkBstrB.xtr
2012-04-06 20:46:33   283416   ——a-w-  C:\Windows\SysWow64\PnkBstrB.exe
2012-04-06 18:59:51   283416   ——a-w-  C:\Windows\SysWow64\PnkBstrB.ex0
2012-04-05 21:00:32   76888   ——a-w-  C:\Windows\SysWow64\PnkBstrA.exe
2012-04-04 13:56:40   24904   ——a-w-  C:\Windows\System32\drivers\mbam.sys
2012-04-03 20:37:54   472808   ——a-w-  C:\Windows\SysWow64\deployJava1.dll
2012-03-30 11:35:47   1918320   ——a-w-  C:\Windows\System32\drivers\tcpip.sys
2012-03-20 18:44:12   98688   ——a-w-  C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-20 18:44:12   203888   ——a-w-  C:\Windows\System32\drivers\MpFilter.sys
.
============= FINISH: 19:46:11.28 ===============

 

 

 

 

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Enterprise
Boot Device: \Device\HarddiskVolume1
Install Date: 23/11/2009 19:55:17
System Uptime: 18/06/2012 18:07:09 (1 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. |  | PH67-UD3-B3
Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz | Socket 1155 | 2475/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 552 GiB total, 13.612 GiB free.
D: is FIXED (NTFS) - 45 GiB total, 2.001 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 101 GiB total, 100.815 GiB free.
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsl28e47db5
Device ID: ROOT\LEGACY_MPKSL28E47DB5\0000
Manufacturer:
Name: MpKsl28e47db5
PNP Device ID: ROOT\LEGACY_MPKSL28E47DB5\0000
Service: MpKsl28e47db5
.
==== System Restore Points ===================
.
RP674: 17/06/2012 23:17:51 - Planlagt kontrolpunkt
.
==== Installed Programs ======================
.
@BIOS
AAC Decoder
Acrobat.com
Adobe AIR
Adobe Community Help
Adobe Flash Media Live Encoder 3.1
Adobe Media Player
Adobe Reader 9.5.1
Advanced Video FX Engine
AGEIA PhysX v7.07.09
APB Reloaded
Apple Application Support
Apple Software Update
ARMA 2
ARMA 2: Operation Arrowhead
Aspell 0.6 Dictionary (Language: da)
Aspell 0.6 Dictionary (Language: de)
Aspell 0.6 Dictionary (Language: en)
Aspell Data
µTorrent
Audacity 1.3.13 (Unicode)
AutoGreen B10.1021.1
AutoUpdate
Bastion
BattlEye for OA Uninstall
BattlEye Uninstall
BioShock 2
Canon IJ Network Scanner Selector EX
Canon IJ Network Tool
Canon Inkjet Printer/Scanner/Fax Extended Survey Program
Canon MG5300 series Brugerregistrering
CCleaner
Company of Heroes Online Launcher (THQ)
Compatibility Pack for the 2007 Office system
Creative Live! Cam Center
Creative Live! Cam Manager
Creative Software AutoUpdate
Creative System Information
Crysis 2 Maximum Edition
Curse Client
D3DX10
Dark Messiah Might and Magic Single Player
Dell Driver Download Manager
DES 2.0
Diablo II
Diablo III
DisplayFusion 3.3.1
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Plus Media Foundation Components
DivX Plus Web Player
DivX Version Checker
Dropbox
Dual-Core Optimizer
Dungeon Keeper 2
Dxtory 2.0.108
Easy Tune 6 B10.1216.1
ESN Sonar
F.lux
Facebook Video Calling 1.2.0.159
Fences
FileZilla Client 3.5.3
Fraps (remove only)
FXAA Post-Process Injector
GameSpy Comrade
Garena Plus
Google Chrome
Google Talk Plugin
H.264 Decoder
Heroes of Newerth
Hi-Rez Studios Authenticate and Update Service
HijackThis 2.0.2
Intel(R) Control Center
Intel(R) Management Engine Components
Internet Download Manager
Java(TM) 6 Update 31
JDownloader 0.9
KeePass Password Safe 1.19b
Last.fm 1.5.4.27091
League of Legends
Legend of Grimrock
Macro Recorder
Malwarebytes Anti-Malware version 1.61.0.1400
Mass Effect 2
Medal of Honor Airborne
Messenger Companion
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft ASP.NET MVC 2
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
Microsoft Chart Controls for Microsoft .NET Framework 3.5
Microsoft Corporation
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual Studio 2010 SharePoint Developer Tools
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
MiKTeX 2.9
mIRC
MKV Splitter
Mobile Partner
Morrowind
Mozilla Firefox 12.0 (x86 da)
Mozilla Maintenance Service
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mumble 1.2.3
Notepad++
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
ON_OFF Charge B11.0110.1
OpenAL
Origin
Patch v4.1
Path of Exile
Project64 1.6
PunkBuster Services
Quake Live Mozilla Plugin
QuickTime
Rapture3D 2.3.26 Game
Razer Lachesis
Razer Tarantula
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
S.T.A.L.K.E.R. Call of Pripyat: Redux
S.T.A.L.K.E.R.: Call of Pripyat
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
SightSpeed (remove only)
Six Updater
Skype Click to Call
Skype™ 5.8
Smart 6 B10.1221.1
SmartFTP Client Setup Files 4.0 (x64) (remove only)
Sniper Elite V2 Demo
Speccy
Spotify
StarCraft II
Steam
Sublime Text 1.4
TeamViewer 6
TES Construction Set
The Witcher 2
Tribes Ascend
Ubisoft Game Launcher
Ubuntu
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VC80CRTRedist - 8.0.50727.4053
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
VLC media player 1.0.5
Warcraft III
Winamp
Winamp Detector Plug-in
WinDirStat 1.1.2
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin
WinFF 1.3.2
XSplit
Xvid 1.2.2 final uninstall
.
==== Event Viewer Messages From Past Week ========
.
18/06/2012 17:31:05, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Mobile Partner. OUC service to connect.
18/06/2012 17:31:05, Error: Service Control Manager [7000]  - The Mobile Partner. OUC service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
17/06/2012 20:06:20, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
14/06/2012 22:13:42, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.    New Signature Version:    Previous Signature Version: 1.127.1922.0     Update Source: Microsoft Update Server     Update Stage: Search     Source Path: http://www.microsoft.com    Signature Type: AntiVirus     Update Type: Full     User: NT AUTHORITY\SYSTEM     Current Engine Version:    Previous Engine Version: 1.1.8403.0     Error code: 0x8024402c     Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
14/06/2012 22:04:35, Error: Service Control Manager [7030]  - The Mobile Partner. OUC service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
14/06/2012 22:04:25, Error: Service Control Manager [7030]  - The HWDeviceService64.exe service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
14/06/2012 20:19:16, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.    New Signature Version:    Previous Signature Version: 1.127.1922.0     Update Source: Microsoft Update Server     Update Stage: Search     Source Path: http://www.microsoft.com    Signature Type: AntiVirus     Update Type: Full     User: NT AUTHORITY\SYSTEM     Current Engine Version:    Previous Engine Version: 1.1.8403.0     Error code: 0x8024402c     Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
14/06/2012 17:51:06, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.    New Signature Version:    Previous Signature Version: 1.127.1922.0     Update Source: Microsoft Update Server     Update Stage: Search     Source Path: http://www.microsoft.com    Signature Type: AntiVirus     Update Type: Full     User: NT AUTHORITY\SYSTEM     Current Engine Version:    Previous Engine Version: 1.1.8403.0     Error code: 0x8024402c     Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
.
==== End Of File ===========================

 

 

 


Jeg takker super mange gange for at du tager din tid til det her! ^^

Administrator
Antal indlæg: 7131

Drop fildeling ->
http://www.spywarefri.dk/artikel/farerne-ved-fildeling/
http://www.spywarefri.dk/forum/viewthread/40284/

Afinstaller µTorrent.

Der er ikke nogen infektioner at se.

Der er nogle (eller noget), der spammer vores router med port tjek, hvilket får den til ikke at fungere. Så vidt jeg kan se, så kommer det fra en PC i huset, så jeg regner med at det er et program der er noget galt med

Det må du gerne uddybe.

Signatur

Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !

Antal indlæg: 34

Jeg bruger ikke µTorrent til at fildele (eller, det kan man vel godt sige), men jeg bruger den til at downloade Linux smile

Det med routeren har ikke vist sig at været noget problem i et stykke tid, så jeg håber lidt at det er stoppet.

Undskyld for det sene svar, jeg må have misset emailen.

Super mange gange tak for hjælpen! Det er dejligt at vide, at min computer er helt frisk.
Hav en god dag!

Administrator
Antal indlæg: 7131

Velbekomme cool smile

Jeg lukker tråden. Du laver bare en ny, hvis du har behov for det wink


Signatur

Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !