TAK for hjælpen.
Combofix hjalp gevaldigt på mine problemer, men den var så meget længe om at køre igennem, og jeg nåede da at få ‘bommet’ logfilen Jeg lukkede vinduet til slut i den tro at nu havde den lagt logfilen ind på c-drevet, men det skulle jeg så ikke have gjort. Den var bare så uendelig længe om at ville lukke det vindue og så poppe op med logfilen.
Herunder er hvad jeg kunne finde som txt i Combofixmappen.
Jeg vil gå i gang med hijack this efter dine instruktioner.
PC’en kører ret fornuftigt nu, men har stadig en ganske lille smule ‘hopperi’ i CPU forbruget
—————————————————
ComboFix 12-07-06.01 - kurt 06-07-2012 14:45:08.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.45.1030.18.1789.728 [GMT 2:00]
Kører fra: C:\Users\kurt\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
C:\$WINDOWS.~Q\DATA\Windows\System32\Desktop_.ini
C:\ProgramData\ntuser.dat
D:\install.exe
((((((((((((((((((((((((((((( Filer skabt fra 2012-06-06 til 2012-07-06 )))))))))))))))))))))))))))))))))))
2012-07-06 13:19:51 . 2012-07-06 13:20:44 ———— d——-w- C:\Users\kurt\AppData\Local\temp
2012-07-06 13:19:51 . 2012-07-06 13:19:51 ———— d——-w- C:\Users\Default\AppData\Local\temp
2012-07-06 11:14:50 . 2012-05-31 03:41:42 6762896 ——a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1CC0C66E-281F-43ED-A26C-A4139BDF25B4}\mpengine.dll
2012-07-06 08:33:50 . 2012-07-06 08:33:50 ———— d——-w- C:\Users\kurt\AppData\Roaming\Malwarebytes
2012-07-06 08:33:34 . 2012-07-06 08:33:34 ———— d——-w- C:\ProgramData\Malwarebytes
2012-06-26 07:45:39 . 2012-07-01 14:24:44 ———— d——-w- C:\Users\kurt\AppData\Roaming\DriverFinder
2012-06-22 06:23:26 . 2012-06-02 22:19:33 53784 ——a-w- C:\Windows\system32\wuauclt.exe
2012-06-22 06:23:26 . 2012-06-02 22:19:33 45080 ——a-w- C:\Windows\system32\wups2.dll
2012-06-22 06:23:26 . 2012-06-02 22:12:32 2422272 ——a-w- C:\Windows\system32\wucltux.dll
2012-06-22 06:23:25 . 2012-06-02 22:19:17 1933848 ——a-w- C:\Windows\system32\wuaueng.dll
2012-06-22 06:22:38 . 2012-06-02 22:19:32 35864 ——a-w- C:\Windows\system32\wups.dll
2012-06-22 06:22:38 . 2012-06-02 22:19:23 577048 ——a-w- C:\Windows\system32\wuapi.dll
2012-06-22 06:22:38 . 2012-06-02 22:12:13 88576 ——a-w- C:\Windows\system32\wudriver.dll
2012-06-22 06:22:21 . 2012-06-02 13:19:42 171904 ——a-w- C:\Windows\system32\wuwebv.dll
2012-06-22 06:22:20 . 2012-06-02 13:12:20 33792 ——a-w- C:\Windows\system32\wuapp.exe
2012-06-20 16:14:20 . 2012-06-20 16:14:20 12800 ——a-w- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
2012-06-19 15:35:14 . 2012-06-19 15:35:14 4967624 ——a-w- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-06-19 07:20:35 . 2012-06-19 07:20:12 476936 ——a-w- C:\Windows\system32\npdeployJava1.dll
2012-06-12 22:48:59 . 2012-04-23 16:00:53 984064 ——a-w- C:\Windows\system32\crypt32.dll
2012-06-12 22:48:59 . 2012-04-23 16:00:53 133120 ——a-w- C:\Windows\system32\cryptsvc.dll
2012-06-12 22:48:58 . 2012-04-23 16:00:53 98304 ——a-w- C:\Windows\system32\cryptnet.dll
2012-06-12 22:47:27 . 2012-05-01 14:03:49 180736 ——a-w- C:\Windows\system32\drivers\rdpwd.sys
2012-06-12 22:47:18 . 2012-05-15 19:51:08 2045440 ——a-w- C:\Windows\system32\win32k.sys
2012-06-12 06:07:39 . 2012-06-01 15:36:14 770384 ——a-w- C:\Program Files\Mozilla Firefox\msvcr100.dll
2012-06-12 06:07:39 . 2012-06-01 15:36:13 421200 ——a-w- C:\Program Files\Mozilla Firefox\msvcp100.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
2012-06-23 09:09:20 . 2012-04-05 07:49:18 426184 ——a-w- C:\Windows\system32\FlashPlayerApp.exe
2012-06-23 09:09:20 . 2011-05-15 08:27:48 70344 ——a-w- C:\Windows\system32\FlashPlayerCPLApp.cpl
2012-06-19 07:20:11 . 2010-04-30 07:37:37 472840 ——a-w- C:\Windows\system32\deployJava1.dll
2012-04-18 18:56:30 . 2012-04-18 18:56:30 94208 ——a-w- C:\Windows\system32\QuickTimeVR.qtx
2012-04-18 18:56:30 . 2012-04-18 18:56:30 69632 ——a-w- C:\Windows\system32\QuickTime.qts
2012-06-01 15:38:43 . 2012-05-04 23:15:07 85472 ——a-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“C:\Program Files\Windows Sidebar\sidebar.exe” [2009-04-11 06:28:03 1233920]
“StartCCC”=“C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” [2006-11-10 11:35:24 90112]
“LDM”=“C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe” [2007-04-26 11:00:50 32768]
“ISUSPM Startup”=“C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe” [2005-08-11 13:30:30 249856]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe” [2007-05-31 22:11:34 171448]
“SUPERAntiSpyware”=“C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2012-06-20 22:16:21 3905408]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2012-06-07 17:17:34 17425072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2006-10-23 03:00:36 815104]
“eDataSecurity Loader”=“C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe” [2007-01-02 17:58:50 464168]
“PCMService”=“C:\Program Files\Acer\Acer Arcade\PCMService.exe” [2007-01-08 23:55:58 151552]
“SetPoint”=“C:\Program Files\Logitech\SetPoint\SetPoint.EXE” [2005-03-31 15:19:14 434176]
“VX6000”=“C:\Windows\vVX6000.exe” [2006-12-19 09:29:00 994072]
“VX1000”=“C:\Windows\vVX1000.exe” [2006-12-05 13:38:58 707360]
“LifeCam”=“C:\Program Files\Microsoft LifeCam\LifeExp.exe” [2007-01-12 15:48:28 275800]
“RtHDVCpl”=“RtHDVCpl.exe” [2006-12-01 05:37:00 4186112]
“WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2012-06-20 16:13:12 74752]
“SPAMfighter Agent”=“C:\Program Files\SPAMfighter\SFAgent.exe” [2009-03-12 08:43:48 326792]
“Adobe ARM”=“C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2012-01-03 13:10:42 843712]
“APSDaemon”=“C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe” [2012-05-30 18:06:18 59280]
“avast”=“C:\Program Files\Alwil Software\Avast5\avastUI.exe” [2012-03-07 00:15:17 4241512]
“TkBellExe”=“c:\program files\real\realplayer\Update\realsched.exe” [2012-05-18 19:09:12 296056]
“QuickTime Task”=“C:\Program Files\QuickTime\QTTask.exe” [2012-04-18 18:56:22 421888]
“SunJavaUpdateSched”=“C:\Program Files\Common Files\Java\Java Update\jusched.exe” [2012-01-18 13:02:04 254696]
“LManager”=“C:\PROGRA~1\LAUNCH~1\LManager.exe” [2006-12-08 08:24:00 614400]
“WarReg_PopUp”=“C:\Acer\WR_PopUp\WarReg_PopUp.exe” [2006-11-05 19:48:22 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [2008-02-26 01:23:34 443968]
“msnmsgr”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe” [2012-03-08 16:50:28 4280184]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Button Manager v1.874.lnk - C:\Program Files\INITIO\Button Manager v1.874\inihid.exe [N/A]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-1-24 528384]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-4-26 450560]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-4-26 434176]
Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe [2012-6-27 572000]
TotalMedia Backup Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-4-1 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= “C:\Program Files\SUPERAntiSpyware\SASSEH.DLL” [2011-08-04 05:47:50 113024]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21:42 548352 ——a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=C:\Windows\System32\eNetHook.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=”“
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
2007-01-14 10:38:48 151552 ——a-w- C:\Acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
—- Andre Services/Drivers i Hukommelsen—-
*NewlyCreated* - WS2IFSL
*Deregistered* - IDSvix86
*Deregistered* - SYMTDI
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Indhold af mappen ‘Planlagte Opgaver’
2012-07-06 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 07:49:18 . 2012-06-23 09:09:22]
2012-07-06 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-11 21:50:32 . 2011-08-11 21:50:14]
2012-07-06 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-11 21:50:32 . 2011-08-11 21:50:14]
2012-07-05 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-307493861-2991341658-3277951488-1000Core.job
- C:\Users\kurt\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-18 20:25:13 . 2012-04-05 07:20:04]
2012-07-06 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-307493861-2991341658-3277951488-1000UA.job
- C:\Users\kurt\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-18 20:25:13 . 2012-04-05 07:20:04]
———- Yderligere scanning———-
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - C:\Windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: bec.dk
Trusted Zone: certifikat.dk\www
Trusted Zone: danskebank.dk
Trusted Zone: e-boks.dk\min
Trusted Zone: e-boks.dk\www
Trusted Zone: nemadgang.dk\www
Trusted Zone: nordea.dk\www.netbank
Trusted Zone: seb.dk\www
Trusted Zone: sebank.se\taz.vv
Trusted Zone: tdc.dk\fxn.selfcare
TCP: DhcpNameServer = 192.168.1.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
FF - ProfilePath - C:\Users\kurt\AppData\Roaming\Mozilla\Firefox\Profiles\5oowe1fh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query;=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query;=
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
- - - - TOMME GENVEJE FJERNET - - - -
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKCU-Run-Acer Tour Reminder - (no file)
HKCU-Run-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe