This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Very slow laptop

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

All of a sudden my laptop got VERY slow. It takes ages to start and using the Internet is a nerve wrecking business. I've cleaned the pc with ATG-Cleaner, but that doesn't help much. Please help!

Below is a hijackthis log (run as an administrator) and a DDS. Attach.txt is attached.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:22:24, on 2009-05-25
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WLANExt.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehtray.exe
C:\Users\ANNELI~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\3\3Connect\AutoUpdateSrv.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NÄTVERKSTJÄNST')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Uppdateringsagent.lnk = ?
O8 - Extra context menu item: Anpassa meny - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fyll i formulär - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RF verktygsfält - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Skicka bild till &Bluetooth-enhet… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Skicka sida till &Bluetooth-enhet… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Skicka som mms… - file://C:\Program Files\Sms och mms i datorn Desktop\sendmms.htm
O8 - Extra context menu item: Skicka som sms… - file://C:\Program Files\Sms och mms i datorn Desktop\sendsms.htm
O8 - Extra context menu item: Spara formulär - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11492 bytes




DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 21:08:36,21 on 2009-05-25
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.46.1053.18.2525.1457 [GMT 2:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WLANExt.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehtray.exe
C:\Users\ANNELI~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\3\3Connect\AutoUpdateSrv.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Annelie Pernheden\Desktop\dds.scr
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [ProductReg] "c:\program files\acer\wr_popup\ProductReg.exe"
mRun: [PLFSetI] c:\windows\PLFSetI.exe
mRun: [eRecoveryService]
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe
mRun: [ZPdtWzdVitaKey MC3000] "c:\program files\acer\acer bio protection\PdtWzd.exe" show
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\uppdat~1.lnk - c:\program files\3\3connect\AutoUpdateSrv.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Anpassa meny - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xportera till Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Fyll i formulär - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RF verktygsfält - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Skicka bild till &Bluetooth-enhet… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Skicka sida till &Bluetooth-enhet… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: Skicka som mms… - file://c:\program files\sms och mms i datorn desktop\sendmms.htm
IE: Skicka som sms… - file://c:\program files\sms och mms i datorn desktop\sendsms.htm
IE: Spara formulär - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AWinNotifyVitaKey MC3000 - c:\program files\acer\acer bio protection\WinNotify.dll
LSA: Notification Packages = scecli c:\program files\acer\acer bio protection\PwdFilter

================= FIREFOX ===================

FF - ProfilePath - c:\users\anneli~1\appdata\roaming\mozilla\firefox\profiles\c4556ti7.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_fs&search=
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\users\annelie pernheden\appdata\roaming\mozilla\firefox\profiles\c4556ti7.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll

—- FIREFOX POLICIES —-
FF - user.js: keyword.enabled - true
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");

============= SERVICES / DRIVERS ===============

R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [2009-1-9 43184]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-5-12 130936]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-2-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-2-12 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-2-12 51792]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-6-25 212992]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-7-15 96856]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-1-9 22072]
S1 AMTBDA_P861F;anysee Capture Service;c:\windows\system32\drivers\anyseeTU.SYS [2008-9-29 481024]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [2009-1-16 81704]

=============== Created Last 30 ================

2009-05-16 20:02 –d—– c:\program files\Startup Inspector for Windows
2009-05-14 21:22 35 a——- c:\users\anneli~1\appdata\roaming\SetValue.bat
2009-05-14 21:22 691 a——- c:\users\anneli~1\appdata\roaming\GetValue.vbs
2009-05-14 21:12 3,244 a——- c:\windows\system32\tmp.reg
2009-05-12 19:13 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-05-12 19:13 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-05-12 19:13 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-12 19:12 –d—– c:\program files\common files\PC Tools
2009-05-12 19:12 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-05-12 19:12 –d—– c:\programdata\PC Tools
2009-05-12 19:12 –d—– c:\progra~2\PC Tools
2009-04-30 22:26 410,984 a——- c:\windows\system32\deploytk.dll
2009-04-29 06:40 81,920 a——- c:\windows\system32\RBK3263.tmp
2009-04-29 06:40 28,672 a——- c:\windows\system32\RBK3268.tmp
2009-04-29 06:40 0 a——- c:\windows\system32\RBK326B.tmp
2009-04-29 06:26 –d—– c:\users\anneli~1\appdata\roaming\wsInspector
2009-04-29 06:19 –d—– c:\users\anneli~1\appdata\roaming\BoostXP2
2009-04-28 20:54 2,419,200 a——- c:\windows\system32\PhotoExplorer2.scr
2009-04-28 20:54 –d—– c:\program files\Systweak BoostXP2
2009-04-27 21:19 –d—– C:\ACERSW
2009-04-26 23:17 –d—– C:\Ny mapp

==================== Find3M ====================

2009-05-12 19:36 647,970 a——- c:\windows\system32\perfh01D.dat
2009-05-12 19:36 138,466 a——- c:\windows\system32\perfc01D.dat
2009-03-17 05:38 40,960 a——- c:\windows\apppatch\apihex86.dll
2009-03-17 05:38 13,824 a——- c:\windows\system32\apilogen.dll
2009-03-17 05:38 24,064 a——- c:\windows\system32\amxread.dll
2009-03-08 13:34 914,944 a——- c:\windows\system32\wininet.dll
2009-03-08 13:34 43,008 a——- c:\windows\system32\licmgr10.dll
2009-03-08 13:33 18,944 a——- c:\windows\system32\corpol.dll
2009-03-08 13:33 109,056 a——- c:\windows\system32\iesysprep.dll
2009-03-08 13:33 109,568 a——- c:\windows\system32\PDMSetup.exe
2009-03-08 13:33 132,608 a——- c:\windows\system32\ieUnatt.exe
2009-03-08 13:33 107,520 a——- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 13:33 107,008 a——- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 13:33 103,936 a——- c:\windows\system32\SetDepNx.exe
2009-03-08 13:33 420,352 a——- c:\windows\system32\vbscript.dll
2009-03-08 13:32 72,704 a——- c:\windows\system32\admparse.dll
2009-03-08 13:32 71,680 a——- c:\windows\system32\iesetup.dll
2009-03-08 13:32 66,560 a——- c:\windows\system32\wextract.exe
2009-03-08 13:32 169,472 a——- c:\windows\system32\iexpress.exe
2009-03-08 13:31 34,816 a——- c:\windows\system32\imgutil.dll
2009-03-08 13:31 48,128 a——- c:\windows\system32\mshtmler.dll
2009-03-08 13:31 45,568 a——- c:\windows\system32\mshta.exe
2009-03-08 13:22 156,160 a——- c:\windows\system32\msls31.dll
2009-03-03 06:46 3,599,328 a——- c:\windows\system32\ntkrnlpa.exe
2009-03-03 06:46 3,547,632 a——- c:\windows\system32\ntoskrnl.exe
2009-03-03 06:39 183,296 a——- c:\windows\system32\sdohlp.dll
2009-03-03 06:39 551,424 a——- c:\windows\system32\rpcss.dll
2009-03-03 06:39 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 06:37 98,304 a——- c:\windows\system32\iasrecst.dll
2009-03-03 06:37 54,784 a——- c:\windows\system32\iasads.dll
2009-03-03 06:37 44,032 a——- c:\windows\system32\iasdatastore.dll
2009-03-03 05:04 666,624 a——- c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 04:38 17,408 a——- c:\windows\system32\iashost.exe
2009-02-18 02:21 103,960 a——- c:\users\anneli~1\appdata\roaming\GDIPFONTCACHEV1.DAT
2009-02-12 11:30 143,360 a——- c:\windows\inf\infstrng.dat
2009-02-12 11:30 86,016 a——- c:\windows\inf\infstor.dat
2009-02-12 11:30 51,200 a——- c:\windows\inf\infpub.dat
2009-01-13 21:32 952 a–sh— c:\programdata\KGyGaAvL.sys
2009-01-13 21:32 952 a–sh— c:\progra~2\KGyGaAvL.sys
2009-01-09 17:51 665,600 a——- c:\windows\inf\drvindex.dat
2008-01-21 08:20 290,490 a——- c:\windows\inf\perflib\041d\perfi.dat
2008-01-21 08:20 290,490 a——- c:\windows\inf\perflib\041d\perfh.dat
2008-01-21 08:20 35,978 a——- c:\windows\inf\perflib\041d\perfd.dat
2008-01-21 08:20 35,978 a——- c:\windows\inf\perflib\041d\perfc.dat
2008-01-21 04:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 21:12:30,77 ===============



Thank you in advance!

Attachments:

Hi Farmor,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Hi Tomk, Thanks for trying to help me out! That's very kind of you. The log didn't show any malwares. Here's a copy of it. Malwarebytes' Anti-Malware 1.37 Database version: 2203 Windows 6.0.6001 Service Pack 1 2009-06-01 00:43:44 mbam-log-2009-06-01 (00-43-44).txt Scan type: Quick Scan Objects scanned: 75391 Time elapsed: 11 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Best regards Farmor
Farmor,

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi, I downloaded ComboFix, disabled AntiVirus and AntiSpyware and started ComboFix. It went on and on and finally said it woul reboot. It closed down but didn't restart. I waited for a while and then tried to start it manually. The start progress goes on for a while and then the computer closes down. I've tried to open up F2 - it works - and then closes down whatever I try. What to do? Best regards Farmor
Farmor,

Let's try Last known Good Configuration


Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Last known Good Configuration using the arrow keys.
Then press enter on your keyboard to boot.

Let me know how it goes.
Hi again,

Most peculiar - I did that this morning (Swedish time) and the laptop closed down, but now it worked. :yeah: Here's the log:

ComboFix 09-05-31.05 - Annelie Pernheden 2009-06-01 10:02.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.46.1053.18.2525.1593 [GMT 2:00]
Körs från: c:\users\Annelie Pernheden\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\tmp.reg

.
(((((((((((((((((((((((( Filer Skapade från 2009-05-01 till 2009-06-01 ))))))))))))))))))))))))))))))
.

2009-06-01 08:24 . 2009-06-01 15:18 ——– d—–w- c:\users\Annelie Pernheden\AppData\Local\temp
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Malwarebytes
2009-05-31 22:25 . 2009-05-26 11:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\programdata\Malwarebytes
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-31 22:25 . 2009-05-26 11:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-29 18:31 . 2009-05-29 18:31 ——– d—–w- c:\programdata\WindowsSearch
2009-05-25 21:55 . 2009-05-25 22:03 ——– d—–w- c:\program files\SpeedBit Video Accelerator
2009-05-25 21:51 . 2009-05-25 21:51 50688 —-a-w- c:\windows\system32\wbhelp2.dll
2009-05-25 21:23 . 2009-05-25 21:28 ——– d—–w- c:\program files\IncrediMail
2009-05-16 18:02 . 2009-05-16 19:00 ——– d—–w- c:\program files\Startup Inspector for Windows
2009-05-14 19:22 . 2009-05-14 19:22 35 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\SetValue.bat
2009-05-12 17:13 . 2008-12-11 06:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-05-12 17:13 . 2009-04-03 09:18 130936 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-05-12 17:13 . 2008-12-18 10:16 73840 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-12 17:12 . 2009-05-12 17:15 ——– d—–w- c:\program files\Common Files\PC Tools
2009-05-12 17:12 . 2008-12-10 09:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-05-12 17:12 . 2009-05-12 17:12 ——– d—–w- c:\programdata\PC Tools
2009-05-07 19:34 . 2008-09-17 08:07 847360 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 15:14 . 2009-01-13 22:02 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\skypePM
2009-06-01 15:14 . 2009-01-13 22:00 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Skype
2009-06-01 08:25 . 2009-01-12 17:35 12 —-a-w- c:\windows\bthservsdp.dat
2009-05-29 21:32 . 2009-04-29 04:26 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\wsInspector
2009-05-29 20:04 . 2009-01-13 14:57 ——– d—–w- c:\program files\Spyware Doctor
2009-05-28 18:49 . 2009-01-13 21:17 ——– d—–w- c:\program files\Paint Shop Pro 7
2009-05-25 21:59 . 2009-01-13 21:46 ——– d—–w- c:\program files\DAP
2009-05-25 21:10 . 2009-04-05 23:59 ——– d—–w- c:\programdata\WinZip
2009-05-14 19:22 . 2009-05-14 19:22 691 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\GetValue.vbs
2009-05-13 21:56 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-12 17:36 . 2008-01-21 06:21 647970 —-a-w- c:\windows\system32\perfh01D.dat
2009-05-12 17:36 . 2008-01-21 06:21 138466 —-a-w- c:\windows\system32\perfc01D.dat
2009-05-07 09:45 . 2009-01-13 20:00 ——– d—–w- c:\program files\AVS4YOU
2009-04-30 20:25 . 2009-04-30 20:26 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-04-30 20:25 . 2009-04-30 20:25 ——– d—–w- c:\program files\Java
2009-04-30 18:29 . 2009-01-09 14:18 ——– d—–w- c:\program files\Google
2009-04-29 05:34 . 2008-03-11 18:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-04-29 05:21 . 2009-04-05 17:26 ——– d—–w- c:\program files\Common Files\ArcSoft
2009-04-29 05:03 . 2009-01-13 22:13 ——– d—–w- c:\program files\FontExpert
2009-04-29 04:40 . 2009-04-29 04:40 81920 —-a-w- c:\windows\system32\RBK3263.tmp
2009-04-29 04:40 . 2009-04-29 04:40 28672 —-a-w- c:\windows\system32\RBK3268.tmp
2009-04-29 04:40 . 2009-04-29 04:40 0 —-a-w- c:\windows\system32\RBK326B.tmp
2009-04-29 04:19 . 2009-04-29 04:19 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\BoostXP2
2009-04-28 18:54 . 2009-04-28 18:54 ——– d—–w- c:\program files\Systweak BoostXP2
2009-04-26 18:50 . 2009-04-05 17:25 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\ArcSoft
2009-04-18 03:38 . 2009-01-10 19:13 ——– d—–w- c:\program files\DreamboxControlCenter
2009-04-06 10:57 . 2009-03-27 23:17 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\U3
2009-04-05 23:29 . 2009-04-05 17:13 ——– d—–w- c:\program files\Greeting Card Designer
2009-04-05 22:43 . 2009-04-05 22:43 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Skerryvore Software
2009-04-05 17:51 . 2009-04-05 17:28 ——– d—–w- c:\programdata\ArcSoft
2009-04-05 17:05 . 2009-04-05 17:05 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Proxima Software
2009-03-17 03:38 . 2009-04-19 18:07 13824 —-a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-19 18:07 24064 —-a-w- c:\windows\system32\amxread.dll
2009-03-08 11:34 . 2009-05-12 17:55 914944 —-a-w- c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-05-12 17:55 43008 —-a-w- c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-05-12 17:55 18944 —-a-w- c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-05-12 17:55 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-05-12 17:55 109568 —-a-w- c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-05-12 17:55 132608 —-a-w- c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-05-12 17:55 107520 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-05-12 17:55 107008 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-05-12 17:55 103936 —-a-w- c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-05-12 17:55 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-05-12 17:55 72704 —-a-w- c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-05-12 17:55 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-05-12 17:55 66560 —-a-w- c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-05-12 17:55 169472 —-a-w- c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-05-12 17:55 34816 —-a-w- c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-05-12 17:55 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-05-12 17:55 45568 —-a-w- c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-05-12 17:55 156160 —-a-w- c:\windows\system32\msls31.dll
2009-03-03 18:23 . 2009-03-03 18:23 40960 —-a-r- c:\users\Annelie Pernheden\AppData\Roaming\Microsoft\Installer\{23970E31-948B-466E-8376-1224D32FDF0C}\NewShortcut11_23970E31948B466E83761224D32FDF0C.exe
2009-03-03 18:23 . 2009-03-03 18:23 40960 —-a-r- c:\users\Annelie Pernheden\AppData\Roaming\Microsoft\Installer\{23970E31-948B-466E-8376-1224D32FDF0C}\NewShortcut1_23970E31948B466E83761224D32FDF0C.exe
2009-03-03 18:23 . 2009-03-03 18:23 1078 —-a-r- c:\users\Annelie Pernheden\AppData\Roaming\Microsoft\Installer\{23970E31-948B-466E-8376-1224D32FDF0C}\ARPPRODUCTICON.exe
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-04-17 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-01-09 3683328]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-30 148888]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-05-25 3364616]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-26 6144000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-23 727592]
Uppdateringsagent.lnk - c:\program files\3\3Connect\AutoUpdateSrv.exe [2008-10-23 442368]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-5-11 525640]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-09 14:49 3077120 —-a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A6165CC5-98E2-47C0-B70F-6FFF205B5E37}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{794E29E7-255B-4B7F-88E0-396200036F43}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{E093252A-D413-4A0C-ADD0-14D58DDD22C3}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{684D9249-ED36-45CE-9D43-D9F83B18F79E}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{4FA566E3-51F3-4CA3-9CFF-63F88622BE75}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{507A697E-D0FB-4E0B-9A50-B714F41CF91F}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{40AFA05B-B91D-4A06-BFAC-CD4B68E320A1}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{2E0D9A21-1467-4962-8018-C1014952C383}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{8CEC2307-3BB1-4AB9-BCD6-0001CAD8C3D7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{D9CD84BD-B285-4895-B761-E1D6338B4851}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= UDP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"UDP Query User{FDD9C5F5-B400-4E12-A2CA-637E0EE5AAC3}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= TCP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"{C3B84E63-9EB0-4497-AD5C-ECC97AE32097}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{5ABECF48-86B5-4C20-B535-0DBF90A130BE}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{D5B42117-CF84-4127-BFD8-50A705D93ADC}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{230ECA62-F144-4855-842E-5B616EE45AB7}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"TCP Query User{5C0CF614-8901-4B79-A437-624ABE7A5859}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= UDP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"UDP Query User{B207CB92-FC7D-4E44-A322-FFCF42A000D3}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= TCP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"TCP Query User{D1D80FFC-C1E3-471D-936A-CBD0FD47EE82}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{5D476576-9CBA-4706-859F-FD0ED104118F}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{5048270E-E6F9-46A4-BA30-B5FED8E39821}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{5D102427-C56A-4C3C-AA67-39B67901A32A}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"TCP Query User{D48D1106-176E-4496-B9F5-A236C8BF2F1C}c:\\program files\\dap\\dap.exe"= UDP:c:\program files\dap\dap.exe:Download Accelerator Plus (DAP)
"UDP Query User{A7EFC5A2-7A6C-4700-922F-A0846B31DEE4}c:\\program files\\dap\\dap.exe"= TCP:c:\program files\dap\dap.exe:Download Accelerator Plus (DAP)
"{ECBA6207-C1CE-473D-BC1F-820855F16976}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{0D9D2BBB-E6B4-4B72-9622-0408C2E20C23}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{E994A0F3-0992-4A34-988B-184FB0BE3C3D}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{9BC8BA17-D736-4B25-A97F-18055C702B50}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\System32\drivers\AlfaFF.sys [2009-01-09 43184]
R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [2009-05-12 130936]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-02-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-02-12 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-02-12 51792]
R2 BcmSqlStartupSvc;Starttjänst för Business Contact Manager SQL Server;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-11 24576]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [2009-01-09 3481088]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [2007-04-17 11032]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-13 348752]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2008-06-25 212992]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [2008-07-15 96856]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [2009-01-09 22072]
S1 AMTBDA_P861F;anysee Capture Service;c:\windows\System32\drivers\anyseeTU.SYS [2008-09-29 481024]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [2009-01-16 81704]

— Övriga tjänster/drivrutiner i minnet —

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

HKLM-Run-eRecoveryService - (no file)


.
——- Extra genomsökning ——-
.
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: Anpassa meny - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xportera; till Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Fyll i formulär - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RF verktygsfält - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Skicka bild till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Skicka sida till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Skicka som mms… - file://c:\program files\Sms och mms i datorn Desktop\sendmms.htm
IE: Skicka som sms… - file://c:\program files\Sms och mms i datorn Desktop\sendsms.htm
IE: Spara formulär - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
FF - ProfilePath - c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_fs&search;=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll

—- FIREFOX POLICY —-
FF - user.js: keyword.enabled - true
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-01 17:16
Windows 6.0.6001 Service Pack 1 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LÅSTA REGISTERNYCKLAR ———————

[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'lsass.exe'(720)
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll
c:\program files\SpeedBit Video Accelerator\Collector.dll
c:\program files\Acer\Acer Bio Protection\PwdFilter.dll

- - - - - - - > 'Explorer.exe'(6848)
c:\windows\system32\btmmhook.dll
c:\windows\System32\SysHook.dll
c:\windows\system32\btncopy.dll
.
———————— Andra processer som körs ————————
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\System32\wlanext.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Alwil Software\Avast4\Setup\avast.setup
c:\windows\System32\conime.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\users\ANNELI~1\AppData\Local\temp\RtkBtMnt.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Sluttid: 2009-06-01 17:36 - datorn startades om.
ComboFix-quarantined-files.txt 2009-06-01 15:35

Före genomsökningen: 103 567 609 856 byte ledigt
Efter genomsökningen: 103 288 918 016 byte ledigt

Current=6 Default=6 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
304 — E O F — 2009-05-26 20:45


Regards :unsure:
Farmor,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\windows\system32\RBK3263.tmp
    c:\windows\system32\RBK3268.tmp
    c:\windows\system32\RBK326B.tmp
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hi, sorry it took some time to do the Kaspersky, but here are both files


ComboFix 09-05-31.06 - Annelie Pernheden 2009-06-01 18:46.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.46.1053.18.2525.1443 [GMT 2:00]
Körs från: c:\users\Annelie Pernheden\Desktop\ComboFix.exe
Använda kommandoväxlar :: c:\users\Annelie Pernheden\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\system32\RBK3263.tmp"
"c:\windows\system32\RBK3268.tmp"
"c:\windows\system32\RBK326B.tmp"
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\RBK3263.tmp
c:\windows\system32\RBK3268.tmp
c:\windows\system32\RBK326B.tmp

.
(((((((((((((((((((((((( Filer Skapade från 2009-05-01 till 2009-06-01 ))))))))))))))))))))))))))))))
.

2009-06-01 17:17 . 2009-06-01 17:19 ——– d—–w- c:\users\Annelie Pernheden\AppData\Local\temp
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Malwarebytes
2009-05-31 22:25 . 2009-05-26 11:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\programdata\Malwarebytes
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-31 22:25 . 2009-05-26 11:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-29 18:31 . 2009-05-29 18:31 ——– d—–w- c:\programdata\WindowsSearch
2009-05-25 21:55 . 2009-05-25 22:03 ——– d—–w- c:\program files\SpeedBit Video Accelerator
2009-05-25 21:51 . 2009-05-25 21:51 50688 —-a-w- c:\windows\system32\wbhelp2.dll
2009-05-25 21:23 . 2009-05-25 21:28 ——– d—–w- c:\program files\IncrediMail
2009-05-16 18:02 . 2009-05-16 19:00 ——– d—–w- c:\program files\Startup Inspector for Windows
2009-05-14 19:22 . 2009-05-14 19:22 35 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\SetValue.bat
2009-05-12 17:13 . 2008-12-11 06:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-05-12 17:13 . 2009-04-03 09:18 130936 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-05-12 17:13 . 2008-12-18 10:16 73840 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-12 17:12 . 2009-05-12 17:15 ——– d—–w- c:\program files\Common Files\PC Tools
2009-05-12 17:12 . 2008-12-10 09:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-05-12 17:12 . 2009-05-12 17:12 ——– d—–w- c:\programdata\PC Tools
2009-05-07 19:34 . 2008-09-17 08:07 847360 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 17:13 . 2009-01-13 22:00 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Skype
2009-06-01 15:45 . 2009-01-13 14:57 ——– d—–w- c:\program files\Spyware Doctor
2009-06-01 15:14 . 2009-01-13 22:02 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\skypePM
2009-06-01 08:25 . 2009-01-12 17:35 12 —-a-w- c:\windows\bthservsdp.dat
2009-05-29 21:32 . 2009-04-29 04:26 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\wsInspector
2009-05-28 18:49 . 2009-01-13 21:17 ——– d—–w- c:\program files\Paint Shop Pro 7
2009-05-25 21:59 . 2009-01-13 21:46 ——– d—–w- c:\program files\DAP
2009-05-25 21:10 . 2009-04-05 23:59 ——– d—–w- c:\programdata\WinZip
2009-05-14 19:22 . 2009-05-14 19:22 691 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\GetValue.vbs
2009-05-13 21:56 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-12 17:36 . 2008-01-21 06:21 647970 —-a-w- c:\windows\system32\perfh01D.dat
2009-05-12 17:36 . 2008-01-21 06:21 138466 —-a-w- c:\windows\system32\perfc01D.dat
2009-05-07 09:45 . 2009-01-13 20:00 ——– d—–w- c:\program files\AVS4YOU
2009-04-30 20:25 . 2009-04-30 20:26 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-04-30 20:25 . 2009-04-30 20:25 ——– d—–w- c:\program files\Java
2009-04-30 18:29 . 2009-01-09 14:18 ——– d—–w- c:\program files\Google
2009-04-29 05:34 . 2008-03-11 18:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-04-29 05:21 . 2009-04-05 17:26 ——– d—–w- c:\program files\Common Files\ArcSoft
2009-04-29 05:03 . 2009-01-13 22:13 ——– d—–w- c:\program files\FontExpert
2009-04-29 04:19 . 2009-04-29 04:19 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\BoostXP2
2009-04-28 18:54 . 2009-04-28 18:54 ——– d—–w- c:\program files\Systweak BoostXP2
2009-04-26 18:50 . 2009-04-05 17:25 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\ArcSoft
2009-04-18 03:38 . 2009-01-10 19:13 ——– d—–w- c:\program files\DreamboxControlCenter
2009-04-06 10:57 . 2009-03-27 23:17 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\U3
2009-04-05 23:29 . 2009-04-05 17:13 ——– d—–w- c:\program files\Greeting Card Designer
2009-04-05 22:43 . 2009-04-05 22:43 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Skerryvore Software
2009-04-05 17:51 . 2009-04-05 17:28 ——– d—–w- c:\programdata\ArcSoft
2009-04-05 17:05 . 2009-04-05 17:05 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Proxima Software
2009-03-17 03:38 . 2009-04-19 18:07 13824 —-a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-19 18:07 24064 —-a-w- c:\windows\system32\amxread.dll
2009-03-08 11:34 . 2009-05-12 17:55 914944 —-a-w- c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-05-12 17:55 43008 —-a-w- c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-05-12 17:55 18944 —-a-w- c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-05-12 17:55 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-05-12 17:55 109568 —-a-w- c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-05-12 17:55 132608 —-a-w- c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-05-12 17:55 107520 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-05-12 17:55 107008 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-05-12 17:55 103936 —-a-w- c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-05-12 17:55 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-05-12 17:55 72704 —-a-w- c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-05-12 17:55 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-05-12 17:55 66560 —-a-w- c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-05-12 17:55 169472 —-a-w- c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-05-12 17:55 34816 —-a-w- c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-05-12 17:55 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-05-12 17:55 45568 —-a-w- c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-05-12 17:55 156160 —-a-w- c:\windows\system32\msls31.dll
2009-03-03 18:23 . 2009-03-03 18:23 40960 —-a-r- c:\users\Annelie Pernheden\AppData\Roaming\Microsoft\Installer\{23970E31-948B-466E-8376-1224D32FDF0C}\NewShortcut11_23970E31948B466E83761224D32FDF0C.exe
2009-03-03 18:23 . 2009-03-03 18:23 40960 —-a-r- c:\users\Annelie Pernheden\AppData\Roaming\Microsoft\Installer\{23970E31-948B-466E-8376-1224D32FDF0C}\NewShortcut1_23970E31948B466E83761224D32FDF0C.exe
2009-03-03 18:23 . 2009-03-03 18:23 1078 —-a-r- c:\users\Annelie Pernheden\AppData\Roaming\Microsoft\Installer\{23970E31-948B-466E-8376-1224D32FDF0C}\ARPPRODUCTICON.exe
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-04-17 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-01-09 3683328]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-30 148888]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-05-25 3364616]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-26 6144000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-23 727592]
Uppdateringsagent.lnk - c:\program files\3\3Connect\AutoUpdateSrv.exe [2008-10-23 442368]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-5-11 525640]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-09 14:49 3077120 —-a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A6165CC5-98E2-47C0-B70F-6FFF205B5E37}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{794E29E7-255B-4B7F-88E0-396200036F43}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{E093252A-D413-4A0C-ADD0-14D58DDD22C3}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{684D9249-ED36-45CE-9D43-D9F83B18F79E}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{4FA566E3-51F3-4CA3-9CFF-63F88622BE75}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{507A697E-D0FB-4E0B-9A50-B714F41CF91F}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{40AFA05B-B91D-4A06-BFAC-CD4B68E320A1}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{2E0D9A21-1467-4962-8018-C1014952C383}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{8CEC2307-3BB1-4AB9-BCD6-0001CAD8C3D7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{D9CD84BD-B285-4895-B761-E1D6338B4851}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= UDP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"UDP Query User{FDD9C5F5-B400-4E12-A2CA-637E0EE5AAC3}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= TCP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"{C3B84E63-9EB0-4497-AD5C-ECC97AE32097}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{5ABECF48-86B5-4C20-B535-0DBF90A130BE}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{D5B42117-CF84-4127-BFD8-50A705D93ADC}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{230ECA62-F144-4855-842E-5B616EE45AB7}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"TCP Query User{5C0CF614-8901-4B79-A437-624ABE7A5859}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= UDP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"UDP Query User{B207CB92-FC7D-4E44-A322-FFCF42A000D3}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= TCP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"TCP Query User{D1D80FFC-C1E3-471D-936A-CBD0FD47EE82}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{5D476576-9CBA-4706-859F-FD0ED104118F}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{5048270E-E6F9-46A4-BA30-B5FED8E39821}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{5D102427-C56A-4C3C-AA67-39B67901A32A}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"TCP Query User{D48D1106-176E-4496-B9F5-A236C8BF2F1C}c:\\program files\\dap\\dap.exe"= UDP:c:\program files\dap\dap.exe:Download Accelerator Plus (DAP)
"UDP Query User{A7EFC5A2-7A6C-4700-922F-A0846B31DEE4}c:\\program files\\dap\\dap.exe"= TCP:c:\program files\dap\dap.exe:Download Accelerator Plus (DAP)
"{D7EB80B0-0B01-4A5E-A472-5757C8DA072B}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{86D05153-BE43-430E-B912-550666A5569C}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{976DA9A1-C095-457B-9BA8-67F728C7BE36}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{7A21254B-3014-44DD-BDA1-9FCDA03E26C3}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\System32\drivers\AlfaFF.sys [2009-01-09 43184]
R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [2009-05-12 130936]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-02-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-02-12 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-02-12 51792]
R2 BcmSqlStartupSvc;Starttjänst för Business Contact Manager SQL Server;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-11 24576]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [2009-01-09 3481088]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [2007-04-17 11032]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-13 348752]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2008-06-25 212992]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [2008-07-15 96856]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [2009-01-09 22072]
S1 AMTBDA_P861F;anysee Capture Service;c:\windows\System32\drivers\anyseeTU.SYS [2008-09-29 481024]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [2009-01-16 81704]

— Övriga tjänster/drivrutiner i minnet —

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

SafeBoot-procexp90.Sys


.
——- Extra genomsökning ——-
.
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: Anpassa meny - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xportera; till Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Fyll i formulär - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RF verktygsfält - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Skicka bild till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Skicka sida till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Skicka som mms… - file://c:\program files\Sms och mms i datorn Desktop\sendmms.htm
IE: Skicka som sms… - file://c:\program files\Sms och mms i datorn Desktop\sendsms.htm
IE: Spara formulär - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
FF - ProfilePath - c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_fs&search;=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll

—- FIREFOX POLICY —-
FF - user.js: keyword.enabled - true
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-01 19:18
Windows 6.0.6001 Service Pack 1 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LÅSTA REGISTERNYCKLAR ———————

[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'lsass.exe'(720)
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll
c:\program files\SpeedBit Video Accelerator\Collector.dll
c:\program files\Acer\Acer Bio Protection\PwdFilter.dll
.
Sluttid: 2009-06-01 19:33
ComboFix-quarantined-files.txt 2009-06-01 17:33
ComboFix2.txt 2009-06-01 15:36

Före genomsökningen: 103 371 649 024 byte ledigt
Efter genomsökningen: 103 273 811 968 byte ledigt

Current=6 Default=6 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
270 — E O F — 2009-05-26 20:45


———————

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, June 2, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Monday, June 01, 2009 19:14:19
Records in database: 2292339
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 147652
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 05:57:33


File name / Threat name / Threats count
C:\Program Files\DAP\DAPIEBar.dll Infected: not-a-virus:AdWare.Win32.Dap.e 1

The selected area was scanned.


Best regards
Farmor
Farmor,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Program Files\DAP\DAPIEBar.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then please post me a new HijackThis log and let me know how it's running.
Hi TOMK, here are the two log files:

ComboFix 09-05-31.06 - Annelie Pernheden 2009-06-02 22:22.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.46.1053.18.2525.1479 [GMT 2:00]
Körs från: c:\users\Annelie Pernheden\Desktop\ComboFix.exe
Använda kommandoväxlar :: c:\users\Annelie Pernheden\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\program files\DAP\DAPIEBar.dll"
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\DAP\DAPIEBar.dll

.
(((((((((((((((((((((((( Filer Skapade från 2009-05-02 till 2009-06-02 ))))))))))))))))))))))))))))))
.

2009-06-02 06:24 . 2009-06-02 06:24 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Acer
2009-06-01 17:40 . 2009-06-01 17:40 ——– d—–w- c:\windows\Sun
2009-06-01 17:33 . 2009-06-02 20:45 ——– d—–w- c:\users\Annelie Pernheden\AppData\Local\temp
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Malwarebytes
2009-05-31 22:25 . 2009-05-26 11:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\programdata\Malwarebytes
2009-05-31 22:25 . 2009-05-31 22:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-31 22:25 . 2009-05-26 11:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-29 18:31 . 2009-05-29 18:31 ——– d—–w- c:\programdata\WindowsSearch
2009-05-25 21:55 . 2009-05-25 22:03 ——– d—–w- c:\program files\SpeedBit Video Accelerator
2009-05-25 21:51 . 2009-05-25 21:51 50688 —-a-w- c:\windows\system32\wbhelp2.dll
2009-05-25 21:23 . 2009-05-25 21:28 ——– d—–w- c:\program files\IncrediMail
2009-05-16 18:02 . 2009-05-16 19:00 ——– d—–w- c:\program files\Startup Inspector for Windows
2009-05-14 19:22 . 2009-05-14 19:22 35 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\SetValue.bat
2009-05-12 17:13 . 2008-12-11 06:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-05-12 17:13 . 2009-04-03 09:18 130936 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-05-12 17:13 . 2008-12-18 10:16 73840 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-12 17:12 . 2009-05-12 17:15 ——– d—–w- c:\program files\Common Files\PC Tools
2009-05-12 17:12 . 2008-12-10 09:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-05-12 17:12 . 2009-05-12 17:12 ——– d—–w- c:\programdata\PC Tools
2009-05-07 19:34 . 2008-09-17 08:07 847360 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 20:45 . 2009-01-13 22:00 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Skype
2009-06-02 20:24 . 2009-01-13 21:46 ——– d—–w- c:\program files\DAP
2009-06-02 15:37 . 2009-01-13 14:57 ——– d—–w- c:\program files\Spyware Doctor
2009-06-02 15:27 . 2009-01-13 22:02 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\skypePM
2009-06-02 06:30 . 2009-01-12 17:35 12 —-a-w- c:\windows\bthservsdp.dat
2009-06-02 05:44 . 2009-01-13 21:17 ——– d—–w- c:\program files\Paint Shop Pro 7
2009-05-29 21:32 . 2009-04-29 04:26 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\wsInspector
2009-05-25 21:10 . 2009-04-05 23:59 ——– d—–w- c:\programdata\WinZip
2009-05-14 19:22 . 2009-05-14 19:22 691 —-a-w- c:\users\Annelie Pernheden\AppData\Roaming\GetValue.vbs
2009-05-13 21:56 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-12 17:36 . 2008-01-21 06:21 647970 —-a-w- c:\windows\system32\perfh01D.dat
2009-05-12 17:36 . 2008-01-21 06:21 138466 —-a-w- c:\windows\system32\perfc01D.dat
2009-05-07 09:45 . 2009-01-13 20:00 ——– d—–w- c:\program files\AVS4YOU
2009-04-30 20:25 . 2009-04-30 20:26 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-04-30 20:25 . 2009-04-30 20:25 ——– d—–w- c:\program files\Java
2009-04-30 18:29 . 2009-01-09 14:18 ——– d—–w- c:\program files\Google
2009-04-29 05:34 . 2008-03-11 18:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-04-29 05:21 . 2009-04-05 17:26 ——– d—–w- c:\program files\Common Files\ArcSoft
2009-04-29 05:03 . 2009-01-13 22:13 ——– d—–w- c:\program files\FontExpert
2009-04-29 04:19 . 2009-04-29 04:19 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\BoostXP2
2009-04-28 18:54 . 2009-04-28 18:54 ——– d—–w- c:\program files\Systweak BoostXP2
2009-04-26 18:50 . 2009-04-05 17:25 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\ArcSoft
2009-04-18 03:38 . 2009-01-10 19:13 ——– d—–w- c:\program files\DreamboxControlCenter
2009-04-06 10:57 . 2009-03-27 23:17 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\U3
2009-04-05 23:29 . 2009-04-05 17:13 ——– d—–w- c:\program files\Greeting Card Designer
2009-04-05 22:43 . 2009-04-05 22:43 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Skerryvore Software
2009-04-05 17:51 . 2009-04-05 17:28 ——– d—–w- c:\programdata\ArcSoft
2009-04-05 17:05 . 2009-04-05 17:05 ——– d—–w- c:\users\Annelie Pernheden\AppData\Roaming\Proxima Software
2009-03-17 03:38 . 2009-04-19 18:07 13824 —-a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-19 18:07 24064 —-a-w- c:\windows\system32\amxread.dll
2009-03-08 11:34 . 2009-05-12 17:55 914944 —-a-w- c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-05-12 17:55 43008 —-a-w- c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-05-12 17:55 18944 —-a-w- c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-05-12 17:55 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-05-12 17:55 109568 —-a-w- c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-05-12 17:55 132608 —-a-w- c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-05-12 17:55 107520 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-05-12 17:55 107008 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-05-12 17:55 103936 —-a-w- c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-05-12 17:55 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-05-12 17:55 72704 —-a-w- c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-05-12 17:55 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-05-12 17:55 66560 —-a-w- c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-05-12 17:55 169472 —-a-w- c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-05-12 17:55 34816 —-a-w- c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-05-12 17:55 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-05-12 17:55 45568 —-a-w- c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-05-12 17:55 156160 —-a-w- c:\windows\system32\msls31.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-01_15.17.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-06-02 15:23 69788 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-06-02 15:24 95478 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-09 14:06 . 2009-06-02 19:27 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-09 14:06 . 2009-06-01 15:16 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-09 14:06 . 2009-06-01 15:16 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-09 14:06 . 2009-06-02 19:27 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-09 14:06 . 2009-06-01 15:16 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-09 14:06 . 2009-06-02 19:27 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-05-18 04:32 . 2009-06-01 15:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-05-18 04:32 . 2009-06-02 15:20 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-09 16:00 . 2009-06-02 15:24 8816 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1874841969-2202082836-4081557059-1003_UserData.bin
+ 2009-06-02 15:20 . 2009-06-02 15:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-06-01 15:11 . 2009-06-01 15:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-06-01 15:11 . 2009-06-01 15:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-02 15:20 . 2009-06-02 15:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-04-17 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-01-09 3683328]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-30 148888]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-05-25 3364616]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-26 6144000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-23 727592]
Uppdateringsagent.lnk - c:\program files\3\3Connect\AutoUpdateSrv.exe [2008-10-23 442368]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-5-11 525640]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-09 14:49 3077120 —-a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A6165CC5-98E2-47C0-B70F-6FFF205B5E37}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{794E29E7-255B-4B7F-88E0-396200036F43}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{E093252A-D413-4A0C-ADD0-14D58DDD22C3}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{684D9249-ED36-45CE-9D43-D9F83B18F79E}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{4FA566E3-51F3-4CA3-9CFF-63F88622BE75}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{507A697E-D0FB-4E0B-9A50-B714F41CF91F}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{40AFA05B-B91D-4A06-BFAC-CD4B68E320A1}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{2E0D9A21-1467-4962-8018-C1014952C383}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{8CEC2307-3BB1-4AB9-BCD6-0001CAD8C3D7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{D9CD84BD-B285-4895-B761-E1D6338B4851}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= UDP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"UDP Query User{FDD9C5F5-B400-4E12-A2CA-637E0EE5AAC3}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= TCP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"TCP Query User{5C0CF614-8901-4B79-A437-624ABE7A5859}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= UDP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"UDP Query User{B207CB92-FC7D-4E44-A322-FFCF42A000D3}c:\\program files\\dreamboxcontrolcenter\\dcc.exe"= TCP:c:\program files\dreamboxcontrolcenter\dcc.exe:Dreambox Control Center
"TCP Query User{D1D80FFC-C1E3-471D-936A-CBD0FD47EE82}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{5D476576-9CBA-4706-859F-FD0ED104118F}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{5048270E-E6F9-46A4-BA30-B5FED8E39821}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{5D102427-C56A-4C3C-AA67-39B67901A32A}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"TCP Query User{D48D1106-176E-4496-B9F5-A236C8BF2F1C}c:\\program files\\dap\\dap.exe"= UDP:c:\program files\dap\dap.exe:Download Accelerator Plus (DAP)
"UDP Query User{A7EFC5A2-7A6C-4700-922F-A0846B31DEE4}c:\\program files\\dap\\dap.exe"= TCP:c:\program files\dap\dap.exe:Download Accelerator Plus (DAP)
"{B7D2FD13-5D2F-4F6C-BF00-FB007C5D8CE6}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{080E57C7-3407-4D4D-A84A-9EAC50FEAB6C}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{3A6E638F-793C-4725-ACC4-D6342F7D9864}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{42D1F59D-9C2D-4E64-88F8-3D6001341F5C}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{14FC7C5D-3D46-44BB-8B5E-23B0ADE3D9DA}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{B433A06C-3562-403D-ADB4-29565CAA3C08}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{AA37B872-757E-4334-93C3-9DE02A13892F}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{3CA6A92E-55D5-4507-86AF-F2EBFBBC621D}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\System32\drivers\AlfaFF.sys [2009-01-09 43184]
R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [2009-05-12 130936]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-02-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-02-12 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-02-12 51792]
R2 BcmSqlStartupSvc;Starttjänst för Business Contact Manager SQL Server;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-11 24576]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [2009-01-09 3481088]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [2007-04-17 11032]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2008-06-25 212992]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [2008-07-15 96856]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [2009-01-09 22072]
S1 AMTBDA_P861F;anysee Capture Service;c:\windows\System32\drivers\anyseeTU.SYS [2008-09-29 481024]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-13 348752]
S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [2009-01-16 81704]

— Övriga tjänster/drivrutiner i minnet —

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Extra genomsökning ——-
.
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: Anpassa meny - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xportera; till Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Fyll i formulär - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RF verktygsfält - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Skicka bild till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Skicka sida till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Skicka som mms… - file://c:\program files\Sms och mms i datorn Desktop\sendmms.htm
IE: Skicka som sms… - file://c:\program files\Sms och mms i datorn Desktop\sendsms.htm
IE: Spara formulär - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
FF - ProfilePath - c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_fs&search;=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Annelie Pernheden\AppData\Roaming\Mozilla\Firefox\Profiles\c4556ti7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll

—- FIREFOX POLICY —-
FF - user.js: keyword.enabled - true
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-02 22:45
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

[0] 0x08558B00

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LÅSTA REGISTERNYCKLAR ———————

[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'lsass.exe'(720)
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll
c:\program files\SpeedBit Video Accelerator\Collector.dll
.
Sluttid: 2009-06-02 22:53
ComboFix-quarantined-files.txt 2009-06-02 20:53
ComboFix2.txt 2009-06-01 17:33
ComboFix3.txt 2009-06-01 15:36

Före genomsökningen: 103 099 838 464 byte ledigt
Efter genomsökningen: 103 004 160 000 byte ledigt

Current=6 Default=6 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
279 — E O F — 2009-05-26 20:45

————–


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:57:18, on 2009-06-02
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\3\3Connect\AutoUpdateSrv.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\IncrediMail\bin\ImApp.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\DllHost.exe
C:\Windows\Explorer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Uppdateringsagent.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Clean; Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Anpassa meny - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fyll i formulär - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RF verktygsfält - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Skicka bild till &Bluetooth-enhet;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Skicka sida till &Bluetooth-enhet;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Skicka som mms… - file://C:\Program Files\Sms och mms i datorn Desktop\sendmms.htm
O8 - Extra context menu item: Skicka som sms… - file://C:\Program Files\Sms och mms i datorn Desktop\sendsms.htm
O8 - Extra context menu item: Spara formulär - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 10086 bytes


I'm going to restart my laptop now and test it and will be back with the result. Thought you could amuse yourself with the log files in the meantime. :yeah: :blush:

Best regrads
Farmor
Hi again, The laptpop is a lot faster, but still not as it was before. Did you find any other carp**, that I need to get rid of? Regards
Farmor,

Here are some entries that aren't bad, but they aren't needed and can contribute to lag.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
      O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
      O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
      O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
      O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
      O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

With that done, Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

I would further suggest that you also read this tutorial on slow running computers
and Help! My computer is slow! by miekiemoes.

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Hi Tomk, Thank you so very much. My laptop is acting like a new "person", same as it used to be. I've fulfilled your 'orders', but haven't read your information links yet. I'll do that as soon as possible. I really wonder how I got this stuff into my laptop. I have been extremely careful with with it and my desktop computer as I use in the same way, isn't infected, neither is my husbands. They are all in the same network at home together with another laptop, which our grandchildren use, when they are here. (Farmor is grandmother in Swedish, if you didn't know.) I'm very impressed of your skills and I wish I could do what you have done, but sadly to say, I'm too old even to try. The heads of elderly ladies are overfilled :pullhair: and if, at least I, fill it with more, something else will fall out. :smack: :wacko: :wacko: Anyway, thank you again and, no hard feelings, but I hope I wont meet you again, at least not on these boards. :thumbup:
Farmor,

Unfortunately I can't help you with how you got infected. It could have been an email that you accidentally clicked a link on. Maybe you inadvertantly clicked on a pop up. I just can't tell.

I am so glad things are working better and that we could help.

I'm too old even to try.

I doubt it. :)

You are very welcome.

Good Luck and Be Well. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI