Gå till innehåll

candela

Medlem
  • Innehållsantal

    455
  • Gick med

  • Besökte senast

  • Dagar vunna

    7

Allt postat av candela

  1. Hej Malou och JoWa, Comodo blockerar inte. Min ver av Comodo är 3.5.57173.439. Bör kanske försöka att avinstallera Comodo och göra ny nerladdning och installation. Återkommer. /candela
  2. Hej Landsfiskalen, har redan testat med Revo (ett mycket bra program tycker jag), men det hjälper inte i detta fall. /candela
  3. Hej Malou, Tack för förslaget. Men det funkade inte. Avinstallerade F-Secure och Bonjour och testade att återinstallera CD BurnerXP. Samma resultat dvs efter installation kan programmet inte startas. Vet inte varför programmet blockeras på något sätt. Hoppas i det längsta att någon kan hjälpa mig så jag slipper den omständiga ominstallationen efter formatering. Mvh candela
  4. Har fått ett underligt problem. Hänger kanske ihop med någon avinstallation. Det började i går med att programmet CD Burner XP inte gick att starta. Avinstallerade programmet och laddade ner en ny version och installerade. Förloppet vid installation verkade OK, men när programmet skulle starta hände ingenting. Har kört med Ccleaner, Anti Malware, Super Antispyware och NOD 32. Inga malware, spyware eller trojaner funna. Datorn har blivit väldigt seg oavsett vilket program eller webbläsare som skall startas. Har börjat misströsta att hitta orsak och åtgärd. Men innan jag tar till formatering med åtföljande jobbiga återställning av funktioner och program hoppas jag någon här på forumet kan vara mig behjälplig att lösa detta. Tar tacksamt emot alla förslag. Bifogar en HJT-logga. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:42:51, on 2009-01-09 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\Explorer.EXE C:\Program\Comodo\Firewall\cmdagent.exe C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program\F-Secure\ExploitShield\fsessrv.exe C:\Program\Java\jre6\bin\jqs.exe C:\Program\McAfee\SiteAdvisor\McSACore.exe C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program\Analog Devices\SoundMAX\spkrmon.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program\Comodo\Firewall\cfp.exe C:\Program\ESET\ESET NOD32 Antivirus\egui.exe C:\Program\F-Secure\ExploitShield\fsesgui.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program\Personal\bin\Personal.exe C:\Program\Secunia\PSI\psi.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Program\Mozilla Firefox 3.1 Beta 2\firefox.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\explorer.exe C:\Program\Trend Micro\HijackThis\Rensare.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar O2 - BHO: (no name) - AutorunsDisabled - (no file) O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program\IEPro\iepro.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program\SpywareGuard\dlprotect.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre6\bin\ssv.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\program\mcafee\siteadvisor\mcieplg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program\mcafee\siteadvisor\mcieplg.dll O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program\Comodo\Firewall\cfp.exe" -h O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [egui] "C:\Program\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [F-Secure ExploitShield] "C:\Program\F-Secure\ExploitShield\fsesgui.exe" O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [sBAutoUpdate] "C:\Program\SpywareBlaster\sbautoupdate.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O4 - Startup: Secunia PSI.lnk = C:\Program\Secunia\PSI\psi.exe O4 - Global Startup: BankID säkerhetsprogram.lnk = C:\Program\Personal\bin\Personal.exe O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program\IEPro\iepro.dll O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program\IEPro\iepro.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\OFFICE11\REFIEBAR.DLL O15 - Trusted Zone: http://download.windowsupdate.com O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program\mcafee\siteadvisor\mcieplg.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\Skype4COM.dll O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\ O20 - Winlogon Notify: GoToAssist - C:\Program\Citrix\GoToAssist\514\G2AWinLogon.dll O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program\Comodo\Firewall\cmdagent.exe O23 - Service: Eset HTTP Server (EHttpSrv) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe O23 - Service: F-Secure Exploit Shield Service (ExploitShield) - F-Secure Corporation - C:\Program\F-Secure\ExploitShield\fsessrv.exe O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program\F-Secure\ORSP Client\fsorsp.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program\NOS\bin\getPlus_HelperSvc.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program\McAfee\SiteAdvisor\McSACore.exe O23 - Service: NBService - Unknown owner - C:\Program\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys O23 - Service: spkrmon - Unknown owner - C:\Program\Analog Devices\SoundMAX\spkrmon.exe -- End of file - 8497 bytes Mvh candela ********************************************* 2009-01-11: Tråden är nu låst eftersom problemet är löst Tycker du att den är felaktigt låst, var god kontakta Mickilina *********************************************
  5. Hej JoWa, Kan jag gå in i Autoruns.exe alt Tjänster och avmarkera de som du angivit? Det är ok att Ccleaner sopar bort men efter att ha använt tex Excel några gånger så ligger filerna kvar tills jag rensar med Cleaner igen. Bäst att fråga dig innan (annars blir det "friskt kopplat hälften brunnit") /candela
  6. Efter olika rensningar med bla Ccleaner ,SuperAntispyvare och Advance System Care så har följande fel upp stått: I Execel och Word har tidigare filer legat kvar till höger i resp program (Office 2003). Nu finns de inte längre kvar utan jag måste gå via Öppna och välja aktuellt dokument varje gång. Nu har också datorn blivit otroligt seg. Efter att ha gått igenom tex en mapp med bilder (I MINA BILDER) så djöjer det länge innan nästa mapp kan öppnas. Förmodar att jag stängt av eller i värsta fall tagit bort någon funktion. Hoppas någon här på forumet kan tipsa om vad som kan/bör göras. Bifogat en HJT-logga Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:37:53, on 2008-12-08 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32LEXBCES.EXE C:WINDOWSsystem32LEXPPS.EXE C:WINDOWSsystem32spoolsv.exe C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe C:ProgramBonjourmDNSResponder.exe C:ProgramComodoFirewallcmdagent.exe C:ProgramESETESET NOD32 Antivirusekrn.exe C:WINDOWSExplorer.EXE C:ProgramDelade filerLightScribeLSSrvc.exe C:ProgramMcAfeeSiteAdvisorMcSACore.exe C:ProgramDelade filerMicrosoft SharedVS7DEBUGMDM.EXE C:ProgramCDBurnerXPNMSAccessU.exe C:WINDOWSsystem32nvsvc32.exe C:ProgramAnalog DevicesSoundMAXspkrmon.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32SearchIndexer.exe C:ProgramComodoFirewallcfp.exe C:ProgramESETESET NOD32 Antivirusegui.exe C:WINDOWSsystem32RUNDLL32.EXE C:WINDOWSsystem32ctfmon.exe C:ProgramSUPERAntiSpywareSUPERAntiSpyware.exe C:ProgramIObitAdvanced SystemCare 3AWC.exe C:ProgramPersonalbinPersonal.exe C:WINDOWSsystem32cisvc.exe C:WINDOWSsystem32cidaemon.exe C:ProgramInternet ExplorerIEXPLORE.EXE C:WINDOWSexplorer.exe C:ProgramTrend MicroHijackThisRensare.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.se/ R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Länkar O2 - BHO: (no name) - AutorunsDisabled - (no file) O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:ProgramIEProiepro.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:ProgramDelade filerAdobeAcrobatActiveXAcroIEHelperShim.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:ProgramSpywareGuarddlprotect.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_07binssv.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:programmcafeesiteadvisormcieplg.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:programmcafeesiteadvisormcieplg.dll O4 - HKLM..Run: [sBAutoUpdate] "C:ProgramSpywareBlastersbautoupdate.exe" O4 - HKLM..Run: [COMODO Firewall Pro] "C:ProgramComodoFirewallcfp.exe" -h O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [egui] "C:ProgramESETESET NOD32 Antivirusegui.exe" /hide /waitservice O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe O4 - HKCU..Run: [sUPERAntiSpyware] C:ProgramSUPERAntiSpywareSUPERAntiSpyware.exe O4 - HKCU..Run: [Advanced SystemCare 3] "C:ProgramIObitAdvanced SystemCare 3AWC.exe" /startup O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'SYSTEM') O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O4 - Global Startup: BankID säkerhetsprogram.lnk = C:ProgramPersonalbinPersonal.exe O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000 O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:ProgramIEProiepro.dll O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:ProgramSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:programmcafeesiteadvisormcieplg.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSkype4COM.dll O20 - AppInit_DLLs: C:WINDOWSsystem32guard32.dll O20 - Winlogon Notify: !SASWinLogon - C:ProgramSUPERAntiSpywareSASWINLO.dll O20 - Winlogon Notify: GoToAssist - C:ProgramCitrixGoToAssist514G2AWinLogon.dll O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:ProgramComodoFirewallcmdagent.exe O23 - Service: Eset HTTP Server (EHttpSrv) - ESET - C:ProgramESETESET NOD32 AntivirusEHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:ProgramESETESET NOD32 Antivirusekrn.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:ProgramNOSbingetPlus_HelperSvc.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:ProgramCitrixGoToAssist514g2aservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver1150Intel 32IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:ProgramDelade filerLightScribeLSSrvc.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:ProgramMcAfeeSiteAdvisorMcSACore.exe O23 - Service: NMIndexingService - Unknown owner - C:ProgramDelade filerAheadLibNMIndexingService.exe (file missing) O23 - Service: NMSAccessU - Unknown owner - C:ProgramCDBurnerXPNMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:WINDOWSsystem32driverspclepci.sys O23 - Service: spkrmon - Unknown owner - C:ProgramAnalog DevicesSoundMAXspkrmon.exe -- End of file - 8511 bytes Mvh candela
  7. LbL, Försök med detta: Starta Pinnacle Studio => Filer=>Öppna Projekt. I mappen som öppnas bör "MIN FILM" ligga. Sedan kan du spara den med annat namn. Så funkar programmet hos mig . Via Document & Settings får du bara "Parkeringshuset" /candela
  8. LbL, Sök under: Mina dokument=>Pinnacle Studio=>My Disc Images=>Min Film=> Video_TS eller Mina dokument=> Mina videoklipp /candela
  9. candela

    NVCPL.DLL

    Det hjälpte inte DimensionX. Körde Malvarebytes Anti Malware och hittade: Malwarebytes' Anti-Malware 1.29 Databasversion: 1302 Windows 5.1.2600 Service Pack 3 2008-11-01 11:54:36 mbam-log-2008-11-01 (11-54-32).txt Skanningstyp: Fullständig skanning (C:|) Antal skannade objekt: 183703 Förfluten tid: 1 hour(s), 1 minute(s), 10 second(s) Infekterade minnesprocesser: 0 Infekterade minnesmoduler: 0 Infekterade registernycklar: 1 Infekterade registervärden: 1 Infekterade registerdataposter: 0 Infekterade mappar: 0 Infekterade filer: 0 Infekterade minnesprocesser: (Inga illasinnade poster hittades) Infekterade minnesmoduler: (Inga illasinnade poster hittades) Infekterade registernycklar: HKEY_CLASSES_ROOTmultimediaControls.chl (Trojan.Zlob) -> No action taken. Infekterade registervärden: HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerToolbarWebBrowser{94a5c93f-bd18-4c46-b777-c94c145c3cab} (Trojan.Zlob) -> No action taken. Infekterade registerdataposter: (Inga illasinnade poster hittades) Infekterade mappar: (Inga illasinnade poster hittades) Infekterade filer: (Inga illasinnade poster hittades) Körde därefter HiJackThis med följande logga: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:03:56, on 2008-11-01 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32LEXBCES.EXE C:WINDOWSsystem32LEXPPS.EXE C:WINDOWSsystem32spoolsv.exe C:WINDOWSExplorer.EXE C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe C:ProgramBonjourmDNSResponder.exe C:ProgramComodoFirewallcmdagent.exe C:ProgramESETESET NOD32 Antivirusekrn.exe C:ProgramJavajre6binjqs.exe C:ProgramDelade filerLightScribeLSSrvc.exe C:ProgramMcAfeeSiteAdvisorMcSACore.exe C:ProgramDelade filerMicrosoft SharedVS7DEBUGMDM.EXE C:ProgramCDBurnerXPNMSAccessU.exe C:WINDOWSsystem32nvsvc32.exe C:WINDOWSsystem32IoctlSvc.exe C:ProgramAnalog DevicesSoundMAXspkrmon.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32SearchIndexer.exe C:ProgramESETESET NOD32 Antivirusegui.exe C:ProgramComodoFirewallcfp.exe C:WINDOWSsystem32ctfmon.exe C:ProgramInternet ExplorerIEXPLORE.EXE C:WINDOWSexplorer.exe C:ProgramTrend MicroHijackThisRensare.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.se/ R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Länkar O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:ProgramIEProiepro.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:ProgramDelade filerAdobeAcrobatActiveXAcroIEHelperShim.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:ProgramSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:ProgramSpywareGuarddlprotect.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre6binssv.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:programmcafeesiteadvisormcieplg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:ProgramJavajre6binjp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:ProgramJavajre6libdeployjqsiejqs_plugin.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:programmcafeesiteadvisormcieplg.dll O4 - HKLM..Run: [sBAutoUpdate] "C:ProgramSpywareBlastersbautoupdate.exe" O4 - HKLM..Run: [egui] "C:ProgramESETESET NOD32 Antivirusegui.exe" /hide /waitservice O4 - HKLM..Run: [COMODO Internet Security] "C:ProgramComodoFirewallcfp.exe" -h O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'SYSTEM') O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000 O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:ProgramIEProiepro.dll O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:ProgramSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5036.cab O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - http://www.superadblocker.com/activex/sabspx.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - http://www.cooliris.com/shared/plinstll.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:programmcafeesiteadvisormcieplg.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSkype4COM.dll O20 - AppInit_DLLs: u????y?yU??D C:WINDOWSsystem32guard32.dll O20 - Winlogon Notify: !SASWinLogon - C:ProgramSUPERAntiSpywareSASWINLO.dll O20 - Winlogon Notify: GoToAssist - C:ProgramCitrixGoToAssist514G2AWinLogon.dll O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:ProgramComodoFirewallcmdagent.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:ProgramESETESET NOD32 AntivirusEHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:ProgramESETESET NOD32 Antivirusekrn.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:ProgramNOSbingetPlus_HelperSvc.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:ProgramCitrixGoToAssist514g2aservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver1150Intel 32IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:ProgramJavajre6binjqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:ProgramDelade filerLightScribeLSSrvc.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:ProgramMcAfeeSiteAdvisorMcSACore.exe O23 - Service: NBService - Nero AG - C:ProgramNeroNero 7Nero BackItUpNBService.exe O23 - Service: NMIndexingService - Nero AG - C:ProgramDelade filerAheadLibNMIndexingService.exe O23 - Service: NMSAccessU - Unknown owner - C:ProgramCDBurnerXPNMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:WINDOWSsystem32driverspclepci.sys O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:WINDOWSsystem32IoctlSvc.exe O23 - Service: spkrmon - Unknown owner - C:ProgramAnalog DevicesSoundMAXspkrmon.exe -- End of file - 9193 bytes Innan jag gör något vidare hoppas jag att hjälp om vad som skall göras och i vilken ordning. Villrådig candela
  10. candela

    NVCPL.DLL

    Tack för tipset. Men hur går jag tillväga? Skall jag gå in via felsäkert läge och avinstallera drivrutinen? Hur får jag tillbaka NVCPL? Mvh candela
  11. candela

    NVCPL.DLL

    Hej DimensionX och tack för snabbt svar. skall jag avinstallera NVIDIA Drivers med Revo Uninstaller och sedan leta efter ny drivrutin på NVIDIA? Skall jag först hämta ny drivrutin och spara den på tex skrivbordet och därefter avinstallera? Hur återfår jag Nvidias kontrollpanel? /candela
  12. candela

    NVCPL.DLL

    När jag startar datorn får jag felmeddelande: Det gick inte att läsa in NVCPL.DLL Det går inte att via kontrollpanelen komma någonstans, får felmeddelande: C:WindowsSystem32nvscpl.dll. När jag går in där går mappen ej att öppna.Se bif bild. Hoppas någon kan förklara varför detta inträffat och vad som kan göras för att avhjälpa felet. /candela
  13. Hej Malou, kunde ta gift på att jag svarat dig men måste ha drabbats av hjärnsläpp. Här kommer HJT-loggan på nytt: HLogfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:50:17, on 2008-09-09 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32LEXBCES.EXE C:WINDOWSsystem32spoolsv.exe C:WINDOWSsystem32LEXPPS.EXE C:WINDOWSExplorer.EXE C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe C:ProgramBonjourmDNSResponder.exe C:ProgramComodoFirewallcmdagent.exe C:ProgramESETESET NOD32 Antivirusekrn.exe C:ProgramDelade filerLightScribeLSSrvc.exe C:ProgramDelade filerMicrosoft SharedVS7DEBUGMDM.EXE C:ProgramCDBurnerXPNMSAccessU.exe C:WINDOWSsystem32nvsvc32.exe C:WINDOWSsystem32IoctlSvc.exe C:ProgramSiteAdvisor6261SAService.exe C:ProgramAnalog DevicesSoundMAXspkrmon.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32SearchIndexer.exe C:ProgramESETESET NOD32 Antivirusegui.exe C:WINDOWSsystem32RUNDLL32.EXE C:ProgramComodoFirewallCPF.exe C:WINDOWSsystem32ctfmon.exe C:ProgramSiteAdvisor6261SiteAdv.exe C:ProgramMicrosoft OfficeOFFICE11OUTLOOK.EXE C:ProgramSMS från Datorn OutlookGWServer.exe C:ProgramMicrosoft OfficeOFFICE11WINWORD.EXE C:ProgramDelade filerAheadLibNMIndexingService.exe C:ProgramDelade filerTeleca SharedGeneric.exe C:ProgramSony EricssonMobile2Mobile Phone Monitorepmworker.exe C:ProgramInternet ExplorerIEXPLORE.EXE C:WINDOWSexplorer.exe C:WINDOWSsystem32SearchProtocolHost.exe C:ProgramTrend MicroHijackThisRensare.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.se/ R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Länkar O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:ProgramIEProiepro.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:ProgramSiteAdvisor6261SiteAdv.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:ProgramDelade filerAdobeAcrobatActiveXAcroIEHelperShim.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:ProgramSpywareGuarddlprotect.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_07binssv.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:ProgramSiteAdvisor6261SiteAdv.dll O4 - HKLM..Run: [sBAutoUpdate] "C:ProgramSpywareBlastersbautoupdate.exe" O4 - HKLM..Run: [egui] "C:ProgramESETESET NOD32 Antivirusegui.exe" /hide /waitservice O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [COMODO Firewall Pro] "C:ProgramComodoFirewallCPF.exe" /background O4 - HKLM..Run: [QuickTime Task] "C:ProgramQuickTimeqttask.exe" -atboottime O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NVMCTRAY.DLL,NvTaskbarInit O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'SYSTEM') O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000 O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSkype4COM.dll O20 - AppInit_DLLs: O20 - Winlogon Notify: GoToAssist - C:ProgramCitrixGoToAssist514G2AWinLogon.dll O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:ProgramComodoFirewallcmdagent.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:ProgramESETESET NOD32 AntivirusEHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:ProgramESETESET NOD32 Antivirusekrn.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:ProgramCitrixGoToAssist514g2aservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver1150Intel 32IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:ProgramDelade filerLightScribeLSSrvc.exe O23 - Service: IEUser Restarter Service (MyIEUserRestarter) - Unknown owner - C:WINDOWSsystem32MacromedDownloadRestartIEUser.exe (file missing) O23 - Service: NBService - Nero AG - C:ProgramNeroNero 7Nero BackItUpNBService.exe O23 - Service: NMIndexingService - Nero AG - C:ProgramDelade filerAheadLibNMIndexingService.exe O23 - Service: NMSAccessU - Unknown owner - C:ProgramCDBurnerXPNMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:WINDOWSsystem32driverspclepci.sys O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:WINDOWSsystem32IoctlSvc.exe O23 - Service: SiteAdvisor-tjänst (SiteAdvisor Service) - Unknown owner - C:ProgramSiteAdvisor6261SAService.exe O23 - Service: spkrmon - Unknown owner - C:ProgramAnalog DevicesSoundMAXspkrmon.exe -- End of file - 7901 bytes Datorn mår superbt och så även jag tack vare dig. Du är fantastisk. Mvh candela
  14. Hej Malou, Datorn verkar att må bra. ;D Helt säker är jag inte att allt är OK förrän du granskat loggarna och lämnat råd om ev. åtgärder. Malwarebytes' Anti-Malware 1.27 Databasversion: 1128 Windows 5.1.2600 Service Pack 3 2008-09-08 16:30:26 mbam-log-2008-09-08 (16-30-26).txt Skanningstyp: Snabb skanning Antal skannade objekt: 46123 Förfluten tid: 3 minute(s), 24 second(s) Infekterade minnesprocesser: 0 Infekterade minnesmoduler: 0 Infekterade registernycklar: 0 Infekterade registervärden: 0 Infekterade registerdataposter: 0 Infekterade mappar: 0 Infekterade filer: 0 Infekterade minnesprocesser: (Inga illasinnade poster hittades) Infekterade minnesmoduler: (Inga illasinnade poster hittades) Infekterade registernycklar: (Inga illasinnade poster hittades) Infekterade registervärden: (Inga illasinnade poster hittades) Infekterade registerdataposter: (Inga illasinnade poster hittades) Infekterade mappar: (Inga illasinnade poster hittades) Infekterade filer: (Inga illasinnade poster hittades) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:31:39, on 2008-09-08 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32LEXBCES.EXE C:WINDOWSsystem32spoolsv.exe C:WINDOWSsystem32LEXPPS.EXE C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe C:ProgramBonjourmDNSResponder.exe C:ProgramCOMODOFirewallcmdagent.exe C:WINDOWSExplorer.EXE C:ProgramESETESET NOD32 Antivirusekrn.exe C:ProgramDelade filerLightScribeLSSrvc.exe C:ProgramDelade filerMicrosoft SharedVS7DEBUGMDM.EXE C:ProgramCDBurnerXPNMSAccessU.exe C:WINDOWSsystem32nvsvc32.exe C:WINDOWSsystem32IoctlSvc.exe C:ProgramSiteAdvisor6261SAService.exe C:ProgramAnalog DevicesSoundMAXspkrmon.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32SearchIndexer.exe C:ProgramESETESET NOD32 Antivirusegui.exe C:WINDOWSsystem32RUNDLL32.EXE C:WINDOWSsystem32ctfmon.exe C:ProgramSpybot - Search & DestroyTeaTimer.exe C:ProgramSiteAdvisor6261SiteAdv.exe C:ProgramCOMODOFirewallcpf.exe C:ProgramMicrosoft OfficeOFFICE11OUTLOOK.EXE C:ProgramSMS från Datorn OutlookGWServer.exe C:ProgramMicrosoft OfficeOFFICE11WINWORD.EXE C:ProgramInternet ExplorerIEXPLORE.EXE C:WINDOWSsystem32SearchProtocolHost.exe C:WINDOWSexplorer.exe C:ProgramTrend MicroHijackThisRensare.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.se/ R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Länkar O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:ProgramIEProiepro.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:ProgramSiteAdvisor6261SiteAdv.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:ProgramDelade filerAdobeAcrobatActiveXAcroIEHelperShim.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:ProgramSpywareGuarddlprotect.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:ProgramSpybot - Search & DestroySDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_07binssv.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:ProgramSiteAdvisor6261SiteAdv.dll O3 - Toolbar: (no name) - {94A5C93F-BD18-4C46-B777-C94C145C3CAB} - (no file) O4 - HKLM..Run: [sBAutoUpdate] "C:ProgramSpywareBlastersbautoupdate.exe" O4 - HKLM..Run: [egui] "C:ProgramESETESET NOD32 Antivirusegui.exe" /hide /waitservice O4 - HKLM..Run: [COMODO Firewall Pro] "C:ProgramComodoFirewallCPF.exe" /background O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU..Run: [spybotSD TeaTimer] C:ProgramSpybot - Search & DestroyTeaTimer.exe O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'SYSTEM') O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000 O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:ProgramSpybot - Search & DestroySDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:ProgramSpybot - Search & DestroySDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5036.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSkype4COM.dll O20 - AppInit_DLLs: O20 - Winlogon Notify: GoToAssist - C:ProgramCitrixGoToAssist514G2AWinLogon.dll O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:ProgramCOMODOFirewallcmdagent.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:ProgramESETESET NOD32 AntivirusEHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:ProgramESETESET NOD32 Antivirusekrn.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:ProgramCitrixGoToAssist514g2aservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver1150Intel 32IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:ProgramDelade filerLightScribeLSSrvc.exe O23 - Service: IEUser Restarter Service (MyIEUserRestarter) - Unknown owner - C:WINDOWSsystem32MacromedDownloadRestartIEUser.exe (file missing) O23 - Service: NBService - Nero AG - C:ProgramNeroNero 7Nero BackItUpNBService.exe O23 - Service: NMIndexingService - Nero AG - C:ProgramDelade filerAheadLibNMIndexingService.exe O23 - Service: NMSAccessU - Unknown owner - C:ProgramCDBurnerXPNMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:WINDOWSsystem32driverspclepci.sys O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:WINDOWSsystem32IoctlSvc.exe O23 - Service: SiteAdvisor-tjänst (SiteAdvisor Service) - Unknown owner - C:ProgramSiteAdvisor6261SAService.exe O23 - Service: spkrmon - Unknown owner - C:ProgramAnalog DevicesSoundMAXspkrmon.exe -- End of file - 8602 bytes Mvh candela
  15. Det stämmer. I min bestörtning skapade jag den första tråden. Som JoWa så riktigt påpekade hade jag glömt att klistra in en kopia av loggarna som du brukar säga att man skall göra. Skapade då tråd nr 2. Därför blev det två trådar. Jag annullerar nu den första. Ursäkta virrigheten. :-[ Hoppas du kan hjälpa mig att få ordning i datorn. Mvh candela
  16. Hej Malou! Har inte själv installerat dessa applikationer och inte heller satt dessa restriktioner. /candela
  17. Hoppas någon här på forumet kan hjälpa mig att städa rent När jag loggade in i dag så kom det upp meddelande om att det spyware och trojaner i min dator. Laddade inte ner föreslaget program utan körde en Spywarw Search & Destroy och hittade en del skräp som tex AntiSpyCheck, Smitfraud-C, Smitfraud-C.gp och Zlob.Downloader.vdt. Följde sedan Malous råd och laddade ner Malwarebytes´Anti-Malware och scannade. bifogar logga samt HJT-logga. Malwarebytes' Anti-Malware 1.27 Databasversion: 1128 Windows 5.1.2600 Service Pack 3 2008-09-08 11:48:38 mbam-log-2008-09-08 (11-48-38).txt Skanningstyp: Snabb skanning Antal skannade objekt: 45995 Förfluten tid: 3 minute(s), 1 second(s) Infekterade minnesprocesser: 0 Infekterade minnesmoduler: 0 Infekterade registernycklar: 4 Infekterade registervärden: 1 Infekterade registerdataposter: 0 Infekterade mappar: 0 Infekterade filer: 3 Infekterade minnesprocesser: (Inga illasinnade poster hittades) Infekterade minnesmoduler: (Inga illasinnade poster hittades) Infekterade registernycklar: HKEY_CLASSES_ROOTCLSID{0bd44ab1-76a7-4e05-92f4-4b065fe72bd6} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOTCLSID{94a5c93f-bd18-4c46-b777-c94c145c3cab} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerSearchScopes{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{0bd44ab1-76a7-4e05-92f4-4b065fe72bd6} (Trojan.Zlob) -> Quarantined and deleted successfully. Infekterade registervärden: HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorerRunsmile (Trojan.Zlob) -> Quarantined and deleted successfully. Infekterade registerdataposter: (Inga illasinnade poster hittades) Infekterade mappar: (Inga illasinnade poster hittades) Infekterade filer: C:ProgramSetup.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:Documents and SettingsAll UsersStart-menyAntivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully. C:Documents and SettingsAll UsersStart-menyOnline Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:49:47, on 2008-09-08 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32LEXBCES.EXE C:WINDOWSsystem32spoolsv.exe C:WINDOWSsystem32LEXPPS.EXE C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe C:ProgramBonjourmDNSResponder.exe C:ProgramCOMODOFirewallcmdagent.exe C:WINDOWSExplorer.EXE C:ProgramESETESET NOD32 Antivirusekrn.exe C:ProgramDelade filerLightScribeLSSrvc.exe C:ProgramDelade filerMicrosoft SharedVS7DEBUGMDM.EXE C:ProgramCDBurnerXPNMSAccessU.exe C:WINDOWSsystem32nvsvc32.exe C:WINDOWSsystem32IoctlSvc.exe C:ProgramSiteAdvisor6261SAService.exe C:ProgramAnalog DevicesSoundMAXspkrmon.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32SearchIndexer.exe C:ProgramESETESET NOD32 Antivirusegui.exe C:WINDOWSsystem32RUNDLL32.EXE C:WINDOWSsystem32ctfmon.exe C:ProgramSpybot - Search & DestroyTeaTimer.exe C:ProgramSiteAdvisor6261SiteAdv.exe C:ProgramCOMODOFirewallcpf.exe C:ProgramInternet ExplorerIEXPLORE.EXE C:ProgramMalwarebytes' Anti-Malwarembam.exe C:WINDOWSsystem32SearchProtocolHost.exe C:WINDOWSexplorer.exe C:ProgramTrend MicroHijackThisRensare.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.se/ R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Länkar O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:ProgramIEProiepro.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:ProgramSiteAdvisor6261SiteAdv.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:ProgramDelade filerAdobeAcrobatActiveXAcroIEHelperShim.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:ProgramSpywareGuarddlprotect.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:ProgramSpybot - Search & DestroySDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_07binssv.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:ProgramSiteAdvisor6261SiteAdv.dll O3 - Toolbar: (no name) - {94A5C93F-BD18-4C46-B777-C94C145C3CAB} - (no file) O4 - HKLM..Run: [sBAutoUpdate] "C:ProgramSpywareBlastersbautoupdate.exe" O4 - HKLM..Run: [egui] "C:ProgramESETESET NOD32 Antivirusegui.exe" /hide /waitservice O4 - HKLM..Run: [COMODO Firewall Pro] "C:ProgramComodoFirewallCPF.exe" /background O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU..Run: [spybotSD TeaTimer] C:ProgramSpybot - Search & DestroyTeaTimer.exe O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'SYSTEM') O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000 O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:ProgramSpybot - Search & DestroySDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:ProgramSpybot - Search & DestroySDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5036.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSkype4COM.dll O20 - AppInit_DLLs: O20 - Winlogon Notify: GoToAssist - C:ProgramCitrixGoToAssist514G2AWinLogon.dll O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:ProgramCOMODOFirewallcmdagent.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:ProgramESETESET NOD32 AntivirusEHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:ProgramESETESET NOD32 Antivirusekrn.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:ProgramCitrixGoToAssist514g2aservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver1150Intel 32IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:ProgramDelade filerLightScribeLSSrvc.exe O23 - Service: IEUser Restarter Service (MyIEUserRestarter) - Unknown owner - C:WINDOWSsystem32MacromedDownloadRestartIEUser.exe (file missing) O23 - Service: NBService - Nero AG - C:ProgramNeroNero 7Nero BackItUpNBService.exe O23 - Service: NMIndexingService - Nero AG - C:ProgramDelade filerAheadLibNMIndexingService.exe O23 - Service: NMSAccessU - Unknown owner - C:ProgramCDBurnerXPNMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:WINDOWSsystem32driverspclepci.sys O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:WINDOWSsystem32IoctlSvc.exe O23 - Service: SiteAdvisor-tjänst (SiteAdvisor Service) - Unknown owner - C:ProgramSiteAdvisor6261SAService.exe O23 - Service: spkrmon - Unknown owner - C:ProgramAnalog DevicesSoundMAXspkrmon.exe -- End of file - 8501 bytes Mvh candela ???
  18. Tack JoWA, här kommer loggan: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 07:47:21, on 2008-09-08 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32LEXBCES.EXE C:WINDOWSsystem32spoolsv.exe C:WINDOWSsystem32LEXPPS.EXE C:WINDOWSExplorer.EXE C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe C:ProgramBonjourmDNSResponder.exe C:ProgramCOMODOFirewallcmdagent.exe C:ProgramESETESET NOD32 Antivirusekrn.exe C:ProgramDelade filerLightScribeLSSrvc.exe C:ProgramDelade filerMicrosoft SharedVS7DEBUGMDM.EXE C:ProgramCDBurnerXPNMSAccessU.exe C:WINDOWSsystem32nvsvc32.exe C:WINDOWSsystem32IoctlSvc.exe C:ProgramSiteAdvisor6261SAService.exe C:ProgramAnalog DevicesSoundMAXspkrmon.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32SearchIndexer.exe C:ProgramApplicationswcs.exe C:ProgramApplicationsiebtm.exe C:ProgramESETESET NOD32 Antivirusegui.exe C:ProgramComodoFirewallCPF.exe C:ProgramApplicationswcm.exe C:WINDOWSsystem32RUNDLL32.EXE C:WINDOWSsystem32ctfmon.exe C:ProgramApplicationsiebtmm.exe C:ProgramSiteAdvisor6261SiteAdv.exe C:ProgramInternet ExplorerIEXPLORE.EXE C:WINDOWSexplorer.exe C:ProgramTrend MicroHijackThisHijackThis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Länkar O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:ProgramIEProiepro.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:ProgramSiteAdvisor6261SiteAdv.dll O2 - BHO: (no name) - {0BD44AB1-76A7-4E05-92F4-4B065FE72BD6} - C:ProgramApplicationsiebt.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:ProgramDelade filerAdobeAcrobatActiveXAcroIEHelperShim.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:ProgramSpywareGuarddlprotect.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_07binssv.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:ProgramSiteAdvisor6261SiteAdv.dll O3 - Toolbar: Internet Service - {94A5C93F-BD18-4C46-B777-C94C145C3CAB} - C:ProgramApplicationsiebr.dll O4 - HKLM..Run: [sBAutoUpdate] "C:ProgramSpywareBlastersbautoupdate.exe" O4 - HKLM..Run: [egui] "C:ProgramESETESET NOD32 Antivirusegui.exe" /hide /waitservice O4 - HKLM..Run: [COMODO Firewall Pro] "C:ProgramComodoFirewallCPF.exe" /background O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NVMCTRAY.DLL,NvTaskbarInit O4 - HKLM..PoliciesExplorerRun: [smile] C:ProgramApplicationswcs.exe O4 - HKLM..PoliciesExplorerRun: [start] C:ProgramApplicationsiebtm.exe O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'SYSTEM') O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000 O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:ProgramIEProiepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_07binssv.dll O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieextend.com/redirect.php (file missing) O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieextend.com/redirect.php (file missing) O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5036.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSkype4COM.dll O20 - AppInit_DLLs: O20 - Winlogon Notify: GoToAssist - C:ProgramCitrixGoToAssist514G2AWinLogon.dll O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:ProgramAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:ProgramCOMODOFirewallcmdagent.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:ProgramESETESET NOD32 AntivirusEHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:ProgramESETESET NOD32 Antivirusekrn.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:ProgramCitrixGoToAssist514g2aservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver1150Intel 32IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:ProgramDelade filerLightScribeLSSrvc.exe O23 - Service: IEUser Restarter Service (MyIEUserRestarter) - Unknown owner - C:WINDOWSsystem32MacromedDownloadRestartIEUser.exe (file missing) O23 - Service: NBService - Nero AG - C:ProgramNeroNero 7Nero BackItUpNBService.exe O23 - Service: NMIndexingService - Nero AG - C:ProgramDelade filerAheadLibNMIndexingService.exe O23 - Service: NMSAccessU - Unknown owner - C:ProgramCDBurnerXPNMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:WINDOWSsystem32driverspclepci.sys O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:WINDOWSsystem32IoctlSvc.exe O23 - Service: SiteAdvisor-tjänst (SiteAdvisor Service) - Unknown owner - C:ProgramSiteAdvisor6261SAService.exe O23 - Service: spkrmon - Unknown owner - C:ProgramAnalog DevicesSoundMAXspkrmon.exe -- End of file - 8533 bytes Mvh candela
  19. ********************************************* 2009-01-08: Tråden är nu låst. Tycker du att den är felaktigt låst, var god kontakta Malou ********************************************* Finns det någon här på forumet som kan hjälpa mig att få bort detta otyg? Bifogar HJT-logga. Mvh candela
  20. Kan detta vara till någon hjälp ??? /candela Viloläge « Skickat till: plun skrivet: September 22, 2007, 21:19 » Citat Svara Radera -------------------------------------------------------------------------------- Hej plun Hittade ett tips som du gav förra året: Kan vara lurigt... Det kan vara din Internetanslutning som vill förnya IP adressen... "Förhandling" sker med ungefär de tiderna mot en DHCP server. Eventuellt går det att avaktivera nätverkskortet att det inte får väckas om datorn är i "viloläge". Det hjälpte att ändra i nätverkskortet . Avbockade "Tillåt att den här enheten tar datorn ur vänteläge". Hade problem med att datorn startade av sig själv trots att jag ställt om i Energialternativ. Datorn startade själv efter några minuter. Men nu är det OK igen Mvh candela[/color]
  21. Hej DimensionX. Har bla testat att återinstallera drivrutin för NVidia GeForce FX 5200. Verkar som det var detta som spökade. Revo X var nog bra men det verkade som den tog bort mer än önskat. Vad har du för erfarenhet av Revo X? /candela
  22. Håller med dig DimensionX. Det är för varmt. Tar ett svalkande dopp och försöker senare Tack för tipsen. /candela
  23. Hjälp! Helt plötsligt kommer en blåskärm med följande: Följande fil kan vara orsaken till problemet: nv4_disp. Drivrutinen har fastnat i en oändlig loop. 0x000000EA(0x898B7348, 0x89839148,0xF78D6CBC, 0x00000001) nv4_disp Finns det någon här på forumet som kan hjälpa mig ??? Problemet dök upp vid start första gången. Efter omstart i felsäkert läge avinstallerade jag nLite ver 1.48 med Revo uninstaller. nLite var det program som installerades sist, dess förinnan funkade datorn OK. Har kollat via sök och fått följande resultat ang nv4_disp /candela
  24. Följde detta råd och avinstallerade sedan med Revo (enl DimensionX). Såg till att doldafiler och mappar visades. Återstartade datorn och nu var den förhatliga mappen borta ;D. Hoppas det är för gott. Tacka alla för råd om lösning. ;D ;D ;D AlltomXP är i mitt tycke bästa forumet. Helpdesk för hjälplösa. ;D ;D ;D /candela
  25. Enda sättet att slippa se mappen BJPrinter var att ändra i Mappalternativ. Bockade i "Visa inte dolda filer och mappar" och så var den borta tills jag ändrar i visning igen. Men var ligger mappen? ??? Vill helst tabort den helt. /candela
×
×
  • Skapa nytt...