Guide: Hur man blir av med "Polisen har blockerat din dator!"

Permalänk
Medlem
Skrivet av CeciliaB:

Hej Ellinor!

Om du har Vista, Windows 7 eller 8 bör följande vara en framkomlig väg.

Ladda ner Farbar Recovery Scan Tool (FRST) och spara på ett USB-minne.
För 64-bitars Windows: http://download.bleepingcomputer.com/farbar/FRST64.exe
För 32-bitars Windows: http://download.bleepingcomputer.com/farbar/FRST.exe

Sedan ska du starta om datorn och utan att starta hela Windows få igång en Kommandotolk. Det finns två alternativ att göra detta. Vilket du ska använda beror på om du har en installationsskiva för Windows 7 resp. Vista.

Alternativ 1 utan Windows-skiva

När datorn startar börjar du trycka på F8-tangenten upprepade gånger till sidan "Avancerade startalternativ" visas med en meny.
I menyn använder du piltangenterna för att välja "Reparera datorn".

Alternativ 2 med Windows-skiva

Stoppa i installationsskivan.
Starta datorn.
När det kommer upp en fråga om du vill starta datorn från installationsskivan så tryck på någon tangent.
Om frågan inte kommer upp utan datorn startas från hårddisken som vanligt, behöver du ändra en BIOS-inställning för att starta från skivan.
När menyn på installationsskivan kommer upp klicka på "Reparera datorn".

För båda alternativen
Välj rätt tangentbord och klicka på "Nästa".
Välj vilket operativsystem du vill reparera. Om där finns flera så ska du välja det som är det infekterade Windows. Klicka på "Nästa".
Välj ditt användarkonto och klicka på "Nästa".
Nu visas menyn "Alternativ för systemåterställning".
Den börjar med "Startreparation" och avslutas med "Kommandotolk".

Välj "Kommandotolk".
Skriv in:
notepad
Tryck på Enter-tangenten.

Programmet Anteckningar startas.
Välj: Arkiv - Öppna
Välj: Dator
Leta upp ditt USB-minne och skriv upp vilken enhetsbokstav det har, t ex g:.
Stäng Anteckningar.

I Kommandotolken skriver du in:
32-bitars Windows: g:\frst.exe
64-bitars Windows: g:\frst64.exe
men ersätt g med enhetsbokstaven USB-minnet har.

Programmet FRST börjar köra.
Läs villkoren för programmet.
Klicka på Yes för att acceptera.
Klicka på Scan-knappen.
När det är klart kommer det att ha skapats en log FRST.txt på USB-minnet.
Kopiera innehållet i loggen och klistra in i ditt svar.

Jag är rädd om mina dokument, går nånting bort när jag gör detta? Uppskattar om någon vet

Permalänk
Medlem
Skrivet av Hugo91:

Jag är rädd om mina dokument, går nånting bort när jag gör detta? Uppskattar om någon vet

Att bara köra FRST på det viset kommer inte att påverka din dator alls. Men genom att kolla loggen som FRST skapar kan man se vad polistrojanen har gjort och vad man sen ska ta bort för att få bort polistrojanen.

Permalänk
Medlem
Skrivet av CeciliaB:

Att bara köra FRST på det viset kommer inte att påverka din dator alls. Men genom att kolla loggen som FRST skapar kan man se vad polistrojanen har gjort och vad man sen ska ta bort för att få bort polistrojanen.

Hur tar jag bort viruset med hjälp av USB enklast? Uppskattar snabba svar då jag har jätte viktiga saker på datan? Jag kan ej göra systemåterställning från exempelvis 2 dagar tidigare?

Permalänk
Medlem
Skrivet av Hugo91:

Hur tar jag bort viruset med hjälp av USB enklast? Uppskattar snabba svar då jag har jätte viktiga saker på datan? Jag kan ej göra systemåterställning från exempelvis 2 dagar tidigare?

Man får söka igenom loggen efter det som ska bort och ge instruktioner till FRST för att göra det. Jag kan göra det när jag ser FRST-loggen men nu kommer jag att lämna datorn för att fira nyår.

Permalänk

Kan du titta på detta?

Hej
Jag har fått samma "s k i t" i min burk... Jag har nu lyckats fixa den första delen av uppgiften, via denna eminenta beskrivning, att scanna. Bifogar min text nedan.

Jag hittar inte "winlogon" under HKU som jag tycker mig förstått att man skulle leta efter...

Tacksam för hjälp att läsa ut vad jag skall klistra in i FRST innan jag trycker på "Fix"

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01
Ran by SYSTEM on MININT-BH4JB71 on 18-07-2014 12:05:49
Running from f:\
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan...
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan...
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how...

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1694016 2011-09-07] ()
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [Net iD] => C:\Program Files\Net iD\iid.exe [163072 2014-03-04] (SecMaker AB)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-08] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Google Desktop Search] => C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2012-01-20] (Google)
HKLM-x32\...\Run: [RemoteControl11] => C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [234792 2011-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150016 2008-08-20] (Hewlett-Packard)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2571288 2014-06-22] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [ApnUpdater] => C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1644680 2013-02-08] (Ask)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.)
HKLM-x32\...\Run: [Net iD] => C:\Program Files (x86)\Net iD\iid.exe [157440 2014-03-04] (SecMaker AB)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\Admin\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3477312 2012-01-19] (DT Soft Ltd)
HKU\Admin\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [908160 2010-03-15] (Microsoft Corporation)
HKU\Admin\...\Run: [Google Update] => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-06-12] (Google Inc.)
HKU\Admin\...\Run: [uTorrent] => C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-07-13] (BitTorrent Inc.)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\autostart.lnk
ShortcutTarget: autostart.lnk -> C:\ProgramData\D7B5C9685B8256B8E9E2748E6DEE1CB3\jbv4wr.cpp ()
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: EnhancedStorageShell -> {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} => No File
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 1 (GFS Unread Stub) -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => No File
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 2 (GFS Stub) -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => No File
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => No File
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 3 (GFS Folder) -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => No File
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 4 (GFS Unread Mark) -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => No File
ShellIconOverlayIdentifiers-x32: SharingPrivate -> {08244EE6-92F0-47f2-9FC9-929BAA2E7235} => No File

==================== Services (Whitelisted) =================

S2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-08-31] (Adobe Systems Incorporated)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
S2 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-19] ()
S2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
S2 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
S3 GoogleDesktopManager-060409-093314; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2012-01-20] (Google)
S2 Net iD Trace; C:\Program Files\Net iD\iid.exe [163072 2014-03-04] (SecMaker AB)
S2 NVWMI; C:\Windows\system32\nvwmi64.exe [590144 2011-12-10] ()
S2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1813528 2014-06-22] (AVG Secure Search)
S2 CltMngSvc; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [X]
S2 Winmgmt; C:\PROGRA~3\D7B5C9685B8256B8E9E2748E6DEE1CB3\rw4vbj.dot [X]

==================== Drivers (Whitelisted) ====================

S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies)
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-01-20] (DT Soft Ltd)
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-04-12] (CyberLink Corp.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-07-18 12:05 - 2014-07-18 12:05 - 00000000 ____D () C:\FRST
2014-07-18 00:57 - 2014-07-18 01:11 - 00001945 _____ () C:\ProgramData\RUNDLL32.EXE-1304-F.txt
2014-07-18 00:50 - 2014-07-18 00:50 - 00000057 _____ () C:\ProgramData\RUNDLL32.EXE-4360-F.txt
2014-07-18 00:33 - 2014-07-18 00:49 - 00002160 _____ () C:\ProgramData\RUNDLL32.EXE-4880-F.txt
2014-07-18 00:31 - 2014-07-18 00:33 - 00105977 _____ () C:\ProgramData\RUNDLL32.EXE-7048-F.txt
2014-07-17 17:15 - 2014-07-18 00:31 - 00000000 ____D () C:\ProgramData\D7B5C9685B8256B8E9E2748E6DEE1CB3
2014-06-22 06:11 - 2014-06-22 06:11 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\BankID
2014-06-22 06:07 - 2014-06-22 06:07 - 00000000 ____D () C:\Program Files (x86)\BankID
2014-06-22 06:02 - 2014-06-22 06:02 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf

==================== One Month Modified Files and Folders =======

2014-07-18 12:05 - 2014-07-18 12:05 - 00000000 ____D () C:\FRST
2014-07-18 01:12 - 2012-01-20 04:59 - 00000200 _____ () C:\Windows\Tasks\AutoKMS.job
2014-07-18 01:12 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-18 01:12 - 2009-07-13 20:51 - 00087840 _____ () C:\Windows\setupact.log
2014-07-18 01:11 - 2014-07-18 00:57 - 00001945 _____ () C:\ProgramData\RUNDLL32.EXE-1304-F.txt
2014-07-18 01:11 - 2012-01-22 21:54 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\uTorrent
2014-07-18 01:11 - 2012-01-20 01:16 - 01572595 _____ () C:\Windows\WindowsUpdate.log
2014-07-18 00:53 - 2013-06-03 04:39 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2014-07-18 00:50 - 2014-07-18 00:50 - 00000057 _____ () C:\ProgramData\RUNDLL32.EXE-4360-F.txt
2014-07-18 00:49 - 2014-07-18 00:33 - 00002160 _____ () C:\ProgramData\RUNDLL32.EXE-4880-F.txt
2014-07-18 00:46 - 2012-12-13 07:36 - 00000338 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job
2014-07-18 00:35 - 2013-06-12 07:03 - 00001004 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001UA.job
2014-07-18 00:33 - 2014-07-18 00:31 - 00105977 _____ () C:\ProgramData\RUNDLL32.EXE-7048-F.txt
2014-07-18 00:33 - 2013-04-12 10:49 - 00000868 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-18 00:33 - 2012-05-04 09:28 - 00000000 ___RD () C:\Users\Admin\Dropbox
2014-07-18 00:31 - 2014-07-17 17:15 - 00000000 ____D () C:\ProgramData\D7B5C9685B8256B8E9E2748E6DEE1CB3
2014-07-17 23:01 - 2012-01-20 05:02 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-17 22:57 - 2012-05-04 09:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Dropbox
2014-07-17 22:56 - 2014-03-16 11:55 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\DropboxMaster
2014-07-17 22:54 - 2012-01-20 04:59 - 00000200 _____ () C:\Windows\Tasks\AutoKMSDaily.job
2014-07-17 22:28 - 2009-07-13 20:45 - 00020640 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-17 22:28 - 2009-07-13 20:45 - 00020640 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-17 17:18 - 2012-03-16 10:06 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\vlc
2014-07-17 06:35 - 2013-06-12 07:03 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001Core.job
2014-07-13 07:57 - 2012-01-20 02:27 - 00661006 _____ () C:\Windows\System32\perfh01D.dat
2014-07-13 07:57 - 2012-01-20 02:27 - 00140808 _____ () C:\Windows\System32\perfc01D.dat
2014-07-13 07:57 - 2009-07-13 21:13 - 01571852 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-07-13 03:57 - 2013-09-20 11:13 - 00000857 _____ () C:\Users\Admin\Desktop\µTorrent.lnk
2014-07-04 07:04 - 2013-10-14 08:50 - 00000965 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-06-28 07:56 - 2013-02-22 09:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype
2014-06-28 07:29 - 2014-04-05 06:13 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-06-28 06:55 - 2009-07-13 21:32 - 00000000 ____D () C:\Windows\System32\FxsTmp
2014-06-22 06:30 - 2013-06-12 07:03 - 00003974 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001UA
2014-06-22 06:30 - 2013-06-12 07:03 - 00003578 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001Core
2014-06-22 06:11 - 2014-06-22 06:11 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\BankID
2014-06-22 06:07 - 2014-06-22 06:07 - 00000000 ____D () C:\Program Files (x86)\BankID
2014-06-22 06:02 - 2014-06-22 06:02 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf
2014-06-22 05:52 - 2014-04-27 10:03 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-06-22 05:52 - 2012-09-29 02:54 - 00050464 _____ (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys
2014-06-22 05:52 - 2012-09-29 02:54 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search

Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\1405.dll
C:\Users\Admin\AppData\Local\Temp\AskSLib.dll
C:\Users\Admin\AppData\Local\Temp\avguidx.dll
C:\Users\Admin\AppData\Local\Temp\CommonInstaller.exe
C:\Users\Admin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpysltcd.dll
C:\Users\Admin\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Admin\AppData\Local\Temp\htmlayout.dll
C:\Users\Admin\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe
C:\Users\Admin\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Admin\AppData\Local\Temp\LMkRstPt.exe
C:\Users\Admin\AppData\Local\Temp\MachineIdCreator.exe
C:\Users\Admin\AppData\Local\Temp\nsf9C3B.exe
C:\Users\Admin\AppData\Local\Temp\nsw559B.exe
C:\Users\Admin\AppData\Local\Temp\oi_{8C2923F6-50DE-43EA-B823-82A4A656A412}.exe
C:\Users\Admin\AppData\Local\Temp\readSTILog.dll
C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Admin\AppData\Local\Temp\ToolbarInstaller.exe
C:\Users\Admin\AppData\Local\Temp\update464937.exe
C:\Users\Admin\AppData\Local\Temp\utt2CF4.tmp.exe
C:\Users\Admin\AppData\Local\Temp\uttC4A2.tmp.exe

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points =========================

Restore point made on: 2014-06-22 06:06:45
Restore point made on: 2014-06-29 10:33:27
Restore point made on: 2014-07-06 14:00:21
Restore point made on: 2014-07-14 14:00:23

==================== Memory info ===========================

Percentage of memory in use: 11%
Total physical RAM: 6143.44 MB
Available physical RAM: 5432.09 MB
Total Pagefile: 6141.64 MB
Available Pagefile: 5423.12 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.04 GB) (Free:88.15 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Center) (Fixed) (Total:1863.01 GB) (Free:786 GB) NTFS
Drive f: () (Removable) (Total:1.86 GB) (Free:1.84 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: AFA2AFA2)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 918973F7)
Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 2 GB) (Disk ID: 6F20736B)
No partition Table on disk 2.
Disk 2 is a removable device.

LastRegBack: 2014-07-17 23:53

==================== End Of Log ============================

Dold text
Permalänk
Medlem

Observera att följande är bara första steget för att få bort allt skadligt från datorn.

Starta Anteckningar.
Kopiera alla rader i rutan:

Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\autostart.lnk ShortcutTarget: autostart.lnk -> C:\ProgramData\D7B5C9685B8256B8E9E2748E6DEE1CB3\jbv4wr.cpp () S2 Winmgmt; C:\PROGRA~3\D7B5C9685B8256B8E9E2748E6DEE1CB3\rw4vbj.dot [X]

och klistra in i Anteckningar. Kontrollera att inga filer har delats upp på två rader.
Spara filen på USB-minnet med namnet fixlist.txt.

På den infekterade datorn från "System Recovery Options"
Starta FRST (32-bitars Windows) resp. FRST64 (64-bitars Windows) på samma sätt som sist.
Klicka på knappen Fix.
Vänta tills programmet är klart.

Programmet skapar en logg Fixlog.txt på USB-minnet.
Klistra in innehållet i den i ditt svar.

Kolla om det nu går att starta den infekterade datorn normalt. I så fall kopierar du FRST från USB-minnet till skrivbordet och kör FRST därifrån. Två loggar, FRST.txt och Addition.txt, kommer att skapas på skrivbordet.
Klistra in innehållet i dem i ditt svar. Folk uppskattar om du använder SPOILER-taggen/funktion runt loggarna.

Permalänk

Tack, nu funkar det som sig bör

Tack för ditt snabba svar!
Nu startat datorn helt normalt. Underbart...

Jag bifogar filerna och säger tack för hjälpen.
/Stinsen

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01
Ran by Admin (administrator) on RISBERG-CENTER on 19-07-2014 14:38:22
Running from C:\Users\Admin\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Engelska (USA)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan...
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan...
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how...

==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\System32\nvwmi64.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\System32\nvwmi64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
(SecMaker AB) C:\Program Files\Net iD\iid.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(SecMaker AB) C:\Program Files\Net iD\iid.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Dropbox, Inc.) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Google) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
() C:\Program Files (x86)\AVG Secure Search\vprot.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1694016 2011-09-07] ()
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [Net iD] => C:\Program Files\Net iD\iid.exe [163072 2014-03-04] (SecMaker AB)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Google Desktop Search] => C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2012-01-20] (Google)
HKLM-x32\...\Run: [RemoteControl11] => C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [234792 2011-04-20] (CyberLink Corp.)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150016 2008-08-20] (Hewlett-Packard)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2571288 2014-06-22] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [ApnUpdater] => C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1644680 2013-02-08] (Ask)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [Net iD] => C:\Program Files (x86)\Net iD\iid.exe [157440 2014-03-04] (SecMaker AB)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-4217374808-157746030-2108746492-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3477312 2012-01-19] (DT Soft Ltd)
HKU\S-1-5-21-4217374808-157746030-2108746492-1001\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [908160 2010-03-16] (Microsoft Corporation)
HKU\S-1-5-21-4217374808-157746030-2108746492-1001\...\Run: [Google Update] => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-06-12] (Google Inc.)
HKU\S-1-5-21-4217374808-157746030-2108746492-1001\...\Run: [uTorrent] => C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-07-13] (BitTorrent Inc.)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://se.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE49BEF825FD7CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sv-SE
URLSearchHook: HKLM-x32 - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
URLSearchHook: HKCU - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3312375&octid=E...
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3312375&octid=E...
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={4C8FB4C0-690A-499F-A8C4-3A... 12:54:56&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {FF41020B-A87C-4BAA-967D-973FDFD05E6C} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&...
BHO: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
BHO-x32: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssie.dll No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: AVG Security Toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Secure Search\18.1.7.644\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: uTorrentBar Toolbar -> {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} -> C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
BHO-x32: Ask Toolbar -> {D4027C7F-154A-4066-A1AD-4243D8127440} -> C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
Toolbar: HKLM-x32 - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
Toolbar: HKLM-x32 - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\18.1.7.644\AVG Secure Search_toolbar.dll (AVG Secure Search)
Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw...
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/sw...
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @bankid.com/BankID säkerhetsprogram,version=6.0.1.5 - C:\Program Files (x86)\BankID\npBispBrowser.dll (Finansiell ID-Teknik BID AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @nsroblox.roblox.com/launcher - C:\Users\Admin\AppData\Local\Roblox\Versions\version-fd63d8cdc8954fbd\\NPRobloxProxy.dll ( ROBLOX Corporation)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Admin\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Admin\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\17.3.0.49

==================== Services (Whitelisted) =================

R2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
R2 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-20] ()
R2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
R2 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
S3 GoogleDesktopManager-060409-093314; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2012-01-20] (Google)
S3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 Net iD Trace; C:\Program Files\Net iD\iid.exe [163072 2014-03-04] (SecMaker AB)
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [590144 2011-12-11] ()
R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1813528 2014-06-22] (AVG Secure Search)
S2 CltMngSvc; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-01-20] (DT Soft Ltd)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-04-12] (CyberLink Corp.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-07-19 14:38 - 2014-07-19 14:38 - 00018963 _____ () C:\Users\Admin\Desktop\FRST.txt
2014-07-19 14:37 - 2014-07-18 11:14 - 02086912 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2014-07-18 22:05 - 2014-07-19 14:38 - 00000000 ____D () C:\FRST
2014-07-18 10:57 - 2014-07-18 11:11 - 00001945 _____ () C:\ProgramData\RUNDLL32.EXE-1304-F.txt
2014-07-18 10:50 - 2014-07-18 10:50 - 00000057 _____ () C:\ProgramData\RUNDLL32.EXE-4360-F.txt
2014-07-18 10:33 - 2014-07-18 10:49 - 00002160 _____ () C:\ProgramData\RUNDLL32.EXE-4880-F.txt
2014-07-18 10:31 - 2014-07-18 10:33 - 00105977 _____ () C:\ProgramData\RUNDLL32.EXE-7048-F.txt
2014-07-18 03:15 - 2014-07-19 21:06 - 00000000 ____D () C:\ProgramData\D7B5C9685B8256B8E9E2748E6DEE1CB3
2014-06-22 16:11 - 2014-06-22 16:11 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\BankID
2014-06-22 16:07 - 2014-06-22 16:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BankID säkerhetsprogram
2014-06-22 16:07 - 2014-06-22 16:07 - 00000000 ____D () C:\Program Files (x86)\BankID
2014-06-22 16:02 - 2014-06-22 16:02 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf

==================== One Month Modified Files and Folders =======

2014-07-19 21:06 - 2014-07-18 03:15 - 00000000 ____D () C:\ProgramData\D7B5C9685B8256B8E9E2748E6DEE1CB3
2014-07-19 14:38 - 2014-07-19 14:38 - 00018963 _____ () C:\Users\Admin\Desktop\FRST.txt
2014-07-19 14:38 - 2014-07-18 22:05 - 00000000 ____D () C:\FRST
2014-07-19 14:38 - 2012-01-20 15:02 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-19 14:37 - 2012-01-23 07:54 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\uTorrent
2014-07-19 14:37 - 2012-01-20 11:16 - 01576914 _____ () C:\Windows\WindowsUpdate.log
2014-07-19 14:36 - 2013-06-12 17:03 - 00001004 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001UA.job
2014-07-19 14:34 - 2013-06-03 14:39 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2014-07-19 14:33 - 2012-01-20 14:59 - 00000200 _____ () C:\Windows\Tasks\AutoKMS.job
2014-07-19 14:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-19 14:33 - 2009-07-14 06:51 - 00087896 _____ () C:\Windows\setupact.log
2014-07-18 11:14 - 2014-07-19 14:37 - 02086912 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2014-07-18 11:11 - 2014-07-18 10:57 - 00001945 _____ () C:\ProgramData\RUNDLL32.EXE-1304-F.txt
2014-07-18 10:50 - 2014-07-18 10:50 - 00000057 _____ () C:\ProgramData\RUNDLL32.EXE-4360-F.txt
2014-07-18 10:49 - 2014-07-18 10:33 - 00002160 _____ () C:\ProgramData\RUNDLL32.EXE-4880-F.txt
2014-07-18 10:46 - 2012-12-13 17:36 - 00000338 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job
2014-07-18 10:33 - 2014-07-18 10:31 - 00105977 _____ () C:\ProgramData\RUNDLL32.EXE-7048-F.txt
2014-07-18 10:33 - 2013-04-12 20:49 - 00000868 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-18 10:33 - 2012-05-04 19:28 - 00000000 ___RD () C:\Users\Admin\Dropbox
2014-07-18 08:57 - 2012-05-04 19:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Dropbox
2014-07-18 08:56 - 2014-03-16 21:55 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\DropboxMaster
2014-07-18 08:54 - 2012-01-20 14:59 - 00000200 _____ () C:\Windows\Tasks\AutoKMSDaily.job
2014-07-18 08:28 - 2009-07-14 06:45 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-18 08:28 - 2009-07-14 06:45 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-18 03:18 - 2012-03-16 20:06 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\vlc
2014-07-17 16:35 - 2013-06-12 17:03 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001Core.job
2014-07-13 17:57 - 2012-01-20 12:27 - 00661006 _____ () C:\Windows\system32\perfh01D.dat
2014-07-13 17:57 - 2012-01-20 12:27 - 00140808 _____ () C:\Windows\system32\perfc01D.dat
2014-07-13 17:57 - 2009-07-14 07:13 - 01571852 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-13 13:57 - 2013-09-20 21:13 - 00000857 _____ () C:\Users\Admin\Desktop\µTorrent.lnk
2014-07-13 13:57 - 2013-09-20 21:13 - 00000837 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-07-04 17:04 - 2014-04-01 20:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-04 17:04 - 2013-10-14 18:50 - 00000965 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-06-28 17:56 - 2013-02-22 19:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype
2014-06-28 17:29 - 2014-04-05 16:13 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-06-28 16:55 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-06-22 16:30 - 2013-06-12 17:03 - 00003974 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001UA
2014-06-22 16:30 - 2013-06-12 17:03 - 00003578 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001Core
2014-06-22 16:11 - 2014-06-22 16:11 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\BankID
2014-06-22 16:07 - 2014-06-22 16:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BankID säkerhetsprogram
2014-06-22 16:07 - 2014-06-22 16:07 - 00000000 ____D () C:\Program Files (x86)\BankID
2014-06-22 16:02 - 2014-06-22 16:02 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf
2014-06-22 15:52 - 2014-04-27 20:03 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-06-22 15:52 - 2012-09-29 12:54 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-06-22 15:52 - 2012-09-29 12:54 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search

Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\1405.dll
C:\Users\Admin\AppData\Local\Temp\AskSLib.dll
C:\Users\Admin\AppData\Local\Temp\avguidx.dll
C:\Users\Admin\AppData\Local\Temp\CommonInstaller.exe
C:\Users\Admin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp6lvcp4.dll
C:\Users\Admin\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Admin\AppData\Local\Temp\htmlayout.dll
C:\Users\Admin\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe
C:\Users\Admin\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Admin\AppData\Local\Temp\LMkRstPt.exe
C:\Users\Admin\AppData\Local\Temp\MachineIdCreator.exe
C:\Users\Admin\AppData\Local\Temp\nsf9C3B.exe
C:\Users\Admin\AppData\Local\Temp\nsw559B.exe
C:\Users\Admin\AppData\Local\Temp\oi_{8C2923F6-50DE-43EA-B823-82A4A656A412}.exe
C:\Users\Admin\AppData\Local\Temp\readSTILog.dll
C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Admin\AppData\Local\Temp\ToolbarInstaller.exe
C:\Users\Admin\AppData\Local\Temp\update464937.exe
C:\Users\Admin\AppData\Local\Temp\utt2CF4.tmp.exe
C:\Users\Admin\AppData\Local\Temp\uttC4A2.tmp.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-07-18 09:53

==================== End Of Log ============================

Dold text

Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2014 01
Ran by Admin at 2014-07-19 14:39:16
Running from C:\Users\Admin\Desktop
Boot Mode: Normal
==========================================================

==================== Security Center ========================

AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.32239 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19140 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.6.0.19140 - Adobe Systems Incorporated) Hidden
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Community Help (x32 Version: 3.5.23 - Adobe Systems Incorporated.) Hidden
Adobe Flash Player 11 ActiveX (HKLM-x32\...\{8A5F5F0A-BE2D-4763-B764-BF6EFE93A68B}) (Version: 11.5.502.146 - Adobe Systems Incorporated)
Adobe Photoshop Elements 10 (HKLM-x32\...\Adobe Photoshop Elements 10) (Version: 10.0 - Adobe Systems Incorporated)
Adobe Photoshop Elements 10 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
Adobe Reader X (10.1.10) - Svenska (HKLM-x32\...\{AC76BA86-7AD7-1053-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
Any DVD Shrink 1.3.7 (HKLM-x32\...\Any DVD Shrink_is1) (Version: - any-dvd-shrink.com)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Apple-programstöd (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.15.0 - Ask.com) <==== ATTENTION
Ask Toolbar Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.4.36191 - Ask.com) <==== ATTENTION
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4716 - AVG Technologies)
AVG 2014 (Version: 14.0.3986 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4716 - AVG Technologies) Hidden
AVG Security Toolbar (HKLM-x32\...\AVG Secure Search) (Version: 18.1.7.644 - AVG Technologies)
BankID säkerhetsprogram (HKLM-x32\...\{4B2557F9-8C03-4BE7-9984-4DE525076580}) (Version: 6.0.1.5 - Finansiell ID-Teknik BID AB)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.0.2905 - CDBurnerXP)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4746 - CDBurnerXP)
Claro ScreenMarker (HKLM-x32\...\{4E5FD3CA-F8C3-4D5A-A44A-6289C179FCFA}) (Version: 1.1.0 - Claro Software)
ClaroCapture (HKLM-x32\...\{42007926-2EB9-4FA2-B4D2-1FBD817CE709}) (Version: 2.0.7 - Claro Software)
ClaroRead Pro (HKLM-x32\...\{C5BF97A7-858A-4C73-95F1-BDB447F867B9}) (Version: 6.1.9 - Claro Software)
ClaroView (HKLM-x32\...\{A836EF85-4F9B-4BE0-904A-A56B6A48293F}) (Version: 1.0.12 - Claro Software)
Codecs for Windows 7 Pack 4.0.5 (HKLM-x32\...\Codecs for Windows 7 Pack) (Version: 4.0.5 - Codecs for Windows 7 Pack)
Common Desktop Agent (Version: 1.62.0 - OEM) Hidden
CyberLink PowerDVD 11 (HKLM-x32\...\InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}) (Version: 11.0.1620.51 - CyberLink Corp.)
CyberLink PowerDVD 11 (x32 Version: 11.0.1620.51 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.2.0287 - DT Soft Ltd)
dBpoweramp [Arrange Audio] Codec (HKLM-x32\...\dBpoweramp [Arrange Audio] Codec) (Version: Release 3 - Illustrate)
dBpoweramp [Audio Info] Codec (HKLM-x32\...\dBpoweramp [Audio Info] Codec) (Version: Release 1 - Illustrate)
dBpoweramp [Channel Split] Codec (HKLM-x32\...\dBpoweramp [Channel Split] Codec) (Version: - )
dBpoweramp [ID Tag Update] Codec (HKLM-x32\...\dBpoweramp [ID Tag Update] Codec) (Version: - )
dBpoweramp [Length Split] Codec (HKLM-x32\...\dBpoweramp [Length Split] Codec) (Version: - )
dBpoweramp [Multi Encoder] Codec (HKLM-x32\...\dBpoweramp [Multi Encoder] Codec) (Version: Release 3 - Illustrate)
dBpoweramp [ReplayGain] Codec (HKLM-x32\...\dBpoweramp [ReplayGain] Codec) (Version: Release 2 - Illustrate)
dBpoweramp [Tag From Filename] Codec (HKLM-x32\...\dBpoweramp [Tag From Filename] Codec) (Version: Release 1 - Illustrate)
dBpoweramp DSP Effects (HKLM-x32\...\dBpoweramp DSP Effects) (Version: Release 4 - Illustrate)
dBpoweramp m4a Codec (HKLM-x32\...\dBpoweramp m4a Codec) (Version: Release 14 r2 - Illustrate)
dBpoweramp Music Converter (HKLM-x32\...\dBpoweramp Music Converter) (Version: Release 13.2 - Illustrate)
dBpoweramp Windows Media Audio 10 Codec (HKLM-x32\...\dBpoweramp Windows Media Audio 10 Codec) (Version: Release 7 - Illustrate)
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
Elements 10 Organizer (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Free Video Joiner (HKLM-x32\...\{14FA6DD9-92ED-493D-A937-81A78870E08A}_is1) (Version: - FreeVideoJoiner.com)
GIMP 2.6.12-2 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.12 - The GIMP Team)
Google Desktop (HKLM-x32\...\Google Desktop) (Version: 5.9.0906.04286 - Google)
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.11182 - HP)
HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
HP Scanjet G2410 and 2400 (HKLM\...\{E5B04674-1885-4B08-BAE7-ECDEC1F84677}) (Version: 13.0 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
hpg2410 (x32 Version: 13.0.0.0 - Ditt företagsnamn) Hidden
HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Hugin 2011.4.0 (HKLM-x32\...\Hugin) (Version: 2011.4.0 hg_cf9be9344356 - The Hugin Development Team)
Inkscape 0.48.3.1 (HKLM-x32\...\Inkscape) (Version: 0.48.3.1 - )
iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: 11.2.2.3 - Apple Inc.)
Java 7 Update 13 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217013FF}) (Version: 7.0.130 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden
LG Mouse Scanner (HKLM-x32\...\{97821186-7938-4FC5-9171-8B508D6DE35A}) (Version: 1.1.0 - LG)
Logitech SetPoint 6.32 (HKLM\...\sp6) (Version: 6.32.20 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
LWS Facebook (x32 Version: 13.50.854.0 - Logitech) Hidden
LWS Gallery (x32 Version: 13.51.827.0 - Logitech) Hidden
LWS Help_main (x32 Version: 13.51.828.0 - Logitech) Hidden
LWS Launcher (x32 Version: 13.51.828.0 - Logitech) Hidden
LWS Motion Detection (x32 Version: 13.51.815.0 - Logitech) Hidden
LWS Pictures And Video (x32 Version: 13.51.815.0 - Logitech) Hidden
LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden
LWS Webcam Software (x32 Version: 13.51.815.0 - Logitech) Hidden
LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden
LWS YouTube Plugin (x32 Version: 13.31.1038.0 - Logitech) Hidden
Läs bruksanvisningen (HKLM-x32\...\View User Guide) (Version: 3.60.02.0 - )
Media Go (HKLM-x32\...\{362AB21A-E2C4-40CE-81C2-8C4D62B0635A}) (Version: 2.4.256 - Sony)
Media Go Video Playback Engine 1.116.110.02030 (HKLM-x32\...\{54215B8A-6212-8DB8-39B4-98EE2BB98BD1}) (Version: 1.116.110.02030 - Sony)
Metadata batcher (HKLM-x32\...\Metadata batcher) (Version: 2.0.6 - Videoscripts)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile Language Pack - SVE (HKLM\...\Microsoft .NET Framework 4 Client Profile SVE Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile SVE Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended Language Pack - SVE (HKLM\...\Microsoft .NET Framework 4 Extended SVE Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended SVE Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Finnish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Swedish) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Net iD 6.1.1 - T1001 (HKLM\...\iid) (Version: 6.1.1.21 - SecMaker AB)
Net iD 6.1.1 (32-bit Edition) - T1001 (HKLM-x32\...\iid) (Version: 6.1.1.21 - SecMaker AB)
NVIDIA 3D Vision Controller Driver (x32 Version: 276.42 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision drivrutin för styrenhet 276.42 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 276.42 - NVIDIA Corporation)
NVIDIA Grafikdrivrutin 276.42 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 276.42 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.275.82.0 - NVIDIA Corporation) Hidden
NVIDIA nView 136.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 136.02 - NVIDIA Corporation)
NVIDIA nView Desktop Manager (Version: 6.14.10.1362 - NVIDIA Corporation) Hidden
NVIDIA WMI 276.42 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 276.42 - NVIDIA Corporation)
NVIDIAs kontrollpanel 276.42 (Version: 276.42 - NVIDIA Corporation) Hidden
OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.7.0 - Prolific Technology INC)
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.14.6.15183 - Sony Computer Entertainment Inc.)
PSE10 STI Installer (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
ROBLOX Player for Admin (HKCU\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
Samsung C410 Series (HKLM-x32\...\Samsung C410 Series) (Version: 1.02 (2013-07-11) - Samsung Electronics Co., Ltd.)
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.03.23.00(2013-05-03) - Samsung Electronics Co., Ltd.)
Samsung Easy Wireless Setup (HKLM-x32\...\Easy Wireless Setup) (Version: 3.60.40.03 - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
ScreenRuler (HKLM-x32\...\{C640829F-E081-47B6-9E85-D07CEB0239F0}) (Version: 3.0.2 - Claro Software)
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.13.2.14 - Client Connect LTD) <==== ATTENTION
Skype™ 6.9 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.9.106 - Skype Technologies S.A.)
Snagit 10.0.1 (HKLM-x32\...\{22FC7536-BE5C-4E88-8069-C24689D34EC5}) (Version: 10.0.1 - TechSmith Corporation)
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Sony Ericsson Update Engine (HKLM-x32\...\Update Engine) (Version: 2.13.6.201305161305 - Sony Ericsson Communications AB)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.12313 - TeamViewer)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 7.56a - Ghisler Software GmbH)
uTorrentBar Toolbar (HKLM-x32\...\uTorrentBar Toolbar) (Version: 6.8.5.1 - uTorrentBar) <==== ATTENTION
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Widevine Media Optimizer IE 6.0.0 (HKCU\...\optimizer_ie) (Version: 6.0.0.12442 - Widevine Technologies)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)

==================== Restore Points =========================

22-06-2014 14:06:22 Installerad BankID säkerhetsprogram.
29-06-2014 18:33:02 Schemalagd kontrollpunkt
06-07-2014 22:00:02 Schemalagd kontrollpunkt
14-07-2014 22:00:01 Schemalagd kontrollpunkt

==================== Hosts content: ==========================

2009-07-14 04:34 - 2011-01-27 16:00 - 00001211 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net

==================== Scheduled Tasks (whitelisted) =============

Task: {0CA8B632-FFFD-48FD-9DA0-A25E11C532CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001Core => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.)
Task: {1E87E551-9D70-4B83-83E1-5B144F0DA38A} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{FD517982-0229-4E51-A1C9-DE00B6CB33C1}.exe
Task: {1FCCD0D1-155E-4AAB-B7A7-A83560342EC0} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe
Task: {32034003-9401-4099-86F0-727B83A439E9} - System32\Tasks\YourFile Update => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION
Task: {43823D1E-190F-4E9B-AFE5-1CF4331CA866} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-12] (Adobe Systems Incorporated)
Task: {45492D7E-BBC3-4F8B-94CA-4F7BE543A12F} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2012-12-13] ()
Task: {5AD3D3C3-DBF0-4FAF-8E69-A1730B0AEBDA} - System32\Tasks\{2F1F87B4-450B-4730-9010-B82D4DBD101B} => Iexplore.exe http://ui.skype.com/ui/0/6.7.0.102/sv/abandoninstall?page=tsP...
Task: {5EF4416B-E021-421B-A1B5-D5B902392804} - System32\Tasks\{114DD727-B148-4229-8023-85281D984C3B} => Iexplore.exe http://ui.skype.com/ui/0/6.3.0.107/sv/abandoninstall?page=tsP...
Task: {78975787-4687-4BA9-B5E5-60A2CC3AEE45} - System32\Tasks\{61F7458E-0C53-41AF-B72C-1D90D40373B2} => Iexplore.exe http://ui.skype.com/ui/0/6.3.0.107/sv/abandoninstall?page=tsP...
Task: {AB6A908E-89D1-4993-9685-D89ED8AA57B8} - System32\Tasks\AdobeAAMUpdater-1.0-Risberg-Center-Admin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-06-16] (Adobe Systems Incorporated)
Task: {BA64E810-0563-4404-8DF0-C02EE3C07DD6} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: {EA0CBBD3-D0A5-4075-B658-3B0D8FCB4115} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-02-08] () <==== ATTENTION
Task: {F8DDC993-3BA7-4972-978A-3C487EABD7CE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001UA => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{FD517982-0229-4E51-A1C9-DE00B6CB33C1}.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001Core.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001UA.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe

==================== Loaded Modules (whitelisted) =============

2012-01-20 13:43 - 2011-12-11 07:01 - 00590144 _____ () C:\Windows\system32\nvwmi64.exe
2012-01-20 13:43 - 2011-12-11 07:01 - 00364864 _____ () C:\Windows\system32\nvWmiShim.dll
2013-05-17 16:02 - 2013-05-17 16:02 - 00034304 _____ () C:\Windows\System32\sst8clm.dll
2012-01-26 19:00 - 2011-04-20 05:56 - 00083240 _____ () C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
2014-06-22 15:52 - 2014-06-22 15:52 - 00159768 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
2010-01-30 03:40 - 2010-01-30 03:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2011-10-07 11:39 - 2011-10-07 11:39 - 01304856 _____ () C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll
2012-03-09 09:58 - 2012-03-09 09:58 - 00462712 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
2012-03-09 09:58 - 2012-03-09 09:58 - 00057208 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll
2012-09-29 12:54 - 2014-06-22 15:52 - 02571288 _____ () C:\Program Files (x86)\AVG Secure Search\vprot.exe
2012-09-13 01:38 - 2012-09-13 01:38 - 00264040 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-06-22 15:52 - 2014-06-22 15:52 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\log4cplusU.dll
2014-07-19 14:35 - 2014-07-19 14:35 - 00043008 _____ () c:\users\admin\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp6lvcp4.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\libcef.dll
2013-12-09 20:11 - 2014-04-27 20:03 - 01632792 _____ () C:\Program Files (x86)\AVG Secure Search\TBAPI.dll
2012-09-13 01:38 - 2012-09-13 01:38 - 02144104 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll
2012-09-13 01:38 - 2012-09-13 01:38 - 07955304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll
2012-09-13 01:38 - 2012-09-13 01:38 - 00341352 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll
2012-09-13 01:38 - 2012-09-13 01:38 - 00028008 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll
2012-09-13 01:38 - 2012-09-13 01:38 - 00127336 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll
2012-09-13 01:39 - 2012-09-13 01:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:264B2CC4

==================== Safe Mode (whitelisted) ===================

==================== EXE Association (whitelisted) =============

==================== MSCONFIG/TASK MANAGER disabled items =========

==================== Faulty Device Manager Devices =============

Name: PS/2-kompatibel mus
Description: PS/2-kompatibel mus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Standardtangentbord - PS/2
Description: Standardtangentbord - PS/2
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtangentbord)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
==================
Error: (07/19/2014 02:35:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/19/2014 02:34:07 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Det gick inte att aktivera Windows-licensen. Fel: 0x80070005.

Error: (07/18/2014 10:53:49 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Det gick inte att aktivera Windows-licensen. Fel: 0x80070005.

Error: (07/18/2014 10:50:39 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Det gick inte att aktivera Windows-licensen. Fel: 0x80070005.

Error: (07/18/2014 10:33:36 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Det gick inte att aktivera Windows-licensen. Fel: 0x80070005.

Error: (07/18/2014 08:55:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/18/2014 08:54:55 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Det gick inte att aktivera Windows-licensen. Fel: 0x80070005.

Error: (07/18/2014 08:13:05 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: Licensaktiveringsschemat (sppuinotify.dll) misslyckades med följande felkod:
0x80070005

Error: (07/18/2014 07:13:05 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: Licensaktiveringsschemat (sppuinotify.dll) misslyckades med följande felkod:
0x80070005

Error: (07/18/2014 06:13:05 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: Licensaktiveringsschemat (sppuinotify.dll) misslyckades med följande felkod:
0x80070005

System errors:
=============
Error: (07/19/2014 02:36:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Tjänsten Search Protect Service kunde inte startas på grund av följande fel:
%%2

Error: (07/18/2014 11:14:10 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Tjänsten Windows Management Instrumentation avbröts med följande fel:
%%126

Error: (07/18/2014 11:13:40 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Tjänsten Windows Management Instrumentation avbröts med följande fel:
%%126

Error: (07/18/2014 11:13:40 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (07/18/2014 11:13:10 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Tjänsten Windows Management Instrumentation avbröts med följande fel:
%%126

Error: (07/18/2014 11:13:02 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Tjänsten IP Helper är beroende av tjänsten Windows Management Instrumentation. Den sistnämnda kunde inte starta på grund av följande fel:
%%126

Error: (07/18/2014 11:13:02 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Tjänsten Windows Management Instrumentation avbröts med följande fel:
%%126

Error: (07/18/2014 11:02:21 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Tjänsten Windows Management Instrumentation avbröts med följande fel:
%%126

Error: (07/18/2014 11:01:51 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Tjänsten Windows Management Instrumentation avbröts med följande fel:
%%126

Error: (07/18/2014 11:01:21 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Tjänsten Windows Management Instrumentation avbröts med följande fel:
%%126

Microsoft Office Sessions:
=========================
Error: (07/19/2014 02:35:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/19/2014 02:34:07 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: 0x800700050x00000000

Error: (07/18/2014 10:53:49 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: 0x800700050x00000000

Error: (07/18/2014 10:50:39 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: 0x800700050x00000000

Error: (07/18/2014 10:33:36 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: 0x800700050x00000000

Error: (07/18/2014 08:55:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/18/2014 08:54:55 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: 0x800700050x00000000

Error: (07/18/2014 08:13:05 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: 0x80070005

Error: (07/18/2014 07:13:05 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: 0x80070005

Error: (07/18/2014 06:13:05 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: 0x80070005

==================== Memory info ===========================

Percentage of memory in use: 27%
Total physical RAM: 6143.44 MB
Available physical RAM: 4447.48 MB
Total Pagefile: 12285.07 MB
Available Pagefile: 10534.61 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.04 GB) (Free:88.12 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Center) (Fixed) (Total:1863.01 GB) (Free:786 GB) NTFS
Drive h: () (Removable) (Total:1.86 GB) (Free:1.84 GB) FAT

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: AFA2AFA2)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 918973F7)
Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 2 GB) (Disk ID: 6F20736B)
No partition Table on disk 2.
Disk 2 is a removable device.

==================== End Of Log ============================

Dold text
Permalänk
Medlem

Det var så lite så

1. Spara AdwCleaner av Xplode på Skrivbordet: http://general-changelog-team.fr/fr/downloads/finish/20-outil...
Stäng alla program, inklusive webbläsare.
Kör AdwCleaner och låt det skanna datorn.
Om du vill att jag ska gå igenom resultatet klickar du på Report-knappen och annars klickar du på Clean-knappen.

2. Avinstallera Java 7 Update 13 eftersom det är en mycket gammal version med många kända säkerhetshål som gör det lätt att infektera datorn från en webbsida t ex med polistrojanen.

3. På sidan http://www.virustotal.com bläddrar du fram C:\ProgramData\RUNDLL32.EXE-1304-F.txt och låter sidan skanna den. Om det kommer upp en fråga om filen ska analyseras om så välj det. Klistra in länken till resultatet här. Upprepa med C:\ProgramData\RUNDLL32.EXE-4880-F.txt.

Permalänk

Dax igen på nästa dator

Hej CeciliaB
Nu har jag fått polisvirustet på en annan dator hemma.

Jag bifogar texten från filen FRST.txt här under.

Jag är hemskt tacksam för hjälp så jag kan köra fix även på denna dator...
/Stinsen

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01 (ATTENTION: ====> FRST version is 47 days old and could be outdated)
Ran by martin.risberg (administrator) on JONSW108 on 31-08-2014 13:24:52
Running from i:\
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 9
Boot Mode: Safe Mode (with Networking)

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan...
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan...
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how...

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2919992 2011-01-27] (Hewlett-Packard Company)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2828072 2011-09-16] (Synaptics Incorporated)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [5398528 2012-08-02] (Broadcom Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-27] (IDT, Inc.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-30] (Adobe Systems Incorporated)
HKLM\...\Run: [Net iD] => C:\Program Files\Net iD\iid.exe [163072 2014-03-04] (SecMaker AB)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [299576 2011-01-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)
HKLM-x32\...\Run: [HPConnectionManager] => c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-04-05] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [HPQuickWebProxy] => c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [76344 2011-02-11] (Hewlett-Packard Company)
HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\F-Secure\Common\FSM32.EXE [301680 2009-11-26] (F-Secure Corporation)
HKLM-x32\...\Run: [F-Secure TNB] => C:\Program Files (x86)\F-Secure\FSGUI\TNBUtil.exe [1653360 2009-11-26] (F-Secure Corporation)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [522736 2011-04-18] ()
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-05-06] (PDF Complete Inc)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2012-11-13] ()
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-30] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2014-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [Net iD] => C:\Program Files (x86)\Net iD\iid.exe [157440 2014-03-04] (SecMaker AB)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-08-19] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-4125922248-3126017621-2310934882-1187\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-05-19] (Hewlett-Packard Company)
HKU\S-1-5-21-4125922248-3126017621-2310934882-1187\...\Run: [PTIM.exe] => C:\Program Files (x86)\WebEx\Productivity Tools\PTIM.exe [429072 2014-04-02] (Cisco WebEx LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SuperOffice CRM.Web Extensions.lnk
ShortcutTarget: SuperOffice CRM.Web Extensions.lnk -> C:\Program Files (x86)\SuperOffice\SuperOffice 7 Web Extensions\SuperOffice.TrayApp.Client.exe (SuperOffice AS)
Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyTellus.appref-ms ()
Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\83C401.cpp ()
Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyTellus.appref-ms ()
Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\83C401.cpp ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://192.168.1.157/TidomatPortal/DesktopDefault.aspx?tabind...
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCOM/15
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/15
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCOM/15
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://se.search.yahoo.com/search?p={searchTerms}&ei={inputEn...
SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://se.search.yahoo.com/search?p={searchTerms}&ei={inputEn...
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
BHO: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: WebEx Productivity Tools -> {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} -> C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll (Cisco WebEx LLC)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: WebEx Productivity Tools -> {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} -> C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
Toolbar: HKLM - WebEx Productivity Tools - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll (Cisco WebEx LLC)
Toolbar: HKLM-x32 - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
Toolbar: HKLM-x32 - WebEx Productivity Tools - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: HKLM {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternatiff.com/distribution/alternatiff-ax-w64-2....
DPF: HKLM-x32 {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternatiff.com/distribution/alternatiff-ax-w32-2....
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw...
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/sw...
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: www.superoffice.com/SuperOfficeWebToolsPlugin - C:\Program Files (x86)\SuperOffice\SuperOffice 7 Web Tools Plugin\npSuperOfficeWebToolsPlugin.dll (SuperOffice)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\mr.SWECAST\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\mr.SWECAST\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-01-19]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-04-03]

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave for Director) - C:\windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Google Dokument) - C:\Users\mr.SWECAST\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-12]
CHR Extension: (Google Drive) - C:\Users\mr.SWECAST\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-12]
CHR Extension: (YouTube) - C:\Users\mr.SWECAST\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-12]
CHR Extension: (Sök på Google) - C:\Users\mr.SWECAST\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-12]
CHR Extension: (Google Wallet) - C:\Users\mr.SWECAST\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\mr.SWECAST\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-06-12]
CHR Extension: (Gmail) - C:\Users\mr.SWECAST\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-12]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

S2 F-Secure Gatekeeper Handler Starter; C:\Program Files (x86)\F-Secure\Anti-Virus\fsgk32st.exe [219760 2009-11-26] (F-Secure Corporation)
S3 F-Secure Network Request Broker; C:\Program Files (x86)\F-Secure\Common\FNRB32.EXE [166512 2009-11-26] (F-Secure Corporation)
S2 FSMA; C:\Program Files (x86)\F-Secure\Common\FSMA32.EXE [186992 2009-11-26] (F-Secure Corporation)
S3 FSORSPClient; C:\Program Files (x86)\F-Secure\ORSP Client\fsorsp.exe [60352 2013-06-06] (F-Secure Corporation)
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
S2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company)
S2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-29] (Hewlett-Packard Company)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-05-19] (Hewlett-Packard Company) [File not signed]
S2 Net iD Trace; C:\Program Files\Net iD\iid.exe [163072 2014-03-04] (SecMaker AB)
S3 OnePointDomainAdminService; C:\windows\OnePointDomainAgent\DCTAgentService.exe [91648 2010-05-20] (Microsoft Corporation) [File not signed]
S2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.)
S2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [4819968 2012-08-02] (Broadcom Corporation) [File not signed]
S2 McAfee Endpoint Encryption Agent; "C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe" [X]
S2 Winmgmt; C:\PROGRA~3\104C38.dot [X]

==================== Drivers (Whitelisted) ====================

S3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.)
S4 F-Secure Filter; C:\Program Files (x86)\F-Secure\Anti-Virus\Win2K\FSfilter.sys [39792 2009-11-26] ()
S3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\Anti-Virus\minifilter\fsgk.sys [202176 2013-07-12] (F-Secure Corporation)
S1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\HIPS\drivers\fshs.sys [57936 2009-11-26] (F-Secure Corporation)
S4 F-Secure Recognizer; C:\Program Files (x86)\F-Secure\Anti-Virus\Win2K\FSrec.sys [25200 2009-11-26] ()
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2012-08-21] ()
R0 fsbts; C:\Windows\SysWOW64\Drivers\fsbts.sys [33408 2012-08-03] ()
S1 fsvista; C:\Program Files (x86)\F-Secure\Anti-Virus\minifilter\fsvista.sys [14904 2009-11-26] ()
R3 johci; C:\Windows\System32\DRIVERS\johci.sys [26712 2011-02-08] (JMicron Technology Corp.)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1863720 2012-06-01] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-08-31 13:24 - 2014-08-31 13:24 - 00000000 ____D () C:\FRST
2014-08-31 12:28 - 2014-08-31 12:28 - 00332532 _____ (Microsoft Corporation) C:\ProgramData\104c38.0ot
2014-08-31 12:27 - 2014-08-31 12:27 - 00175023 _____ () C:\ProgramData\83C401.cpp
2014-08-31 10:31 - 2014-08-31 10:31 - 00000000 ____D () C:\Users\martin.risberg\AppData\Local\Hewlett-Packard
2014-08-31 10:31 - 2014-08-31 10:31 - 00000000 ____D () C:\Users\martin.risberg
2014-08-26 15:27 - 2014-08-26 15:27 - 00082514 _____ () C:\Users\mr.SWECAST\Documents\Inbjudningslista 2011 från Sten.xlsx
2014-08-25 15:00 - 2014-08-25 15:23 - 00018692 _____ () C:\Users\mr.SWECAST\Documents\Kopia av Kundansvarig till avdelningscheferna_PP 140825.xlsx
2014-08-22 14:23 - 2014-08-22 14:23 - 00000000 ____D () C:\Users\mr.SWECAST\AppData\Roaming\SuperOffice
2014-08-21 13:26 - 2014-08-22 14:23 - 00000000 ____D () C:\Program Files (x86)\SuperOffice
2014-08-21 08:34 - 2014-08-21 08:34 - 04377793 _____ () C:\Users\mr.SWECAST\Desktop\Presentation Swerea SWECAST svensk ny.pptx
2014-08-17 11:37 - 2014-08-17 11:53 - 00000000 ____D () C:\Users\mr.SWECAST\Desktop\Ebba_Sommarminne 2014
2014-08-14 20:32 - 2014-08-14 20:32 - 00203264 _____ () C:\Users\mr.SWECAST\Desktop\Nya generationens verktyg genom additiv tillverkning på www.metalliskamaterial.se.msg

==================== One Month Modified Files and Folders =======

2014-08-31 13:24 - 2014-08-31 13:24 - 00000000 ____D () C:\FRST
2014-08-31 13:14 - 2011-03-05 01:40 - 00000000 ____D () C:\ProgramData\Sonic
2014-08-31 13:13 - 2013-06-12 21:21 - 00000986 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-31 13:13 - 2013-06-12 21:21 - 00000982 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-31 13:13 - 2012-08-22 14:15 - 00000000 ____D () C:\Users\mr.SWECAST\AppData\Local\Deployment
2014-08-31 13:11 - 2011-03-05 01:28 - 00000000 ____D () C:\ProgramData\PDFC
2014-08-31 13:11 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-08-31 13:11 - 2009-07-14 06:51 - 00108750 _____ () C:\windows\setupact.log
2014-08-31 12:30 - 2012-08-02 20:52 - 01334275 _____ () C:\windows\WindowsUpdate.log
2014-08-31 12:28 - 2014-08-31 12:28 - 00332532 _____ (Microsoft Corporation) C:\ProgramData\104c38.0ot
2014-08-31 12:27 - 2014-08-31 12:27 - 00175023 _____ () C:\ProgramData\83C401.cpp
2014-08-31 12:10 - 2012-10-08 08:53 - 00000000 ____D () C:\Users\mr.SWECAST\Documents\Outlook-filer
2014-08-31 12:09 - 2013-06-12 11:03 - 00001008 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-607446313-2454335297-1406949535-1633UA.job
2014-08-31 10:31 - 2014-08-31 10:31 - 00000000 ____D () C:\Users\martin.risberg\AppData\Local\Hewlett-Packard
2014-08-31 10:31 - 2014-08-31 10:31 - 00000000 ____D () C:\Users\martin.risberg
2014-08-31 10:31 - 2013-04-06 20:44 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-08-31 10:31 - 2012-08-26 12:06 - 00000052 _____ () C:\windows\SysWOW64\DOErrors.log
2014-08-31 10:27 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-31 10:27 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-31 10:24 - 2014-04-01 20:35 - 01595196 _____ () C:\windows\system32\PerfStringBackup.INI
2014-08-31 10:24 - 2011-03-05 01:26 - 00670688 _____ () C:\windows\system32\perfh01D.dat
2014-08-31 10:24 - 2011-03-05 01:26 - 00145376 _____ () C:\windows\system32\perfc01D.dat
2014-08-29 14:50 - 2012-10-07 20:05 - 00000000 ____D () C:\Users\mr.SWECAST\AppData\Roaming\vlc
2014-08-29 14:40 - 2012-08-03 10:39 - 00000560 _____ () C:\windows\system32\config\netlogon.ftl
2014-08-29 08:05 - 2012-08-21 15:50 - 00000000 ____D () C:\Swerea_SWECAST
2014-08-29 07:44 - 2014-07-19 17:09 - 00003240 _____ () C:\windows\System32\Tasks\HPCeeScheduleFormartin.risberg
2014-08-29 07:44 - 2014-07-19 17:09 - 00000368 _____ () C:\windows\Tasks\HPCeeScheduleFormartin.risberg.job
2014-08-28 15:09 - 2013-06-12 11:03 - 00000956 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-607446313-2454335297-1406949535-1633Core.job
2014-08-26 15:27 - 2014-08-26 15:27 - 00082514 _____ () C:\Users\mr.SWECAST\Documents\Inbjudningslista 2011 från Sten.xlsx
2014-08-25 15:23 - 2014-08-25 15:00 - 00018692 _____ () C:\Users\mr.SWECAST\Documents\Kopia av Kundansvarig till avdelningscheferna_PP 140825.xlsx
2014-08-25 13:33 - 2012-08-26 11:56 - 00000000 ____D () C:\Martin
2014-08-24 17:22 - 2012-08-02 23:07 - 00079780 _____ () C:\windows\PFRO.log
2014-08-22 14:23 - 2014-08-22 14:23 - 00000000 ____D () C:\Users\mr.SWECAST\AppData\Roaming\SuperOffice
2014-08-22 14:23 - 2014-08-21 13:26 - 00000000 ____D () C:\Program Files (x86)\SuperOffice
2014-08-21 14:27 - 2013-10-21 15:28 - 00003446 __RSH () C:\Users\mr.SWECAST\ntuser.pol
2014-08-21 14:27 - 2012-08-03 09:41 - 00000000 ____D () C:\Users\mr.SWECAST
2014-08-21 13:00 - 2013-07-04 08:49 - 00000000 ____D () C:\Users\mr.SWECAST\AppData\Local\Downloaded Installations
2014-08-21 08:34 - 2014-08-21 08:34 - 04377793 _____ () C:\Users\mr.SWECAST\Desktop\Presentation Swerea SWECAST svensk ny.pptx
2014-08-21 07:39 - 2014-04-03 17:39 - 00004708 __RSH () C:\ProgramData\ntuser.pol
2014-08-17 11:53 - 2014-08-17 11:37 - 00000000 ____D () C:\Users\mr.SWECAST\Desktop\Ebba_Sommarminne 2014
2014-08-14 20:32 - 2014-08-14 20:32 - 00203264 _____ () C:\Users\mr.SWECAST\Desktop\Nya generationens verktyg genom additiv tillverkning på www.metalliskamaterial.se.msg
2014-08-13 10:48 - 2012-08-03 05:52 - 00000000 ____D () C:\windows\rescache
2014-08-01 08:58 - 2012-09-02 20:43 - 00003218 _____ () C:\windows\System32\Tasks\HPCeeScheduleForJONSW108$
2014-08-01 08:58 - 2012-09-02 20:43 - 00000342 _____ () C:\windows\Tasks\HPCeeScheduleForJONSW108$.job

Some content of TEMP:
====================
C:\Users\mr.SWECAST\AppData\Local\Temp\atgpcdec.dll
C:\Users\mr.SWECAST\AppData\Local\Temp\dcrw.dll
C:\Users\mr.SWECAST\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\mr.SWECAST\AppData\Local\Temp\vlc-2.1.3-win32.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-08-27 08:12

==================== End Of Log ============================

Dold text
Permalänk
Medlem
Skrivet av Stinsen73:

Hej CeciliaB
Nu har jag fått polisvirustet på en annan dator hemma.

Jag bifogar texten från filen FRST.txt här under.

Jag är hemskt tacksam för hjälp så jag kan köra fix även på denna dator...
/Stinsen

Du behöver se över dina surfvanor och se till att hålla alla program uppdaterade. Du har gamla Java-versioner installerade med kända säkerhetshål. Se till att avinstallera dem i kontrollpanelen, Firefox och Chrome.

Hur gammal är din F-secure egentligen?
Det är viktigt att ha senaste årsmodellen/versionen för bästa skydd.

Citat:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01 (ATTENTION: ====> FRST version is 47 days old and could be outdated)

Ta bort den FRST du har och hämta senaste versionen:
För 64-bitars Windows: http://download.bleepingcomputer.com/farbar/FRST64.exe
För 32-bitars Windows: http://download.bleepingcomputer.com/farbar/FRST.exe
Eftersom Windows går att starta kan du spara FRST på skrivbordet så blir det enklare.

Starta Anteckningar.
Kopiera alla rader i rutan:

Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\83C401.cpp ()
Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\83C401.cpp ()
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
S2 McAfee Endpoint Encryption Agent; "C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe" [X]
S2 Winmgmt; C:\PROGRA~3\104C38.dot [X]
2014-08-31 12:28 - 2014-08-31 12:28 - 00332532 _____ (Microsoft Corporation) C:\ProgramData\104c38.0ot
2014-08-31 12:27 - 2014-08-31 12:27 - 00175023 _____ () C:\ProgramData\83C401.cpp

Dold text

och klistra in i Anteckningar. Kontrollera att inga filer har delats upp på två rader.
Spara filen på skrivbordet med namnet fixlist.txt.

Starta FRST som finns på skrivbordet.
Klicka på knappen Fix.
Vänta tills programmet är klart.

Programmet skapar en logg Fixlog.txt på skrivbordet.
Klistra in innehållet i den i ditt svar.

Permalänk

Hej igen
Tack för ditt snabba svar! Underbart, nu funjkar det igen!!!

Jo, visst är det så... det finns alltid uppdateringar att göra men.
Här kommer texten från Fixlog.txt

/Stinsen

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-08-2014
Ran by martin.risberg at 2014-08-31 15:24:40 Run:1
Running from i:\
Boot Mode: Safe Mode (with Networking)
==============================================

Content of fixlist:
*****************
Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\83C401.cpp ()
Startup: C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\83C401.cpp ()
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=390&sys...
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
S2 McAfee Endpoint Encryption Agent; "C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe" [X]
S2 Winmgmt; C:\PROGRA~3\104C38.dot [X]
2014-08-31 12:28 - 2014-08-31 12:28 - 00332532 _____ (Microsoft Corporation) C:\ProgramData\104c38.0ot
2014-08-31 12:27 - 2014-08-31 12:27 - 00175023 _____ () C:\ProgramData\83C401.cpp

*****************

C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk => Moved successfully.
C:\ProgramData\83C401.cpp => Moved successfully.
C:\Users\mr.SWECAST\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk not found.
C:\ProgramData\83C401.cpp not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully.
"HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully.
"HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
"HKLM\Software\MozillaPlugins\FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)" => Key not found.
"FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)" => not found.
"HKLM\Software\MozillaPlugins\FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)" => Key not found.
"FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)" => not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)" => Key not found.
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)" => Key not found.
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) not found.
McAfee Endpoint Encryption Agent => Service deleted successfully.
Winmgmt => Service restored successfully.
C:\ProgramData\104c38.0ot => Moved successfully.
"C:\ProgramData\83C401.cpp" => File/Directory not found.

The system needed a reboot.

==== End of Fixlog ====

Dold text
Permalänk
Medlem

Utmärkt!

Avinstallera FRST så här:
Ladda ner avinstallationsprogrammet OTC till Skrivbordet: http://oldtimer.geekstogo.com/OTC.exe
Starta programmet och klicka på CleanUp!.

För att få en extra kontroll av datorn, utifall att F-secure har missat något, kör Malwarebytes Anti-Malware (MBAM) Free: https://www.malwarebytes.org/
och Esets online-skanner: http://www.eset.com/onlinescan/
Den behöver konfigureras för bästa detektering:

Avbocka alternativet Remove found threats om du inte vill riskera att ett falsklarm tar bort en fil.
Bocka för Scan Archives

Klicka på Advanced Settings
Bocka för:
Scan for potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth Technology

Kontrollera dessutom hur det är med säkerhetshål i datorn genom att köra Secunias Software Inspector. Den engelska sidan http://www.bleepingcomputer.com/tutorials/detect-vulnerable-p... beskriver hur man installerar och använder programmet.

Permalänk

Trådskaparen nämner ju Sverige och USA, men lite nyfiket undrar jag om det egentligen finns en sådan där buffsida för alla Jordens länder, där du utger sig för att vara respektive lands poliskår?

Permalänk

Hej igen CeciliaB
Jag behöver vekligen göra något åt min dator och mina surfvanor... Nu har jag fått polisviruset igen... Jag har dock INTE surfat på samma typ av sidor denna gång. Jag tror att jag bara skall läsa Aftonbladet, Wikipedia och Sweclockers efter detta!!!

Här är texten från FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by SYSTEM on MININT-2AVDAIB on 14-09-2014 19:27:18
Running from f:\
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how...

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1694016 2011-09-07] ()
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-08] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Google Desktop Search] => C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2012-01-20] (Google)
HKLM-x32\...\Run: [RemoteControl11] => C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [234792 2011-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150016 2008-08-20] (Hewlett-Packard)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2640408 2014-08-25] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [ApnUpdater] => C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1644680 2013-02-08] (Ask)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\Admin\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3477312 2012-01-19] (DT Soft Ltd)
HKU\Admin\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [908160 2010-03-15] (Microsoft Corporation)
HKU\Admin\...\Run: [Google Update] => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-06-12] (Google Inc.)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-08-31] (Adobe Systems Incorporated)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.)
S2 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-19] ()
S2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
S2 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
S3 GoogleDesktopManager-060409-093314; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2012-01-20] (Google)
S2 NVWMI; C:\Windows\system32\nvwmi64.exe [590144 2011-12-10] ()
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-13] (AVG Secure Search)
S2 CltMngSvc; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.)
S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-13] (AVG Technologies)
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-01-20] (DT Soft Ltd)
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-04-12] (CyberLink Corp.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-10 10:28 - 2014-09-10 10:28 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Oracle
2014-09-10 10:28 - 2014-09-10 10:28 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-10 10:27 - 2014-09-10 10:27 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-10 10:27 - 2014-09-10 10:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-10 10:27 - 2014-09-10 10:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-10 10:27 - 2014-09-10 10:27 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\Program Files (x86)\AVG Security Toolbar
2014-08-21 10:45 - 2014-08-21 10:45 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files\iTunes
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files\iPod
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files (x86)\iTunes

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-14 19:27 - 2014-07-18 12:05 - 00000000 ____D () C:\FRST
2014-09-14 02:45 - 2012-01-20 01:16 - 01823445 _____ () C:\Windows\WindowsUpdate.log
2014-09-14 02:35 - 2013-06-12 07:03 - 00001004 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001UA.job
2014-09-14 02:33 - 2013-04-12 10:49 - 00000868 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-14 01:46 - 2012-12-13 07:36 - 00000338 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job
2014-09-13 22:28 - 2012-01-20 05:02 - 00000000 ____D () C:\ProgramData\MFAData
2014-09-13 06:35 - 2013-06-12 07:03 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4217374808-157746030-2108746492-1001Core.job
2014-09-13 03:59 - 2012-01-20 04:59 - 00000200 _____ () C:\Windows\Tasks\AutoKMSDaily.job
2014-09-11 09:13 - 2013-01-09 07:45 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\.minecraft
2014-09-10 10:28 - 2014-09-10 10:28 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Oracle
2014-09-10 10:28 - 2014-09-10 10:28 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-10 10:27 - 2014-09-10 10:27 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-10 10:27 - 2014-09-10 10:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-10 10:27 - 2014-09-10 10:27 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-10 10:27 - 2014-09-10 10:27 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-09-10 10:26 - 2012-01-22 21:54 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\uTorrent
2014-09-10 10:25 - 2012-01-20 14:20 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\GHISLER
2014-09-10 10:23 - 2013-04-20 00:07 - 00000000 ____D () C:\ProgramData\Sony Ericsson
2014-09-10 10:23 - 2013-04-20 00:07 - 00000000 ____D () C:\Program Files (x86)\Sony Ericsson
2014-09-10 10:23 - 2012-04-12 00:24 - 00000000 ____D () C:\Program Files\Net iD
2014-09-10 10:23 - 2012-04-12 00:24 - 00000000 ____D () C:\Program Files (x86)\Net iD
2014-09-08 11:22 - 2012-05-04 09:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Dropbox
2014-09-08 11:20 - 2013-06-03 04:39 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2014-09-08 11:20 - 2012-01-20 04:59 - 00000200 _____ () C:\Windows\Tasks\AutoKMS.job
2014-09-08 11:20 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-08 11:20 - 2009-07-13 20:51 - 00089296 _____ () C:\Windows\setupact.log
2014-09-07 10:58 - 2009-07-13 20:45 - 00020640 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-07 10:58 - 2009-07-13 20:45 - 00020640 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-02 22:35 - 2013-10-14 08:50 - 00000965 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-08-31 05:15 - 2014-07-19 04:37 - 02104320 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2014-08-31 03:14 - 2012-01-20 02:27 - 00661006 _____ () C:\Windows\System32\perfh01D.dat
2014-08-31 03:14 - 2012-01-20 02:27 - 00140808 _____ () C:\Windows\System32\perfc01D.dat
2014-08-31 03:14 - 2009-07-13 21:13 - 01571852 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-08-30 18:34 - 2012-03-16 10:06 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\vlc
2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\Program Files (x86)\AVG Security Toolbar
2014-08-25 11:53 - 2012-09-29 02:54 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search
2014-08-24 11:57 - 2014-04-05 06:13 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-08-22 06:45 - 2014-05-10 09:19 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-21 10:45 - 2014-08-21 10:45 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files\iTunes
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files\iPod
2014-08-21 10:45 - 2014-08-21 10:45 - 00000000 ____D () C:\Program Files (x86)\iTunes

Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\AskSLib.dll
C:\Users\Admin\AppData\Local\Temp\avguidx.dll
C:\Users\Admin\AppData\Local\Temp\CommonInstaller.exe
C:\Users\Admin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplc6nug.dll
C:\Users\Admin\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Admin\AppData\Local\Temp\htmlayout.dll
C:\Users\Admin\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe
C:\Users\Admin\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Admin\AppData\Local\Temp\LMkRstPt.exe
C:\Users\Admin\AppData\Local\Temp\MachineIdCreator.exe
C:\Users\Admin\AppData\Local\Temp\nsf9C3B.exe
C:\Users\Admin\AppData\Local\Temp\nsw559B.exe
C:\Users\Admin\AppData\Local\Temp\oi_{8C2923F6-50DE-43EA-B823-82A4A656A412}.exe
C:\Users\Admin\AppData\Local\Temp\readSTILog.dll
C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Admin\AppData\Local\Temp\ToolbarInstaller.exe
C:\Users\Admin\AppData\Local\Temp\update464937.exe
C:\Users\Admin\AppData\Local\Temp\utt2CF4.tmp.exe
C:\Users\Admin\AppData\Local\Temp\uttC4A2.tmp.exe
C:\Users\Admin\AppData\Local\Temp\vlc-2.1.5-win32.exe

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points =========================

Restore point made on: 2014-08-23 14:00:20
Restore point made on: 2014-08-31 14:00:16
Restore point made on: 2014-09-08 12:42:31
Restore point made on: 2014-09-10 10:24:06
Restore point made on: 2014-09-10 10:27:15

==================== Memory info ===========================

Percentage of memory in use: 10%
Total physical RAM: 6143.44 MB
Available physical RAM: 5472.22 MB
Total Pagefile: 6141.64 MB
Available Pagefile: 5460.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.04 GB) (Free:89.15 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Center) (Fixed) (Total:1863.01 GB) (Free:794.72 GB) NTFS
Drive f: () (Removable) (Total:1.9 GB) (Free:1.9 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: AFA2AFA2)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 918973F7)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 1.9 GB) (Disk ID: 0D0C0B0A)
Partition 1: (Active) - (Size=1.9 GB) - (Type=06)

LastRegBack: 2014-09-05 14:03

==================== End Of Log ============================

Dold text

Jag är hemskt tacksam för hjälp så jag kan köra fix även på denna dator...

Permalänk
Medlem
Skrivet av Stinsen73:

Hej igen CeciliaB
Jag behöver vekligen göra något åt min dator och mina surfvanor... Nu har jag fått polisviruset igen... Jag har dock INTE surfat på samma typ av sidor denna gång. Jag tror att jag bara skall läsa Aftonbladet, Wikipedia och Sweclockers efter detta!!!

Här är texten från FRST.txt

Jag är hemskt tacksam för hjälp så jag kan köra fix även på denna dator...

När det gäller polisviruset är det viktigaste att hålla alla program i datorn uppdaterade!
Har du installerat Secunias Software Inspector som jag skrev om tidigare (#222)?
Men naturligtvis ska man också hålla sig till välrenommerade sidor för att minska risken, samt hålla sig borta från cracks.

Men jag kan inte se något skadligt i loggen. Vad händer när du startar datorn?

Du kan pröva med t ex Kaspersky Rescue Disk: http://support.kaspersky.com/viruses/rescuedisk

Permalänk

Ytterligare ett offer

Nu har ytterligare en stackare drabbats av polistrojanen och jag skulle verkligen uppskatta CeciliaBs hjälp.

Jag fick ett flertal varningar från mitt AVG om att en trojan upptäckts på systemet för ett par dagar sedan och efter att ha sagt åt programmet att ta bort den så försvann varningarna, tills det att skärmbilden från "Polisen" dök upp och blockerade mig. Har sedan försökt komma in genom Felsäkert läge utan resultat, och detsamma genom att starta virus/spyware-program från ett USB-minne (trojanen har lyckats blockera även dem).

Har nu kört FRST (64-bit) enligt instruktionerna och här är resultatet:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-10-2014
Ran by SYSTEM on MINWINPC on 26-10-2014 12:41:59
Running from f:\
Platform: Windows Vista (TM) Home Premium (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how...

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8294680 2014-02-28] (Logitech Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [AVG_UI] => "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\Daniel\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
HKU\Daniel\...\Run: [AVG-Secure-Search-Update_0214c] => C:\Users\Daniel\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=922722bfe73f47d297c5d1530bbbea7f-8965854003fb817574ea5bc75e9c4136ee93ec5e /CMPID=0214c
HKU\Daniel\...\Run: [WMPNSCFG] => C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
HKU\Default\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\77A2ACA8.cpp (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3364368 2014-09-05] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [293448 2014-09-05] (AVG Technologies CZ, s.r.o.)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S2 Winmgmt; C:\ProgramData\8ACA2A77.dot [332288 2014-10-24] ()
S2 WinDefend; %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [247576 2014-07-24] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-20] (AVG Technologies CZ, s.r.o.)
S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.)
S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [270616 2014-07-02] (AVG Technologies CZ, s.r.o.)
S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 12:41 - 2014-10-26 12:41 - 00000000 ____D () C:\FRST
2014-10-26 09:33 - 2014-10-26 09:33 - 00000680 _____ () C:\Users\Daniel\AppData\Local\d3d9caps.dat
2014-10-25 12:27 - 2014-10-25 12:28 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Skyrim
2014-10-25 12:27 - 2014-10-25 12:27 - 00976018 _____ () C:\Users\Daniel\AppData\Local\dd_NET_Framework35_LangPack_MSI2EC8.txt
2014-10-25 12:27 - 2014-10-25 12:27 - 00416998 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35install_lp.txt
2014-10-25 12:27 - 2014-10-25 12:27 - 00000002 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35error_lp.txt
2014-10-25 12:26 - 2014-10-25 12:26 - 02817942 _____ () C:\Users\Daniel\AppData\Local\dd_NET_Framework35_x64_MSI2E7A.txt
2014-10-25 12:25 - 2014-10-25 12:27 - 00999312 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35install.txt
2014-10-25 12:25 - 2014-10-25 12:27 - 00235287 _____ () C:\Users\Daniel\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
2014-10-25 12:25 - 2014-10-25 12:25 - 00000002 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35error.txt
2014-10-25 09:39 - 2014-10-25 09:39 - 00000218 _____ () C:\Users\Daniel\AppData\Local\recently-used.xbel
2014-10-25 09:11 - 2014-10-25 09:11 - 00000872 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2014-10-25 09:10 - 2014-10-25 09:11 - 00000000 ____D () C:\ProgramData\AVG2015
2014-10-25 09:10 - 2014-10-25 09:10 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Avg
2014-10-25 09:05 - 2014-10-25 09:05 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Avg2015
2014-10-24 17:32 - 2014-10-24 17:32 - 00332288 ____T () C:\ProgramData\8ACA2A77.dot
2014-10-23 17:57 - 2014-10-23 17:57 - 00233656 _____ (Microsoft Corporation) C:\ProgramData\77A2ACA8.cpp
2014-10-11 17:32 - 2014-10-13 18:26 - 00021647 _____ () C:\Users\Daniel\Documents\TombRaider.log
2014-10-05 10:59 - 2014-10-05 10:59 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\.mono
2014-10-05 10:59 - 2014-10-05 10:59 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Castle Story Prototype

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 12:39 - 2006-11-02 16:42 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-26 12:39 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-26 12:38 - 2006-11-02 16:27 - 00033946 _____ () C:\Windows\setupact.log
2014-10-26 12:38 - 2006-11-02 16:22 - 00003664 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-26 12:38 - 2006-11-02 16:22 - 00003664 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-26 11:24 - 2014-03-21 19:39 - 00000656 _____ () C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-10-26 09:43 - 2006-11-02 16:27 - 01988920 _____ () C:\Windows\WindowsUpdate.log
2014-10-25 13:28 - 2006-11-21 07:09 - 00643440 _____ () C:\Windows\System32\perfh01D.dat
2014-10-25 13:28 - 2006-11-21 07:09 - 00138488 _____ () C:\Windows\System32\perfc01D.dat
2014-10-25 13:28 - 2006-11-02 13:46 - 01530984 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-10-25 13:26 - 2014-03-21 20:11 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-10-25 13:22 - 2014-03-21 19:15 - 00000000 ____D () C:\ProgramData\AVG2014
2014-10-25 13:22 - 2014-03-21 19:11 - 00000000 ____D () C:\ProgramData\MFAData
2014-10-25 13:22 - 2014-03-21 14:17 - 00053246 _____ () C:\Windows\PFRO.log
2014-10-25 12:24 - 2014-03-22 10:27 - 00195975 _____ () C:\Windows\DirectX.log
2014-10-25 11:36 - 2014-04-27 13:35 - 00000000 ____D () C:\Users\Daniel\Documents\My Games
2014-10-25 09:37 - 2014-03-22 10:11 - 00000000 ____D () C:\Users\Daniel\Downloads\Bitlord (nerladd.)
2014-10-25 09:37 - 2014-03-22 10:10 - 00000000 ____D () C:\Users\Daniel\Downloads\BitLord
2014-10-25 09:12 - 2014-03-21 19:15 - 00000000 ___HD () C:\$AVG
2014-10-25 09:12 - 2014-03-21 19:14 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-10-15 18:19 - 2014-03-20 20:09 - 00000000 ____D () C:\users\Daniel
2014-10-14 18:08 - 2014-03-21 18:52 - 00181248 _____ () C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-10-09 17:55 - 2014-03-28 16:38 - 00000000 ____D () C:\ProgramData\Origin
2014-10-09 17:51 - 2014-03-28 16:38 - 00000000 ____D () C:\Program Files (x86)\Origin

Some content of TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\ExPromo.exe
C:\Users\Daniel\AppData\Local\Temp\NiG4.dll
C:\Users\Daniel\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Daniel\AppData\Local\Temp\SIntf16.dll
C:\Users\Daniel\AppData\Local\Temp\SIntf32.dll
C:\Users\Daniel\AppData\Local\Temp\SIntfNT.dll
C:\Users\Daniel\AppData\Local\Temp\uninstall.exe
C:\Users\Daniel\AppData\Local\Temp\vlc-2.1.3-win32.exe
C:\Users\Daniel\AppData\Local\Temp\war3_Install.exe
C:\Users\Daniel\AppData\Local\Temp\_isD152.exe

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points =========================

Restore point made on: 2014-08-20 17:23:51
Restore point made on: 2014-08-23 09:47:31
Restore point made on: 2014-09-02 18:01:23
Restore point made on: 2014-09-11 08:57:29
Restore point made on: 2014-10-11 17:32:52
Restore point made on: 2014-10-12 19:23:44
Restore point made on: 2014-10-13 18:58:40
Restore point made on: 2014-10-14 17:44:18
Restore point made on: 2014-10-20 19:03:47
Restore point made on: 2014-10-21 19:16:11
Restore point made on: 2014-10-25 09:10:06
Restore point made on: 2014-10-25 09:10:24
Restore point made on: 2014-10-25 12:24:30

==================== Memory info ===========================

Percentage of memory in use: 9%
Total physical RAM: 8189.69 MB
Available physical RAM: 7394.29 MB
Total Pagefile: 7793.59 MB
Available Pagefile: 7463.55 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.76 GB) (Free:221.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:465.76 GB) (Free:38.09 GB) NTFS
Drive e: (LRMCxFRE_SV_DVD) (CDROM) (Total:3.44 GB) (Free:0 GB) UDF
Drive f: (ADATA UFD) (Removable) (Total:3.76 GB) (Free:3.75 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 7B2CAFFA)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 4D59CA7F)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 3.8 GB) (Disk ID: 04DD5721)
Partition 1: (Active) - (Size=3.8 GB) - (Type=0C)

LastRegBack: 2014-10-26 09:35

==================== End Of Log ============================

Dold text

Uppskattar all hjälp jag kan få då jag hoppas undvika både Systemåterställning och formatering.

Permalänk
Medlem
Skrivet av Pessimisten:

Nu har ytterligare en stackare drabbats av polistrojanen och jag skulle verkligen uppskatta CeciliaBs hjälp.

Jag fick ett flertal varningar från mitt AVG om att en trojan upptäckts på systemet för ett par dagar sedan och efter att ha sagt åt programmet att ta bort den så försvann varningarna, tills det att skärmbilden från "Polisen" dök upp och blockerade mig. Har sedan försökt komma in genom Felsäkert läge utan resultat, och detsamma genom att starta virus/spyware-program från ett USB-minne (trojanen har lyckats blockera även dem).

Har nu kört FRST (64-bit) enligt instruktionerna och här är resultatet:

Uppskattar all hjälp jag kan få då jag hoppas undvika både Systemåterställning och formatering.

Starta Anteckningar.
Kopiera alla rader i rutan:

Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk ShortcutTarget: program.lnk -> C:\ProgramData\77A2ACA8.cpp (Microsoft Corporation) S2 Winmgmt; C:\ProgramData\8ACA2A77.dot [332288 2014-10-24] () 2014-10-24 17:32 - 2014-10-24 17:32 - 00332288 ____T () C:\ProgramData\8ACA2A77.dot 2014-10-23 17:57 - 2014-10-23 17:57 - 00233656 _____ (Microsoft Corporation) C:\ProgramData\77A2ACA8.cpp

och klistra in i Anteckningar. Kontrollera att inga filer har delats upp på två rader.
Spara filen på USB-minnet med namnet fixlist.txt.

På den infekterade datorn från "System Recovery Options"
Starta FRST på den infekterade datorn på samma sätt som sist.
Klicka på knappen Fix.
Vänta tills programmet är klart.

Programmet skapar en logg Fixlog.txt på USB-minnet.
Klistra in innehållet i den i ditt svar.

Permalänk

Wow, det var verkligen ett snabbt svar. Skulle nästan kunna tro att du bara sitter och väntar på att klantar som jag ska få problem så att du kan komma till undsättning som en riddare i skinande rustning, CeciliaB.

Här är fixloggen, och tack för den snabba undsättningen.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-10-2014
Ran by SYSTEM at 2014-10-26 13:48:17 Run:1
Running from F:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk
ShortcutTarget: program.lnk -> C:\ProgramData\77A2ACA8.cpp (Microsoft Corporation)
S2 Winmgmt; C:\ProgramData\8ACA2A77.dot [332288 2014-10-24] ()
2014-10-24 17:32 - 2014-10-24 17:32 - 00332288 ____T () C:\ProgramData\8ACA2A77.dot
2014-10-23 17:57 - 2014-10-23 17:57 - 00233656 _____ (Microsoft Corporation) C:\ProgramData\77A2ACA8.cpp
*****************

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk => Moved successfully.
C:\ProgramData\77A2ACA8.cpp => Moved successfully.
Winmgmt => Service restored successfully.
C:\ProgramData\8ACA2A77.dot => Moved successfully.
"C:\ProgramData\77A2ACA8.cpp" => File/Directory not found.

==== End of Fixlog ====

Dold text
Permalänk
Medlem

Du har tur för tillfället men nu kommer jag att lämna datorn under flera timmar.

Går det att starta datorn nu?
I så fall flytta FRST från USB-minnet till skrivbordet.

Starta FRST.
Klicka på Scan-knappen.
När det är klart kommer det att ha skapats två loggar FRST.txt och Addition.txt på skrivbordet, klistra in dem så får vi se om där är något mer som ska bort samt vad du har för säkerhetshål i datorn.

Permalänk

Jo, det verkar funka för tillfället.

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2014
Ran by Daniel (administrator) on DANIEL-DATOR on 26-10-2014 14:13:26
Running from C:\Users\Daniel\Desktop
Loaded Profile: Daniel (Available profiles: Daniel)
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how...

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader\Reader\reader_sl.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\SetPoint\SetPoint.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\Logitech\SetPoint\x86\SetPoint32.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8294680 2014-02-28] (Logitech Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [AVG_UI] => "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-492103507-2440866364-2864248887-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
HKU\S-1-5-21-492103507-2440866364-2864248887-1000\...\Run: [AVG-Secure-Search-Update_0214c] => C:\Users\Daniel\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=922722bfe73f47d297c5d1530bbbea7f-8965854003fb817574ea5bc75e9c4136ee93ec5e /CMPID=0214c
HKU\S-1-5-21-492103507-2440866364-2864248887-1000\...\Run: [WMPNSCFG] => C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files (x86)\Adobe\Reader\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
ShortcutTarget: Adobe Reader Synchronizer.lnk -> C:\Program Files (x86)\Adobe\Reader\Reader\AdobeCollabSync.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Gaming.lnk
ShortcutTarget: Logitech Gaming.lnk -> C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files (x86)\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fz.se/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {A8C6CEAB-5B5F-438E-9E52-86F86455F65F} URL = http://www.google.com/search?hl=sv&q={searchTerms}
SearchScopes: HKCU - URL http://www.trovigo.com/Results.aspx?gd=&ctid=CT3319597&octid=...
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={s...
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {A8C6CEAB-5B5F-438E-9E52-86F86455F65F} URL = http://www.google.com/search?hl=sv&q={searchTerms}
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.)
BHO-x32: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 195.67.199.21 195.67.199.22

FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uagc13ak.default
FF Homepage: hxxp://www.fz.se/
FF Plugin-x32: @bankid.com/BankID säkerhetsprogram,version=5.1.3.2 -> C:\Program Files (x86)\BankID\npBispBrowser.dll (Finansiell ID-Teknik BID AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Daniel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: sony.com/MediaGoDetector -> C:\Program Files (x86)\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-03-21]

Chrome:
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3364368 2014-09-05] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [293448 2014-09-05] (AVG Technologies CZ, s.r.o.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S2 WinDefend; %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [247576 2014-07-24] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-20] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [270616 2014-07-02] (AVG Technologies CZ, s.r.o.)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 14:13 - 2014-10-26 14:13 - 00011828 _____ () C:\Users\Daniel\Desktop\FRST.txt
2014-10-26 14:13 - 2014-10-26 14:13 - 00000000 ____D () C:\Users\Daniel\Desktop\FRST-OlderVersion
2014-10-26 12:41 - 2014-10-26 14:13 - 00000000 ____D () C:\FRST
2014-10-26 12:22 - 2014-10-26 14:13 - 02113024 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2014-10-26 09:33 - 2014-10-26 09:33 - 00000680 _____ () C:\Users\Daniel\AppData\Local\d3d9caps.dat
2014-10-25 12:27 - 2014-10-25 12:28 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Skyrim
2014-10-25 12:27 - 2014-10-25 12:27 - 00976018 _____ () C:\Users\Daniel\AppData\Local\dd_NET_Framework35_LangPack_MSI2EC8.txt
2014-10-25 12:27 - 2014-10-25 12:27 - 00416998 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35install_lp.txt
2014-10-25 12:27 - 2014-10-25 12:27 - 00000002 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35error_lp.txt
2014-10-25 12:26 - 2014-10-25 12:26 - 02817942 _____ () C:\Users\Daniel\AppData\Local\dd_NET_Framework35_x64_MSI2E7A.txt
2014-10-25 12:25 - 2014-10-25 12:27 - 00999312 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35install.txt
2014-10-25 12:25 - 2014-10-25 12:27 - 00235287 _____ () C:\Users\Daniel\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
2014-10-25 12:25 - 2014-10-25 12:25 - 00000002 _____ () C:\Users\Daniel\AppData\Local\dd_dotnetfx35error.txt
2014-10-25 09:39 - 2014-10-25 09:39 - 00000218 _____ () C:\Users\Daniel\AppData\Local\recently-used.xbel
2014-10-25 09:11 - 2014-10-25 09:11 - 00000872 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2014-10-25 09:11 - 2014-10-25 09:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-10-25 09:10 - 2014-10-25 09:11 - 00000000 ____D () C:\ProgramData\AVG2015
2014-10-25 09:10 - 2014-10-25 09:10 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Avg
2014-10-25 09:05 - 2014-10-25 09:05 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Avg2015
2014-10-11 17:32 - 2014-10-13 18:26 - 00021647 _____ () C:\Users\Daniel\Documents\TombRaider.log
2014-10-05 10:59 - 2014-10-05 10:59 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\.mono
2014-10-05 10:59 - 2014-10-05 10:59 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Castle Story Prototype

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 14:11 - 2014-03-21 19:39 - 00000656 _____ () C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-10-26 14:11 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-26 14:11 - 2006-11-02 16:22 - 00003664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-26 14:11 - 2006-11-02 16:22 - 00003664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-26 12:39 - 2006-11-02 16:42 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-26 12:38 - 2006-11-02 16:27 - 00033946 _____ () C:\Windows\setupact.log
2014-10-26 09:43 - 2006-11-02 16:27 - 01988920 _____ () C:\Windows\WindowsUpdate.log
2014-10-25 13:28 - 2006-11-21 07:09 - 00643440 _____ () C:\Windows\system32\perfh01D.dat
2014-10-25 13:28 - 2006-11-21 07:09 - 00138488 _____ () C:\Windows\system32\perfc01D.dat
2014-10-25 13:28 - 2006-11-02 13:46 - 01530984 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-25 13:26 - 2014-03-21 20:11 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-10-25 13:22 - 2014-03-21 19:15 - 00000000 ____D () C:\ProgramData\AVG2014
2014-10-25 13:22 - 2014-03-21 19:11 - 00000000 ____D () C:\ProgramData\MFAData
2014-10-25 13:22 - 2014-03-21 14:17 - 00053246 _____ () C:\Windows\PFRO.log
2014-10-25 12:24 - 2014-03-22 10:27 - 00195975 _____ () C:\Windows\DirectX.log
2014-10-25 11:36 - 2014-04-27 13:35 - 00000000 ____D () C:\Users\Daniel\Documents\My Games
2014-10-25 09:37 - 2014-03-22 10:11 - 00000000 ____D () C:\Users\Daniel\Downloads\Bitlord (nerladd.)
2014-10-25 09:37 - 2014-03-22 10:10 - 00000000 ____D () C:\Users\Daniel\Downloads\BitLord
2014-10-25 09:12 - 2014-03-21 19:15 - 00000000 ___HD () C:\$AVG
2014-10-25 09:12 - 2014-03-21 19:14 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-10-15 18:19 - 2014-03-20 20:09 - 00000000 ____D () C:\Users\Daniel
2014-10-14 18:08 - 2014-03-21 18:52 - 00181248 _____ () C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-10-09 17:55 - 2014-03-28 16:38 - 00000000 ____D () C:\ProgramData\Origin
2014-10-09 17:51 - 2014-03-28 16:38 - 00000000 ____D () C:\Program Files (x86)\Origin

Some content of TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\ExPromo.exe
C:\Users\Daniel\AppData\Local\Temp\NiG4.dll
C:\Users\Daniel\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Daniel\AppData\Local\Temp\SIntf16.dll
C:\Users\Daniel\AppData\Local\Temp\SIntf32.dll
C:\Users\Daniel\AppData\Local\Temp\SIntfNT.dll
C:\Users\Daniel\AppData\Local\Temp\uninstall.exe
C:\Users\Daniel\AppData\Local\Temp\vlc-2.1.3-win32.exe
C:\Users\Daniel\AppData\Local\Temp\war3_Install.exe
C:\Users\Daniel\AppData\Local\Temp\_isD152.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-10-26 09:35

==================== End Of Log ============================

Dold text

Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2014
Ran by Daniel at 2014-10-26 14:13:50
Running from C:\Users\Daniel\Desktop
Boot Mode: Normal
==========================================================

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition 2015 (Disabled - Out of date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG AntiVirus Free Edition 2015 (Disabled - Out of date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader 8 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A80000000002}) (Version: 8.0.0 - Adobe Systems Incorporated)
Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.4.2.0 - Auslogics Labs Pty Ltd)
AutoREALM Version 2.2.1 (HKLM-x32\...\AutoREALM_is1) (Version: - )
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5315 - AVG Technologies)
AVG 2015 (Version: 15.0.4189 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5315 - AVG Technologies) Hidden
Banished (HKLM-x32\...\Steam App 242920) (Version: - Shining Rock Software LLC)
BankID säkerhetsprogram (HKLM-x32\...\{2D6973ED-BBF2-434E-993C-37E05087B8C8}) (Version: 5.1.3.2 - Finansiell ID-Teknik BID AB)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitLord 2.3 (HKLM-x32\...\BitLord) (Version: 2.3.2-254 - House of Life)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.4.1.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: - )
Canon MG6200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6200_series) (Version: - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
Castle Story (HKLM-x32\...\Steam App 227860) (Version: - Sauropod Studio)
Cataclysm (HKLM-x32\...\Cataclysm) (Version: - )
CC3 (HKLM-x32\...\CC3) (Version: 3.42 - ProFantasy Software)
CC3 (x32 Version: 3.42 - ProFantasy Software) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.09 - Piriform)
CDDRV_Installer (x32 Version: 1.00.0000 - Logitech) Hidden
CPUID CPU-Z 1.58 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
Dead Space™ (HKLM-x32\...\{6E6F22D7-8AD6-4A87-9A47-733E6E996F50}) (Version: 1.0.0.222 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
FastCAD (HKLM-x32\...\FastCAD) (Version: - )
Francesco's leveled creatures-items mod 4.5b (HKLM-x32\...\Francesco's leveled creatures-items mod_is1) (Version: - Francesco)
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.56.5183 - Gretech Corporation)
Gray Matter (HKLM-x32\...\Steam App 260570) (Version: - WizarBox Production)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Heroes of Might and Magic® IV (HKLM-x32\...\Heroes of Might and Magic IV) (Version: - )
Homeworld (HKLM-x32\...\Homeworld) (Version: - )
Homeworld2 (HKLM-x32\...\Homeworld2) (Version: - Sierra)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
KhalInstallWrapper (Version: 4.00.121 - Logitech) Hidden
Loadout (HKLM-x32\...\Steam App 208090) (Version: - Edge of Reality)
Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden
Logitech Gaming Software 8.52 (HKLM\...\Logitech Gaming Software) (Version: 8.52.15 - Logitech Inc.)
Logitech SetPoint (HKLM-x32\...\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}) (Version: 4.00 - Logitech)
Media Go (HKLM-x32\...\{7547239C-FA8A-4FA4-84A6-31EAC0777E1B}) (Version: 2.7.341 - Sony)
Media Go Network Downloader (HKLM-x32\...\{73FA7631-3015-4EEC-A002-09488C47A07C}) (Version: 1.5.19.0 - Sony)
Media Go Video Playback Engine 2.4.127.12060 (HKLM-x32\...\{7C5AEEE1-6D7C-8922-4548-7BF9096077EC}) (Version: 2.4.127.12060 - Sony)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (svenska) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1053) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Morrowind (HKLM-x32\...\{055A1919-3BBA-4BD5-8B3C-3851879AC185}) (Version: - )
Mozilla Firefox 20.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 20.0 (x86 en-US)) (Version: 20.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 20.0 - Mozilla)
NVIDIA 3D Vision drivrutin för styrenhet 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 337.88 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1 - NVIDIA Corporation)
NVIDIA Grafikdrivrutin 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA HD audiodrivrutin 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX systemprogramvara 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA Update Core (Version: 14.6.22 - NVIDIA Corporation) Hidden
NVIDIAs kontrollpanel 337.88 (Version: 337.88 - NVIDIA Corporation) Hidden
NVIDIA-uppdatering 14.6.22 (Version: 14.6.22 - NVIDIA Corporation) Hidden
Oblivion - Horse Armor Pack (HKLM-x32\...\{3ABEBD00-299D-4DCA-967F-B912163AB5EA}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion - Knights of the Nine (HKLM-x32\...\{14C87AA7-08E6-419F-A165-998EBE5023D7}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion - Mehrunes Razor (HKLM-x32\...\{EF295F5C-7B57-47AA-8889-6B3E8E214E89}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion - Orrery (HKLM-x32\...\{EC425CFC-EE78-4A91-AA25-3BFA65B75364}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion - Spell Tomes (HKLM-x32\...\{16D919E6-F019-4E15-BFBE-4A85EF19DA57}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion - Thieves Den (HKLM-x32\...\{FFFFFD17-B460-41EB-93F1-C48ABAD63828}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion - Vile Lair (HKLM-x32\...\{520F4B09-3A51-47A2-82B0-9FF1DC2D20FA}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion - Wizard's Tower (HKLM-x32\...\{2F2E3D62-8B8C-448F-8900-451325E50948}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion (HKLM-x32\...\{35CB6715-41F8-4F99-8881-6FC75BF054B0}) (Version: 1.00.0000 - Bethesda Softworks)
Oblivion mod manager 1.1.12 (HKLM-x32\...\Oblivion mod manager_is1) (Version: - Timeslip)
OpenOffice 4.0.1 (HKLM-x32\...\{46BCB691-9148-4FCB-B215-CCDF70B5D95A}) (Version: 4.01.9714 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.)
Sniper Elite V2 (HKLM-x32\...\Steam App 63380) (Version: - Rebellion)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Språkpaket för Microsoft .NET Framework 3.5 SP 1 - sve (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - sve) (Version: - Microsoft Corporation)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
The Walking Dead: Season Two (HKLM-x32\...\Steam App 261030) (Version: - Telltale Games)
The Wolf Among Us (HKLM-x32\...\Steam App 250320) (Version: - Telltale Games)
Theme Hospital (HKLM-x32\...\GOGPACKTHEMEHOSPITAL_is1) (Version: 2.0.0.5 - GOG.com)
Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics)
Total War: ROME II (HKLM-x32\...\Steam App 214950) (Version: - Creative Assembly)
Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
Unofficial Oblivion Patch v3.4.5 (HKLM-x32\...\Unofficial Oblivion Patch_is1) (Version: 3.4.5 - Quarn, Kivan, and Arthmoor)
Unofficial Official Mods Patch v18 (HKLM-x32\...\Unofficial Official Mods Patch_is1) (Version: v18 - Quarn, Kivan, and Arthmoor)
Warcraft III (HKLM-x32\...\Warcraft III) (Version: - )
Warcraft III: All Products (HKCU\...\Warcraft III) (Version: - )
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)
World of Warplanes (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C813EU}_is1) (Version: - Wargaming.net)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

==================== Restore Points =========================

20-08-2014 16:23:43 Schemalagd kontrollpunkt
23-08-2014 08:47:23 Schemalagd kontrollpunkt
02-09-2014 17:01:15 Schemalagd kontrollpunkt
11-09-2014 07:57:22 Schemalagd kontrollpunkt
11-10-2014 16:32:40 DirectX har installerats
12-10-2014 18:23:35 Schemalagd kontrollpunkt
13-10-2014 17:58:32 Schemalagd kontrollpunkt
14-10-2014 16:44:10 Schemalagd kontrollpunkt
20-10-2014 18:03:36 Schemalagd kontrollpunkt
21-10-2014 18:16:04 Schemalagd kontrollpunkt
25-10-2014 08:09:54 Installed AVG 2015
25-10-2014 08:10:17 Installed AVG 2015
25-10-2014 11:24:23 DirectX har installerats

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 13:34 - 2014-03-21 21:20 - 00450628 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com

There are 1000 more lines.

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {3D54CE5B-B331-401B-A287-EAF277BC93C2} - System32\Tasks\Scan the system (Spybot - Search & Destroy) => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {48218A8E-C591-4E3D-824E-6B7BBC0FFBD0} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {4E36527E-1862-4005-B0B1-5DD18786BDEB} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => C:\Windows\servicing\vsp1ceip.exe [2008-01-19] (Microsoft Corporation)
Task: {4E946E6C-49EC-4FD9-8F58-EB5AF1752C5D} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries
Task: {7B26A248-03EA-4DDC-8E18-924F1DB92B33} - System32\Tasks\Check for updates (Spybot - Search & Destroy) => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {91C1D899-784A-4C62-B7B6-6D5ACA58D79E} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2014-03-20] ()
Task: {EE09E3BD-A9BF-452D-8A94-4176AB1AF8B3} - System32\Tasks\Refresh immunization (Spybot - Search & Destroy) => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {F87582C9-4A61-4FA3-9062-D97DC2DF9F3A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe

==================== Loaded Modules (whitelisted) =============

2014-03-21 17:07 - 2007-04-23 04:00 - 00077824 _____ () C:\Program Files (x86)\Logitech\SetPoint\x86\SetPoint32.exe
2014-03-21 19:39 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-03-21 19:39 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-03-21 19:39 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-03-21 19:39 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-03-21 19:39 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

========================= Accounts: ==========================

Administratör (S-1-5-21-492103507-2440866364-2864248887-500 - Administrator - Disabled)
Daniel (S-1-5-21-492103507-2440866364-2864248887-1000 - Administrator - Enabled) => C:\Users\Daniel
Gäst (S-1-5-21-492103507-2440866364-2864248887-501 - Limited - Disabled)

==================== Faulty Device Manager Devices =============

Name: Ljudstyrenhet för multimedia
Description: Ljudstyrenhet för multimedia
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: SM-busstyrenhet
Description: SM-busstyrenhet
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (10/26/2014 00:27:40 PM) (Source: Software Licensing Service) (EventID: 1001) (User: )
Description: Software Licensing Service kunde inte startas. hr=0x80070002, [2, 4]

Error: (10/26/2014 10:12:19 AM) (Source: Software Licensing Service) (EventID: 1001) (User: )
Description: Software Licensing Service kunde inte startas. hr=0x80070002, [2, 4]

Error: (10/25/2014 01:43:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Felet uppstod i programmet rundll32.exe, version 6.0.6000.16386, tidsstämpel 0x4549b0e1, felet uppstod i modulen 77A2ACA8.cpp, version 5.2.3790.0, tidsstämpel 0x2a425e19, undantagskod 0xc0000005, felförskjutning 0x00001c19,
process-ID 0xd34, programmets starttid 0xrundll32.exe0.

Error: (10/25/2014 00:24:58 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Det gick inte att skapa en återställningspunkt på volymen
(Process = E:\Games\Steam\steamapps\common\Skyrim\DirectX10\DXSETUP.exe /silent; Beskrivning = äxKv; Hr = 0x80070057).

Error: (10/23/2014 05:57:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programmet iexplore.exe, version 9.0.8112.16540, avslutades eftersom det slutade att samverka med Windows. Ytterligare information kan finnas i problemhistoriken på kontrollpanelen för Problemrapporter och lösningar.
Process-ID: 1230
Starttid: 01cfeee092c58e4c
Avslutningstid: 8

Error: (10/23/2014 05:57:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Felet uppstod i programmet rundll32.exe, version 6.0.6000.16386, tidsstämpel 0x4549b0e1, felet uppstod i modulen NiG4.dll, version 5.2.3790.0, tidsstämpel 0x2a425e19, undantagskod 0xc0000005, felförskjutning 0x00001c19,
process-ID 0xd3c, programmets starttid 0xrundll32.exe0.

Error: (10/15/2014 05:24:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Felet uppstod i programmet iexplore.exe, version 9.0.8112.16540, tidsstämpel 0x5309896b, felet uppstod i modulen AUDIOSES.DLL, version 6.0.6002.18005, tidsstämpel 0x49e03703, undantagskod 0xc0000005, felförskjutning 0x00009efa,
process-ID 0xc94, programmets starttid 0xiexplore.exe0.

Error: (10/12/2014 06:54:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Felet uppstod i programmet TombRaider.exe, version 1.1.748.0, tidsstämpel 0x519379a7, felet uppstod i modulen TombRaider.exe, version 1.1.748.0, tidsstämpel 0x519379a7, undantagskod 0xc0000005, felförskjutning 0x00794573,
process-ID 0x1304, programmets starttid 0xTombRaider.exe0.

Error: (10/12/2014 06:54:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Felet uppstod i programmet TombRaider.exe, version 1.1.748.0, tidsstämpel 0x519379a7, felet uppstod i modulen TombRaider.exe, version 1.1.748.0, tidsstämpel 0x519379a7, undantagskod 0xc0000005, felförskjutning 0x001baa4c,
process-ID 0x1304, programmets starttid 0xTombRaider.exe0.

Error: (10/11/2014 05:32:57 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Det gick inte att skapa en återställningspunkt på volymen
(Process = E:\Games\Steam\steamapps\common\Tomb Raider\redist\DXSetup.exe Raider\redist\DXSetup.exe" /silent; Beskrivning = äx®u; Hr = 0x80070057).

System errors:
=============
Error: (10/26/2014 02:11:38 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: AVGIDSAgent3758213659 (0xE001CA1B)

Error: (10/26/2014 02:11:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Windows Defender%%126

Error: (10/26/2014 02:11:34 PM) (Source: Dhcp) (EventID: 1002) (User: )
Description: IP-adresslånet 192.168.0.5 för det nätverkskort som har nätverksadressen 001A4D5EF61C har nekats av DHCP-servern 192.168.0.1 (DHCP-servern skickade ett DHCPNACK-meddelande).

Error: (10/26/2014 11:24:41 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (10/26/2014 11:22:35 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (10/26/2014 11:20:26 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (10/26/2014 11:17:44 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (10/26/2014 11:10:48 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (10/26/2014 11:08:11 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (10/26/2014 11:06:10 AM) (Source: PlugPlayManager) (EventID: 10) (User: )
Description: Ett fel inträffade vid skrivning till en installations-pipe på servern

Microsoft Office Sessions:
=========================
Error: (10/26/2014 00:27:40 PM) (Source: Software Licensing Service) (EventID: 1001) (User: )
Description: hr=0x80070002, [2, 4]

Error: (10/26/2014 10:12:19 AM) (Source: Software Licensing Service) (EventID: 1001) (User: )
Description: hr=0x80070002, [2, 4]

Error: (10/25/2014 01:43:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rundll32.exe6.0.6000.163864549b0e177A2ACA8.cpp5.2.3790.02a425e19c000000500001c19d3401cff04e6efdba48

Error: (10/25/2014 00:24:58 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: E:\Games\Steam\steamapps\common\Skyrim\DirectX10\DXSETUP.exe /silentäxKv0x80070057

Error: (10/23/2014 05:57:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16540123001cfeee092c58e4c8

Error: (10/23/2014 05:57:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rundll32.exe6.0.6000.163864549b0e1NiG4.dll5.2.3790.02a425e19c000000500001c19d3c01cfeee25a4fb07c

Error: (10/15/2014 05:24:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe9.0.8112.165405309896bAUDIOSES.DLL6.0.6002.1800549e03703c000000500009efac9401cfe88e60aa7b38

Error: (10/12/2014 06:54:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: TombRaider.exe1.1.748.0519379a7TombRaider.exe1.1.748.0519379a7c000000500794573130401cfe629304bf3a1

Error: (10/12/2014 06:54:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: TombRaider.exe1.1.748.0519379a7TombRaider.exe1.1.748.0519379a7c0000005001baa4c130401cfe629304bf3a1

Error: (10/11/2014 05:32:57 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: E:\Games\Steam\steamapps\common\Tomb Raider\redist\DXSetup.exe Raider\redist\DXSetup.exe" /silentäx®u0x80070057

CodeIntegrity Errors:
===================================
Date: 2014-10-26 14:13:28.714
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-26 14:13:28.621
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-26 14:13:28.543
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-26 14:13:28.449
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-25 10:12:07.642
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\Drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-25 10:12:07.545
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\Drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-25 10:12:07.448
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\Drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-25 10:12:07.350
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\Drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-25 10:12:07.247
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-10-25 10:12:07.150
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
Percentage of memory in use: 21%
Total physical RAM: 8189.58 MB
Available physical RAM: 6441.57 MB
Total Pagefile: 16428.2 MB
Available Pagefile: 14710.22 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.76 GB) (Free:221.91 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: () (Fixed) (Total:465.76 GB) (Free:38.09 GB) NTFS
Drive j: (ADATA UFD) (Removable) (Total:3.76 GB) (Free:3.76 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 7B2CAFFA)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 4D59CA7F)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 6 (Size: 3.8 GB) (Disk ID: 04DD5721)
Partition 1: (Active) - (Size=3.8 GB) - (Type=0C)

==================== End Of Log ============================

Dold text
Permalänk
Medlem

Avinstallera "Java 7 Update 51" eftersom det är en gammal version med många kända säkerhetshål som kan utnyttjas av en webbsida t ex för att få in polistrojanen i en dator. De flesta klarar sig bra utan Java men om man måste ha Java är det väldigt viktigt att alltid ha senaste versionen, vilket just nu är "Java 8 Update 25".

Rensa bort Conduit mm med hjälp av AdwCleaner av Xplode: https://toolslib.net/downloads/viewdownload/1-adwcleaner/
Stäng alla program innan du kör det.
Granska det som programmet hittar på alla flikar innan du låter programmet rensa bort något, för falsklarm förekommer.

Skanna datorn online på http://www.eset.com/onlinescan/ och använd helst Internet Explorer till det.
För att inte skannern ska ta för lång tid på sig stäng av ditt antivirusprogram under tiden.

Välj alternativet Enable detection of potentially unwanted applications.

Klicka på Advanced Settings.
Ta bort bocken framför Remove found threats.
Bocka för:
Scan Archives
Scan for potentially unsafe applications
Enable Anti-Stealth Technology

Klicka på Start

När skanningen är klar klicka på List of found threats, följt av Export to a text file. Spara till en fil på skrivbordet, öppna filen, kopiera resultatet och klistra sedan in det i ditt svar.

Permalänk

Okej, här är resultatet av skanningen.

C:\FRST\Quarantine\C\ProgramData\77A2ACA8.cpp.xBAD Win32/Reveton.AJ trojan
C:\FRST\Quarantine\C\ProgramData\8ACA2A77.dot.xBAD a variant of Win64/Kryptik.GK trojan
C:\Program Files (x86)\BitLord 2\StubInstaller.exe Win32/Toolbar.Conduit potentially unwanted application
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XG2YDA3\0ofe3298tp[1].htm JS/Exploit.Agent.NHK trojan
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BP39SKE0\7fgxk65eme[1].htm JS/Exploit.Agent.NHK trojan
C:\Users\Daniel\Patches\1. Program\Auslogic Disk Defrag.exe Win32/InstallMonetizer.AQ potentially unwanted application
C:\Users\Daniel\Patches\1. Program\CCleaner v4.09.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Daniel\Patches\1. Program\CPU-Z v1.58.exe a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Users\Daniel\Patches\1. Program\DAEMON Tools Lite v4.41.3.exe Win32/OpenCandy potentially unsafe application
C:\Users\Daniel\Patches\1. Program\GOM Player v2.1.37.5085.EXE a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Users\Daniel\Patches\1. Program\Miro v4.0.4.exe Win32/OpenCandy potentially unsafe application

Dold text

Det här är faktiskt första gången på min tjugoåriga karriär som datoranvändare som jag haft några problem med intrång som jag inte lyckats lösa på egen hand. Har du några tips om bra (gärna gratis) program som fortsatt kan hålla datorn ren i framtiden? Har kört med AVG som antivirus och Spybot Search & Destroy som antispionprogram, men de verkar ju inte ha lyckats upptäcka de här trojanerna.

Efter att ha tittat runt lite så verkar det också som om Windows Defender fått sig en törn. När jag kom in i datorn igen så var det avaktiverat och nu när jag försöker aktivera det igen så blir datorn stillastående någon minut då programmet "svarar inte" och slutar med ett felmeddelande: "Det inträffade ett fel i Windows Defender: 0x800705b4. Åtgärden misslyckades eftersom tidsgränsen överskreds."

Permalänk
Medlem

Du har ett antal installationsfiler som vill installera annonsprogram som du ser i loggen.

Starta Anteckningar.
Kopiera alla rader i rutan:

C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XG2YDA3\0ofe3298tp[1].htm JS/Exploit.Agent.NHK trojan C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BP39SKE0\7fgxk65eme[1].htm JS/Exploit.Agent.NHK trojan

och klistra in i Anteckningar. Kontrollera att inga filer har delats upp på två rader.
Spara filen på skrivbordet med namnet fixlist.txt.

Starta FRST som finns på skrivbordet.
Klicka på knappen Fix.
Vänta tills programmet är klart.

Verkar allt bra med datorn nu?
Några fler frågor?

Om allt är bra:

1. Stäng alla program, inklusive webbläsare.
Dubbelklicka på AdwCleaner för att starta programmet.
Klicka på Uninstall-knappen.

2. Ladda ner avinstallationsprogrammet OTC till Skrivbordet: http://oldtimer.geekstogo.com/OTC.exe
Dubbelklicka på filen för att starta programmet.
Tryck på knappen CleanUp! och FRST kommer att avinstalleras efter en omstart av datorn. Ta bort eventuella loggar.

3. Det är mycket viktigt att hålla alla småprogram i datorn uppdaterade, gamla versioner av t ex Flash, Java och Adobe Reader innehåller kända säkerhetshål, vilka kan användas av en webbsida för att infektera datorn. Jag tycker att Secunias program är en bra hjälp för att kontrollera hur det står till med säkerhetshål i datorn och ange vad som behöver åtgärdas.
http://secunia.com/products/consumer/

Permalänk

Jag märker inte av några uppenbara problem nu, de visar sig väl med tiden om de finns där. Det enda är att Windows Defender inte verkar vilja komma igång, men det kanske inte har så stor effekt om man köra andra program med samma funktion?

Tack så mycket för hjälpen. Jag återkommer väl om jag får nya problem. Ska också ta en titt på det där Secunia.

Permalänk
Medlem

Hejsan!
Helt ny på detta forum, men behöver hjälp då jag fått detta virus nu.
Satt o spelade spel då rutan poppade upp, av reflex höll jag ned strömknappen tills datorn slocknade. Startade upp den igen, och rutan kom tillbaka..
Lyckades ej starta felsäkert läge heller, då den startade upp den normalt endå.
Så..jag startade den normalt, agerade snabbt och gjorde en systemåterställning till förra veckan. Startade upp datorn igen och rutan dök inte upp nå mer.
Laddade ned spyhunter search and destroy och malwarebytes och gjorde sökningar i både normalt och i felsäkert läge, malwarebytes hittade en trojan vid namn "trojan.reveton" vilket jag snabbt tryckte den skulle radera. Efter de har jag sökt om 2 ggr med båda programmen utan att hitta något.
Mina frågor är alltså...
Är min dator troligen "ren" från denna ohyra nu? Hade jag bara "tur" och drabbades av en lindrigare version av detta virus? Eller äre något viktigt steg i rensningen jag missat?
Väldigt nojjig trots att programmen inte hittar något :).

Permalänk
Medlem
Skrivet av Pessimisten:

Jag märker inte av några uppenbara problem nu, de visar sig väl med tiden om de finns där. Det enda är att Windows Defender inte verkar vilja komma igång, men det kanske inte har så stor effekt om man köra andra program med samma funktion?

Tack så mycket för hjälpen. Jag återkommer väl om jag får nya problem. Ska också ta en titt på det där Secunia.

AV: AVG AntiVirus Free Edition 2015 (Disabled - Out of date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG AntiVirus Free Edition 2015 (Disabled - Out of date) {B5F5C120-2089-702E-0001-553BB0D5A664}
Det är många antivirusprogram som stänger av Defender för att undvika konflikter.
Spybot S&D verkar inte vara uppdaterad.

Skrivet av Uttern90:

Hejsan!
Helt ny på detta forum, men behöver hjälp då jag fått detta virus nu.
Satt o spelade spel då rutan poppade upp, av reflex höll jag ned strömknappen tills datorn slocknade. Startade upp den igen, och rutan kom tillbaka..
Lyckades ej starta felsäkert läge heller, då den startade upp den normalt endå.
Så..jag startade den normalt, agerade snabbt och gjorde en systemåterställning till förra veckan. Startade upp datorn igen och rutan dök inte upp nå mer.
Laddade ned spyhunter search and destroy och malwarebytes och gjorde sökningar i både normalt och i felsäkert läge, malwarebytes hittade en trojan vid namn "trojan.reveton" vilket jag snabbt tryckte den skulle radera. Efter de har jag sökt om 2 ggr med båda programmen utan att hitta något.
Mina frågor är alltså...
Är min dator troligen "ren" från denna ohyra nu? Hade jag bara "tur" och drabbades av en lindrigare version av detta virus? Eller äre något viktigt steg i rensningen jag missat?
Väldigt nojjig trots att programmen inte hittar något :).

Kanske inte hann sätta sig så djupt när du stängde av datorn så kvickt eller så var det en enklare variant.

"trojan.reveton" är polistrojanen.

Skanna datorn online på http://www.eset.com/onlinescan/
För att inte skannern ska ta för lång tid på sig stäng av ditt antivirusprogram under tiden.

Välj alternativet Enable detection of potentially unwanted applications.

Klicka på Advanced Settings.
Ta bort bocken framför Remove found threats eftersom falsklarm förekommer när man gör så här noggrann kontroll.
Bocka för:
Scan Archives
Scan for potentially unsafe applications
Enable Anti-Stealth Technology

Klicka på Start

När skanningen är klar klicka på List of found threats, följt av Export to a text file. Spara till en fil på skrivbordet, öppna filen, kopiera resultatet och klistra sedan in det i ditt svar om du vill att jag ska kolla den.

Permalänk
Medlem

Tack för ditt snabba svar!
Har nu på morgonen kört scanningen. Resultatet.

C:\ProgramData\65772DED.dot a variant of Win64/Kryptik.GK trojan
C:\ProgramData\DED27756.cpp a variant of Win32/Kryptik.CONE trojan
C:\Users\All Users\65772DED.dot a variant of Win64/Kryptik.GK trojan
C:\Users\All Users\DED27756.cpp a variant of Win32/Kryptik.CONE trojan
C:\Users\Mickis\Desktop\Genvägar\Setup-SopCast-3.9.3-2014-9-22.exe a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application

Dold text

Edit: Har nu på morgonen också, efter att läst dina svar till några tidigare, uppdaterat: Java, Adobe reader och flash via respektives hemsida. Har även laddat ned secunia och scannat med det.
Har också gjort en scanning med Malwarebytes nu på morgonen, utan resultat..
Tog också bort programmet "Sopcast" då jag ej använder det.

Permalänk
Medlem
Skrivet av Uttern90:

Tack för ditt snabba svar!
Har nu på morgonen kört scanningen. Resultatet.

C:\ProgramData\65772DED.dot a variant of Win64/Kryptik.GK trojan
C:\ProgramData\DED27756.cpp a variant of Win32/Kryptik.CONE trojan
C:\Users\All Users\65772DED.dot a variant of Win64/Kryptik.GK trojan
C:\Users\All Users\DED27756.cpp a variant of Win32/Kryptik.CONE trojan
C:\Users\Mickis\Desktop\Genvägar\Setup-SopCast-3.9.3-2014-9-22.exe a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application

Dold text

Edit: Har nu på morgonen också, efter att läst dina svar till några tidigare, uppdaterat: Java, Adobe reader och flash via respektives hemsida. Har även laddat ned secunia och scannat med det.
Har också gjort en scanning med Malwarebytes nu på morgonen, utan resultat..
Tog också bort programmet "Sopcast" då jag ej använder det.

C:\ProgramData\65772DED.dot a variant of Win64/Kryptik.GK trojan
C:\ProgramData\DED27756.cpp a variant of Win32/Kryptik.CONE trojan
C:\Users\All Users\65772DED.dot a variant of Win64/Kryptik.GK trojan
C:\Users\All Users\DED27756.cpp a variant of Win32/Kryptik.CONE trojan
Kan du ta bort ovanstående fyra filer själv?
De hänger alla ihop med polistrojanen, så du fick in filerna men verkar ha klarat dig från att få in automatiska starter av dem.

Permalänk
Medlem

Hej!
Hittar filerna som ligger i "programdata" men de i User mappen hittar jag ej..är de samma, men att de ligger där för att de gäller ALLA users på datorn?..hoppas du förstår min krångliga förklaring :S

"Only C:\ProgramData actually exists as a "real" folder. C:\Users\All Users is a symbolic link to C:\ProgramData. That is, C:\Users\All Users points to C:\ProgramData, so if you navigate to the former, you are automatically redirected to the latter. That is why they appear identical."

Bara ta bort som i " Shift + Delete"?

Permalänk
Medlem
Skrivet av Uttern90:

Hej!
Hittar filerna som ligger i "programdata" men de i User mappen hittar jag ej..är de samma, men att de ligger där för att de gäller ALLA users på datorn?..hoppas du förstår min krångliga förklaring :S

"Only C:\ProgramData actually exists as a "real" folder. C:\Users\All Users is a symbolic link to C:\ProgramData. That is, C:\Users\All Users points to C:\ProgramData, so if you navigate to the former, you are automatically redirected to the latter. That is why they appear identical."

Bara ta bort som i " Shift + Delete"?

Japp, det är samma filer förstås och ta bort med Shift+Delete.