Avatar billede westman Nybegynder
25. juli 2003 - 00:45 Der er 14 kommentarer og
1 løsning

Er det her en virus?

http://www.frip.dk/west/problem.jpg

Hver gang jeg skal ind på xplayn, eller noget andet, plejer jeg at skrive xplayn.com uden www., men når jeg skriver det, så kommer det der frem. Norton eller Ad-aware kan ikke finde noget, så er det en virus?

Jeg har hentet HiJack-This og scannet:

Logfile of HijackThis v1.95.1
Scan saved at 12:29:24 AM, on 7/25/2003
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\loadqm.exe
D:\program files\powerstrip\pstrip.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
D:\PROGRA~2\NORTON~1\navapw32.exe
D:\Program Files\RefreshLock\RefreshLock.exe
F:\Program Files\D-Tools\daemon.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\System32\RUNDLL32.EXE
D:\Program Files\re-flex CS Playtime Counter by NiTo\cscounter.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\LOLSADOALSD\EZMacros.exe
D:\Program Files\NoNameScript\mirc.exe
D:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\PROGRA~2\WINZIP\winzip32.exe
C:\Documents and Settings\west1\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://sharempeg.com/xfind/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://sharempeg.com/xfind/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://sharempeg.com/xfind/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xplayn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://193.125.201.50
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://sharempeg.com/xfind/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = 203
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://193.125.201.50
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://search.xrenoder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main\,HomeOldSP = http://www.bestcrawler.com/
O1 - Hosts: 193.125.201.50 msn.com
O1 - Hosts: 193.125.201.50 search.msn.com
O1 - Hosts: 193.125.201.50 auto.search.msn.com
O1 - Hosts: 193.125.201.50 ie.search.msn.com
O1 - Hosts: 193.125.201.46 thehun.net
O1 - Hosts: 193.125.201.46 www.thehun.net
O1 - Hosts: 193.125.201.46 thehun.com
O1 - Hosts: 193.125.201.46 www.thehun.com
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [PowerStrip] d:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [rb32 lptt01] "C:\Program Files\rb32\rb32.exe"
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~2\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~2\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [RefreshLock] D:\Program Files\RefreshLock\RefreshLock.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "F:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [winmain] winmain.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [Icon Phile] D:\Iphile.exe -trans
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [5-4-4-13] c:\program files\Webdialer\5-4-4-13.exe -m
O4 - HKCU\..\Run: [rxcscounter] D:\Program Files\re-flex CS Playtime Counter by NiTo\cscounter.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Download with GetRight - D:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - D:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O13 - DefaultPrefix: http://193.125.201.50/?trk=
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.axis.com/products/camera_servers/AxisCamControl.ocx
O16 - DPF: {AE609930-A6EB-4A78-B7DA-B3200705FEBD} (Mophun Control) - http://www.sonyericsson.com/T310/mophun.cab
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/v3/download/pdpplugin5094_hd3ptdmgainads.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) - http://213.150.57.68/speedtest/SpeedTest_2.cab
Avatar billede aovergaard Nybegynder
25. juli 2003 - 00:58 #1
Hent og installere dette prg. http://www.spywareinfo.com/~merijn/files/cwshredder.zip

Derefter smider du en ny logfil herind.
Husk at fjerne systemgendannelse hvis du kører med XP eller ME for ellers gendanner virus sig.
Avatar billede westman Nybegynder
25. juli 2003 - 01:32 #2
Done!

- 0 registry values were killed
- Hostsfile was OK
- Bootconf.exe was not found
- Trusted Zone was OK
- User stylesheet was OK

- Ser ud til at den ikke fandt noget. Hvad skal jeg så gøre?
Avatar billede fromsej Praktikant
25. juli 2003 - 09:22 #3
Du får nogle linier af os, den skal du fixe med Hijackthis, men ikke før vi er færdige*S*
Avatar billede fromsej Praktikant
25. juli 2003 - 09:49 #4
Fixes:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://sharempeg.com/xfind/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://sharempeg.com/xfind/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://sharempeg.com/xfind/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://193.125.201.50
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://sharempeg.com/xfind/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = 203
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://193.125.201.50
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://search.xrenoder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main\,HomeOldSP = http://www.bestcrawler.com/
O1 - Hosts: 193.125.201.50 msn.com
O1 - Hosts: 193.125.201.50 search.msn.com
O1 - Hosts: 193.125.201.50 auto.search.msn.com
O1 - Hosts: 193.125.201.50 ie.search.msn.com
O1 - Hosts: 193.125.201.46 thehun.net
O1 - Hosts: 193.125.201.46 www.thehun.net
O1 - Hosts: 193.125.201.46 thehun.com
O1 - Hosts: 193.125.201.46 www.thehun.com
O4 - HKLM\..\Run: [winmain] winmain.exe  -->Hvis du ikke kender den.
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [Icon Phile] D:\Iphile.exe -trans -->Hvis du ikke kender den.
O4 - HKCU\..\Run: [5-4-4-13] c:\program files\Webdialer\5-4-4-13.exe -m
O8 - Extra context menu item: Download with GetRight - D:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - D:\Program Files\GetRight\GRbrowse.htm
O13 - DefaultPrefix: http://193.125.201.50/?trk=
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/v3/download/pdpplugin5094_hd3ptdmgainads.cab
Avatar billede fromsej Praktikant
25. juli 2003 - 09:52 #5
O4 - HKLM\..\Run: [winmain] winmain.exe  -->Hvis du ikke kender den.
O4 - HKCU\..\Run: [Icon Phile] D:\Iphile.exe -trans -->Hvis du ikke kender den.
Hvis du kender de to her, og de er gode nok så lad dem være, ellers væk.
Så starter du Hijackthis igen, sætter flueben ved alle de linier, jeg har markeret, lukker alle vinduer, undtaget Hijackthis og vælger fix Checked.
Når det er gjort, genstarter du og laver en ny logfil, som du så smider her, så vi kan se om det hjalp.
Avatar billede fromsej Praktikant
25. juli 2003 - 09:59 #6
C:\Program Files\ISTsvc\istsvc.exe
Det skal slettes.
Skal evt gøres fra fejlsikret tilstand, men først Hijackthis.
Avatar billede fromsej Praktikant
25. juli 2003 - 11:40 #7
O4 - HKLM\..\Run: [winmain] winmain.exe
O4 - HKCU\..\Run: [Icon Phile] D:\Iphile.exe -trans

De er gode nok.
Avatar billede westman Nybegynder
25. juli 2003 - 13:32 #8
Logfile of HijackThis v1.95.1
Scan saved at 1:31:54 PM, on 7/25/2003
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\loadqm.exe
D:\program files\powerstrip\pstrip.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
D:\PROGRA~2\NORTON~1\navapw32.exe
D:\Program Files\RefreshLock\RefreshLock.exe
F:\Program Files\D-Tools\daemon.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\System32\RUNDLL32.EXE
D:\Program Files\re-flex CS Playtime Counter by NiTo\cscounter.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\PROGRA~2\WINZIP\winzip32.exe
C:\Documents and Settings\west1\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xplayn.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [PowerStrip] d:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [rb32 lptt01] "C:\Program Files\rb32\rb32.exe"
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~2\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~2\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [RefreshLock] D:\Program Files\RefreshLock\RefreshLock.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "F:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [winmain] winmain.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [Icon Phile] D:\Iphile.exe -trans
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [rxcscounter] D:\Program Files\re-flex CS Playtime Counter by NiTo\cscounter.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.axis.com/products/camera_servers/AxisCamControl.ocx
O16 - DPF: {AE609930-A6EB-4A78-B7DA-B3200705FEBD} (Mophun Control) - http://www.sonyericsson.com/T310/mophun.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) - http://213.150.57.68/speedtest/SpeedTest_2.cab
Avatar billede fromsej Praktikant
25. juli 2003 - 16:03 #9
Tæt på, men vi må på den igen.
Denne fil skal fjernes:
C:\Program Files\ISTsvc\istsvc.exe

Fixes:
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [rb32 lptt01] "C:\Program Files\rb32\rb32.exe"
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe

Det skulle være det.
Prøv evt om du kan afinstallere Messenger Plus, men ikke før du har fixet, det kan også være vi får resterne nu.
Derefter skal du installere nogle små programmer til at holde skidtet væk.
Avatar billede westman Nybegynder
25. juli 2003 - 18:17 #10
Hvilke programmer skal jeg installere?
Avatar billede fromsej Praktikant
25. juli 2003 - 18:48 #11
Fik du det hele væk nu?
Så skal du gå ind her:
http://www.spywarefri.dk/vaerktoj.htm
Hente Spywareblaster, Spywareguard, IE-Spyad, og cookiewall, så er du meget bedre beskyttet i din færden på nettet.
Tak for point.*S*
Avatar billede fromsej Praktikant
25. juli 2003 - 19:00 #12
Men jeg ville godt lige se en ny logfil.
Desuden bør du hente Servicepack 4 til din windows 2000.
Den ligger her til download.
http://www.it-service.sdu.dk/vis.php?side=84
Avatar billede westman Nybegynder
25. juli 2003 - 21:40 #13
Var så lidt. :)

Logfile of HijackThis v1.95.1
Scan saved at 9:39:34 PM, on 7/25/2003
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\loadqm.exe
D:\program files\powerstrip\pstrip.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
D:\PROGRA~2\NORTON~1\navapw32.exe
D:\Program Files\RefreshLock\RefreshLock.exe
F:\Program Files\D-Tools\daemon.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\System32\RUNDLL32.EXE
D:\Program Files\re-flex CS Playtime Counter by NiTo\cscounter.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\LOLSADOALSD\EZMacros.exe
D:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\SpywareGuard\sgmain.exe
F:\Program Files\SpywareGuard\sgbhp.exe
F:\Program Files\SurfWare\Aaron's WebVacuum 2\WebVacuumfree.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\PROGRA~2\WINZIP\winzip32.exe
C:\Documents and Settings\west1\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xplayn.com/
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - F:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [PowerStrip] d:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~2\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~2\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [RefreshLock] D:\Program Files\RefreshLock\RefreshLock.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "F:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [winmain] winmain.exe
O4 - HKCU\..\Run: [Icon Phile] D:\Iphile.exe -trans
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [rxcscounter] D:\Program Files\re-flex CS Playtime Counter by NiTo\cscounter.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: SpywareGuard.lnk = F:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.axis.com/products/camera_servers/AxisCamControl.ocx
O16 - DPF: {AE609930-A6EB-4A78-B7DA-B3200705FEBD} (Mophun Control) - http://www.sonyericsson.com/T310/mophun.cab
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/4/download/pdpplugin_5094_bundle7v1p10.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) - http://213.150.57.68/speedtest/SpeedTest_2.cab


Det der "gator" finder jeg altid når jeg scanner med ad-aware. Jeg har installeret alle de programmer du sagde, undstagen IE-Spyad, for deres hjemmesiden er simpelthen så forvirrende, så jeg opgav *S*.
Avatar billede perhaps Nybegynder
25. juli 2003 - 22:11 #14
Prøv lige Spywarefri's onlinescanner og se om Gator også dukker op der. Den har nemlig også Gator i databasen. Link: http://www.spywarefri.dk/spywarefri-onlinescan.htm
Avatar billede perhaps Nybegynder
25. juli 2003 - 22:13 #15
Du har vel fixet denne
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/4/download/pdpplugin_5094_bundle7v1p10.cab
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester