Avatar billede johanholten Nybegynder
19. juni 2004 - 10:09 Der er 8 kommentarer

Endnu et hijack offer

Jeg er desværre blevet endnu et af de mange godtroende ofre for adware. Måske er der nogen der kan hjælpe mig med min hijack this log:

Logfile of HijackThis v1.97.7
Scan saved at 10:05:21, on 19.06.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Apoint\Apoint.exe
C:\Programme\Sony\HotKey Utility\HKserv.exe
C:\Programme\Sony\Jog Dial Navigator\JogServ2.exe
C:\PROGRA~1\NORTON~2\navapw32.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Programme\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Programme\Sunbelt Software\iHateSpam\siService.exe
C:\PROGRA~1\GlueWipe\Bend Blah Store.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Eyeball\Eyeball Chat\EyeballChat.exe
C:\Programme\Sunbelt Software\iHateSpam\siSpamFilterEngine.exe
C:\Programme\Apoint\Apntex.exe
C:\Programme\PowerPanel\Program\PcfMgr.exe
C:\Programme\Microsoft Office\Office\1030\OLFSNT40.EXE
C:\Programme\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Programme\Internet Explorer\iexplore.exe
D:\Johan\andet\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allaboutsearching.com/passthrough/index.html?http://www.faz.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.sony-europe.com
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Upload Atom - {7DB9AF1B-F0F5-1CC7-034B-6A5821B90615} - C:\PROGRA~1\FILELO~1\playblue.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Programme\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [JOGSERV2.EXE] C:\Programme\Sony\Jog Dial Navigator\JogServ2.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programme\Gemeinsame Dateien\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programme\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Programme\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [siService.exe] "C:\Programme\Sunbelt Software\iHateSpam\siService.exe"
O4 - HKLM\..\Run: [REMOTE WARN] C:\PROGRA~1\GlueWipe\Bend Blah Store.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [CommCtr] C:\PROGRA~1\NET2PH~1\CommCtr.exe -auto
O4 - HKCU\..\Run: [Eyeball Chat] "C:\Programme\Eyeball\Eyeball Chat\EyeballChat.exe" -min
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PowerPanel.lnk = ?
O4 - Global Startup: Symantec WinFax Starter Port.lnk = C:\Programme\Microsoft Office\Office\1030\OLFSNT40.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpeg: C:\Programme\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} (TurnTool Scene) - http://www.turntool.com/ViewerInstall.exe
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.dfhweb.dk/tsweb/test/msrdp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

På forhånd tak, Johan
Avatar billede magictouch Nybegynder
19. juni 2004 - 10:46 #1
Kigger på den.
Imens kan du køre en tur med Spybot og Adware:
Spybot: http://www.majorgeeks.com/download2471.html
Install, update, immunize and run. Fix all, marked with red

http://www.spywarefri.dk/vaerktoj.htm#adaware læs tip, lid ned på siden
Avatar billede magictouch Nybegynder
19. juni 2004 - 11:16 #2
Hvordan går det efter du har kørt de to programmer?
Genstart  til fejlsikret tilstand- tryk F8  under genstarten. Luk alle andre vinduer. Scan, ving dem her af,  og fix:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allaboutsearching.com/passthrough/index.html?http://www.faz.net/
Hvis du ikke kender den her så fix:
O3 - Toolbar: Upload Atom - {7DB9AF1B-F0F5-1CC7-034B-6A5821B90615} -  C:\PROGRA~1\FILELO~1\playblue.dll
O4 - HKLM\..\Run: [REMOTE WARN] C:\PROGRA~1\GlueWipe\Bend Blah Store.exe



Hvis du har fixet ovenstående, slet dem her:
C:\PROGRA~1\FILELO~1\playblue.dll
C:\PROGRA~1\GlueWipe\Bend Blah Store.exe

Genstart og ny log
Avatar billede johanholten Nybegynder
20. juni 2004 - 00:28 #3
Har slettet de ovenstående. I folderen med Bend Blah Store.exe er der yderlige to meget suspekt udseende filer med exe navne: wxzxnqki.exe og fwpexaui.exe . Skal jeg slette dem også?

Jeg har allerede kørt både adaware og spybot flere gange. Men de renser mig ikke.

Den dårlige nyhed er, at mens jeg sidder her og skriver er der stadig forskellige vinduer der uanmeldt åbner sig selv ved siden af... hvad skal jeg dog gøre?

Her den seneste log:

Logfile of HijackThis v1.97.7
Scan saved at 00:23:02, on 20.06.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Apoint\Apoint.exe
C:\Programme\Sony\HotKey Utility\HKserv.exe
C:\Programme\Sony\Jog Dial Navigator\JogServ2.exe
C:\PROGRA~1\NORTON~2\navapw32.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Sunbelt Software\iHateSpam\siService.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Apoint\Apntex.exe
C:\Programme\Sunbelt Software\iHateSpam\siSpamFilterEngine.exe
C:\Programme\PowerPanel\Program\PcfMgr.exe
C:\Programme\Microsoft Office\Office\1030\OLFSNT40.EXE
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Programme\Internet Explorer\iexplore.exe
D:\Johan\andet\hjt.exe

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Programme\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [JOGSERV2.EXE] C:\Programme\Sony\Jog Dial Navigator\JogServ2.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programme\Gemeinsame Dateien\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [siService.exe] "C:\Programme\Sunbelt Software\iHateSpam\siService.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [CommCtr] C:\PROGRA~1\NET2PH~1\CommCtr.exe -auto
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PowerPanel.lnk = ?
O4 - Global Startup: Symantec WinFax Starter Port.lnk = C:\Programme\Microsoft Office\Office\1030\OLFSNT40.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpeg: C:\Programme\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} (TurnTool Scene) - http://www.turntool.com/ViewerInstall.exe
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.dfhweb.dk/tsweb/test/msrdp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

Johan
Avatar billede magictouch Nybegynder
20. juni 2004 - 05:37 #4
wxzxnqki.exe og fwpexaui.exe = slet hele mappen, for det er ikke gode tegn, at der kommer nye mystiske filer!
Hvis du ikke har fået en sikkerhedspakke, vil jeg foreslå det;) http://www.spywarefri.dk/pakken.htm

Installer-Spywareblaster-Spywareguard- Ie-Spyad og Ie Privacy keeper som minimum.

Fortæl om det hjælper på vinduer der åbner
Avatar billede johanholten Nybegynder
21. juni 2004 - 00:07 #5
jeg har installeret pakken nu, men der er stadig vinduer der åbner. Siden min sidste genstart prøver allaboutsearching.com ca. hvert halve minut at installere sig som ny hjemmeside, hvilket spyguard fortæller mig om, og jeg så afviser. Men hvordan fanden kommer jeg af med grunden til at den prøver det hele tiden?

Yderligere havde upload atom tool fået erstattet min google tool bar i browseren. Interessant nok optrådte den dog under værktøjsmenuen som google og ikke upload atom som den egentlig hedder. Den står nedenunder, men uden flueben!

Det er vist noger ret hårdt spyware jeg har fået mig tillagt her på min stakkels pc!

Her er IP adressen på det vindue der bliver ved med at åbne: http://69.20.62.53/yyy4.html

Og her er loggen fra spyguard. Læg lige mærke til at hjemmesiden allerede er blevet ændret til zestyfind.com (også

Johan
Avatar billede johanholten Nybegynder
21. juni 2004 - 00:08 #6
... fortsat besked.... af spyware, og allaboutsearching forsøger så at ændre den igen!)


--------------------------------------------------------------------------------
NEW BHO DETECTION ALERT
On 00:00:25 06.21.2004 a new BHO installation attempt was detected.
BHO: {F7529157-FABD-4E86-1CED-BCBEDCC33A80}
ProgramID: Drive.Idlelink.1
File Location: C:\PROGRA~1\FILELO~1\dvd dale.dll
User Action Taken: REMOVE BHO

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:00:42 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Search Page
Old Value: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
New Value: http://allaboutsearching.com/searchbar.html
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:00:49 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:00:56 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Search Bar
Old Value:
New Value: http://allaboutsearching.com/searchbar.html
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:01:03 06.21.2004 a browser page change was detected.
Registry Location: HKLM\Software\Microsoft\Internet Explorer\Main\
Value Name: Search Page
Old Value: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
New Value: http://allaboutsearching.com/searchbar.html
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:01:07 06.21.2004 a browser page change was detected.
Registry Location: HKLM\Software\Microsoft\Internet Explorer\Main\
Value Name: Search Bar
Old Value:
New Value: http://allaboutsearching.com/searchbar.html
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:01:14 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:01:54 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:02:35 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:03:14 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:03:58 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:04:33 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:05:11 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:05:51 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:06:30 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:07:10 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:07:49 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:08:28 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:09:07 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE

--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 00:09:46 06.21.2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value: www.zestyfind.com/
New Value: allaboutsearching.com
User Action Taken: RESTORE OLD VALUE


Johan
Avatar billede magictouch Nybegynder
21. juni 2004 - 06:23 #7
Vil du sende en ny logfil herind?
Avatar billede dracuni Nybegynder
06. juli 2004 - 14:26 #8
Jeg har kæmpet med en led "About:blank" startside, og alle steder jeg kigger efter dette problem siger experterne at du skal redigere din reg.database. Men fortvivl ikke. Hent adwareAway og dit problem er løst. Foretag en normal scanning (Husk at lukke alt andet ned. Genstart, åben programmet igen og klik på "More". Gå ind uder HijackerAway og klik på den startside som du bøvler med. I mit tilfælle var det så About:blank.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester