Avatar billede notice Nybegynder
10. september 2005 - 21:24 Der er 8 kommentarer og
1 løsning

WinFixer 2005 og lidt virus

Jeg har af uforklarelige årsager fået mig et program der hedder "WinFixer 2005" - Det er ret stædigt, og jeg kan ikke komme af med det...

Jeg har enda bevæget mig ud og købet "Norton internet security 2005" men har alligevel fået mig lidt ballade.

Når det så er sagt, så har jeg også et andet relateret problem. Når jeg skanner min maskine for virus finder Norton 10 registreringer, men den skriver "kan ikke slettes", når jeg forsøger at slette dem. Jeg har også prøvet at starte op i fejlsikret tilstand, uden held...

Filerne det drejer sig om:
Ams.exe
Asmps.dll
UWFX5NetInstaller.exe
UWFX5NetInstaller.exe
substq1.037010102 (netsky)
substq1.037010102 (netsky)

Håber der er en der kan hjælpe en stakkels frustreret ung mand...
Avatar billede fromsej Praktikant
10. september 2005 - 21:56 #1
>>Jeg har enda bevæget mig ud og købet "Norton internet security 2005" men har alligevel fået mig lidt ballade.<<
Hmm, havde du købt Kaspersky, Bullguard eller Norman havde pengene været givet noget bedre ud.
Nok om det.

Følg vejledningen i denne artikel, punktet "Generelle skridt inden du laver en Hijackthislog".
http://www.eksperten.dk/artikler/755
Kopier Hijackthisloggen, Ewidologgen og Dr.Webloggen herind, for Dr.Webs vedkommende KUN det nederste, startende med Scan Statistics.
Avatar billede notice Nybegynder
11. september 2005 - 19:03 #2
Det var en omfattende operation... Jeg var af den overbevisning at hvis man havde Norton og adaware6, så var man ret godt sikret!! Det er åbenbart ikke tilfældet...

Håber at nedenstående giver mere mening for fromsej!


-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 39646
Infected objects found: 18
Objects with modifications found: 0
Suspicious objects found: 1
Objects cured: 0
Objects deleted: 17
Objects renamed: 1
Objects moved: 0
Scan speed: 582 Kb/s
Scan time: 00:43:51
-----------------------------------------------------------------------------


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            18:27:53, 11-09-2005
+ Report-Checksum:        FAAE2DFD

+ Scan result:

    HKLM\SOFTWARE\Classes\ADM25.ADM25 -> Spyware.Altnet : Cleaned with backup
    HKLM\SOFTWARE\Classes\ADM25.ADM25\CurVer -> Spyware.Altnet : Cleaned with backup
    HKLM\SOFTWARE\Classes\ADM4.ADM4 -> Spyware.Altnet : Cleaned with backup
    HKLM\SOFTWARE\Classes\ADM4.ADM4\CurVer -> Spyware.Altnet : Cleaned with backup
    HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Spyware.Altnet : Cleaned with backup
    HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Spyware.Altnet : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{1D6711C8-7154-40BB-8380-3DEA45B69CBF} -> TrojanDownloader.WebP2P : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0} -> Spyware.RXToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{4D1C4E8B-A32A-416b-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-90F0-F66AB581A933} -> Spyware.MyWebSearch : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{630D6140-04C5-4db0-B27A-020D766FF09B} -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{C91E8926-D4BE-4685-99F4-0D996B96BAC0} -> Spyware.P2PNetworking : Cleaned with backup
    HKLM\SOFTWARE\Classes\instafink.INSTAFINK -> Spyware.InstaFinder : Cleaned with backup
    HKLM\SOFTWARE\Classes\instafink.INSTAFINK\Clsid -> Spyware.InstaFinder : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{16097036-894C-4C00-A61F-93CA0D49A70E} -> Spyware.TOPicks : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{2ED5AF98-9258-45BA-B79B-06625C92F662} -> Spyware.TOPicks : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{4D1C4E8A-A32A-416B-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{4D1C4E8C-A32A-416B-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{700DC0DD-F409-42E0-9DE5-21EE1A2BA9FD} -> Spyware.TOPicks : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{C91E8926-D4BE-4685-99F4-0D996B96BAC0} -> Spyware.P2PNetworking : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{D273D427-57C6-4B12-860F-BBB8195F6E2A} -> Spyware.TOPicks : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{FD42F6D3-7AB1-470C-979B-7996EDC99099} -> Spyware.TOPicks : Cleaned with backup
    HKLM\SOFTWARE\Classes\Need2FindBar.SettingsPlugin -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\Need2FindBar.SettingsPlugin\CLSID -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\Need2FindBar.SettingsPlugin\CurVer -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\Need2FindBar.ToolbarPlugin -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\Need2FindBar.ToolbarPlugin\CLSID -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\Need2FindBar.ToolbarPlugin\CurVer -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Classes\RXToolBar.TBInfo -> Spyware.RXToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\RXToolBar.TBInfo\CLSID -> Spyware.RXToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\RXToolBar.TBInfo\CurVer -> Spyware.RXToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\TypeLib\{66B20295-DC57-42B6-ACDF-52D916E86464} -> Spyware.RXToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\TypeLib\{F720B40F-3A38-4B22-B30D-DCF095D42498} -> Spyware.P2PNetworking : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D6711C8-7154-40BB-8380-3DEA45B69CBF} -> TrojanDownloader.WebP2P : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00D6A7E7-4A97-456f-848A-3B75BF7554D7} -> Spyware.KeenValue : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-90F0-F66AB581A933} -> Spyware.MyWebSearch : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Need2FindBar Uninstall -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RXToolBar -> Spyware.RXToolbar : Cleaned with backup
    HKLM\SOFTWARE\Need2Find -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
    HKLM\SOFTWARE\Need2Find\bar\Partner -> Spyware.Need2Find : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_100 -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_100\Loct_4 -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_329 -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0 -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1 -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2 -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3 -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services\Queue -> Spyware.Cydoor : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00D6A7E7-4A97-456F-848A-3B75BF7554D7} -> Spyware.KeenValue : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0} -> Spyware.RXToolbar : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-90F0-F66AB581A933} -> Spyware.MyWebSearch : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Need2Find -> Spyware.Need2Find : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
    HKU\S-1-5-21-117609710-1343024091-682003330-1003\Software\RX Toolbar -> Spyware.RXToolbar : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@ads23.bpath[1].txt -> Spyware.Cookie.Bpath : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@adtech[1].txt -> Spyware.Cookie.Adtech : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@e-2dj6wjliahdzogp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@e-2dj6wjlocidjsgp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@e-2dj6wjlooldjidp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@e-2dj6wjlygpczclo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Cookies\nikolaj@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Local Settings\Temp\asmfiles.cab/asm.exe -> Spyware.Altnet : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Local Settings\Temp\asmfiles.cab/asmps.dll -> Spyware.Altnet : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Local Settings\Temp\p2psetup.exe -> Spyware.P2PNetworking : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Local Settings\Temp\remove.exe -> TrojanDownloader.Keenval.f : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Local Settings\Temp\__unin__.exe -> Spyware.Altnet : Cleaned with backup
    C:\Documents and Settings\Nikolaj\Local Settings\Temporary Internet Files\Content.IE5\WH2B4TEJ\WinFixer2005ScannerInstall[1].cab/UWFX5NetInstaller.exe -> Not-A-Virus.Downloader.Agent.c : Cleaned with backup
    C:\Program Files\Diet K\dk\dietk3.dat -> Spyware.Cydoor : Cleaned with backup
    C:\Program Files\INSTAFINK -> Spyware.404Search : Cleaned with backup
    C:\Program Files\INSTAFINK\Cache -> Spyware.404Search : Cleaned with backup
    C:\Program Files\INSTAFINK\Cache\instafinktb0302.cfg -> Spyware.404Search : Cleaned with backup
    C:\Program Files\INSTAFINK\Cache\NewCfg -> Spyware.404Search : Cleaned with backup
    C:\Program Files\INSTAFINK\Uninstall.exe -> Spyware.404Search : Cleaned with backup
    C:\Program Files\Need2Find -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\1.bin -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\1.bin\NPND2FN.DLL -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\Cache -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\Cache\07A6FFC8 -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\Cache\07A70314 -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\Cache\files.ini -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\History -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\History\search -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\Settings -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\Need2Find\bar\Settings\prevcfg.htm -> Spyware.Need2Find : Cleaned with backup
    C:\Program Files\RXToolBar -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CThttps___www_netbank_nordea_dk_netbank_servlet_Logoff_prefix=00868397411124024890968302&command=2NC -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTloginnet_passport_com_logout_srf__lang=EN&lc=1033&id=2&ru=http%3a%2f%2fwww%2emsn%2edk&dontall=NC -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTwww_airtickets_dk_ -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTwww_google_com_ -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTwww_google_dk_ -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTwww_lego_com_ -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTwww_microsoft_com_ -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTwww_newz_dk_ -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\CTwww_nordea_dk_ -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\U963284 -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\Cache\U963351 -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\CacheCatolog.rx -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\additional.gif -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\additional_active.gif -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\background.jpg -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\blue_hr_horz.GIF -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\gray_hr_horz.GIF -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\thumbtack.gif -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\thumbtack_active.gif -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\graphics\thumbtack_click.gif -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\HTML -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\HTML\content.htm -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\HTML\main.htm -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\rxtoolbar.cfg -> Spyware.RXToolbar : Cleaned with backup
    C:\Program Files\RXToolBar\RXToolBar.dll -> Spyware.RXToolbar : Cleaned with backup


::Report End









Logfile of HijackThis v1.99.1
Scan saved at 18:58:09, on 11-09-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\USBPNP.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\eEye Digital Security\Retina 5\Scanner\RetinaEngine.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\eEye Digital Security\Application Bus\eeyeevnt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NuCam\CamCheck\CamCheck.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Documents and Settings\Nikolaj\Local Settings\Temporary Internet Files\Content.IE5\STYJ8DUF\hijackthis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newz.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = gateway:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ISLP2STA.EXE] ISLP2STA.EXE START
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [OSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [XTNDConnect PC - ErPhn2] C:\PROGRA~1\COMMON~1\XCPCSync\TRANSL~1\ErPhn2\ErTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CamCheck] C:\Program Files\NuCam\CamCheck\CamCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NI.UWFX5] "C:\WINDOWS\Downloaded Program Files\UWFX5NetInstaller.exe"
O4 - Startup: Trillian.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://kc.bar.need2find.com/KC/menusearch.html?p=KC
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/28bbcaa8d20e81795a05/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125671358437
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://buddha.notice-design.dk/admin/XUpload.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{90969A0B-DA4F-48D3-9CE4-660CF2A9FDD1}: NameServer = 194.239.143.131,194.239.143.129
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Blink2PnP - Unknown owner - C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: eEye Application Bus (eeyeevnt) - eEye Digital Security - C:\Program Files\Common Files\eEye Digital Security\Application Bus\eeyeevnt.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: eEye Retina Engine (RetinaEngine) - eEye Digital Security - C:\Program Files\eEye Digital Security\Retina 5\Scanner\RetinaEngine.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Avatar billede notice Nybegynder
11. september 2005 - 20:11 #3
Skal lige nævne at jeg nu har skannet med Norton og den melder "all clear"... Det var rart, men skal jeg stole på det??
Avatar billede fromsej Praktikant
11. september 2005 - 21:38 #4
Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, genstart.

O3 - Toolbar: (no name) - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - (no file)
O8 - Extra context menu item: &Search - http://kc.bar.need2find.com/KC/menusearch.html?p=KC
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/28bbcaa8d20e81795a05/netzip/RdxIE601.cab

---------------------------------------
Genstart normalt, hent og installer programmet Ad-aware hvis du da ikke har det i forvejen. Opdater det straks efter installationen, og inden du kører en scanning med denne. Fjern alt hvad den finder. Programmet samt brugervejledning på dansk finder du her: http://www.spywarefri.dk/tipsogtricks.htm#adaware
Følg også vejledningen her til udvidet søgning:
http://www.spywarefri.dk/manualer/adaware-manual.htm
---------------------------
Genstart normalt det skulle være det hele.

Du spørger om Norton og Ad-Aware er nok i sig selv, til det er svaret nej, desværre ikke.
Alene Dr.Web loggen taler for sig selv, 18 objects cleaned.
Nu er jeg ikke ligefrem kendt som Norton fan, det program er i mine øjne opreklameret, for dyrt, sløvende og ikke i stand til at fange ret meget, der findes freeware alternativer der er klasser bedre, for ikke at tale om andre betalingsprogrammer.
Vi ser den ene gang efter den anden, logs hvor Norton er installeret smækfyldte med virus og andet "godt".

Du bør lige deaktivere systemgendannelse, genstarte og genaktivere den.
http://spywarefri.dk/virusscannere.htm#alle - Systemgendannelse.

For at holde den ren kan du kigge på vores pakke til formålet.
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm
Som minimum anbefaler jeg Spywareguard, Spywareblaster, IE-Spyad og IE Privacy Keeper.
Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
http://fromsej.dk/html/avoid.html
Mvh:
Fromsej/Team Spywarefri.
Avatar billede notice Nybegynder
12. september 2005 - 09:57 #5
Takker mange gange for hjælpen og håber ikke jeg får brug for dig igen... Ment på en pæn måde!!
Avatar billede fromsej Praktikant
12. september 2005 - 10:46 #6
Velbekomme, jeg forstår udmærket ønsket. ;-)

Hvis du så lige markerer mit navn i boksen, og klikker på Accepter, så er her lukket på den rigtige måde.
Avatar billede fromsej Praktikant
12. september 2005 - 11:29 #7
Tak for point.*S*
Avatar billede notice Nybegynder
12. september 2005 - 12:07 #8
Det var så lidt - har du en mail-adr.?
Avatar billede fromsej Praktikant
12. september 2005 - 12:14 #9
Ja.
from09sej (at) webspeed.dk
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester