Avatar billede kimooo Nybegynder
21. december 2005 - 11:58 Der er 1 kommentar

HJT Log, Spysheriff

Hej..
Jeg har lige fået et eller andet spyware. Det er noget Spysheriff og måske mere. Jeg har kørt Microsoft AntiSpyware og Spywarefri onlinescanner. Det har fjernet lidt, men det er der stadig. Det er pop-ups, ændret skrivebords baggrund, taskbar, påmindelser, IE ændringer mm.

Logfile of HijackThis v1.99.1
Scan saved at 23:08:43, on 20-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsdkhp.exe
C:ProgrammerNVIDIA CorporationNetworkAccessManagerApache GroupApache2inapache.exe
C:ProgrammerNVIDIA CorporationNetworkAccessManagerin SvcIp.exe
C:ProgrammerNVIDIA CorporationNetworkAccessManagerin SvcLog.exe
C:WINDOWSsystem32 vsvc32.exe
C:ProgrammerAlcohol 120StarWindStarWindService.exe
C:ProgrammerNVIDIA CorporationNetworkAccessManagerin TrayFw.exe
C:ProgrammerMicrosoft AntiSpywaregcasServ.exe
C:ProgrammerJavainjusched.exe
D:SpilToolsRefreshLock.exe
C:WINDOWSmfced32.exe
C:WINDOWSsystem32ctfmon.exe
C:ProgrammerMSN MessengerMsnMsgr.Exe
C:ProgrammerMicrosoft AntiSpywaregcasDtServ.exe
C:ProgrammerNVIDIA CorporationNetworkAccessManagerApache GroupApache2inapache.exe
C:ProgrammerInternet Exploreriexplore.exe
C:ProgrammerInternet Exploreriexplore.exe
C:ProgrammerInternet Exploreriexplore.exe
C:Documents and SettingsKim Brun NissenSkrivebordHijackThisHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSpnxyy.dll/sp.html#17702%everything4find.com
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSpnxyy.dll/sp.html#17702%everything4find.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = res://C:WINDOWSpnxyy.dll/sp.html#17702%everything4find.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSpnxyy.dll/sp.html#17702%everything4find.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSpnxyy.dll/sp.html#17702%everything4find.com
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSpnxyy.dll/sp.html#17702%everything4find.com
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSpnxyy.dll/sp.html#17702%everything4find.com
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: Class - {08513E59-0400-6BA4-A3DF-9337E2F8AE68} - C:WINDOWSsystem32crmx32.dll (file missing)
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:ProgrammerIpswitch WS_FTP Prowsbho2k0.dll
O2 - BHO: Class - {AEB90959-0093-AADA-C479-6B1F6B9B24D6} - C:WINDOWSwinmr.dll
O4 - HKLM..Run: [NVMixerTray] "C:ProgrammerNVIDIA CorporationNvMixerNVMixerTray.exe"
O4 - HKLM..Run: [nTrayFw] C:ProgrammerNVIDIA CorporationNetworkAccessManagerin TrayFw.exe
O4 - HKLM..Run: [gcasServ] "C:ProgrammerMicrosoft AntiSpywaregcasServ.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] C:ProgrammerJavainjusched.exe
O4 - HKLM..Run: [RefreshLock] D:SpilToolsRefreshLock.exe
O4 - HKLM..Run: [NVIDIA nTune] "C:ProgrammerNVIDIA Corporation Tune\nTune.exe" clear
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [mfced32.exe] C:WINDOWSmfced32.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [Steam] "c:spilsteamsteam.exe" -silent
O4 - HKCU..Run: [MsnMsgr] "C:ProgrammerMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [updateMgr] C:ProgrammerAdobe ReaderReaderAdobeUpdateManager.exe AcRdB7_0_3 -reboot 1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammerJavain pjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammerJavain pjpi150_04.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/v...
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.0....
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Con...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/c...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5C...
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:PROGRA~1MSNMES~1msgrapp.dll" (file missing)
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:WINDOWSsdkhp.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:ProgrammerNVIDIA CorporationNetworkAccessManagerApache GroupApache2inapache.exe" -k runservice (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:ProgrammerNVIDIA CorporationNetworkAccessManagerin SvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:ProgrammerNVIDIA CorporationNetworkAccessManagerin SvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32 vsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:ProgrammerAlcohol 120StarWindStarWindService.exe
Avatar billede kimooo Nybegynder
21. december 2005 - 13:58 #1
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester