Avatar billede drugless Nybegynder
24. februar 2006 - 13:28 Der er 17 kommentarer og
1 løsning

Hvad skal jeg fjerne?

Har kørt Hijackthis, og har fået denne logfil

Logfile of HijackThis v1.99.1
Scan saved at 13:24:11, on 24-02-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Andy Drugless\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bt.dk/sport/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGDACCESS_1074.dll,InstantAccess
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google-søgning - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Oversæt engelsk ord - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Lignende sider - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Tilbage via links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Øjebliksbillede af side i cache - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39EA2F6F-3F50-4F58-9C63-4B3D53B0926E} - http://scripts.downloadv3.com/binaries/P2EClient/EGAUTH_1049_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137513526980
O16 - DPF: {6AA85413-165C-4200-8154-71166077B22E} - http://scripts.downloadv3.com/binaries/IA/sysiasvc32_EN_XP.cab
O16 - DPF: {8B3B8135-9DAA-40E7-8941-962795F9C1CB} - http://scripts.downloadv3.com/binaries/IA/syswbsvc32_EN_XP.cab
O16 - DPF: {8D8BAF56-B581-4B90-A549-C4AC6B03F1BB} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1074_XP.cab
O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/sysinetsvc32_EN_XP.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
25. februar 2006 - 11:47 #1
Velkommen til Eksperten.dk
Generelt -> http://expfaq.1go.dk/
25. februar 2006 - 11:48 #2
Generelt oprydning:
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

Bruger du denne messenger:
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
25. februar 2006 - 11:52 #3
Ved du selv hvad dette er :
[Instant Access]
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGDACCESS_1074.dll,InstantAccess
(Ser mistænkelig ud?)
25. februar 2006 - 11:53 #4
... ellers generelt rul resten af proceduren herfra -> http://www.eksperten.dk/artikler/755
27. februar 2006 - 18:39 #5
Blev du klogere ?
Avatar billede drugless Nybegynder
27. februar 2006 - 21:37 #6
Ja lidt men så alligevel ikke - jeg har fjernet [O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGDACCESS_1074.dll,InstantAccess]

op til flere gange

men den dukker op igen efter et stykke tid - og ja den er meget mistænkelig - men hvordan kommer jeg permanent af med det:
28. februar 2006 - 10:45 #7
... hvad med resten af proceduren i http://www.eksperten.dk/artikler/755 ? ...
Avatar billede drugless Nybegynder
28. februar 2006 - 14:17 #8
Jeg vil gerne takke dig for svaret er først nu kørt procedure i artiklen - og jeg skal nok tildele dig pointene - men lige for at opklare noget i artiklen:

Der står at jeg skal kopier loglister "herind" hvor skal jeg placere dem for at få yderligere svar: er det noget jeg kan gøre i denne tråd eller skal jeg stille et nyt spørgsmål for at få svar på det.

Jeg tror godt du kan se at jeg er en ren amatør til dette her - og selve proceduren fra artiklen har været et større projekt der har taget flere timer på min PC.
28. februar 2006 - 20:32 #9
Her er et tilfældig eksempel på en tråd med omtalte logs -> http://www.eksperten.dk/spm/689600

Joooo - det ka' let blive et størrer 'project' - for at være sikker på at få alt 'snavs' ryddet ud...
Avatar billede drugless Nybegynder
28. februar 2006 - 22:21 #10
Ja jeg må hellere selv oprette en tråd til med log - især fordi programmet drweb's logfil af en eller anden grund ikke er til at finde - slevom den fandt adskillige infectede filer
28. februar 2006 - 22:30 #11
"...selv oprette en tråd til med log..." - hvad mener du ?

... kom med det du ka' ...
Avatar billede drugless Nybegynder
01. marts 2006 - 09:38 #12
Log fra:

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on:            15:45:45, 28-02-2006
+ Report-Checksum:        30EC564A

+ Scan result:

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Instant Access -> Dialer.Generic : Cleaned with backup
    HKU\S-1-5-21-2025429265-1957994488-854245398-1003\Software\BTGrab -> Adware.BetterInternet : Cleaned with backup
    HKU\S-1-5-21-2025429265-1957994488-854245398-1003\Software\EGDHTML -> Dialer.Generic : Cleaned with backup
    C:\Documents and Settings\All Users\Application Data\IEService\v28____1.#xe -> Dropper.VB.cd : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@abetterinternet[2].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@adtech[1].txt -> TrackingCookie.Adtech : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@casinodelrio[1].txt -> TrackingCookie.Casinodelrio : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@casinopays[1].txt -> TrackingCookie.Casinopays : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@casinotropez[1].txt -> TrackingCookie.Casinotropez : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@crbanner.casinopays[2].txt -> TrackingCookie.Casinopays : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@vegasred[2].txt -> TrackingCookie.Vegasred : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@www.casinodelrio[2].txt -> TrackingCookie.Casinodelrio : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@www.casinotropez[2].txt -> TrackingCookie.Casinotropez : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Cookies\andy drugless@www.vegasred[2].txt -> TrackingCookie.Vegasred : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Desktop\backup fra hijack\backup-20051215-105049-821.#ll -> Dialer.InstantAccess.e : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Desktop\backup fra hijack\backup-20051215-105050-271.#ll -> Dialer.InstantAccess.e : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\btgupg_0.#xe -> Adware.BetterInternet : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@cliks[2].txt -> TrackingCookie.Cliks : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@linkbuddies[2].txt -> TrackingCookie.Linkbuddies : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@s.abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@vegasred[2].txt -> TrackingCookie.Vegasred : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@www.popuptraffic[2].txt -> TrackingCookie.Popuptraffic : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\Cookies\andy drugless@www.vegasred[2].txt -> TrackingCookie.Vegasred : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\randrec0.#xe -> Adware.BetterInternet : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\temp___0.#r00C0 -> Dialer.InstantAccess.f : Cleaned with backup
    C:\Documents and Settings\Andy Drugless\Local Settings\Temp\temp___0.#r6ECB -> Dialer.InstantAccess.m : Cleaned with backup
    C:\Documents and Settings\Hea\Local Settings\Temp\Cookies\hea@com[2].txt -> TrackingCookie.Com : Cleaned with backup
    C:\Documents and Settings\Hea\Local Settings\Temp\Cookies\hea@s.abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
    C:\WINDOWS\eg_auth_1049.dll -> Trojan.P2E.cl : Cleaned with backup
    C:\WINDOWS\p2esocks_1049.dll -> Trojan.P2E.cl : Cleaned with backup
    C:\WINDOWS\system32\EGCOMLIB_1035.#ll -> Dialer.InstantAccess : Cleaned with backup
    C:\WINDOWS\system32\EGDACCESS.#ll -> Dialer.InstantAccess.m : Cleaned with backup
    C:\WINDOWS\system32\EGDACCESS_1074.#ll -> Dialer.InstantAccess.m : Cleaned with backup
    C:\WINDOWS\system32\eg_auth_srv_1049.dll -> Trojan.P2E.cl : Cleaned with backup
    C:\WINDOWS\system32\msplock32.#ll -> Adware.NaviPromo : Cleaned with backup
    C:\WINDOWS\system32\netia32.dll -> Dialer.EGroup.h : Cleaned with backup
    C:\WINDOWS\system32\P2ECOM.#ll -> Trojan.P2E.al : Cleaned with backup
    C:\WINDOWS\system32\sysinetsvc32.#ll -> Dialer.InstantAccess.e : Cleaned with backup
    C:\WINDOWS\system32\syswbsvc32.#ll -> Dialer.InstantAccess.e : Cleaned with backup


::Report End
Avatar billede drugless Nybegynder
01. marts 2006 - 09:38 #13
Log fra:
Logfile of HijackThis v1.99.1
Scan saved at 15:47:28, on 28-02-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Andy Drugless\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bt.dk/sport/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google-søgning - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Oversæt engelsk ord - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Lignende sider - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Tilbage via links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Øjebliksbillede af side i cache - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39EA2F6F-3F50-4F58-9C63-4B3D53B0926E} - http://scripts.downloadv3.com/binaries/P2EClient/EGAUTH_1049_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137513526980
O16 - DPF: {6AA85413-165C-4200-8154-71166077B22E} - http://scripts.downloadv3.com/binaries/IA/sysiasvc32_EN_XP.cab
O16 - DPF: {87C1805D-C5AE-4455-AB39-E245BB516136} - http://scripts.dlv4.com/binaries/egaccess4/egaccess4_1059_XP.cab
O16 - DPF: {8B3B8135-9DAA-40E7-8941-962795F9C1CB} - http://scripts.downloadv3.com/binaries/IA/syswbsvc32_EN_XP.cab
O16 - DPF: {8D8BAF56-B581-4B90-A549-C4AC6B03F1BB} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1074_XP.cab
O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/sysinetsvc32_EN_XP.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Avatar billede drugless Nybegynder
01. marts 2006 - 09:41 #14
Jeg kørte desuden drweb 2 gange, da jeg ikke kunne finde den lograpport der efter artiklen skulle komme. Det hjalp mig dog ikke til at finde rapporten, at jeg kørte den en ekstra gang.

Tilgengæld fandt den rigeligt med inficerede filer og andet skidt begge gange. Om de så er forsvundet af den grund er en anden sag.
03. april 2006 - 11:00 #15
(Øhhh - Er denne stadig aktuel?)
Avatar billede drugless Nybegynder
03. april 2006 - 11:25 #16
nej det er den ikke - jeg tror jeg har givet point og tråden dermed skulle være afsluttet, men der er måske noget jeg har gjort forkert i pointgivningen?
03. april 2006 - 16:32 #17
(Du fik givet Point til dig selv: [27/02-2006 21:37:03] ... og så opfatter folk 'sagen' som _meget_ afsluttet... )
Avatar billede drugless Nybegynder
04. april 2006 - 08:54 #18
ok, det var ikke intentionen, men jeg ville da gerne give point til dig, men kræver det ikke at man bruger svar knappen istedet for kommentar?
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester