Avatar billede obmm Nybegynder
03. april 2006 - 18:22 Der er 11 kommentarer og
2 løsninger

Ekstra searchbar m.m.

Min datter har fået en ekstra searchbar, og hun har svært ved selv at få lov til at vælge startside, jeg synes ikke rigtig jeg har haft held til at få "snavset" fjernet., håber på hjælp.
Logfile of HijackThis v1.99.1
Scan saved at 18:16:28, on 03-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\j2re1.4.2_01\bin\jusched.exe
C:\Programmer\Creative\Shared Files\CAMTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Programmer\Logitech\SetPoint\kem.exe
C:\Programmer\Logitech\SetPoint\KHALMNPR.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Programmer\FirstClass\fcc32.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Mette\Skrivebord\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nassmankkglnyxyegohay.com/TOyQLHKVKguuCZOGFjr2qW5gQfEfB4RWwHCSvnZadRsgiO7Dd7EwoeORxf2_AAT0.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {B706CDC7-34FC-413E-0675-7481F744F8BC} - C:\DOCUME~1\Mette\APPLIC~1\OKAYRE~1\Proxyextra.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programmer\Creative\Shared Files\CamTray.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Spyware Stormer] C:\Programmer\Spyware Stormer\SpywareStormer.Exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [List bait] C:\DOCUME~1\Mette\APPLIC~1\CURBUP~1\Bird Phone Skip.exe
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O18 - Protocol: bw+0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
Avatar billede jacla Nybegynder
03. april 2006 - 19:13 #1
Jeg ville finde Toolbaren i tilføj fjer programmer.

Står den ikke der, kan du downloade Belarc Advisor som kan vise alt om din pc, herunder software oplysninger.

Derefter START => KØR (skriv regedit) tast enter søg på toolbar eller det navn den nu måtte have.

Installere regSupreme og kør programmet (Vælg grundig)

MVH

Jan
Avatar billede ejvindh Ekspert
03. april 2006 - 19:44 #2
Jeg kigger på loggen :-)
Avatar billede ejvindh Ekspert
03. april 2006 - 19:55 #3
Gå ind i kontrolpanel-tilføj/fjern programmer, og se om du kan få lov til at afinstallere følgende programmer:
Messenger+
Spyware Stormer

Hent dette program: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Kør herefter HJT, og fix følgende linier:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nassmankkglnyxyegohay.com/TOyQLHKVKguuCZOGFjr2qW5gQfEfB4RWwHCSvnZadRsgiO7Dd7EwoeORxf2_AAT0.html
O2 - BHO: (no name) - {B706CDC7-34FC-413E-0675-7481F744F8BC} - C:\DOCUME~1\Mette\APPLIC~1\OKAYRE~1\Proxyextra.exe
O4 - HKLM\..\Run: [Spyware Stormer] C:\Programmer\Spyware Stormer\SpywareStormer.Exe
O4 - HKCU\..\Run: [List bait] C:\DOCUME~1\Mette\APPLIC~1\CURBUP~1\Bird Phone Skip.exe
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

ALLE LINIER, DER STARTER SÅDAN HER:
O18 - Protocol: bw

O18 - Protocol: offline-8876480 - {62FDF0C5-9779-451F-A5B6-675FB60B666B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

Genstart herefter til fejlsikret tilstand (tryk F8 under opstarten). Sørg for at du kan se alle filer og mapper:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

Slet herefter følgende mapper:
C:\Programmer\Spyware Stormer\
C:\Documents and Settings\Mette\Application Data\CURBUP~1\
C:\Documents and Settings\Mette\Application Data\OKAYRE~1\
(bemærk at navnet på de sidste 2 mapper er forkortet)

Kør herefter et scan med DrWeb: Dobbeltklik på drweb-cureit.exe, den vil køre en expressscan, det siger du ja til.
Når den skriver Done nederst til venstre, skal du klikke på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de valgte.
Klik så på den grønne fodgænger ovre til højre på siden, så starter scanningen.
Klik så på Start->Søg, find filen drweb32w.log kopier det nederste af teksten herind, startende med:
Scan statistics.

Genstart til normal tilstand. Hent denne lille fil: http://www.fbeej.ctrlaltdel.dk/Programmer/fl.zip
Pak fl.zip ud og dobbeltklik på fl.bat - Notesblok åbner en lille tekstfil du skal kopiere herind.

Lav også en ny log med HJT, som du lægger herind.
Avatar billede obmm Nybegynder
03. april 2006 - 21:56 #4
Okay bliver først i morgen.
Avatar billede obmm Nybegynder
04. april 2006 - 12:54 #5
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\Administrator\Application Data

Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\All Users\Application Data

24-10-2003  20:18    <DIR>          Adobe
12-06-2005  15:38    <DIR>          Body That Byte Meet
04-04-2006  09:42    <DIR>          Chic Comp Seek Dog
02-07-2003  11:24    <DIR>          MSN6
04-04-2006  09:43    <DIR>          NounUploadLinkOpen
29-09-2003  19:22    <DIR>          shockwave.com
07-08-2005  18:20    <DIR>          Spybot - Search & Destroy
              0 fil(er)                0 byte
              7 mappe(r)  12.138.987.520 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\Mette\Application Data

24-10-2003  20:20    <DIR>          Adobe
20-11-2003  18:29    <DIR>          AdobeUM
18-01-2005  18:24    <DIR>          ArcSoft
09-01-2004  19:50    <DIR>          Creative
24-05-2005  17:40    <DIR>          FirstClass
19-11-2003  15:45            67.184 GDIPFONTCACHEV1.DAT
20-02-2004  09:42    <DIR>          Help
02-09-2000  19:05            65.514 hiscore_background.jpg
16-03-2005  19:00    <DIR>          ICQLite
29-06-2003  22:56    <DIR>          Identities
24-05-2005  17:40    <DIR>          InstallShield Installation Information
30-06-2004  10:24    <DIR>          InterTrust
19-10-2003  13:19    <DIR>          Jasc
18-01-2005  20:07    <DIR>          Jasc Software Inc
12-06-2005  18:25    <DIR>          Lavasoft
25-12-2004  13:34    <DIR>          Logitech
14-10-2003  17:01    <DIR>          Macromedia
21-02-2005  22:01    <DIR>          MSN6
29-09-2003  19:22    <DIR>          shockwave.com
17-04-2004  10:51            9.556 sportybthiscore.html
26-10-2003  19:26    <DIR>          Sun
              3 fil(er)          142.254 byte
              18 mappe(r)  12.138.983.424 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\Default User\Application Data

29-06-2003  22:03    <DIR>          .
29-06-2003  22:03    <DIR>          ..
29-06-2003  22:03                62 desktop.ini
              1 fil(er)              62 byte
              2 mappe(r)  12.138.979.328 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\LocalService\Application Data

Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\NetworkService\Application Data
Avatar billede obmm Nybegynder
04. april 2006 - 13:06 #6
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 132891
Infected objects found: 448
Objects with modifications found: 0
Suspicious objects found: 1
Adware programs found: 8
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 448
Objects renamed: 1
Objects moved: 0
Objects ignored: 1
Scan speed: 40 Kb/s
Scan time: 03:10:58
Avatar billede obmm Nybegynder
04. april 2006 - 13:06 #7
Logfile of HijackThis v1.99.1
Scan saved at 13:06:29, on 04-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\j2re1.4.2_01\bin\jusched.exe
C:\Programmer\Creative\Shared Files\CamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Logitech\SetPoint\kem.exe
C:\Programmer\Logitech\SetPoint\KHALMNPR.EXE
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Mette\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eksperten.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {3D79D893-EBEA-05E2-1ECF-444EFB9DBCA7} - C:\DOCUME~1\Mette\APPLIC~1\OKAYRE~1\CLOSE ARMY.exe (file missing)
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programmer\Creative\Shared Files\CamTray.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Link Open Mix Spam] C:\Documents and Settings\All Users\Application Data\NounUploadLinkOpen\CORN GREAT.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
Avatar billede ejvindh Ekspert
04. april 2006 - 13:16 #8
Det tog noget af den. Men den nåede også at nygenerere sig. Prøv nu følgende:

Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O2 - BHO: (no name) - {3D79D893-EBEA-05E2-1ECF-444EFB9DBCA7} - C:\DOCUME~1\Mette\APPLIC~1\OKAYRE~1\CLOSE ARMY.exe (file missing)
O4 - HKLM\..\Run: [Link Open Mix Spam] C:\Documents and Settings\All Users\Application Data\NounUploadLinkOpen\CORN GREAT.exe

Kopier teksten mellem de stiplede linier ind i et notepad-vindue. Gem filen som vislop.bat, hvor du sikrer dig, at der under Filtype står "Alle filer"
-----------------------------------
cd\
attrib -r -s -h /s /d "C:\Documents and Settings\All Users\Application Data\Body That Byte Meet"
rd /s /q "C:\Documents and Settings\All Users\Application Data\Body That Byte Meet"
attrib -r -s -h /s /d "C:\Documents and Settings\All Users\Application Data\Chic Comp Seek Dog"
rd /s /q "C:\Documents and Settings\All Users\Application Data\Chic Comp Seek Dog"
attrib -r -s -h /s /d "C:\Documents and Settings\All Users\Application Data\NounUploadLinkOpen"
rd /s /q "C:\Documents and Settings\All Users\Application Data\NounUploadLinkOpen"

if exist c:\findlop.txt del c:\findlop.txt
set savepath=%CD%
%homedrive%
cd %USERPROFILE%
cd ..

FOR /F "tokens=*" %%G IN ('dir/b ^"*.^"') DO dir ^"%%G\Application Data\^" >> c:\findlop.txt
FOR /F "tokens=*" %%G IN ('dir/b /ah ^"*.^"') DO dir /ah ^"%%G\Application Data\^" >> c:\findlop.txt

dir %Windir%\tasks /a h >> c:\findlop.txt
notepad c:\findlop.txt

cd %savepath%
-----------------------------------
Dobbeltklik på den nye fil, og læg den tekst, der kommer frem herved ind i tråden.

Genstart computeren, lav en ny HJT-log, som du sender herind til check.
Avatar billede obmm Nybegynder
04. april 2006 - 13:59 #9
Logfile of HijackThis v1.99.1
Scan saved at 13:58:43, on 04-04-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\D-Tools\daemon.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\j2re1.4.2_01\bin\jusched.exe
C:\Programmer\Creative\Shared Files\CamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Logitech\SetPoint\kem.exe
C:\Programmer\Logitech\SetPoint\KHALMNPR.EXE
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Mette\Skrivebord\hijackthis.exe
C:\WINDOWS\system32\wscntfy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eksperten.dk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programmer\Creative\Shared Files\CamTray.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
Avatar billede obmm Nybegynder
04. april 2006 - 14:14 #10
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\Administrator\Application Data

Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\All Users\Application Data

24-10-2003  20:18    <DIR>          Adobe
02-07-2003  11:24    <DIR>          MSN6
29-09-2003  19:22    <DIR>          shockwave.com
07-08-2005  18:20    <DIR>          Spybot - Search & Destroy
              0 fil(er)                0 byte
              4 mappe(r)  12.124.585.984 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\Mette\Application Data

24-10-2003  20:20    <DIR>          Adobe
20-11-2003  18:29    <DIR>          AdobeUM
18-01-2005  18:24    <DIR>          ArcSoft
09-01-2004  19:50    <DIR>          Creative
24-05-2005  17:40    <DIR>          FirstClass
19-11-2003  15:45            67.184 GDIPFONTCACHEV1.DAT
20-02-2004  09:42    <DIR>          Help
02-09-2000  19:05            65.514 hiscore_background.jpg
16-03-2005  19:00    <DIR>          ICQLite
29-06-2003  22:56    <DIR>          Identities
24-05-2005  17:40    <DIR>          InstallShield Installation Information
30-06-2004  10:24    <DIR>          InterTrust
19-10-2003  13:19    <DIR>          Jasc
18-01-2005  20:07    <DIR>          Jasc Software Inc
12-06-2005  18:25    <DIR>          Lavasoft
25-12-2004  13:34    <DIR>          Logitech
14-10-2003  17:01    <DIR>          Macromedia
21-02-2005  22:01    <DIR>          MSN6
29-09-2003  19:22    <DIR>          shockwave.com
17-04-2004  10:51            9.556 sportybthiscore.html
26-10-2003  19:26    <DIR>          Sun
              3 fil(er)          142.254 byte
              18 mappe(r)  12.124.581.888 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\Default User\Application Data

29-06-2003  22:03    <DIR>          .
29-06-2003  22:03    <DIR>          ..
29-06-2003  22:03                62 desktop.ini
              1 fil(er)              62 byte
              2 mappe(r)  12.124.581.888 byte ledig
Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\LocalService\Application Data

Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\Documents and Settings\NetworkService\Application Data

Disken i drev C har ikke noget navn.
Diskens serienummer er B019-BFFE

Indhold af C:\WINDOWS\tasks

04-04-2006  09:03    <DIR>          .
04-04-2006  09:03    <DIR>          ..
09-10-2001  14:00                65 desktop.ini
04-04-2006  13:58                6 SA.DAT
              2 fil(er)              71 byte

Indhold af C:\Documents and Settings
Avatar billede ejvindh Ekspert
04. april 2006 - 14:55 #11
Så blev loggene rene. Har du også fået løst problemerne?

For at gøre arbejdet helt færdig:
Det kan være en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse (http://www.spywarefri.dk/virusscannere.htm#alle) - genstart din computer - aktiver systemgendannelse.
Og så kan det også være en god ide at skjule dine systemfiler og -mapper igen, så du ikke ved en fejl kommer til at slette en vigtig fil. Det gør du samme sted, hvor du satte det til at vise alle filer, denne gang vælger du bare: Vis ikke skjulte filer og mapper.

Det kan også være en god ide at få renset ud i dine midlertidige filer. Det kan gøres på en hurtig og nem måde med denne fil
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------

For at forhindre gentagelser, vil jeg anbefale dig at lægge nogle små programmer ind, som forhindrer spyware i at komme ind i første omgang. Du finder links og gode råd her (så vidt jeg kan se, er der ikke engang Antivirus på computeren?):
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at du læser denne artikel om hvordan du kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
Avatar billede ejvindh Ekspert
08. april 2006 - 13:14 #12
Husk at lukke spørgsmålet efter dig :-)
Avatar billede obmm Nybegynder
08. april 2006 - 13:51 #13
Tak for hjælpen..
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
Alle kurser indenfor Microsoft 365 – både til begyndere og øvede.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester