Avatar billede gf400 Nybegynder
12. april 2004 - 14:26 Der er 15 kommentarer og
1 løsning

tjek af HijackThis log fil

er der nogle der vil tjekke min fil?

Logfile of HijackThis v1.97.7
Scan saved at 2:16:38 PM, on 12/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\TGTSoft\StyleXP\StyleXPService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
E:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
E:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe
E:\WINDOWS\System32\devldr32.exe
E:\Programmer\Logitech\iTouch\iTouch.exe
E:\Programmer\Logitech\MouseWare\system\em_exec.exe
E:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe
E:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe
E:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Programmer\MSN Messenger\MsnMsgr.Exe
E:\Programmer\PeerGuardian_1.99pr7\PeerGuardian_1.99b_pr7.exe
E:\Programmer\Ergosensor 2.0\Ergosensor.exe
E:\Programmer\Crazy Browser\Crazy Browser.exe
E:\HijackThis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchcentral.cc/search.php?v=4&aff=3723
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchcentral.cc/index.php?v=4&aff=3723
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchcentral.cc/index.php?v=4&aff=3723
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://searchcentral.cc/index.php?v=4&aff=3723
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3212BCA5-DFC1-4587-AD42-A4462C1D417E} - (no file)
O2 - BHO: (no name) - {82315A18-6CFB-44a7-BDFD-90E36537C252} - E:\Programmer\QuickSearch\QuickSearchBar1_27.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Programmer\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - E:\Programmer\QuickSearch\QuickSearchBar1_27.dll
O4 - HKLM\..\Run: [ATIPTA] E:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off
O4 - HKLM\..\Run: [SoundMAXPnP] E:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "E:\Programmer\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [zBrowser Launcher] E:\Programmer\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [turedct] E:\WINDOWS\turedct.exe
O4 - HKLM\..\Run: [tipuf] E:\WINDOWS\tipuf.exe
O4 - HKLM\..\Run: [pccguide.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\WINDOWS\System32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Iaam] E:\Documents and Settings\kasper\Application Data\bwap.exe
O4 - HKCU\..\Run: [WAPI] E:\WINDOWS\System32\wtstr.exe
O4 - Startup: Ergosensor.lnk = E:\Programmer\Ergosensor 2.0\Ergosensor.exe
O4 - Global Startup: PeerGuardian.lnk = E:\Programmer\PeerGuardian_1.99pr7\PeerGuardian_1.99b_pr7.exe
O8 - Extra context menu item: Download all by Net Transport - E:\PROGRA~1\Xi\NETTRA~1\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - E:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html
O8 - Extra context menu item: Download with TrueSpeed Download Manager - E:\Programmer\TrueSpeed\DBooster.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38080.5925925926
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Avatar billede fromsej Praktikant
12. april 2004 - 14:38 #1
Tjek i Tilføj/Fjern programmer om QuickSearchBar er til stede, hvis ja, fjern den.
Hent cwshredder her:
http://www.spywareinfo.com/~merijn/junk/CWShredder.exe
Kør programmet, tjek for updates, luk alle vinduer, undtaget cwshredder, klik på Next, den scanner nu, når den er færdig klik på Fix, klik på Exit.
Derefter genstart, og en ny hijackthislog.
Avatar billede gf400 Nybegynder
12. april 2004 - 14:53 #2
Logfile of HijackThis v1.97.7
Scan saved at 2:51:57 PM, on 12/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\TGTSoft\StyleXP\StyleXPService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
E:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe
E:\WINDOWS\System32\devldr32.exe
E:\Programmer\Logitech\iTouch\iTouch.exe
E:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
E:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe
E:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe
E:\Programmer\Logitech\MouseWare\system\em_exec.exe
E:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Programmer\MSN Messenger\MsnMsgr.Exe
E:\Programmer\PeerGuardian_1.99pr7\PeerGuardian_1.99b_pr7.exe
E:\Programmer\Ergosensor 2.0\Ergosensor.exe
E:\HijackThis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3212BCA5-DFC1-4587-AD42-A4462C1D417E} - (no file)
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Programmer\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] E:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off
O4 - HKLM\..\Run: [SoundMAXPnP] E:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "E:\Programmer\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [zBrowser Launcher] E:\Programmer\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [turedct] E:\WINDOWS\turedct.exe
O4 - HKLM\..\Run: [tipuf] E:\WINDOWS\tipuf.exe
O4 - HKLM\..\Run: [pccguide.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\WINDOWS\System32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Iaam] E:\Documents and Settings\kasper\Application Data\bwap.exe
O4 - HKCU\..\Run: [WAPI] E:\WINDOWS\System32\wtstr.exe
O4 - Startup: Ergosensor.lnk = E:\Programmer\Ergosensor 2.0\Ergosensor.exe
O4 - Global Startup: PeerGuardian.lnk = E:\Programmer\PeerGuardian_1.99pr7\PeerGuardian_1.99b_pr7.exe
O8 - Extra context menu item: Download all by Net Transport - E:\PROGRA~1\Xi\NETTRA~1\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - E:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html
O8 - Extra context menu item: Download with TrueSpeed Download Manager - E:\Programmer\TrueSpeed\DBooster.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38080.5925925926
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Avatar billede fromsej Praktikant
12. april 2004 - 15:04 #3
Flyt først filen Hijackthis til en mappe oprettet kun til den.

Deaktiver systemgendannelse:
http://www.spywarefri.dk/virusscannere.htm#alle

Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, genstart i fejlsikret(Tryk <F8> under opstart) og slet filerne listet nederst.
Dobbelttjek, så alt kommer med.

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
O2 - BHO: (no name) - {3212BCA5-DFC1-4587-AD42-A4462C1D417E} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "E:\WINDOWS\System32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Iaam] E:\Documents and Settings\kasper\Application Data\bwap.exe
O4 - HKCU\..\Run: [WAPI] E:\WINDOWS\System32\wtstr.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
---------------------------------------
Kender du? Ellers fixes.
O4 - HKLM\..\Run: [turedct] E:\WINDOWS\turedct.exe
O4 - HKLM\..\Run: [tipuf] E:\WINDOWS\tipuf.exe
---------------------------------------
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".
---------------------------------------
Slettes i fejlsikret.
E:\Documents and Settings\kasper\Application Data\bwap.exe
E:\WINDOWS\System32\wtstr.exe
---------------------------------------
Genstart og kom med en ny logfil, så jeg kan se om alt er med.
Avatar billede gf400 Nybegynder
12. april 2004 - 15:09 #4
det er første gang det her men fatter ikke helt havd jeg skal
Avatar billede fromsej Praktikant
12. april 2004 - 15:14 #5
http://www.sitecenter.dk/fromsej/nss-folder/mappe/Hijackthis/
Hent billederne 2-5.jpg , højreklik->Gem destination som.
Det er en vejledning i billedform.
Avatar billede gf400 Nybegynder
12. april 2004 - 15:18 #6
jeg fatter godt at få den der log fil men jeg fatter ikke alt det jeg skal gøre ved min pc som du har skreven
Avatar billede fromsej Praktikant
12. april 2004 - 15:26 #7
Kør Hijackthis igen, klik på Scan, den liste du får frem, der sætter du et flueben udfor de linier jeg har listet ovenover.
Når det er gjort klikker du på Fix checked, og væk er de.
Derefter finder og sletter du de to filer jeg har skrevet, prøv bare i normal tilstand først.
Genstart så og kom med en frisk logfil.
Avatar billede gf400 Nybegynder
12. april 2004 - 15:28 #8
okay
Avatar billede gf400 Nybegynder
12. april 2004 - 15:30 #9
skal de her slettes

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
O2 - BHO: (no name) - {3212BCA5-DFC1-4587-AD42-A4462C1D417E} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "E:\WINDOWS\System32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Iaam] E:\Documents and Settings\kasper\Application Data\bwap.exe
O4 - HKCU\..\Run: [WAPI] E:\WINDOWS\System32\wtstr.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
Avatar billede fromsej Praktikant
12. april 2004 - 15:38 #10
Ja.
Avatar billede gf400 Nybegynder
12. april 2004 - 15:38 #11
okay er det i regedit?
Avatar billede fromsej Praktikant
12. april 2004 - 15:40 #12
Nej med hijackthis, det er de linier du skal sætte flueben ved.
Avatar billede gf400 Nybegynder
12. april 2004 - 15:41 #13
også trykke?
Avatar billede fromsej Praktikant
12. april 2004 - 15:42 #14
Ja, så skal du trykke på Fix checked.
Avatar billede gf400 Nybegynder
12. april 2004 - 15:57 #15
Logfile of HijackThis v1.97.7
Scan saved at 3:57:04 PM, on 12/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\TGTSoft\StyleXP\StyleXPService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe
E:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe
E:\WINDOWS\System32\devldr32.exe
E:\Programmer\Logitech\iTouch\iTouch.exe
E:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe
E:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe
E:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe
E:\Programmer\Logitech\MouseWare\system\em_exec.exe
E:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Programmer\MSN Messenger\MsnMsgr.Exe
E:\Programmer\PeerGuardian_1.99pr7\PeerGuardian_1.99b_pr7.exe
E:\Programmer\Ergosensor 2.0\Ergosensor.exe
E:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
E:\Programmer\Outlook Express\msimn.exe
E:\Programmer\Messenger\msmsgs.exe
E:\HijackThis\hijackthis.exe
E:\Programmer\Crazy Browser\Crazy Browser.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Programmer\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] E:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off
O4 - HKLM\..\Run: [SoundMAXPnP] E:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "E:\Programmer\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [zBrowser Launcher] E:\Programmer\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [pccguide.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "E:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Ergosensor.lnk = E:\Programmer\Ergosensor 2.0\Ergosensor.exe
O4 - Global Startup: PeerGuardian.lnk = E:\Programmer\PeerGuardian_1.99pr7\PeerGuardian_1.99b_pr7.exe
O8 - Extra context menu item: Download all by Net Transport - E:\PROGRA~1\Xi\NETTRA~1\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - E:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html
O8 - Extra context menu item: Download with TrueSpeed Download Manager - E:\Programmer\TrueSpeed\DBooster.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38080.5925925926
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Avatar billede fromsej Praktikant
12. april 2004 - 16:04 #16
Så er din log ren, for at holde den ren bør du kigge i vores artikler her:
http://www.eksperten.dk/artikler/144
http://www.eksperten.dk/artikler/254
Som minimum anbefaler jeg Spywareguard, Spywareblaster, IE-Spyad og IE Privacy Keeper.
Mvh:
Fromsej/Team Spywarefri.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester