Avatar billede smeier Nybegynder
21. oktober 2004 - 23:23 Der er 23 kommentarer og
2 løsninger

Hijack log

Nogen der gider kigge på den. Er bange for den er fucked.

Logfile of HijackThis v1.98.2
Scan saved at 23:20:52, on 21-10-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\HPQ\One-Touch\OneTouch.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\WINDOWS\System32\carpserv.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Programmer\EasyPHP1-7\easyphp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Skyr@cer Pro Utility\WLANPRO.exe
C:\PROGRA~1\EASYPH~1\Apache\apache.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Programmer\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\PROGRA~1\EASYPH~1\Apache\apache.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\EASYPH~1\MySql\bin\mysqld.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Troels Roar Meier\Skrivebord\hjt.exe
C:\Programmer\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TV Now] C:\Programmer\HPQ\Notebook Utilities\TvNow.exe /RK
O4 - HKLM\..\Run: [Display Settings] C:\Programmer\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Programmer\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Programmer\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programmer\Fælles filer\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programmer\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [EasyPHP] "C:\Programmer\EasyPHP1-7\easyphp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Skyr@cer Pro Configuration Utility.lnk = C:\Programmer\Skyr@cer Pro Utility\WLANPRO.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
Avatar billede tonnybrandt Nybegynder
21. oktober 2004 - 23:30 #1
jeg kigger lige på den ..
Avatar billede tonnybrandt Nybegynder
21. oktober 2004 - 23:33 #2
Hmm.. den er faktisk helt ren.

Hvilke problemer har du med den ?
Avatar billede smeier Nybegynder
21. oktober 2004 - 23:35 #3
Min computer er meget MEGET langsom til at starte op og starte programmer. Enkelte programmer kan slet ikke starte eller kører dårligt. F.eks. dreamweaver.
Avatar billede tonnybrandt Nybegynder
21. oktober 2004 - 23:42 #4
Prøv at klikke start | kør, skriv:

sfc /scannow

og tryk enter.
Den checker at dine systemfiler er de korrekte  og at de er der. Du skal have din xp cdrom i drevet imens.
Avatar billede forevernewbie Nybegynder
22. oktober 2004 - 00:14 #5
Du har også mange programmer der starter med Windows. Disse skulle være ok at disable i MSCONFIG. Du kan altid sætte dem til at køre igen, hvis du ønsker det, eller der er noget der ikke kører helt som du vil have det. Især HP filerne er "tunge" ;)

Gå i Start-> Kør, skriv-> msconfig, klik-> ok, fanebladet-> Start, og fjern fluebenet ved:

O4 - HKLM\..\Run: [Display Settings] C:\Programmer\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Programmer\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [HPHUPD05] c:\Programmer\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Programmer\Fælles filer\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Programmer\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
Avatar billede smeier Nybegynder
22. oktober 2004 - 00:17 #6
Forlod computeren en halv time mens den stod og tjeckede. Da jeg kom tilbage var det bare lukket ned, så går ud fra at det var i orden?
Avatar billede tonnybrandt Nybegynder
22. oktober 2004 - 00:19 #7
Ja, det skulle det være.
Prøv at følge forevernewbies råd mht at deaktivere nogle af dine mange programmer som startes automatisk sammen med windows. Det burde hjælpe på problemet.
Avatar billede johnstigers Seniormester
22. oktober 2004 - 00:20 #8
jep så er det der skulle fixes blevet fixet.
Avatar billede smeier Nybegynder
22. oktober 2004 - 00:25 #9
Det hjalp lidt men ikke meget. Må nok kontakte HP og få dem til at komme og hente den.

tonnybrandt og forevernewbie smid et svar.
Avatar billede forevernewbie Nybegynder
22. oktober 2004 - 00:29 #10
Hmm, inden du gør der, så prøv lige at køre denne scanner http://www.spywareinfo.dk/download/mwav.exe. Der kunne ligge et eller andet som ikke kan ses i HJT
Avatar billede forevernewbie Nybegynder
22. oktober 2004 - 00:29 #11
Tager lang tid at køre ;)
Avatar billede smeier Nybegynder
22. oktober 2004 - 00:51 #12
Bliver nødt til at sove nu. Men tjecker scanneren som det første imorgen tidligt.
Avatar billede tonnybrandt Nybegynder
29. oktober 2004 - 11:51 #13
Har scanneren kørt færdig ? *s*
Avatar billede smeier Nybegynder
29. oktober 2004 - 16:20 #14
Den har kørt. Kan ikke rigtigt huske hvilken computer jeg kørte den tidligere på. Men denne resulterede i Dette:
File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken.
File C:\WINDOWS\wsem218.dll infected by "TrojanDownloader.Win32.Dyfuca.cn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\nem218.dll infected by "TrojanDownloader.Win32.Dyfuca.gen" Virus. Action Taken: File Deleted.
File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken.
File C:\WINDOWS\fxiehbym.exe infected by "TrojanDownloader.Win32.VB.df" Virus. Action Taken: File Deleted.
File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken.
File C:\WINDOWS\kplec.exe infected by "TrojanClicker.Win32.VB.ca" Virus. Action Taken: File Deleted.
File C:\WINDOWS\mm20.ocx infected by "TrojanDownloader.Win32.VB.db" Virus. Action Taken: File Deleted.
File C:\WINDOWS\webhdll.dll tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\WINDOWS\whCC-MOTOR.exe tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\Documents and Settings\Troels Meier\Application Data\avshoqpo.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Troels Meier\Application Data\bxoecpze.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Troels Meier\Application Data\mpyqiovw.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Troels Meier\Application Data\qjhwcovc.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\Klh1.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\Rem14.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\Rem34.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\Rem4.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\Rem5.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\Rem6.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\Rem7.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\RemF.exe tagged as not-a-virus:AdWare.Lop. No Action Taken.
File C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp\trickler_4010.ex_ tagged as not-a-virus:AdWare.Gator. No Action Taken.
File C:\Programmer\Fælles filer\GMT\GUninstaller.exe tagged as not-a-virus:AdWare.Gator. No Action Taken.
File C:\Programmer\Norton AntiVirus\Quarantine\005C6DA2 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\006F698C infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\043C4E9E infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\045D35AC infected by "I-Worm.Sobig.e" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\08C163F5 infected by "I-Worm.Klez.h" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\09D06DD8 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\09FA0FAA infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0B11115F infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0BCA7C4C infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0C46675A infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0DA91A4B infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0E563B38 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0FA84485 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0FCC125D infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\0FDD644B infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\113D5BAE.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\1244140F infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\14447B00 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\146E2D26 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\156E6988 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\1A232D08 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\1F7177B0 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\20CC4F9C infected by "I-Worm.Swen" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\21682EEF infected by "I-Worm.Swen" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\22F74B64 infected by "I-Worm.Klez.h" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\236334EE infected by "I-Worm.Klez.h" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\28DC1111 infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programmer\Norton AntiVirus\Quarantine\29603653 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\29912C1D infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\2AC12041 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\2B52385C infected by "Trojan.Java.Nocheat" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\2C8220C6 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\2DCA3A50 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\2ECB1240 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\33F6255F infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\3EA31A78 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\4044464E infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\417D7048 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\43E370CC infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\452840ED.dat infected by "Worm.P2P.Tanked.14" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\47337EAE.dat infected by "Worm.P2P.Tanked.14" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\476C7F90 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\481125B9.dat infected by "Worm.P2P.Surnova.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\48132DD5.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\490348AF.dat infected by "Worm.P2P.Surnova.a" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\4D401D3C infected by "Trojan.JS.Loop" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\4DF641CC infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\4E0713BA infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\4E1A0FA4 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\4F3873D5 infected by "I-Worm.Klez.h" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\4FE6696F infected by "I-Worm.Sober.g" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\57B4231B infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5CD600CC infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5DD60950 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5E14270B infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5E1A7B04 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5E2478F9 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5E2B4CF2 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5E3120EB infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5E3B1EE0 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\5E9463CB infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\64B35616 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\6A1B27F9 infected by "Trojan.Java.Nocheat" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\6DB5030A infected by "I-Worm.NetSky.aa" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\7001232F infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\709A5886 infected by "I-Worm.NetSky.b" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\7C24080C infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\7C6F4DB9 infected by "I-Worm.NetSky.q" Virus. Action Taken: File Deleted.
File C:\Programmer\Norton AntiVirus\Quarantine\7D395067.dat infected by "Win32.HLLP.Hantaner.a" Virus. Action Taken: File Disinfected.
File C:\Programmer\whInstall\Webhdll.dll tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\Programmer\whInstall\WhAgent.exe tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\Programmer\whInstall\WhSurvey.exe tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\Programmer\WildTangent\Components\SystemConfig0100.dll tagged as not-a-virus:AdWare.WildTangent. No Action Taken.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091492.dll infected by "TrojanDownloader.Win32.Dyfuca.cn" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091493.dll infected by "TrojanDownloader.Win32.Dyfuca.gen" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091494.exe infected by "TrojanDownloader.Win32.VB.df" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091495.exe infected by "TrojanClicker.Win32.VB.ca" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091496.ocx infected by "TrojanDownloader.Win32.VB.db" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091497.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091498.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091499.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP426\A0091500.exe infected by "TrojanDownloader.Win32.Small.bp" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Downloaded Program Files\internazionale_ver3.ocx infected by "TrojanClicker.Win32.Adpower.b" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Downloaded Program Files\roing18.ocx infected by "TrojanDownloader.Win32.VB.bo" Virus. Action Taken: File Deleted.
File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken.
File C:\WINDOWS\webhdll.dll tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\WINDOWS\whCC-MOTOR.exe tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\WINDOWS\wt\wtbgm\wtbgmtt.exe tagged as not-a-virus:AdWare.WildTangent. No Action Taken.
File G:\RECYCLER\S-1-5-21-2052111302-842925246-839522115-1003\Dg124.exe infected by "TrojanDownloader.Win32.Small.jl" Virus. Action Taken: File Deleted.
File G:\System Volume Information\_restore{034EF9DA-3576-4287-BBB9-58CE2AB64878}\RP427\A0091503.exe infected by "TrojanDownloader.Win32.Small.jl" Virus. Action Taken: File Deleted.

plus en 15 mb stor logfil
http://smeier.dk/log.txt
Avatar billede tonnybrandt Nybegynder
29. oktober 2004 - 16:29 #15
Puha, det var en del.

Du skal ihvertfald slette hele indholdet af:
C:\Documents and Settings\Troels Meier\Lokale indstillinger\Temp

Ikke selve mappen, men alt hvad der er i den.
Avatar billede smeier Nybegynder
29. oktober 2004 - 16:41 #16
får ikke lov til at slette følgende:
~e5d141.tmp
~ef4e5d  -mapper
~ef009d
~ef5870
Avatar billede smeier Nybegynder
29. oktober 2004 - 16:43 #17
fik slettes den øverste da den kørte som process der skulle lukkes. De andre kan jeg ikke gøre noget ved.
Avatar billede tonnybrandt Nybegynder
29. oktober 2004 - 17:35 #18
Prøv igen i fejlsikret tilstand. Så går det nok lidt bedre.
Avatar billede smeier Nybegynder
31. oktober 2004 - 23:04 #19
tror ikke at den bliver bedre lige nu. Læg et svar.
Avatar billede tonnybrandt Nybegynder
31. oktober 2004 - 23:15 #20
Ok, det kommer her ...
Avatar billede forevernewbie Nybegynder
31. oktober 2004 - 23:22 #21
Og her ;) Hmm, dit Norton antivirus har jo egentligt ikke været særligt effektivt ;) Der er et nogle gode gratis her http://www.avast.com/eng/down_home.html http://free.grisoft.com/freeweb.php/doc/16/lng/us/tpl/v5  http://www.free-av.com/
Avatar billede forevernewbie Nybegynder
31. oktober 2004 - 23:27 #22
Måske også en ide, at køre en scanning med Spybot. Ser lige at E-scan ikke fjernede al spy/adwaren ;) http://www.safer-networking.org/en/mirrors/index.html
Avatar billede smeier Nybegynder
31. oktober 2004 - 23:32 #23
tak.
Avatar billede tonnybrandt Nybegynder
31. oktober 2004 - 23:37 #24
Alternativt kan du blot manuelt slette filerne i stifinderen:

File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken.
File C:\WINDOWS\webhdll.dll tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\WINDOWS\whCC-MOTOR.exe tagged as not-a-virus:AdWare.WebHancer. No Action Taken.
File C:\WINDOWS\wt\wtbgm\wtbgmtt.exe tagged as not-a-virus:AdWare.WildTangent. No Action Taken.

Takker for point :)
Avatar billede forevernewbie Nybegynder
31. oktober 2004 - 23:48 #25
Tak for point :)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester