Avatar billede jerrysvendborg Nybegynder
23. april 2005 - 15:02 Der er 21 kommentarer og
1 løsning

Fjerne Hotoffer.com

Hej
Jeg har virus. Ved Scanning med Spybot blev der konstateret, DyFuCA, Spyblocks link og Elitum.Elitebar.
Spybot kan ikke fjerne dem.
Jeg fandt i panik nogen programmer på nettet som umiddelbart har fjernet DyFuCA og Elitum. Spyblocks fjernes for at dukke op med det samme igen og smider 20 genveje af tvivlsom indhold på skrivebordet,
Hvordan fjerner jeg uhyret?
Avatar billede thesurfer Nybegynder
23. april 2005 - 15:53 #1
Følg instruktionerne: http://www.eksperten.dk/artikler/127
Avatar billede jerrysvendborg Nybegynder
23. april 2005 - 18:05 #2
Må jeg lige stille et nok tåbeligt spørgsmål....jeg har gjort det hele og har en log liggende i notesblok...hvordan får jeg den kopieret og lagt ind her? :-)
Avatar billede thesurfer Nybegynder
23. april 2005 - 18:13 #3
Du skal bare markerer hele teksten, vælg menuen Rediger, og derefter kopier.
Så hopper du her over, klikker i kommentar/tekst-feltet, vælger menuen Rediger og derefter sæt ind (eller "indsæt).

Du kan også bare bruge CTRL+C (hold CTRL knappen nede, og tryk på C-tasten) til at kopiere, og CTRL+V til at sætte ind.
Avatar billede kalp Novice
23. april 2005 - 20:28 #4
Download hijackthis herfra og gem det i en folder for sig selv på dit skrivebord

http://downloadportal.dk/showdownload.asp?rid=3967&sp=Hijackthis%201.91
eller et direkte download link herfra www.arlet.dk/hjt.exe

Start programmet og vælge, at udføre en scan samt gemme en log fil.
Når hijackthis er færdig med, at scanne vil den bede dig om en placering hvor du vil gemme "hijackthis" en tekst fil.
Gem den i samme folder som hijackthis. Når du har sagt okay hopper der et nyt vindue frem nemlig notepad med en masse tekst linjer. Marker alle linjerne og kopir dem herind så jeg kan kigge på dem. Du må ikke selv begynde, at fikse noget i hijackthis.
Avatar billede jerrysvendborg Nybegynder
23. april 2005 - 23:45 #5
Hej igen nu tror jeg det går...havde glemt hvordan man gjorde
Logfile of HijackThis v1.99.1
Scan saved at 17:51:58, on 04/23/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WIND\System32\smss.exe
D:\WIND\system32\csrss.exe
D:\WIND\system32\winlogon.exe
D:\WIND\system32\services.exe
D:\WIND\system32\lsass.exe
D:\WIND\system32\svchost.exe
D:\WIND\System32\svchost.exe
D:\Programmer\Sygate\SPF\smc.exe
D:\WIND\System32\svchost.exe
D:\WIND\System32\svchost.exe
D:\WIND\system32\spoolsv.exe
D:\WIND\Explorer.EXE
D:\WIND\System32\spool\drivers\w32x86\3\hpztsb06.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Programmer\Odigo\Bin\Odigo.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\WIND\System32\svchost.exe
D:\Programmer\TuneUp Utilities 2004\MemOptimizer.exe
C:\Program Files\PDF\pdfSaver\pdfSaver3.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\WIND\System32\ctfmon.exe
D:\Programmer\Spyware Doctor\swdoctor.exe
D:\WIND\System32\spool\DRIVERS\W32X86\3\HPZENG07.EXE
D:\WIND\System32\devldr32.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
D:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
D:\Programmer\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
D:\WIND\System32\wbem\wmiprvse.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
D:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe
D:\Programmer\Odigo\Bin\obrw.exe
D:\Documents and Settings\Ejer\Skrivebord\Hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.50.191.53/search.cgi?b11001
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://69.50.191.53/search.cgi?a11001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.50.191.53/search.cgi?b11001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://69.50.191.53/search.cgi?a11001
F2 - REG:system.ini: UserInit=D:\WIND\System32\Userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn2\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: IEHelperObj Class - {6754A456-BAD9-11D4-93D3-00B0D03A2F91} - D:\PROGRA~1\Odigo\Bin\OdigoBHO.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - D:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WIND\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] D:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [RunOdigo] D:\Programmer\Odigo\Bin\Odigo.exe -m
O4 - HKLM\..\Run: [Easy-PrintToolBox] D:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [THGuard] "D:\Programmer\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "D:\Programmer\TuneUp Utilities 2004\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [pdfSaver3] "c:\Program Files\PDF\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WIND\System32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Vanisher] D:\Programmer\FreeScanner.exe -FastScan
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Programmer\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = D:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = D:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = D:\Programmer\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoftofficeny\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Programmer\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Bloker alle billeder fra den samme server - D:\Programmer\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Marker forekomster af ord på denne side - D:\Programmer\Avant Browser\Highlight.htm
O8 - Extra context menu item: Søg på ord - D:\Programmer\Avant Browser\Search.htm
O8 - Extra context menu item: Tilføj til Ad Blocker - D:\Programmer\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Programmer\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Programmer\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Åben alle links på denne side... - D:\Programmer\Avant Browser\OpenAllLinks.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Programmer\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Programmer\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O15 - Trusted Zone: *.dapsol.com
O15 - Trusted Zone: *.bestsearch.cc (HKLM)
O15 - Trusted Zone: *.dapsol.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NDdapter (NDIS Layer Transport Device) - Unknown owner - D:\WIND\System32\D:\WIND\System32\D:\WIND\System32\D:\WIND\System32\forbot.exe" -netsvcs (file missing)
O23 - Service: Pml Driver HPZ12 - HP - D:\WIND\System32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - D:\Programmer\Sygate\SPF\smc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\Programmer\TuneUp Utilities 2004\WinStylerThemeSvc.exe
Avatar billede kalp Novice
23. april 2005 - 23:51 #6
Download DelDomains.inf
http://www.mvps.org/winhelp2002/DelDomains.inf
eller
http://www.greyknight17.com/spy/DelO15Domains.inf

Højreklik på DelDomains.inf og vælg: Install

Genstart i Fejlsikret tilstand ved at taste F8 under opstart.

Kør HijackThis, scan og sæt et flueben ud for disse linjer - luk øvrige programvinduer. Dobbelt tjeck alt kom med!. Klik herefter "Fix checked" i hijackthis:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.50.191.53/search.cgi?b11001
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://69.50.191.53/search.cgi?a11001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.50.191.53/search.cgi?b11001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://69.50.191.53/search.cgi?a11001
F2 - REG:system.ini: UserInit=D:\WIND\System32\Userinit.exe
O4 - HKCU\..\Run: [Spyware Vanisher] D:\Programmer\FreeScanner.exe -FastScan
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O23 - Service: NDdapter (NDIS Layer Transport Device) - Unknown owner - D:\WIND\System32\D:\WIND\System32\D:\WIND\System32\D:\WIND\System32\forbot.exe" -netsvcs (file missing)

Slet denne fil

D:\Programmer\FreeScanner.exe

Gå herefter i Start -> Programmer -> Tilbehør -> Systemværktøjer -> Diskoprydning og slet temp-filer, temporary internet files og papirkurv.

Tryk start->kør og skriv "regedit"
marker denne computer i regedit vinduet
tryk rediger-> søg og skriv "forbot.exe"
slet alt du finder.
Luk regedit vinduet igen.

Genstart normalt og kopir en ny log herind så jeg kan se om vi fik ramt på det hele eller om noget er blevet overset:)
Avatar billede fromsej Praktikant
24. april 2005 - 00:04 #7
Jeg ved ikke om du kender denne Kalp:
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
Den er lige til at lukke op og puste grise i.

Spyware Killer 1spywarekiller.com
surfertools.com false positives work as goad to purchase; poor scan reporting; dubious corp. associations (1); same app as  Max Privacy Protector, SpyDoctor, SpyFirewall, Spyinator, SpyKiller 2005, SpyLax, SpySpotter, SpywareThis, & Spyware Protection Pro; Ad-aware knockoff [A: 10-5-04 / U: 2-7-05]
Avatar billede kalp Novice
24. april 2005 - 00:06 #8
*G* well så fix da også den med:) dvs. sæt blot flueben ud for den sammen med de andre jeg har bedt dig om fjerne:)
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 02:16 #9
Kommer lige tilbage i morgen...ok
Avatar billede kalp Novice
24. april 2005 - 08:57 #10
yes yes
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 09:37 #11
Logfile of HijackThis v1.99.1
Scan saved at 09:31:03, on 04/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WIND\System32\smss.exe
D:\WIND\system32\csrss.exe
D:\WIND\system32\winlogon.exe
D:\WIND\system32\services.exe
D:\WIND\system32\lsass.exe
D:\WIND\system32\svchost.exe
D:\WIND\System32\svchost.exe
D:\Programmer\Sygate\SPF\smc.exe
D:\WIND\System32\svchost.exe
D:\WIND\System32\svchost.exe
D:\WIND\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\WIND\System32\svchost.exe
D:\WIND\Explorer.EXE
D:\WIND\System32\spool\drivers\w32x86\3\hpztsb06.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Programmer\Odigo\Bin\Odigo.exe
D:\Programmer\TuneUp Utilities 2004\MemOptimizer.exe
C:\Program Files\PDF\pdfSaver\pdfSaver3.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\WIND\System32\ctfmon.exe
D:\Programmer\Spyware Doctor\swdoctor.exe
D:\WIND\System32\devldr32.exe
D:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
D:\WIND\System32\wbem\wmiprvse.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
D:\Programmer\Odigo\Bin\obrw.exe
D:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
D:\Programmer\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
D:\Programmer\Yahoo!\Messenger\yupdater.exe
D:\WIND\System32\wuauclt.exe
D:\Programmer\Yahoo!\Messenger\ymsgr_tray.exe
D:\Documents and Settings\Ejer\Skrivebord\Hijackthis\hijackthis.exe

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn2\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: IEHelperObj Class - {6754A456-BAD9-11D4-93D3-00B0D03A2F91} - D:\PROGRA~1\Odigo\Bin\OdigoBHO.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - D:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WIND\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] D:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [RunOdigo] D:\Programmer\Odigo\Bin\Odigo.exe -m
O4 - HKLM\..\Run: [Easy-PrintToolBox] D:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [THGuard] "D:\Programmer\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "D:\Programmer\TuneUp Utilities 2004\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [pdfSaver3] "c:\Program Files\PDF\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WIND\System32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Programmer\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Programmer\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = D:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = D:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = D:\Programmer\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoftofficeny\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Programmer\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Bloker alle billeder fra den samme server - D:\Programmer\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Marker forekomster af ord på denne side - D:\Programmer\Avant Browser\Highlight.htm
O8 - Extra context menu item: Søg på ord - D:\Programmer\Avant Browser\Search.htm
O8 - Extra context menu item: Tilføj til Ad Blocker - D:\Programmer\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Programmer\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Programmer\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Åben alle links på denne side... - D:\Programmer\Avant Browser\OpenAllLinks.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Programmer\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Programmer\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WIND\System32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - D:\Programmer\Sygate\SPF\smc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\Programmer\TuneUp Utilities 2004\WinStylerThemeSvc.exe

Hej....men jeg har stadig den røde cirkel med krydset i bundlinien og advarsel om spyware m.v.  I Regedit forbot.ece kunne jeg ikke slette der hvor der stod Standard Reg_SZ
ved ikke om det betyder noget
Avatar billede kalp Novice
24. april 2005 - 09:42 #12
hvorfor kunne den ikke slettes? ikke at det er årsagen til du stadig har meddelelsen.

men ja så bliver jeg nød til at spørge til

D:\Programmer\Odigo

hvad det er.. for at sikre mig den er lega.

Hent silentrunner her:
http://www.silentrunners.org/Silent%20Runners.vbs

og send mig en log med den.
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 09:46 #13
Odigo er et chatprogram jeg har haft i mange år. Medens jeg skrev her til dig nu væltede Hotoffersiden ind i hovedet på mig igen så jeg måtte starte forfra.
Jeg kører silentfilen med en ny log
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 09:50 #14
"Silent Runners.vbs", revision 35, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"TuneUp MemOptimizer" = ""D:\Programmer\TuneUp Utilities 2004\MemOptimizer.exe" autostart" ["TuneUp Software GmbH"]
"pdfSaver3" = ""c:\Program Files\PDF\pdfSaver\pdfSaver3.exe"" ["Tracker Software Products Ltd."]
"msnmsgr" = ""D:\Programmer\MSN Messenger\msnmsgr.exe" /background" [MS]
"CTFMON.EXE" = "D:\WIND\System32\ctfmon.exe" [MS]
"Spyware Doctor" = ""D:\Programmer\Spyware Doctor\swdoctor.exe" /Q" ["PCTools"]
"Yahoo! Pager" = "D:\Programmer\Yahoo!\Messenger\ypager.exe -quiet" ["Yahoo! Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"HPDJ Taskbar Utility" = "D:\WIND\System32\spool\drivers\w32x86\3\hpztsb06.exe" ["HP"]
"AVG7_CC" = "D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"SmcService" = "D:\PROGRA~1\Sygate\SPF\smc.exe -startgui" ["Sygate Technologies, Inc."]
"RunOdigo" = "D:\Programmer\Odigo\Bin\Odigo.exe -m" ["Odigo"]
"Easy-PrintToolBox" = "D:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon" ["CANON INC."]
"THGuard" = ""D:\Programmer\TrojanHunter 4.2\THGuard.exe"" ["Mischel Internet Security"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA05670}\(Default) = "Yahoo! Companion BHO" [from CLSID]
  -> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn2\ycomp5_5_7_0.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
  -> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}\(Default) = "PCTools Site Guard" [from CLSID]
  -> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll" ["PC Tools"]
{6754A456-BAD9-11D4-93D3-00B0D03A2F91}\(Default) = "IEHelperObj Class" [from CLSID]
  -> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\Odigo\Bin\OdigoBHO.dll" ["Odigo"]
{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\(Default) = "ST" [from CLSID]
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll" [MS]
{B56A7D7D-6927-48C8-A975-17DF180C71AC}\(Default) = "PCTools Browser Monitor" [from CLSID]
  -> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll" ["GuideWorks Pty. Ltd."]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = "MSNToolBandBHO" [from CLSID]
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Kontrolpanel-udvidelse til skærmpanorering"
  -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal-ikon"
  -> {CLSID}\InProcServer32\(Default) = "D:\WIND\System32\hticons.dll" ["Hilgraeve, Inc."]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
  -> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\Yahoo!\Common\ymmapi.dll" ["Yahoo! Inc."]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
  -> {CLSID}\InProcServer32\(Default) = "D:\Microsoftofficeny\Office10\msohev.dll" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
  -> {CLSID}\InProcServer32\(Default) = "D:\Microsoftofficeny\Office10\OLKFSTUB.DLL" [MS]
"{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}" = "TuneUp Shredder Shell Context Menu Extension"
  -> {CLSID}\InProcServer32\(Default) = ""D:\Programmer\TuneUp Utilities 2004\sdshelex.dll"" ["TuneUp Software GmbH"]
"{F802F260-519B-11D1-BB5D-0060974C6013}" = "ICQ Shell Extension"
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\ICQ\ICQShExt.dll" ["ICQ"]
"{FED7043D-346A-414D-ACD7-550D052499A7}" = "dBpowerAMP Music Converter 1"
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\Illustrate\dBpowerAMP\dBShell.dll" [empty string]
"{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5}" = "dBpowerAMP Music Converter"
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\Illustrate\dBpowerAMP\dMCShell.dll" [empty string]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
  -> {CLSID}\InProcServer32\(Default) = "D:\WIND\System32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
  -> {CLSID}\InProcServer32\(Default) = "D:\WIND\System32\Audiodev.dll" [MS]
"{acb4a560-3606-11d3-aef4-00104bd0f92d}" = "KodakShellExtension"
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\Fælles filer\KODAK\IFSCore\kodakshx.dll" ["Eastman Kodak Company"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
INFECTION WARNING! "{D56A1203-1452-EBA1-7294-EE3377770000}" = "Interlinking Memory Support"
  -> {CLSID}\InProcServer32\(Default) = "D:\WIND\System32\param32.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{9EF34FF2-3396-4527-9D27-04C8C1C67806}" = "Microsoft AntiSpyware Service Hook"
  -> {CLSID}\InProcServer32\(Default) = "D:\Programmer\Microsoft AntiSpyware\shellextension.dll" [MS]

HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
"load" = (value not set)
"run" = (value not set)

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
"AppInit_DLLs" = (value not set)


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "D:\WIND\System32\ssflwbox.scr" [MS]


Enabled Wallpaper and Active Desktop:
-------------------------------------

Active Desktop is disabled.

HKCU\Control Panel\Desktop\
"Wallpaper" = "D:\Documents and Settings\Ejer\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp"
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 09:51 #15
Var det den.....eller en ny fra Hijackthis?
Avatar billede kalp Novice
24. april 2005 - 09:52 #16
Det var den.. og har fundet slynglen.. 2 sek.
Avatar billede kalp Novice
24. april 2005 - 09:55 #17
Genstart i Fejlsikret tilstand ved at taste F8 under opstart.

Åbn Stifinder, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".


Slet disse filer

Disse burde ikke volde dig problemer.

guninst.exe
popup_bl.dll


Denne kan være besværlig.. evt. omdøb den først.. genstart og slet den så.
eller slet den via. http://www.spywareinfo.dk/download/KillBox.zip
så forsvinder den!

param32.dll

Alle filerne ligger nok herinde.

D:\WIND\System32\

men ellers søg på filnavnene

Genstart normalt og ny hijackthis log.

Ps. det er dem som holder Hotoffer siden i live.
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 10:00 #18
ok...kommer tilbage
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 10:27 #19
Ved opstart er der ingen røde cirkler og..heller ingen andre dårlige ting.....fandt alle filerne og omdøbte den sidste fordi jeg ikke kunne slette i første omgang som du sagde....nu er den slettet. og her er så loggen...jeg krydser fingre :-)
Logfile of HijackThis v1.99.1
Scan saved at 10:24:32, on 04/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WIND\System32\smss.exe
D:\WIND\system32\csrss.exe
D:\WIND\system32\winlogon.exe
D:\WIND\system32\services.exe
D:\WIND\system32\lsass.exe
D:\WIND\system32\svchost.exe
D:\WIND\System32\svchost.exe
D:\Programmer\Sygate\SPF\smc.exe
D:\WIND\System32\svchost.exe
D:\WIND\System32\svchost.exe
D:\WIND\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\WIND\System32\svchost.exe
D:\WIND\Explorer.EXE
D:\WIND\System32\spool\drivers\w32x86\3\hpztsb06.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Programmer\TuneUp Utilities 2004\MemOptimizer.exe
C:\Program Files\PDF\pdfSaver\pdfSaver3.exe
D:\Programmer\MSN Messenger\msnmsgr.exe
D:\WIND\System32\ctfmon.exe
D:\Programmer\Spyware Doctor\swdoctor.exe
D:\WIND\System32\devldr32.exe
D:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
D:\WIND\System32\wbem\wmiprvse.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
D:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
D:\Programmer\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
D:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
D:\Programmer\Yahoo!\Messenger\ymsgr_tray.exe
D:\WIND\System32\wuauclt.exe
D:\Documents and Settings\Ejer\Skrivebord\Hijackthis\hijackthis.exe

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn2\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: IEHelperObj Class - {6754A456-BAD9-11D4-93D3-00B0D03A2F91} - D:\PROGRA~1\Odigo\Bin\OdigoBHO.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - D:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WIND\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] D:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [RunOdigo] D:\Programmer\Odigo\Bin\Odigo.exe -m
O4 - HKLM\..\Run: [Easy-PrintToolBox] D:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [THGuard] "D:\Programmer\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "D:\Programmer\TuneUp Utilities 2004\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [pdfSaver3] "c:\Program Files\PDF\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WIND\System32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Programmer\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Programmer\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = D:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = D:\Programmer\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = D:\Programmer\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoftofficeny\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Programmer\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Bloker alle billeder fra den samme server - D:\Programmer\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Marker forekomster af ord på denne side - D:\Programmer\Avant Browser\Highlight.htm
O8 - Extra context menu item: Søg på ord - D:\Programmer\Avant Browser\Search.htm
O8 - Extra context menu item: Tilføj til Ad Blocker - D:\Programmer\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Programmer\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Programmer\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Åben alle links på denne side... - D:\Programmer\Avant Browser\OpenAllLinks.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Programmer\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Programmer\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WIND\System32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - D:\Programmer\Sygate\SPF\smc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\Programmer\TuneUp Utilities 2004\WinStylerThemeSvc.exe
Avatar billede kalp Novice
24. april 2005 - 10:30 #20
Loggen er ren:) problem solved:)

Det var de sidste 3 filer som var skyld i dit problem.. genkendte "param32.dll" fra en tråd i går hvor jeg stødte på den for første gang:) der havde jeg været igennem en log fra et program kaldet dllcompare som ikke kunne finde "param32.dll" filen.

Men det godt udvalget af værktøjer er stort:) vi fik da ram på det:P
Avatar billede jerrysvendborg Nybegynder
24. april 2005 - 10:37 #21
Hej.......fantastisk godt....5 stjerner til dig....hvis 5 er det højeste så er det dine.
Jeg var lige på nippet til at formatere harddisk og hele balladen i går....TAKKKKKKKKKKK
Avatar billede kalp Novice
24. april 2005 - 10:41 #22
Selv tak:)) det var da hyggeligt nok hehe

for at lukke spørgsmålet skal du markere mit navn helt nede i venstre hjørne og trykke på accepter:) kan se du en ny bruger så det viste du sikkert ikke:)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester