Avatar billede stry Nybegynder
07. maj 2005 - 15:48 Der er 13 kommentarer og
1 løsning

HijackThis log

Er der nogen der vil kigge på denne log?

På forhånd tak :-)

Logfile of HijackThis v1.99.1
Scan saved at 15:43:06, on 07-05-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\devldr32.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\MsPMSPSv.exe
F:\WINDOWS\system32\HotFixQ0306270.exe
H:\FingerprintMV\FPManager.exe
F:\WINDOWS\System32\Drivers\FPSAP\FD.exe
F:\WINDOWS\FG\FG.exe
H:\FingerprintMV\BioSecure\ZF.exe
H:\FingerprintMV\fpHide.exe
H:\FingerprintMV\BioLogin\AutoLogin.exe
H:\FreeRam\FreeRAM XP Pro 1.40.exe
H:\FingerprintMV\BioLock\FPLock.exe
H:\Folder View\folderview.exe
H:\Logitech\SetPoint\KEM.exe
F:\WINDOWS\StartupMonitor.exe
H:\WebMon\WebMon.exe
H:\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
H:\Logitech\SetPoint\KHALMNPR.EXE
H:\MOZILL~1\FIREFOX.EXE
H:\Logitech\iTouch\iTouch\iTouch.exe
f:\Program Files\Windows Media Player\wmplayer.exe
H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\sandra.exe
H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe
F:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
F:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
h:\bullguard\bdmcon.exe
H:\BullGuard\vsserv.exe
H:\Download\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/danskenetbank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/danskenetbank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - H:\FreshDevices\FreshDownload\fdcatch.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - F:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
O2 - BHO: (no name) - {9470E8E6-E19F-4675-9832-5DE295F77E89} - H:\FOLDER~2\fvhelper.dll
O2 - BHO: AL2Spy Class - {DC200356-0864-4F66-8964-5D43A19300F5} - F:\WINDOWS\system32\al2dll.dll
O3 - Toolbar: &Folder View - {DAF2C8C2-1CD1-48F8-A5C6-3B438127A8FD} - H:\FOLDER~2\fvband.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [zBrowser Launcher] H:\Logitech\iTouch\iTouch\iTouch.exe
O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [BDMCon] H:\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [PLFFAP] F:\WINDOWS\system32\HotFixQ0306270.exe
O4 - HKLM\..\Run: [BioManager] H:\FingerprintMV\FPManager.exe
O4 - HKLM\..\Run: [FD_SAP] F:\WINDOWS\System32\Drivers\FPSAP\FD.exe
O4 - HKLM\..\Run: [FG] F:\WINDOWS\FG\FG.exe
O4 - HKLM\..\Run: [ZF] H:\FingerprintMV\BioSecure\ZF.exe X X
O4 - HKLM\..\Run: [RunLogonUtility] "F:\WINDOWS\system32\LTool.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "H:\FreeRam\FreeRAM XP Pro 1.40.exe" -win
O4 - HKCU\..\Run: [Folder View] "H:\Folder View\folderview.exe"
O4 - Startup: Logitech SetPoint.lnk = H:\Logitech\SetPoint\KEM.exe
O4 - Startup: StartupMonitor.lnk = F:\WINDOWS\StartupMonitor.exe
O4 - Startup: WebMon.lnk = H:\WebMon\WebMon.exe
O4 - Startup: Yahoo! Desktop Search System Tray.lnk = H:\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra button: ID/Password AutoLogin - {D04AA3F7-DEE7-479B-A153-24E6C36300C0} - F:\WINDOWS\system32\al2dll.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.com.com
O15 - Trusted Zone: http://www.danskebank.dk
O15 - Trusted Zone: http://dk.trendmicro-europe.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O18 - Protocol: bw+0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - H:\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: copernicdesktopsearch - {D9656C75-5090-45C3-B27E-436FBC7ACFA7} - F:\PROGRA~1\COPERN~1\COPERN~2.DLL
O18 - Protocol: offline-8876480 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: BullGuard Scan Server (bdss) - Unknown owner - F:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe" /service (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe
O23 - Service: BullGuard Virus Shield (VSSERV) - Unknown owner - H:\BullGuard\vsserv.exe
O23 - Service: BullGuard Communicator (XCOMM) - Unknown owner - F:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe" /service (file missing)
Avatar billede kalp Novice
07. maj 2005 - 15:49 #1
ser på den
Avatar billede kalp Novice
07. maj 2005 - 15:58 #2
Du har en masse interessant installeret så hvad er følgende? eller rettere.. kender du disse programmer?

H:\FingerprintMV\
F:\WINDOWS\FG\
H:\Folder View
H:\WebMon\

Og så en enkelt fil
F:\WINDOWS\system32\LTool.exe

Download og gem denne scanner på skrivebordet. (Vi skal bruge den senere)
http://www.spywareinfo.dk/download/mwav.exe

Genstart i Fejlsikret tilstand ved at taste F8 under opstart.

Afinstaller eller slet disse programmer/mapper manuelt.

F:\PROGRA~1\COPERN~1\

Kør HijackThis, scan og sæt et flueben ud for disse linjer - luk øvrige programvinduer. Dobbelt tjeck alt kom med!. Klik herefter "Fix checked" i hijackthis:

O2 - BHO: AL2Spy Class - {DC200356-0864-4F66-8964-5D43A19300F5} - F:\WINDOWS\system32\al2dll.dll
O9 - Extra button: ID/Password AutoLogin - {D04AA3F7-DEE7-479B-A153-24E6C36300C0} - F:\WINDOWS\system32\al2dll.dll

Alle 018 linjerne. Altså disse
8 - Protocol: bw+0 - {B608EAAE-F1EB-4ED9-9351-D19C70AFD096} - H:\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: copernicdesktopsearch - {D9656C75-5090-45C3-B27E-436FBC7ACFA7} - F:\PROGRA~1\COPERN~1\COPERN~2.DLL
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Åbn Stifinder, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

Filen

F:\WINDOWS\system32\al2dll.dll

Gå herefter i Start -> Programmer -> Tilbehør -> Systemværktøjer -> Diskoprydning og slet temp-filer, temporary internet files og papirkurv.

Klik på mwav.exe som du hentede, programmet pakker sig selv ud og starter.
Sæt flueben i følgende:
Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende:
All local drives og Scan all files

Tryk start->kør og skriv "regedit"
marker denne computer i regedit vinduet.
Tryk rediger->søg og skriv "WinPcap"
slet alt du finder.

Genstart normalt og kopir en ny log herind så jeg kan se om vi fik ramt på det hele eller om noget er blevet overset:)
Avatar billede stry Nybegynder
07. maj 2005 - 16:03 #3
H:\FingerprintMV\
F:\WINDOWS\FG\
H:\Folder View
H:\WebMon\

Disse 4 kender jeg og det er ikke spyware.
LTool.exe kender jeg ikke umiddelbart, så jeg ved ikke om det er "snavs".
Avatar billede kalp Novice
07. maj 2005 - 16:05 #4
kan du lige højreklikke på LTool.exe og vælge egenskaber..se hvilket program den tilhøre
Avatar billede stry Nybegynder
07. maj 2005 - 16:17 #5
Filen findes ikke i den angivne mappe....mystisk.

Er "Copernic desktop search" spyware?
Avatar billede kalp Novice
07. maj 2005 - 16:19 #6
Åbn Stifinder, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

se om du kan finde filen herefter.

og nej Copernic desktop search er ikke spyware..
Avatar billede stry Nybegynder
07. maj 2005 - 16:24 #7
Den er der ikke, der kun en Ltool.ini fil.
Avatar billede kalp Novice
07. maj 2005 - 16:29 #8
hvad står der i den? jeg kan ikke finde noget på filen
Avatar billede stry Nybegynder
07. maj 2005 - 16:34 #9
===========================
[Logon]
CheckUpdate=1
Was_Update_Checked=Year2005 Month5 WeekD4 Day5
===========================

Skal jeg forsat slette de ting der vedrører Copernic desktop search?
Avatar billede kalp Novice
07. maj 2005 - 16:40 #10
vi venter med ltool filen.

Som sagt er copernic desktop ikke spyware så det er op til dig selv om du vil af med den:)
Avatar billede stry Nybegynder
07. maj 2005 - 19:33 #11
Så er virusscanningen færdig og her kommer den nye Hijack - log:

Logfile of HijackThis v1.99.1
Scan saved at 19:30:07, on 07-05-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\devldr32.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\MsPMSPSv.exe
F:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
F:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
H:\Logitech\iTouch\iTouch\iTouch.exe
H:\BullGuard\bdmcon.exe
F:\WINDOWS\system32\HotFixQ0306270.exe
H:\FingerprintMV\FPManager.exe
F:\WINDOWS\System32\Drivers\FPSAP\FD.exe
F:\WINDOWS\FG\FG.exe
H:\FreeRam\FreeRAM XP Pro 1.40.exe
H:\FingerprintMV\fpHide.exe
H:\Folder View\folderview.exe
H:\FingerprintMV\BioSecure\ZF.exe
H:\FingerprintMV\BioLogin\AutoLogin.exe
H:\BullGuard\vsserv.exe
H:\FingerprintMV\BioLock\FPLock.exe
H:\Logitech\SetPoint\KEM.exe
F:\WINDOWS\StartupMonitor.exe
H:\WebMon\WebMon.exe
H:\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
F:\WINDOWS\system32\wuauclt.exe
H:\Logitech\SetPoint\KHALMNPR.EXE
H:\Mozilla Firefox\firefox.exe
H:\Download\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/danskenetbank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/danskenetbank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - H:\FreshDevices\FreshDownload\fdcatch.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - F:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
O2 - BHO: (no name) - {9470E8E6-E19F-4675-9832-5DE295F77E89} - H:\FOLDER~2\fvhelper.dll
O3 - Toolbar: &Folder View - {DAF2C8C2-1CD1-48F8-A5C6-3B438127A8FD} - H:\FOLDER~2\fvband.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [zBrowser Launcher] H:\Logitech\iTouch\iTouch\iTouch.exe
O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [BDMCon] H:\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [PLFFAP] F:\WINDOWS\system32\HotFixQ0306270.exe
O4 - HKLM\..\Run: [BioManager] H:\FingerprintMV\FPManager.exe
O4 - HKLM\..\Run: [FD_SAP] F:\WINDOWS\System32\Drivers\FPSAP\FD.exe
O4 - HKLM\..\Run: [FG] F:\WINDOWS\FG\FG.exe
O4 - HKLM\..\Run: [ZF] H:\FingerprintMV\BioSecure\ZF.exe X X
O4 - HKCU\..\Run: [FreeRAM XP] "H:\FreeRam\FreeRAM XP Pro 1.40.exe" -win
O4 - HKCU\..\Run: [Folder View] "H:\Folder View\folderview.exe"
O4 - Startup: Logitech SetPoint.lnk = H:\Logitech\SetPoint\KEM.exe
O4 - Startup: StartupMonitor.lnk = F:\WINDOWS\StartupMonitor.exe
O4 - Startup: WebMon.lnk = H:\WebMon\WebMon.exe
O4 - Startup: Yahoo! Desktop Search System Tray.lnk = H:\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.com.com
O15 - Trusted Zone: http://www.danskebank.dk
O15 - Trusted Zone: http://dk.trendmicro-europe.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: BullGuard Scan Server (bdss) - Unknown owner - F:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe" /service (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Pinnacle Systems GmbH - (no file)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe
O23 - Service: BullGuard Virus Shield (VSSERV) - Unknown owner - H:\BullGuard\vsserv.exe
O23 - Service: BullGuard Communicator (XCOMM) - Unknown owner - F:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe" /service (file missing)
Avatar billede kalp Novice
07. maj 2005 - 20:46 #12
Genstart i fejlsikret tilstand

Tryk start->kør og skriv "regedit"
marker denne computer i regedit vinduet.
Tryk rediger->søg og skriv "rpcapd"
slet alt du finder.

Fix denne i hijackthis

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Pinnacle Systems GmbH - (no file)

fandt mwav scanneren noget?
Avatar billede stry Nybegynder
07. maj 2005 - 22:24 #13
mwav scanneren fandt ikke nogle vira men noget "Riskware" (VNC o.l.) som den ikke gjorde noget ved.

Regedit fandt en del med "rpcapd" som jeg har slettet men også "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_RPCAPD" som jeg ikke kan få lov at slette, er det et problem?

Jeg kan heller ikke få HJT til at slette de to 023-linier med "missing files"


Logfile of HijackThis v1.99.1
Scan saved at 22:11:54, on 07-05-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\devldr32.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\MsPMSPSv.exe
F:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
F:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
H:\Logitech\iTouch\iTouch\iTouch.exe
H:\BullGuard\bdmcon.exe
F:\WINDOWS\system32\HotFixQ0306270.exe
H:\FingerprintMV\FPManager.exe
F:\WINDOWS\System32\Drivers\FPSAP\FD.exe
F:\WINDOWS\FG\FG.exe
H:\FingerprintMV\BioSecure\ZF.exe
H:\FreeRam\FreeRAM XP Pro 1.40.exe
H:\Folder View\folderview.exe
H:\FingerprintMV\fpHide.exe
H:\BullGuard\vsserv.exe
H:\FingerprintMV\BioLogin\AutoLogin.exe
H:\FingerprintMV\BioLock\FPLock.exe
H:\Logitech\SetPoint\KEM.exe
F:\WINDOWS\StartupMonitor.exe
H:\WebMon\WebMon.exe
H:\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
F:\WINDOWS\system32\wuauclt.exe
H:\Logitech\SetPoint\KHALMNPR.EXE
H:\Download\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/danskenetbank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/danskenetbank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - H:\FreshDevices\FreshDownload\fdcatch.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - F:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
O2 - BHO: (no name) - {9470E8E6-E19F-4675-9832-5DE295F77E89} - H:\FOLDER~2\fvhelper.dll
O3 - Toolbar: &Folder View - {DAF2C8C2-1CD1-48F8-A5C6-3B438127A8FD} - H:\FOLDER~2\fvband.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [zBrowser Launcher] H:\Logitech\iTouch\iTouch\iTouch.exe
O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [BDMCon] H:\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [PLFFAP] F:\WINDOWS\system32\HotFixQ0306270.exe
O4 - HKLM\..\Run: [BioManager] H:\FingerprintMV\FPManager.exe
O4 - HKLM\..\Run: [FD_SAP] F:\WINDOWS\System32\Drivers\FPSAP\FD.exe
O4 - HKLM\..\Run: [FG] F:\WINDOWS\FG\FG.exe
O4 - HKLM\..\Run: [ZF] H:\FingerprintMV\BioSecure\ZF.exe X X
O4 - HKCU\..\Run: [FreeRAM XP] "H:\FreeRam\FreeRAM XP Pro 1.40.exe" -win
O4 - HKCU\..\Run: [Folder View] "H:\Folder View\folderview.exe"
O4 - Startup: Logitech SetPoint.lnk = H:\Logitech\SetPoint\KEM.exe
O4 - Startup: StartupMonitor.lnk = F:\WINDOWS\StartupMonitor.exe
O4 - Startup: WebMon.lnk = H:\WebMon\WebMon.exe
O4 - Startup: Yahoo! Desktop Search System Tray.lnk = H:\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.com.com
O15 - Trusted Zone: http://www.danskebank.dk
O15 - Trusted Zone: http://dk.trendmicro-europe.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: BullGuard Scan Server (bdss) - Unknown owner - F:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe" /service (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - H:\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe
O23 - Service: BullGuard Virus Shield (VSSERV) - Unknown owner - H:\BullGuard\vsserv.exe
O23 - Service: BullGuard Communicator (XCOMM) - Unknown owner - F:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe" /service (file missing)
Avatar billede kalp Novice
07. maj 2005 - 22:33 #14
læs om tilladelser i registry
http://www.eksperten.dk/artikler/683

og slet den:)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester