Hjælp til Hi-Jack This Log
Da jeg startede computeren op her til morgen, er der pludselig en sort baggrund med teksten:"Warning! Your computer might be infected with spyware or adware!!!" Og så står der noget om at man skal downloade spyware removal software osv. Har selvfølgelig ikke klikket på linket, men det undrer mig at det kan komme ind, for jeg har både Windows Firewall (Og det er SP2), Norton Antivirus & Firewall samt Sygate Firewall!
Har så kørt Hi-Jack This med følgende resultat:
Logfile of HijackThis v1.99.1
Scan saved at 09:49:49, on 13-08-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammerTGTSoftStyleXPStyleXPService.exe
F:ProgrammerSygateSPFsmc.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32shnlog.exe
C:WINDOWSpopuper.exe
C:WINDOWSsystem32msole32.exe
C:WINDOWSSOUNDMAN.EXE
F:ProgrammerABITABIT uGuruuGuru.exe
F:ProgrammerMessenger Plus! 3MsgPlus.exe
C:WINDOWSsystem32intmonp.exe
F:ProgrammerLogitechiTouchiTouch.exe
F:ProgrammerLogitechMouseWaresystemem_exec.exe
F:ProgrammerD-Toolsdaemon.exe
F:ProgrammerABITABIT uGuruuGuru_Event_Receiver.exe
F:PROGRA~1NORTON~1 avapw32.exe
C:WINDOWSsystem32intmon.exe
F:ProgrammerNorton Internet SecurityIAMAPP.EXE
F:ProgrammerQuickTimeqttask.exe
C:ProgrammerLogitechVideoLogiTray.exe
F:ProgrammerCyberLinkPowerDVDPDVDServ.exe
C:WINDOWSsystem32 undll32.exe
C:ProgrammerSaveSave.exe
F:ProgrammerPinnaclePCTV USB2RemoteRemoterm.exe
F:ProgrammerWinampwinampa.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:WINDOWSsystem32ctfmon.exe
C:ApacheApache.exe
C:ProgrammerMSN Messengermsnmsgr.exe
C:ProgrammerVIARAID aid_tool.exe
F:ProgrammerBilliontonBluetooth-softwareintwdins.exe
C:WINDOWSsystem32LVComS.exe
C:WINDOWSsystem32driversCDAC11BA.EXE
F:ProgrammerBilliontonBluetooth-softwareBTTray.exe
C:ProgrammerPinnacleShared FilesProgramsSchedulerPCLEScheduler.exe
F:ProgrammerNorton AntiVirus avapsvc.exe
F:ProgrammerNorton Internet SecurityNISUM.EXE
F:ProgrammermausWay2k.exe
C:WINDOWSsystem32 vsvc32.exe
C:WINDOWSsystem32svchost.exe
F:ProgrammerNorton Internet SecuritySymProxySvc.exe
C:ApacheApache.exe
F:ProgrammerNorton Internet SecurityNISSERV.EXE
C:ProgrammerFælles filerSymantec SharedSecurity CenterSymWSC.exe
C:ProgrammerMessengermsmsgs.exe
D:Dokumenter(Heino)exe- og ace-filerhijackthisHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.bestwebslinks.com/search.php?qq=%1
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.bestwebslinks.com/bar.html
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.bestwebslinks.com/search.php?qq=%1
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.bestwebslinks.com/search.php?qq=%1
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://www.bestwebslinks.com/search.php?qq=%1
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://www.bestwebslinks.com/search.php?qq=%1
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = http://www.bestwebslinks.com/
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSSYSTEMlank.htm
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe
O2 - BHO: HP Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:WINDOWSsystem32hp4778.tmp
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:ProgrammerNorton AntiVirusNavShExt.dll (file missing)
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [ABIT uGuru] F:ProgrammerABITABIT uGuruuGuru.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [MessengerPlus3] "F:ProgrammerMessenger Plus! 3MsgPlus.exe"
O4 - HKLM..Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM..Run: [zBrowser Launcher] F:ProgrammerLogitechiTouchiTouch.exe
O4 - HKLM..Run: [DAEMON Tools-1033] "F:ProgrammerD-Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [LogitechVideoRepair] C:ProgrammerLogitechVideoISStart.exe
O4 - HKLM..Run: [NAV Agent] F:PROGRA~1NORTON~1 avapw32.exe
O4 - HKLM..Run: [iamapp] F:ProgrammerNorton Internet SecurityIAMAPP.EXE
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [SmcService] F:PROGRA~1SygateSPFsmc.exe -startgui
O4 - HKLM..Run: [QuickTime Task] "F:ProgrammerQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe /Consumer
O4 - HKLM..Run: [LogitechVideoTray] C:ProgrammerLogitechVideoLogiTray.exe
O4 - HKLM..Run: [RemoteControl] F:ProgrammerCyberLinkPowerDVDPDVDServ.exe
O4 - HKLM..Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM..Run: [WhenUSave] "C:ProgrammerSaveSave.exe"
O4 - HKLM..Run: [PCTVUSB2Remote] F:ProgrammerPinnaclePCTV USB2RemoteRemoterm.exe
O4 - HKLM..Run: [WinampAgent] F:ProgrammerWinampwinampa.exe
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [RegSvr32] C:WINDOWSsystem32msmsgs.exe
O4 - HKLM..Run: [intell32.exe] C:WINDOWSsystem32intell32.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MessengerPlus3] "F:ProgrammerMessenger Plus! 3MsgPlus.exe" /WinStart
O4 - HKCU..Run: [STYLEXP] C:ProgrammerTGTSoftStyleXPStyleXP.exe -Hide
O4 - HKCU..Run: [MSMSGS] "C:ProgrammerMessengermsmsgs.exe" /background
O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background
O4 - Startup: Samurize.lnk = F:ProgrammerSamurizeClient.exe
O4 - Startup: mausWay2k.lnk = F:ProgrammermausWay2k.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:ProgrammerLogitechDesktop Messenger8876480ProgramLDMConf.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:ProgrammerVIARAID aid_tool.exe
O4 - Global Startup: Microsoft Office.lnk = F:ProgrammerMicrosoft OfficeOfficeOSA9.EXE
O4 - Global Startup: Symantec WinFax Starter Port.lnk = F:ProgrammerMicrosoft OfficeOffice1030OLFSNT40.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Pinnacle Scheduler.lnk = ?
O8 - Extra context menu item: Send til &Bluetooth - F:ProgrammerBilliontonBluetooth-softwaretsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:ProgrammerBilliontonBluetooth-softwaretsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:ProgrammerBilliontonBluetooth-softwaretsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O12 - Plugin for .spop: C:ProgrammerInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab3...
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStat...
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/ClickYesToContin...
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.c...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStat...
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://www.kortal.dk/ecwplugins/ncs.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetu...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab328...
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShow...
O23 - Service: Apache - Unknown owner - C:ApacheApache.exe" --ntservice (file missing)
O23 - Service: Apache2 - Unknown owner - C:apacheApache2inApache.exe" -k runservice (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - F:ProgrammerBilliontonBluetooth-softwareintwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:WINDOWSsystem32driversCDAC11BA.EXE
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - F:ProgrammerNorton AntiVirus avapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - F:ProgrammerNorton Internet SecurityNISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - F:ProgrammerNorton Internet SecurityNISUM.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32 vsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%WinPcap pcapd.exe" -d -f "%ProgramFiles%WinPcap pcapd.ini (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:PROGRA~1FÆLLES~1SYMANT~1SCRIPT~1SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - F:ProgrammerSygateSPFsmc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:ProgrammerFælles filerSymantec SharedSNDSrvc.exe
O23 - Service: StyleXPService - Unknown owner - C:ProgrammerTGTSoftStyleXPStyleXPService.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - F:ProgrammerNorton Internet SecuritySymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:ProgrammerFælles filerSymantec SharedSecurity CenterSymWSC.exe
Hvad skal jeg gøre for at reparere det? Har slettet alle de steder hvor der står noget med http://www.bestweblinks.com, men de kommer bare igen! Hjælp!
