Avatar billede dallezuper Nybegynder
13. december 2005 - 17:28 Der er 29 kommentarer og
1 løsning

Underlig virus eller trojan?

Hejsa,

Min brors computer er blevet infected. Den popper op med alt muligt og viser ikoner i startlinien.

Når jeg fjerner med adaware, så kommer den igen ved genstart.
Jeg har fået fantstisk god hjælp før så håber at jeg igen kan få en ren computer.

Hijack This loggen ser sådan her ud:

Logfile of HijackThis v1.99.1

Scan saved at 17:26:06, on 13/12/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Programmer\Canon\BJCard\Bjmcmng.exe

C:\WINDOWS\System32\gearsec.exe

C:\Programmer\Norton Utilities\NPROTECT.EXE

C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe

C:\Programmer\Speed Disk\nopdb.exe

C:\WINDOWS\System32\svchost.exe

C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

C:\WINDOWS\system32\nvctrl.exe

C:\WINDOWS\system32\mssearchnet.exe

C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe

C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe

C:\Programmer\USB Product Driver v1.20r037\shwicon.exe

C:\Programmer\HP\HP Share-to-Web\hpgs2wnd.exe

C:\PROGRA~1\NORTON~1\navapw32.exe

C:\WINDOWS\System32\hphmon05.exe

C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe

C:\PROGRA~1\FLLESF~1\PCSuite\DATALA~1\DATALA~1.EXE

C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Programmer\HP\HP Share-to-Web\hpgs2wnf.exe

C:\Programmer\Apoint2K\Apoint.exe

C:\PROGRA~1\FLLESF~1\PCSuite\Services\SERVIC~1.EXE

C:\WINDOWS\AGRSMMSG.exe

C:\Programmer\HP\Digital Imaging\Unload\hpqcmon.exe

C:\Programmer\Canon\BJPV\TVMon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programmer\Avaya_Wireless\Client Manager\CMAVA.EXE

C:\Programmer\Apoint2K\Apntex.exe

C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe

C:\Programmer\Norton Utilities\SYSDOC32.EXE

C:\Programmer\MSN Messenger\msnmsgr.exe

C:\Programmer\Internet Explorer\iexplore.exe

C:\DOCUME~1\TIMMIG~1\LOKALE~1\Temp\mwavscan.com

C:\DOCUME~1\TIMMIG~1\LOKALE~1\Temp\kavss.exe

C:\Programmer\Microsoft Office\OFFICE11\WINWORD.EXE

C:\WINDOWS\system32\ntvdm.exe

C:\Documents and Settings\Timmi Gaye\Skrivebord\Ny mappe\hjt.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks

O2 - BHO: HomepageBHO - {1ca480cd-c0e5-4548-874e-b85b17905b3a} - C:\WINDOWS\system32\hpEF90.tmp

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmer\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll (file missing)

O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r

O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot

O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [ShowIcon_Zynet_USB Product Driver v1.20r037] "C:\Programmer\USB Product Driver v1.20r037\shwicon.exe" -t"Zynet\USB Product Driver v1.20r037"

O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\HP\HP Share-to-Web\hpgs2wnd.exe

O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe

O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\FLLESF~1\PCSuite\DATALA~1\DATALA~1.EXE

O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [THGuard] "C:\Programmer\TrojanHunter 4.1\THGuard.exe"

O4 - HKLM\..\Run: [CamMonitor] C:\Programmer\HP\Digital Imaging\Unload\hpqcmon.exe

O4 - HKLM\..\Run: [BJPD HID Control] C:\Programmer\Canon\BJPV\TVMon.exe

O4 - HKLM\..\Run: [SpyAxe] C:\Programmer\SpyAxe\spyaxe.exe /h

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = ?

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Avaya Wireless Client Manager.lnk = ?

O4 - Global Startup: GStartup.lnk = C:\RECYCLER\NPROTECT\00025885.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Norton System Doctor.lnk = C:\Programmer\Norton Utilities\SYSDOC32.EXE

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com

O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab

O16 - DPF: {1819853F-A3CA-4BC4-AD65-EC29D7448494} (CBPLauncher Class) - https://secure.centrebet.com/poker/centrebetpokerlauncher.cab

O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://gandalf.certifikat.dk/csp/authenticode/PrimeInkCSP-1204.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/027d26d2a3c4e066c205/netzip/RdxIE601.cab

O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k00719/sb02a.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O23 - Service: Adobe LM Service - Unknown owner - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: Canon BJ Memory Card Manager (Bjmcmng) - CANON INC. - C:\Programmer\Canon\BJCard\Bjmcmng.exe

O23 - Service: Sikkerhedsservice til udstyr (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe

O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe

O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton Utilities\NPROTECT.EXE

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Speed Disk service - Symantec Corporation - C:\Programmer\Speed Disk\nopdb.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe


På forhånd mange tak.
13. december 2005 - 17:50 #1
Suk - endnu et [SpyAxe] offer !!!
Hvad mon har folk haft 'fat i' siden den kommer ind i putter ? - og hos så mange ?

Der skal nok komme en [SpyAxe] specialist til dig...
Avatar billede dallezuper Nybegynder
13. december 2005 - 17:53 #2
er den helt vild lige i tiden?

Ved faktisk ikke hvad han har roddet med.

Lyder godt med en specialist.
Avatar billede HiACE Praktikant
13. december 2005 - 17:59 #3
http://www.spywarefri.dk/
her er der nogle specialister
Avatar billede dallezuper Nybegynder
13. december 2005 - 18:03 #4
der plejer også at være nogle herinde. kender godt spywarefri.dk
13. december 2005 - 18:03 #5
Jeg har 'pinget' en gut...
Avatar billede dallezuper Nybegynder
13. december 2005 - 18:04 #6
okay. lyder godt, mange tak.
Den er sku bare for nederen.
Avatar billede halvamatoer Nybegynder
13. december 2005 - 19:03 #7
Med spyaxe kan vi jo lige starte op med at fjerne den:
For øvrigt en træels log du har med mellemrummene, gør det lidt svært at læse.

Citat:fromsej.

For at fjerne spyaxe start med:
1. Hent og dobbeltklik på smitRem.exe

http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

Programmet pakker sig ud til mappen smitRem.

2. Hent Ewido, hvis du ikke har den i forvejen:

http://www.spywarefri.dk/downloads1/ewido-setup.exe

Installer og kør Ewido - Opdater straks efter installationen programmet (men lad være med at scanne endnu).


3. Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:

http://fromsej.dk/html/xpfejl.html


4. Åbn mappen smitRem, og dobbeltklik på RunThis.bat (Følg vejledningen i vinduet.)

5. Kør en fuld scanning med Ewido. Programmet laver en lille log, som du skal kopiere herind.

6. Genstart og kom med en frisk Hijackthislog, samt loggen fra Ewido. Find smitfiles.txt via Start/Søg. Kopier også denne log ind.
Avatar billede dallezuper Nybegynder
13. december 2005 - 20:45 #8
okay. sorry for mellemrum, kigger jeg lige på.

Gør lige de ting der, så kopier jeg log ind.
Avatar billede fromsej Praktikant
13. december 2005 - 20:52 #9
Fint, så kigger vi på resten bagefter.*S*
Halvamatoer >> Du eller jeg? (Vi har rigeligt, og jeg skal nok kigge over skulderen.*S*)
Avatar billede halvamatoer Nybegynder
13. december 2005 - 20:58 #10
Jeg tager
Avatar billede halvamatoer Nybegynder
13. december 2005 - 23:41 #11
Fromsej når du får tid må du gerne kigge på: http://www.eksperten.dk/spm/671952
Avatar billede dallezuper Nybegynder
14. december 2005 - 19:36 #12
Så er jeg færdig med standard proceduren, og de 3 log filer kommer her:

Hijackthis:
Logfile of HijackThis v1.99.1

Scan saved at 19:02:14, on 14/12/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Programmer\Canon\BJCard\Bjmcmng.exe

C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoctrl.exe

C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoguard.exe

C:\WINDOWS\System32\gearsec.exe

C:\Programmer\Norton Utilities\NPROTECT.EXE

C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe

C:\Programmer\Speed Disk\nopdb.exe

C:\WINDOWS\System32\svchost.exe

C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe

C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe

C:\Programmer\USB Product Driver v1.20r037\shwicon.exe

C:\Programmer\HP\HP Share-to-Web\hpgs2wnd.exe

C:\PROGRA~1\NORTON~1\navapw32.exe

C:\Programmer\HP\HP Share-to-Web\hpgs2wnf.exe

C:\WINDOWS\System32\hphmon05.exe

C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe

C:\PROGRA~1\FLLESF~1\PCSuite\DATALA~1\DATALA~1.EXE

C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Programmer\Apoint2K\Apoint.exe

C:\WINDOWS\AGRSMMSG.exe

C:\PROGRA~1\FLLESF~1\PCSuite\Services\SERVIC~1.EXE

C:\Programmer\HP\Digital Imaging\Unload\hpqcmon.exe

C:\Programmer\Canon\BJPV\TVMon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programmer\Apoint2K\Apntex.exe

C:\Programmer\Avaya_Wireless\Client Manager\CMAVA.EXE

C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe

C:\Programmer\Norton Utilities\SYSDOC32.EXE

C:\Programmer\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ntvdm.exe

C:\WINDOWS\system32\msiexec.exe

C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE

C:\Programmer\Microsoft Office\OFFICE11\WINWORD.EXE

C:\Documents and Settings\Timmi Gaye\Skrivebord\Ny mappe\hjt.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmer\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll (file missing)

O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r

O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot

O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [ShowIcon_Zynet_USB Product Driver v1.20r037] "C:\Programmer\USB Product Driver v1.20r037\shwicon.exe" -t"Zynet\USB Product Driver v1.20r037"

O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\HP\HP Share-to-Web\hpgs2wnd.exe

O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe

O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\FLLESF~1\PCSuite\DATALA~1\DATALA~1.EXE

O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [THGuard] "C:\Programmer\TrojanHunter 4.1\THGuard.exe"

O4 - HKLM\..\Run: [CamMonitor] C:\Programmer\HP\Digital Imaging\Unload\hpqcmon.exe

O4 - HKLM\..\Run: [BJPD HID Control] C:\Programmer\Canon\BJPV\TVMon.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = ?

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Avaya Wireless Client Manager.lnk = ?

O4 - Global Startup: GStartup.lnk = C:\RECYCLER\NPROTECT\00025885.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Norton System Doctor.lnk = C:\Programmer\Norton Utilities\SYSDOC32.EXE

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com

O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab

O16 - DPF: {1819853F-A3CA-4BC4-AD65-EC29D7448494} (CBPLauncher Class) - https://secure.centrebet.com/poker/centrebetpokerlauncher.cab

O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://gandalf.certifikat.dk/csp/authenticode/PrimeInkCSP-1204.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/027d26d2a3c4e066c205/netzip/RdxIE601.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O23 - Service: Adobe LM Service - Unknown owner - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: Canon BJ Memory Card Manager (Bjmcmng) - CANON INC. - C:\Programmer\Canon\BJCard\Bjmcmng.exe

O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoctrl.exe

O23 - Service: ewido security suite guard - ewido networks - C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoguard.exe

O23 - Service: Sikkerhedsservice til udstyr (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe

O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe

O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton Utilities\NPROTECT.EXE

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Speed Disk service - Symantec Corporation - C:\Programmer\Speed Disk\nopdb.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

Ewido:
ewido security suite - Scanningsrapport

---------------------------------------------------------



+ Oprettet den:                                                                22:06:42, 13/12/2005

+ Rapport-Checksum:                                17177D89



+ Scanningsresultat:

                      HKLM\SOFTWARE\Classes\Interface\{AA4939C3-DECA-4A48-A454-97CD587C0EF5} -> Spyware.ISTBar : Renset med backup

                      HKLM\SOFTWARE\Classes\Interface\{EEE4A2E5-9F56-432F-A6ED-F6F625B551E0} -> Dialer.Generic : Renset med backup

                      HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{640B39C1-D713-464F-92C3-75BD972B95EE} -> Spyware.SideStep : Renset med backup

                      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Spyware.HotBar : Renset med backup

                      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Renset med backup

                      HKU\S-1-5-21-4274628303-155659875-2332014710-1007\Software\hsb -> Spyware.Hotsearchbar : Renset med backup

                      HKU\S-1-5-21-4274628303-155659875-2332014710-1007\Software\hsb\ccc -> Spyware.Hotsearchbar : Renset med backup

                      HKU\S-1-5-21-4274628303-155659875-2332014710-1007\Software\hsb\eee -> Spyware.Hotsearchbar : Renset med backup

                      HKU\S-1-5-21-4274628303-155659875-2332014710-1007\Software\hsb\rrr -> Spyware.Hotsearchbar : Renset med backup

                      HKU\S-1-5-21-4274628303-155659875-2332014710-1007\Software\hsb\ttt -> Spyware.Hotsearchbar : Renset med backup

                      HKU\S-1-5-21-4274628303-155659875-2332014710-1007\Software\hsb\www -> Spyware.Hotsearchbar : Renset med backup

                      C:\Documents and Settings\Timmi Gaye\Internet Optimizer\update\actalert.exe -> Downloader.Dyfuca.dp : Renset med backup

                      C:\Program Files\Internet Optimizer\actalert.exe -> Downloader.Dyfuca.dp : Renset med backup

                      C:\RECYCLER\NPROTECT\00043947.exe -> Adware.Spyaxe : Renset med backup

                      C:\RECYCLER\NPROTECT\00043999.exe -> Adware.Spyaxe : Renset med backup

                      C:\RECYCLER\NPROTECT\00044172.exe -> Adware.Spyaxe : Renset med backup

                      C:\RECYCLER\NPROTECT\00150172.exe -> Adware.Spyaxe : Renset med backup

                      C:\WINDOWS\system32\playa.exe -> Spyware.WinFetcher.b : Renset med backup





::Rapport slut

Smitfiles.txt:
smitRem © log file

    version 2.8



    by noahdfear





Microsoft Windows XP [version 5.1.2600]



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



checking for ShudderLTD key



ShudderLTD key not present!



checking for PSGuard.com key





PSGuard.com key not present!









~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



SpyAxeFix © by noahdfear



spyaxe directory present



spyaxe uninstaller present



Starting spyaxe uninstaller



REGEDIT4



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"

"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Existing Pre-run Files





~~~ Program Files ~~~







~~~ Shortcuts ~~~







~~~ Favorites ~~~







~~~ system32 folder ~~~



ioctrl.dll

1024 dir

msvol.tlb

ld****.tmp

mssearchnet.exe

ncompat.tlb

nvctrl.exe

mscornet.exe

hp***.tmp

logfiles





~~~ Icons in System32 ~~~



ts.ico

ot.ico





~~~ Windows directory ~~~







~~~ Drive root ~~~





~~~ Miscellaneous Files/folders ~~~









~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~







Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03

Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org

Killing PID 764 'explorer.exe'



Starting registry repairs



Deleting files





  Remaining Post-run Files





~~~ Program Files ~~~







~~~ Shortcuts ~~~







~~~ Favorites ~~~







~~~ system32 folder ~~~







~~~ Icons in System32 ~~~







~~~ Windows directory ~~~







~~~ Drive root ~~~







~~~ Miscellaneous Files/folders ~~~









~~~ Wininet.dll ~~~



CLEAN! :)


Det var de scanninger. Hvad skal nu gøres.

På forhånd mange tak. fantastisk med god hjælp fra folk.
Avatar billede halvamatoer Nybegynder
14. december 2005 - 20:04 #13
Fix lige den her: (Evt. i fejlsikker)

O4 - Global Startup: GStartup.lnk = C:\RECYCLER\NPROTECT\00025885.exe

så burde vi være der.
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:11 #14
heysa,

Det prøver jeg lige.

skal det være i fejlsikret eller er det ligemeget? Det er via hijackthis jeg skal fixe den ikke?
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:13 #15
undskyld for mellemrummene igen. Underligt at den laver det når jeg kopiere det herind.
Avatar billede halvamatoer Nybegynder
14. december 2005 - 20:14 #16
helst uden fejlsikker, men det kan blive nødvendigt.
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:14 #17
okay. jeg prøver. skal jeg kopiere en ny hijackthis ind efter jeg har gjort det?
Avatar billede halvamatoer Nybegynder
14. december 2005 - 20:15 #18
ja tak
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:20 #19
okay,

ny log fil:

Logfile of HijackThis v1.99.1

Scan saved at 20:19:05, on 14/12/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Programmer\Canon\BJCard\Bjmcmng.exe

C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoctrl.exe

C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoguard.exe

C:\WINDOWS\System32\gearsec.exe

C:\Programmer\Norton Utilities\NPROTECT.EXE

C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe

C:\Programmer\Speed Disk\nopdb.exe

C:\WINDOWS\System32\svchost.exe

C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe

C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe

C:\Programmer\USB Product Driver v1.20r037\shwicon.exe

C:\Programmer\HP\HP Share-to-Web\hpgs2wnd.exe

C:\PROGRA~1\NORTON~1\navapw32.exe

C:\Programmer\HP\HP Share-to-Web\hpgs2wnf.exe

C:\WINDOWS\System32\hphmon05.exe

C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe

C:\PROGRA~1\FLLESF~1\PCSuite\DATALA~1\DATALA~1.EXE

C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Programmer\Apoint2K\Apoint.exe

C:\WINDOWS\AGRSMMSG.exe

C:\PROGRA~1\FLLESF~1\PCSuite\Services\SERVIC~1.EXE

C:\Programmer\HP\Digital Imaging\Unload\hpqcmon.exe

C:\Programmer\Canon\BJPV\TVMon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programmer\Apoint2K\Apntex.exe

C:\Programmer\Avaya_Wireless\Client Manager\CMAVA.EXE

C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe

C:\Programmer\Norton Utilities\SYSDOC32.EXE

C:\Programmer\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ntvdm.exe

C:\Documents and Settings\Timmi Gaye\Skrivebord\Ny mappe\hjt.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmer\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll (file missing)

O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r

O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot

O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [ShowIcon_Zynet_USB Product Driver v1.20r037] "C:\Programmer\USB Product Driver v1.20r037\shwicon.exe" -t"Zynet\USB Product Driver v1.20r037"

O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\HP\HP Share-to-Web\hpgs2wnd.exe

O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe

O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Programmer\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\FLLESF~1\PCSuite\DATALA~1\DATALA~1.EXE

O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [THGuard] "C:\Programmer\TrojanHunter 4.1\THGuard.exe"

O4 - HKLM\..\Run: [CamMonitor] C:\Programmer\HP\Digital Imaging\Unload\hpqcmon.exe

O4 - HKLM\..\Run: [BJPD HID Control] C:\Programmer\Canon\BJPV\TVMon.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = ?

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Avaya Wireless Client Manager.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Norton System Doctor.lnk = C:\Programmer\Norton Utilities\SYSDOC32.EXE

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programmer\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com

O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab

O16 - DPF: {1819853F-A3CA-4BC4-AD65-EC29D7448494} (CBPLauncher Class) - https://secure.centrebet.com/poker/centrebetpokerlauncher.cab

O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://gandalf.certifikat.dk/csp/authenticode/PrimeInkCSP-1204.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/027d26d2a3c4e066c205/netzip/RdxIE601.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O23 - Service: Adobe LM Service - Unknown owner - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: Canon BJ Memory Card Manager (Bjmcmng) - CANON INC. - C:\Programmer\Canon\BJCard\Bjmcmng.exe

O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoctrl.exe

O23 - Service: ewido security suite guard - ewido networks - C:\Documents and Settings\Timmi Gaye\Skrivebord\security suite\ewidoguard.exe

O23 - Service: Sikkerhedsservice til udstyr (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe

O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe

O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton Utilities\NPROTECT.EXE

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Speed Disk service - Symantec Corporation - C:\Programmer\Speed Disk\nopdb.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:21 #20
igen med mellemrum. sorry. den laver det om fra mailen og så herind.
Avatar billede halvamatoer Nybegynder
14. december 2005 - 20:35 #21
ikke noget at gøre ved det.
loggen er ren nu

Tøm din papirkurv.
skriv cleanmgr i kør og lav en rens af c-drev for midlertidige internetfiler.
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:40 #22
mange tak. lige en sidste ting. en rens af c drev. er det en egenskaber for C drev og så tryk på diskoprydning? sletter vel ikke ngoet ved det?
Avatar billede halvamatoer Nybegynder
14. december 2005 - 20:42 #23
den sletter alle midlertidige internet-filer (Du skal ikke vinke mere af, end den selv foreslår). Det betyder at næste gang du går på en hjemmeside kan det tage lidt længere, da den ikke mere har evt. billeder liggende lokalt på disken
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:44 #24
okay.

jeg prøver.
Avatar billede dallezuper Nybegynder
14. december 2005 - 20:53 #25
Sådan, mange tak for hjælpen.

min start - værktøjslinie er godt nok ændret. den er grå nu og skrifttypen er underlig?
Avatar billede dallezuper Nybegynder
15. december 2005 - 16:21 #26
kan du hjælpe med det også?
Avatar billede halvamatoer Nybegynder
15. december 2005 - 18:17 #27
Hvordan underlig ligner den "gode" gl. win-98, hvis ja så:
højreklik start-knappen vælg egenskaber -> flyt markeringen fra klassisk windows.
Avatar billede dallezuper Nybegynder
15. december 2005 - 18:53 #28
okay. cool. men hvordan laves den grå værktøjslinie om til blå igen?
Avatar billede halvamatoer Nybegynder
16. december 2005 - 12:01 #29
Sorry tabte dit spørgsmål i farten.

Egenskaber for skærm temaer-fanen vælg windows xp.
Avatar billede dallezuper Nybegynder
17. december 2005 - 11:50 #30
okay. takker. det prøver jeg lige.

Tak tak
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester