Avatar billede mons73 Nybegynder
29. maj 2006 - 02:23 Der er 13 kommentarer og
1 løsning

Hvad er piyqoy.exe

Jeg har i min opstart af computeren (win2000 pro) et program, piyqoy.exe, der selv om det bliver deaktiveret, efter nogen tid aktiverer sig selv igen? Men hvad er det?
Google giver 0 resultater, og har Antivir, og Ad-aware, som intet finder.
Det skal lige siges at computeren ikke opfører sig på nogen måde underligt, men programmets opførsel er lidt "virus-agtig". Har søgt i registreringsdatabasen, men der er heller intet spor af den?
Avatar billede forevernewbie Nybegynder
29. maj 2006 - 02:46 #1
Den lyder ikke særligt "hæderlig". Upload den til scanning her http://www.virustotal.com/en/indexf.html

Følg så denne vejledning, og kopier logsene her ind i tråden.
http://www.eksperten.dk/artikler/954
Avatar billede mons73 Nybegynder
29. maj 2006 - 03:03 #2
Hmm.... Meget mærkeligt. Ifølge msconfig skulle den ligge i WINNT/system32.... men der kan jeg så ikke finde den. Er der ikke nogen der har hørt om den før?
Avatar billede forevernewbie Nybegynder
29. maj 2006 - 03:09 #3
Hverken Google, MSN, eller Yahoo kender den, så den er højst sandsynligt snavs. Det kan være, at dette får den frem i lyset:

For at kunne se alle filer og mapper, gør du dette http://www.spywareinfo.dk/#/tip-og-tricks/mappeindstillinger.htm
Avatar billede mons73 Nybegynder
29. maj 2006 - 03:23 #4
Det er gjort.... men stadig ingen fil. Der er dog filer på computeren der f.eks. hedder piyqoy.exe.q_63B7A03_q.ini som ligger i mappen Documents and Settings/All users/Application data/SecTaskMan. Men her er heller ingen .exe-filer, kun dll-filer, et par .ini-filer, og nogle filer med mærkelige navne som f.eks. icn_7E9E09EF851A78648835FD76A739A916 (ingen extensions).
Avatar billede forevernewbie Nybegynder
29. maj 2006 - 03:29 #5
Kan du se filen i Security Task Manager ? Hvis ja, hvad siger den om filen/filerne ?
Avatar billede mons73 Nybegynder
29. maj 2006 - 16:25 #6
Problemet er at jeg ikke længere har Security Task Manager, så det er lidt svært.....
29. maj 2006 - 19:51 #7
"Følg så denne vejledning, og kopier logsene her ind i tråden.
http://www.eksperten.dk/artikler/954 "

Den vil afsløre en del (=meget)...
Avatar billede forevernewbie Nybegynder
29. maj 2006 - 20:08 #8
Kom også lige med en log fra dette program:

Hent Blacklight her http://www.f-secure.com/blacklight/try.shtml Scroll ned på siden, og klik "iaccept". På næste side kan du downloade Blacklight til skrivebordet. Dobbeltklik filen, og klik scan. Når den er færdig laver den en log på skrivebordet. Kopier loggen her ind. Du skal ikke lade Blacklight fjerne noget endnu.
Avatar billede mons73 Nybegynder
29. maj 2006 - 22:42 #9
Her er i første omgang logs for Dr.Web og SAS.

Fra Dr. Web

[Scan path] C:\
C:\Installationsfiler\VNC_Remote\vnc_x86_win32\vncviewer\vncviewer.exe is riskware program Program.RemoteAdmin - renamed
C:\winnt\system32\Lavan\mainhq.dbx infected with IRC.Randon - deleted

[Scan path] D:\
D:\Documents and Settings\Frank Johansen\NTUSER.DAT - read error
D:\Documents and Settings\Frank Johansen\NTUSER~1.LOG - read error
D:\Documents and Settings\Frank Johansen\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat - read error
D:\Documents and Settings\Frank Johansen\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error
D:\Documents and Settings\Frank Johansen\Lokale indstillinger\Temp\VVSNInst.exe is adware program Adware.SaveNow - renamed
D:\Documents and Settings\Frank Johansen\Lokale indstillinger\Temp\temp.fr891E\ACM.dll is adware program Adware.SaveNow - renamed
D:\Programmer\WinRAR\Rar.exe infected with Trojan.Peflog.30 - incurable - moved
D:\WINNT\system32\config\default - read error
D:\WINNT\system32\config\default.LOG - read error
D:\WINNT\system32\config\SAM - read error
D:\WINNT\system32\config\SAM.LOG - read error
D:\WINNT\system32\config\SECURITY - read error
D:\WINNT\system32\config\SECURITY.LOG - read error
D:\WINNT\system32\config\software - read error
D:\WINNT\system32\config\software.LOG - read error
D:\WINNT\system32\config\system - read error
D:\WINNT\system32\config\SYSTEM.ALT - read error


Scan statistics

Objects scanned: 117601
Infected objects found: 2
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 2
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 1
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 1
Objects renamed: 3
Objects moved: 1
Objects ignored: 0
Scan speed: 326 Kb/s
Scan time: 01:21:38

------------------------------------------

Fra SAS

SUPERAntiSpyware Scan Log
Generated 05/29/2006 at 10:16 PM

Core Rules Database Version : 2955
Trace Rules Database Version: 1062

Memory threats detected  : 0
Registry threats detected : 93
File threats detected    : 76

Adware.Tracking Cookie
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@dist.belnk[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@www.webstat[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@e-2dj6wflionazggp.stats.esomniture[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@revsci[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@ilead.itrack[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@tacoda[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@adopt.hbmediapro[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@burstnet[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@2o7[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@track.adform[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@stat.if[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@elitehost[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@tdstats[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@as1.falkag[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@qnsr[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@911190555233333[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@estat[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@52412438[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@adtech[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@74139060[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@tribalfusion[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@ad.yieldmanager[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@posten[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@offeroptimizer[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@bannere.fyens[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@xiti[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@1069953711[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@oddcast[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@yadro[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@cgi-bin[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@belnk[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@e2.emediate[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@i.screensavers[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@stats1.reliablestats[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@ad1.emediate[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@tradedoubler[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@starware[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@server.iad.liveperson[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@globalstat[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@www.screensavers[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@adserver.banneradministration[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@data1.perf.overture[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@indextools[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@statcounter[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@sel.as-eu.falkag[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@ads.arto[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@overture[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@adfair[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@1071420755[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@image.masterstats[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@admarketplace[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@interclick[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@vhost.oddcast[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@pphlogger[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@stat.postdanmark[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@1070832645[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@as-eu.falkag[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@data2.perf.overture[1].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@crazywin_track_2006_09[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@danskemeninger_confirm_track_2006_03[2].txt
    D:\Documents and Settings\Frank Johansen\Cookies\frank johansen@danskemeninger_reg_track_2006_03[2].txt
    D:\Documents and Settings\Frank Johansen\Lokale indstillinger\Temp\Cookies\frank johansen@track.adform[1].txt

Adware.WhenU
    HKCR\WUSN.1
    HKCR\WUSN.1#WUSN_Id
    HKCR\ACM.ACMFactory
    HKCR\ACM.ACMFactory\CLSID
    HKCR\ACM.ACMFactory\CurVer
    HKCR\ACM.ACMFactory.1
    HKCR\ACM.ACMFactory.1\CLSID
    HKCR\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}
    HKCR\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\ProxyStubClsid
    HKCR\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\ProxyStubClsid32
    HKCR\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\TypeLib
    HKCR\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\TypeLib#Version
    HKCR\AppId\{127DF9B4-D75D-44A6-AF78-8C3A8CEB03DB}
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}#AppID
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\InprocServer32
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\InprocServer32#ThreadingModel
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\ProgID
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\Programmable
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\TypeLib
    HKCR\CLSID\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\VersionIndependentProgID
    HKCR\AppId\ACM.DLL
    HKCR\AppId\ACM.DLL#AppID
    HKCR\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}
    HKCR\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0
    HKCR\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0\0
    HKCR\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0\0\win32
    HKCR\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0\FLAGS
    HKCR\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0\HELPDIR
    HKCR\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}
    HKCR\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\ProxyStubClsid
    HKCR\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\ProxyStubClsid32
    HKCR\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\TypeLib
    HKCR\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\TypeLib#Version
    HKCR\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}
    HKCR\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\ProxyStubClsid
    HKCR\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\ProxyStubClsid32
    HKCR\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\TypeLib
    HKCR\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\TypeLib#Version
    HKLM\Software\WhenUSave
    HKLM\Software\WhenUSave#db_script_update
    HKLM\Software\WhenUSave#InstallDir
    HKLM\Software\WhenUSave#pats_url
    HKLM\Software\WhenUSave#pat_chunks_url
    HKLM\Software\WhenUSave#script_url
    HKLM\Software\WhenUSave#update_url
    HKLM\Software\WhenUSave#ver_url
    HKLM\Software\WhenUSave#Version
    HKLM\Software\WhenUSave#timedDBUpdate_rs
    HKLM\Software\WhenUSave#SystemParam_rs
    HKLM\Software\WhenUSave#extra_url
    HKLM\Software\WhenUSave#extraver_url
    HKLM\Software\WhenUSave#ziptomsa_url
    HKLM\Software\WhenUSave#InstallTime
    HKLM\Software\WhenUSave#LastPartner
    HKLM\Software\WhenUSave#zip
    HKLM\Software\WhenUSave#acm_rs
    HKLM\Software\WhenUSave#TotalPartner
    HKLM\Software\WhenUSave#newuser_rs
    HKLM\Software\WhenUSave#Partner
    HKLM\Software\WhenUSave#PartnerB
    HKLM\Software\WhenUSave#PartnerDesc
    HKLM\Software\WhenUSave#TotalPopup
    HKLM\Software\WhenUSave#HeartbeatTime
    HKLM\Software\WhenUSave#HeartbeatCount
    HKLM\Software\WhenUSave#FullDBTime
    HKLM\Software\WhenUSave#brandskin_url
    HKLM\Software\WhenUSave#brandstrip_rs
    HKLM\Software\WhenUSave#brandstrip_url
    HKLM\Software\WhenUSave#bstat_rs
    HKLM\Software\WhenUSave#himp_url
    HKLM\Software\WhenUSave#iptomsa_url
    HKLM\Software\WhenUSave#maxPopups_rs
    HKLM\Software\WhenUSave#redir3p_url
    HKLM\Software\WhenUSave#src_url
    HKLM\Software\WhenUSave#uninstalltag_rs
    HKLM\Software\WhenUSave#db_stamp_rs
    HKLM\Software\WhenUSave#db_server_update
    HKLM\Software\WhenUSave#MSA
    HKLM\Software\WhenUSave#IPToMsaTime_rs
    HKLM\Software\WhenUSave#UrlChangeCount
    HKLM\Software\WhenUSave\Partners
    HKLM\Software\WhenUSave\Partners\EEPE
    HKLM\Software\WhenUSave\Partners\EEPE#Partner
    HKLM\Software\WhenUSave\Partners\EEPE#InstallTime
    HKLM\Software\WhenUSave\Partners\EEPE#PartnerDesc
    HKLM\Software\WhenUSave\Partners\EEPE#PartnerFile

Adware.WebNexus
    HKLM\Software\qstat
    HKLM\Software\qstat#double
    HKLM\Software\qstat#brr
    HKLM\Software\qstat#unq
    HKLM\Software\qstat#lid
    HKLM\Software\qstat#stat

Adware.SurfSideKick
    D:\Programmer\Common Files\VCClient\ClientUpdater.bat
    D:\Programmer\Common Files\VCClient\ICSharpCode.SharpZipLib.dll
    D:\Programmer\Common Files\VCClient\temp.txt
    D:\Programmer\Common Files\VCClient\VCClient.exe.config
    D:\Programmer\Common Files\VCClient\VCUpdate.exe
    D:\Programmer\Common Files\VCClient\VCUpdate.exe.config
    D:\Programmer\Common Files\VCClient\Version.txt
    D:\Programmer\Common Files\VCClient
    D:\Documents and Settings\All Users\Application Data\SecTaskMan\VCMain.exe.q_16A74000_q

BearShare File Sharing Client
    D:\Programmer\BearShare\BearShare.exe
    D:\Documents and Settings\All Users\Menuen Start\Programmer\BearShare.lnk
    D:\Documents and Settings\Frank Johansen\Application Data\Microsoft\Internet Explorer\Quick Launch\BearShare.lnk
    D:\Documents and Settings\Frank Johansen\Skrivebord\BearShare.lnk

Worm.RBot-APT
    D:\WINNT\system32\up32.pif


Hijackthis kommer om lidt.
Avatar billede mons73 Nybegynder
29. maj 2006 - 22:45 #10
Og her er fra Hijackthis.

Logfile of HijackThis v1.99.1
Scan saved at 22:45:43, on 29-05-2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\SYSTEM32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\Programmer\AntiVir PersonalEdition Classic\sched.exe
D:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
D:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
D:\WINNT\System32\svchost.exe
D:\Programmer\VeriSign\NAVI\naviagent.exe
D:\WINNT\system32\nvsvc32.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe
D:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
D:\WINNT\system32\internat.exe
D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Documents and Settings\Frank Johansen\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - D:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - D:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [avgnt] "D:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: BTTray.lnk = D:\Programmer\WIDCOMM\Bluetooth-software\BTTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Send til &Bluetooth - D:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmer\WIDCOMM\Bluetooth-software\btsendto_ie.htm
O9 - Extra button: i-Nav Hjælp - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: i-Nav Hjælp - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - D:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O9 - Extra 'Tools' menuitem: i-Nav Indstillinger - {CE000996-A58C-4441-8938-744CD72AB27F} - D:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {FC647808-D789-43D4-97AE-4914A4394D4C} (RequestLoginX Control) - http://www.toleranceonline.com/RequestLoginProj1.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{D483E685-C584-4CE4-88D6-A24D1A3E5D65}: NameServer = 212.242.40.3,212.242.40.51
O20 - Winlogon Notify: SASWinLogon - D:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Programmer\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - D:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - D:\Programmer\WIDCOMM\Bluetooth-software\bin\btwdins.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: VeriSign Updater (navi) - VeriSign, Inc. - D:\Programmer\VeriSign\NAVI\naviagent.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
30. maj 2006 - 09:34 #11
Du har hermed allerede fået ryddet op i diverse uønskede elementer - der var rester fra bla. [BearShare] med tilbehør...

Ruller putter bedre nu ?
30. maj 2006 - 09:35 #12
Det kunne også være sundt at rulle:
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Problemer]...)
Avatar billede mons73 Nybegynder
30. maj 2006 - 15:43 #13
Ja, det hjalp faktisk.
Smider du lige svar, så jeg kan give point?
30. maj 2006 - 16:37 #14
Ping...

(Det var et [svar]...)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester