Avatar billede Slettet bruger
01. september 2007 - 13:35 Der er 21 kommentarer

Fjernelse af alle toolbars!

Hej kan I hjælpe mig med min hijakthis:


Logfile of HijackThis v1.99.1
Scan saved at 13:33:31, on 01-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\Programmer\Arcade\PCMService.exe
C:\Programmer\Launch Manager\QtZgAcer.EXE
C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
C:\Programmer\Google\Google Updater\GoogleUpdater.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\acer\eRecovery\Monitor.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Programmer\Java\jre1.5.0_10\bin\jucheck.exe
C:\Programmer\RegistrySmart\RegistrySmart.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\acer\Lokale indstillinger\Temporary Internet Files\Content.IE5\G1ON07WB\alternativ[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [PCMService] "C:\Programmer\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LManager] C:\Programmer\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Google Updater.lnk = C:\Programmer\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8C379EAB-FB26-4B71-BB5C-05B4C96E4851} (Hjemmeside.KvikFoto) - http://www.123hjemmeside.dk/builder/pages/KvikFoto-1-0-5.CAB
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programmer\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmer\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
Avatar billede arlet Juniormester
01. september 2007 - 16:09 #1
jeg kigger på den nu
Avatar billede arlet Juniormester
01. september 2007 - 16:21 #2
Du skal nu til at i gang med at fixe:
Kør Hijackthis, scan, sæt flueben ved linien/linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.

R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)

O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll (file missing)

O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

find og slet denne manuelt: C:\Programmer\Yahoo <-hele mappen

----------

Kør trin 1  her http://www.malwarecheck.dk/forum/viewtopic.php?t=11

Genstart og ny hijackthis log samt loggen fra SAS
Avatar billede Slettet bruger
01. september 2007 - 16:50 #3
Jeg er igang med det, og har kørt Hijackthis, og er igang med downloade filen der står i trin 1.
Avatar billede Slettet bruger
01. september 2007 - 16:53 #4
Glemte lige at skrive, at jeg har også et andet problem, ved ikke om det er væk efter jeg har kørt dette du har skrevet, men når jeg starter op (før hen i hvert fald), så kommer der en 'Alert' frem i Windows med beskeden 'Konfiguration kan ikke indlæses'.

Ved ikke hvorfor.
Avatar billede arlet Juniormester
01. september 2007 - 17:14 #5
DEt kigger vi på bagefter..

Læg lige mærke til den, hvis den kommer igen, der må stå noget mere..
Avatar billede Slettet bruger
01. september 2007 - 17:33 #6
Okay fint nok er igang med SUPERAntiSpyware programmet... Den kører testen nu.
Avatar billede Slettet bruger
01. september 2007 - 17:39 #7
Fra SuperAntiSpyware:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/01/2007 at 05:33 PM

Application Version : 3.9.1008

Core Rules Database Version : 3298
Trace Rules Database Version: 1306

Scan type      : Complete Scan
Total Scan Time : 00:35:01

Memory items scanned      : 554
Memory threats detected  : 0
Registry items scanned    : 5406
Registry threats detected : 0
File items scanned        : 33478
File threats detected    : 105

Adware.Tracking Cookie
    C:\Documents and Settings\acer\Cookies\acer@ncom.banneradministration[2].txt
    C:\Documents and Settings\acer\Cookies\acer@tracking.veille-referencement[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.tibaco[1].txt
    C:\Documents and Settings\acer\Cookies\acer@stat.novasol[1].txt
    C:\Documents and Settings\acer\Cookies\acer@86843942[1].txt
    C:\Documents and Settings\acer\Cookies\acer@eas.apm.emediate[2].txt
    C:\Documents and Settings\acer\Cookies\acer@ads2.jubii[1].txt
    C:\Documents and Settings\acer\Cookies\acer@bannere.fyens[2].txt
    C:\Documents and Settings\acer\Cookies\acer@ad1.emediate[2].txt
    C:\Documents and Settings\acer\Cookies\acer@3.adbrite[1].txt
    C:\Documents and Settings\acer\Cookies\acer@track.adform[1].txt
    C:\Documents and Settings\acer\Cookies\acer@cgi-bin[4].txt
    C:\Documents and Settings\acer\Cookies\acer@stat.mthojgaard[2].txt
    C:\Documents and Settings\acer\Cookies\acer@48940962[2].txt
    C:\Documents and Settings\acer\Cookies\acer@centrebet.advertserve[1].txt
    C:\Documents and Settings\acer\Cookies\acer@cgi-bin[5].txt
    C:\Documents and Settings\acer\Cookies\acer@server.cpmstar[5].txt
    C:\Documents and Settings\acer\Cookies\acer@ad.zanox[1].txt
    C:\Documents and Settings\acer\Cookies\acer@stat.inleadmedia[1].txt
    C:\Documents and Settings\acer\Cookies\acer@doubleclick[1].txt
    C:\Documents and Settings\acer\Cookies\acer@overture[1].txt
    C:\Documents and Settings\acer\Cookies\acer@image.masterstats[2].txt
    C:\Documents and Settings\acer\Cookies\acer@mtg.banneradministration[2].txt
    C:\Documents and Settings\acer\Cookies\acer@media.hotels[1].txt
    C:\Documents and Settings\acer\Cookies\acer@offers.intermediainteractive[2].txt
    C:\Documents and Settings\acer\Cookies\acer@e2.emediate[5].txt
    C:\Documents and Settings\acer\Cookies\acer@m1.webstats.motigo[2].txt
    C:\Documents and Settings\acer\Cookies\acer@S137445[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.heias[1].txt
    C:\Documents and Settings\acer\Cookies\acer@adtech[2].txt
    C:\Documents and Settings\acer\Cookies\acer@advertising[1].txt
    C:\Documents and Settings\acer\Cookies\acer@mb[1].txt
    C:\Documents and Settings\acer\Cookies\acer@focalex[2].txt
    C:\Documents and Settings\acer\Cookies\acer@stat.if[1].txt
    C:\Documents and Settings\acer\Cookies\acer@59207812[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.us.e-planning[1].txt
    C:\Documents and Settings\acer\Cookies\acer@882183888888128[1].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[3].txt
    C:\Documents and Settings\acer\Cookies\acer@marine[1].txt
    C:\Documents and Settings\acer\Cookies\acer@nextag[1].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[5].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[11].txt
    C:\Documents and Settings\acer\Cookies\acer@911190555233333[1].txt
    C:\Documents and Settings\acer\Cookies\acer@tracking.notabenestats[1].txt
    C:\Documents and Settings\acer\Cookies\acer@clickbank[2].txt
    C:\Documents and Settings\acer\Cookies\acer@precisionclick[1].txt
    C:\Documents and Settings\acer\Cookies\acer@nl.sitestat[1].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[4].txt
    C:\Documents and Settings\acer\Cookies\acer@qxl.banneradministration[2].txt
    C:\Documents and Settings\acer\Cookies\acer@banner.fynskemedier[1].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[10].txt
    C:\Documents and Settings\acer\Cookies\acer@ilead.itrack[3].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[1].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[6].txt
    C:\Documents and Settings\acer\Cookies\acer@cgi-bin[3].txt
    C:\Documents and Settings\acer\Cookies\acer@xiti[1].txt
    C:\Documents and Settings\acer\Cookies\acer@gamenextdk.oberon-media[2].txt
    C:\Documents and Settings\acer\Cookies\acer@marpow[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.freeway[1].txt
    C:\Documents and Settings\acer\Cookies\acer@click.tdc-online[1].txt
    C:\Documents and Settings\acer\Cookies\acer@mtgnewmedia[1].txt
    C:\Documents and Settings\acer\Cookies\acer@bonnier.banneradministration[2].txt
    C:\Documents and Settings\acer\Cookies\acer@www.googleadservices[2].txt
    C:\Documents and Settings\acer\Cookies\acer@mediametrics.mpsa[2].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.habbogroup[1].txt
    C:\Documents and Settings\acer\Cookies\acer@windowsmedia[2].txt
    C:\Documents and Settings\acer\Cookies\acer@ad.ofir[1].txt
    C:\Documents and Settings\acer\Cookies\acer@belnk[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.habbohotel[1].txt
    C:\Documents and Settings\acer\Cookies\acer@dist.belnk[2].txt
    C:\Documents and Settings\acer\Cookies\acer@m1.webstats4u[1].txt
    C:\Documents and Settings\acer\Cookies\acer@image.masterstats[1].txt
    C:\Documents and Settings\acer\Cookies\acer@server.cpmstar[1].txt
    C:\Documents and Settings\acer\Cookies\acer@server.cpmstar[3].txt
    C:\Documents and Settings\acer\Cookies\acer@m1.webstats4u[2].txt
    C:\Documents and Settings\acer\Cookies\acer@web.neuroticmedia[1].txt
    C:\Documents and Settings\acer\Cookies\acer@e2.emediate[1].txt
    C:\Documents and Settings\acer\Cookies\acer@macromedia[1].txt
    C:\Documents and Settings\acer\Cookies\acer@c.goclick[1].txt
    C:\Documents and Settings\acer\Cookies\acer@upspiral[1].txt
    C:\Documents and Settings\acer\Cookies\acer@www.upspiral[2].txt
    C:\Documents and Settings\acer\Cookies\acer@e2.emediate[4].txt
    C:\Documents and Settings\acer\Cookies\acer@upspiral[2].txt
    C:\Documents and Settings\acer\Cookies\acer@m1.webstats4u[3].txt
    C:\Documents and Settings\acer\Cookies\acer@server.cpmstar[4].txt
    C:\Documents and Settings\acer\Cookies\acer@focalex[1].txt
    C:\Documents and Settings\acer\Cookies\acer@c.goclick[2].txt
    C:\Documents and Settings\acer\Cookies\acer@bannere.fyens[1].txt
    C:\Documents and Settings\acer\Cookies\acer@atwola[1].txt
    C:\Documents and Settings\acer\Cookies\acer@www.upspiral[1].txt
    C:\Documents and Settings\acer\Cookies\acer@burstnet[2].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.freeonlinegames[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.ipfrom[1].txt
    C:\Documents and Settings\acer\Cookies\acer@e2.emediate[2].txt
    C:\Documents and Settings\acer\Cookies\acer@stat.mthojgaard[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.arto[2].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.estart[2].txt
    C:\Documents and Settings\acer\Cookies\acer@adfair[2].txt
    C:\Documents and Settings\acer\Cookies\acer@ncom.banneradministration[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ilead.itrack[1].txt
    C:\Documents and Settings\acer\Cookies\acer@server.cpmstar[2].txt
    C:\Documents and Settings\acer\Cookies\acer@adfair[1].txt
    C:\Documents and Settings\acer\Cookies\acer@postclicktracking[1].txt
    C:\Documents and Settings\acer\Cookies\acer@ads.arto[3].txt

Adware.Casino Games (Golden Palace Casino)
    C:\PROGRAMMER\EGAMES\MASTERS SERIES 151\CASINO.EXE
Avatar billede arlet Juniormester
01. september 2007 - 17:44 #8
Så mangler jeg en ny hijackthis og hvordan computeren kører nu..
Avatar billede Slettet bruger
01. september 2007 - 17:50 #9
Hvad gør jeg med SuperAntiSpyware programmet skal jeg ikke gøre noget efter testen?
Slette ect.?
Avatar billede arlet Juniormester
01. september 2007 - 17:53 #10
det kan du godt lave være på computeren. Det er vældig fint til at scanne med en gang imellem
Avatar billede Slettet bruger
01. september 2007 - 17:55 #11
Jamen skal jeg slette noget af det jeg har scannet?
Avatar billede Slettet bruger
01. september 2007 - 18:02 #12
Her er det fra HiJackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:00:52, on 01-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\Programmer\Arcade\PCMService.exe
C:\Programmer\Launch Manager\QtZgAcer.EXE
C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\sistray.exe
C:\Programmer\Google\Google Updater\GoogleUpdater.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\acer\Skrivebord\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [PCMService] "C:\Programmer\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LManager] C:\Programmer\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Google Updater.lnk = C:\Programmer\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8C379EAB-FB26-4B71-BB5C-05B4C96E4851} (Hjemmeside.KvikFoto) - http://www.123hjemmeside.dk/builder/pages/KvikFoto-1-0-5.CAB
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programmer\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmer\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmer\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 8528 bytes
Avatar billede arlet Juniormester
01. september 2007 - 18:02 #13
Ja, det hele, hvis du ikke har gjort det..
Avatar billede Slettet bruger
01. september 2007 - 18:07 #14
Jeg gjorder det hele ja... :D
Men fejlen i windows dukker op igen.

(Har lige genstartet før jeg tog HiJackThis'en)
Avatar billede arlet Juniormester
01. september 2007 - 18:11 #15
Du skrev det her: ""Glemte lige at skrive, at jeg har også et andet problem, ved ikke om det er væk efter jeg har kørt dette du har skrevet, men når jeg starter op (før hen i hvert fald), så kommer der en 'Alert' frem i Windows med beskeden 'Konfiguration kan ikke indlæses'.

Ved ikke hvorfor.""

Står der ikke noget mere??
Avatar billede Slettet bruger
01. september 2007 - 18:13 #16
Nej det er alt hvad der står.

I toppen af fejl vinduet står der 'Application fejl' eller sådan noget.
Og så fejlen jeg har skrevet.
Avatar billede Slettet bruger
01. september 2007 - 18:27 #17
Nogen idé?
Avatar billede arlet Juniormester
01. september 2007 - 19:17 #18
Har slet ingen ide om hvad det kan være, men du skal nok prøve ovre i xp kategorien, for det har intet med snavs at gøre..
01. september 2007 - 20:39 #19
PS: - Måske dette -> Kør en tur mere med HiJackThis.exe men du skal skal du OMDØBE programfilen HiJackThis.exe til ALTERNATIV.exe , da visse uønskede elementer har en tendens til at skjule sig når der kører en process ved navn HiJackThis.exe !!!
11. september 2007 - 19:17 #20
???
Avatar billede Slettet bruger
20. september 2007 - 04:28 #21
Ja problemet er bare lige pt. har jeg ikke adgang til computeren, da det er en af mine venners, som jeg sjældent ser.

Men hvem skal ha' points?
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester