Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Software \ Sikkerhed
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

- hijackthis Log kig fobi :)

Af Gæst Søren burgaard | 04-11-2004 10:20 | 1396 visninger | 1 svar, hop til seneste
Min computer køre ikke så hurtig mere. Vi du ikke lige se om der kunne være noget snavs tak:) Logfile of HijackThis v1.97.7 Scan saved at 09:01:46, on 03-11-2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe C:\WINDOWS\system32\spoolsv.exe C:\Programmer\Ahead\InCD\InCDsrv.exe C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe C:\Programmer\Trend Micro\PC-cillin 2002\Tmntsrv.exe C:\Programmer\Trend Micro\PC-cillin 2002\PCCPFW.exe C:\WINDOWS\Explorer.EXE C:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe C:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe C:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe C:\Program Files\ASUS\Probe\AsusProb.exe C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Programmer\Ahead\InCD\InCD.exe C:\Programmer\QuickTime\qttask.exe C:\WINDOWS\System32\caeocb.exe C:\Programmer\Web_Rebates\WebRebates0.exe C:\windows\system32\saie.exe C:\Programmer\Messenger Plus! 3\MsgPlus.exe C:\WINDOWS\system32\ctfmon.exe C:\Programmer\Messenger\MSMSGS.EXE C:\Programmer\TGTSoft\StyleXP\StyleXP.exe C:\Programmer\Sony Corporation\Image Transfer\SonyTray.exe C:\Programmer\VIA\RAID\raid_tool.exe C:\Programmer\WebSecureAlert\WebSecureAlert.exe C:\Programmer\mausWay2k.exe C:\Programmer\MSN Messenger\msnmsgr.exe C:\Programmer\Web_Rebates\WebRebates1.exe G:\Spil\Valve\Steam\Steam.exe C:\Programmer\Internet Explorer\iexplore.exe C:\Documents and Settings\Søren Burgård\Lokale indstillinger\Temporary Internet Files\Content.IE5\L72LYWO4\HijackThis[1].exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://results.dashbar.com[...] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tv2.dk[...] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - C:\WINDOWS\DOWNLO~1\megasear.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll O3 - Toolbar: MEGASEAR - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - C:\WINDOWS\DOWNLO~1\megasear.dll O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll O4 - HKLM\..\Run: [pccguide.exe] "C:\Programmer\Trend Micro\PC-cillin 2002\pccguide.exe" O4 - HKLM\..\Run: [PCCClient.exe] "C:\Programmer\Trend Micro\PC-cillin 2002\PCCClient.exe" O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Programmer\Trend Micro\PC-cillin 2002\Pop3trap.exe" O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Programmer\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [wirbpi] C:\WINDOWS\System32\caeocb.exe O4 - HKLM\..\Run: [WebRebates0] "C:\Programmer\Web_Rebates\WebRebates0.exe" O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe O4 - HKLM\..\Run: [saie] c:\windows\system32\saie.exe O4 - HKLM\..\Run: [mrub] C:\WINDOWS\mrub.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [updater] C:\Programmer\Common files\updater\wupdater.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [STYLEXP] C:\Programmer\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [Steam] G:\Valve\Steam\Steam.exe -silent O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background O4 - Startup: mausWay2k.lnk = C:\Programmer\mausWay2k.exe O4 - Global Startup: Date Manager.lnk = C:\Programmer\Date Manager\DateManager.exe O4 - Global Startup: GStartup.lnk = ? O4 - Global Startup: Image Transfer.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmer\VIA\RAID\raid_tool.exe O4 - Global Startup: WebSecureAlert.lnk = C:\Programmer\WebSecureAlert\WebSecureAlert.exe O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html O8 - Extra context menu item: Web Rebates - file://C: \Programmer\Web_Rebates\Sy1150\Tp1150\scri1150a.htm O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com[...] O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com[...] O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com[...] O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://www.advnt01.com[...] O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com[...] O17 - HKLM\System\CCS\Services\Tcpip\..\{7FCBB044-8617-4A78-8FF8-308682E771D6}: NameServer = 195.231.241.25,193.162.240.6
--
Gæstebruger, opret dit eget login og få din egen signatur.
#1
v3xX
Ny på siden
07-11-2004 19:24

Rapporter til Admin
Fix de nedenstående, I hjt R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://results.dashbar.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.tv2.dk[...] O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - C:WINDOWSDOWNLO~1megasear.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programmergooglegoogletoolbar2.dll O3 - Toolbar: MEGASEAR - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - C:WINDOWSDOWNLO~1megasear.dll O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programmergooglegoogletoolbar2.dll O4 - HKLM..Run: [wirbpi] C:WINDOWSSystem32caeocb.exe O4 - HKLM..Run: [VBouncer] C:PROGRA~1VBouncerVirtualBouncer.exe O4 - HKLM..Run: [saie] c:windowssystem32saie.exe O4 - HKLM..Run: [mrub] C:WINDOWSmrub.exe O4 - Global Startup: Date Manager.lnk = C:ProgrammerDate ManagerDateManager.exe O4 - Global Startup: GStartup.lnk = ? O4 - Global Startup: WebSecureAlert.lnk = C:ProgrammerWebSecureAlertWebSecureAlert.exe O8 - Extra context menu item: &Google Search - res://c:programmergoogleGoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:programmergoogleGoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:programmergoogleGoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:programmergoogleGoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:programmergoogleGoogleToolbar2.dll/cmtrans.html O8 - Extra context menu item: Web Rebates - file://C: ProgrammerWeb_RebatesSy1150Tp1150scri1150a.htm O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://www.advnt01.com[...] Disse filer ikke gode at have! C:ProgrammerWeb_RebatesWebRebates0.exe C:ProgrammerWeb_RebatesWebRebates1.exe C:WINDOWSSystem32caeocb.exe C:windowssystem32saie.exe C:ProgrammerWebSecureAlertWebSecureAlert.exe Så dem skal du ind og fjerne i MSConfig som kan åbnes fra "Kør-funktionen", i startmenuen, Når du kommer derind åbner du Fanebladet "start" derinde fra finder du de ovenstående processer, fjerner hakkerne, aflutter med "OK" og genstarter. Download Spysweeper, herfra http://www.webroot.com[...] Installér og Sweep. Download derefter CWshredder, herfra http://cwshredder.net[...] Installér og Fix ->
--
Marhhh² !!!1 <o&#8595;o>

Opret svar til indlægget: - hijackthis Log kig fobi :)

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning