God aften - eller skal vi sige godnat?
Vores naboer har denne computer, som stadig har noget snavs. Har lige været igennem den med Spybot, men der mangler stadig noget.
DSO Exploit = 5 entries, som ikke kommer væk.
Da de kun har et 56K-modem, har jeg fået den tvivlsomme ære, at låne den i week-enden, så jeg kan få opdateret Windows xp. Jeg har ikke haft den på nettet endnu, for jeg vil gerne hvis den kunne holde op med at ville kalde op hele tiden.
Jeg sender log-filen her:
——————————————————————————————————-
Logfile of HijackThis v1.97.7
Scan saved at 23:26:10, on 04-02-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/csrss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/LEXBCES.EXE
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/system32/LEXPPS.EXE
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/System32/alg.exe
C:/NORMAN/Nvc/BIN/NPFSVICE.EXE
C:/Norman/NVC/BIN/Zanda.exe
C:/WINDOWS/system32/slserv.exe
C:/WINDOWS/System32/igfxtray.exe
C:/WINDOWS/System32/hkcmd.exe
C:/WINDOWS/SOUNDMAN.EXE
C:/NORMAN/Nvc/BIN/ZLH.EXE
C:/windows/temp/CtFVP.exe
C:/documents and settings/jan/lokale indstillinger/temp/yxb3M2qLz.exe
C:/WINDOWS/System32/avmeter1.exe
C:/WINDOWS/System32/Audio3D7.exe
C:/documents and settings/jan/lokale indstillinger/temp/a4cY.exe
C:/PROGRA~1/FLLESF~1/WinTools/WToolsA.exe
C:/windows/system32/eQybi.exe
C:/windows/system32/CR.exe
C:/NORMAN/Nvc/BIN/NYMSE.EXE
C:/NORMAN/Nvc/BIN/NIP.EXE
C:/Programmer/Messenger/msmsgs.exe
C:/Documents and Settings/Jan/Application Data/wp?h.exe
C:/NORMAN/Nvc/BIN/npfmsg2.exe
C:/WINDOWS/system32/eQybi.exe
C:/Programmer/Fælles filer/WinTools/WSup.exe
C:/NORMAN/Nvc/BIN/nvcoas.exe
C:/NORMAN/Nvc/BIN/NVCSCHED.EXE
C:/NORMAN/Nvc/BIN/nipsvc.exe
C:/NORMAN/Nvc/BIN/NJEEVES.EXE
C:/NORMAN/Nvc/BIN/cclaw.exe
C:/WINDOWS/System32/wuauclt.exe
C:/Documents and Settings/Jan/Skrivebord/HijackThis/HijackThis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = file://C:/WINDOWS/System32/SearchBar.htm
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.google.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.get2net.dk/
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Reader/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:/PROGRA~1/FLLESF~1/WinTools/WToolsB.dll
O2 - BHO: (no name) - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:/Programmer/eSyndicate/esyn.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O4 - HKLM/../Run: [IgfxTray] C:/WINDOWS/System32/igfxtray.exe
O4 - HKLM/../Run: [HotKeysCmds] C:/WINDOWS/System32/hkcmd.exe
O4 - HKLM/../Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM/../Run: [NeroFilterCheck] C:/WINDOWS/system32/NeroCheck.exe
O4 - HKLM/../Run: [Norman ZANDA] C:/NORMAN/Nvc/BIN/ZLH.EXE /LOAD /SPLASH
O4 - HKLM/../Run: [CtFVP] C:/windows/temp/CtFVP.exe
O4 - HKLM/../Run: [yxb3M2qLz] C:/documents and settings/jan/lokale indstillinger/temp/yxb3M2qLz.exe
O4 - HKLM/../Run: [194e7b6fd5e6] C:/WINDOWS/System32/avmeter1.exe
O4 - HKLM/../Run: [5d6587afb261] C:/WINDOWS/System32/Audio3D7.exe
O4 - HKLM/../Run: [a4cY] C:/documents and settings/jan/lokale indstillinger/temp/a4cY.exe
O4 - HKLM/../Run: [WinTools] C:/PROGRA~1/FLLESF~1/WinTools/WToolsA.exe
O4 - HKLM/../Run: [eQybi.exe] c:/windows/system32/eQybi.exe
O4 - HKLM/../Run: [CR] C:/windows/system32/CR.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Programmer/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [starter] scvhosting.exe
O4 - HKCU/../Run: [Windows Network Controller] Win9x.exe
O4 - HKCU/../Run: [Scbl] C:/Documents and Settings/Jan/Application Data/wp?h.exe
O4 - Startup: Skrivebord.lnk = ?
O8 - Extra context menu item: Web Rebates - file://C:/Programmer/Web_Rebates/Sy1150/Tp1150/scri1150a.htm
O9 - Extra ‘Tools’ menuitem: MaxSpeed (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra ‘Tools’ menuitem: Show &Related; Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.get2net.dk/
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
——————————————————————————————————-
Håber I kan hjælpe, så bliver de så glade.
