Er min log ren, eller skal den renses? :)
  tueN
Antal indlæg: 676

Logfile of HijackThis v1.97.7
Scan saved at 15:49:12, on 04-08-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Programmer/TGTSoft/StyleXP/StyleXPService.exe
C:/WINDOWS/Explorer.EXE
C:/Programmer/Fælles filer/Symantec Shared/ccSetMgr.exe
C:/Programmer/Fælles filer/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe
D:/Programmer/Zone Labs/ZoneAlarm/zlclient.exe
D:/Programmer/CursorXP/CursorXP.exe
D:/Programmer/SpeedFan/speedfan.exe
D:/Programmer/Norton AntiVirus/navapsvc.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/ZoneLabs/vsmon.exe
D:/Programmer/Norton AntiVirus/SAVScan.exe
D:/Programmer/Winamp/Winamp.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Programmer/Internet Explorer/iexplore.exe
H:/Installations programmer/Spyware programmer/hijackthis1977/HijackThis.exe

R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.google.dk/
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:/programmer/google/googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:/Programmer/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:/programmer/google/googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:/Programmer/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NvMcTray.dll,NvTaskbarInit
O4 - HKLM/../Run: [ccApp] “C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [Zone Labs Client] “D:/Programmer/Zone Labs/ZoneAlarm/zlclient.exe”
O4 - HKCU/../Run: [STYLEXP] C:/Programmer/TGTSoft/StyleXP/StyleXP.exe -Hide
O4 - HKCU/../Run: [CursorXP] D:/Programmer/CursorXP/CursorXP.exe -s
O4 - Startup: SpeedFan.lnk = D:/Programmer/SpeedFan/speedfan.exe
O8 - Extra context menu item: &Google; Search - res://C:/Programmer/Google/GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:/Programmer/Google/GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:/Programmer/Google/GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:/Programmer/Google/GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:/Programmer/Google/GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ICQ (HKLM)
O9 - Extra ‘Tools’ menuitem: ICQ (HKLM)
O16 - DPF: {22D6F312-B0F6-11D0-4A00-000000000000} - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38188.7100231481
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Redaktør
Antal indlæg: 3529

Prøv lige igen med den sidste nye version af HijackThis - http://www.spywarefri.dk/vaerktoj.htm

  tueN
Antal indlæg: 676

Ehm, det her fatter jeg ikke. Den kommer med 2 fejl nårh jeg scanner med den nye HiJackThis :S

  tueN
Antal indlæg: 676

Her er loggen, skulle bare blive ved med og åbne programmet smile

Logfile of HijackThis v1.98.1
Scan saved at 16:08:45, on 04-08-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Programmer/TGTSoft/StyleXP/StyleXPService.exe
C:/WINDOWS/Explorer.EXE
C:/Programmer/Fælles filer/Symantec Shared/ccSetMgr.exe
C:/Programmer/Fælles filer/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe
D:/Programmer/Zone Labs/ZoneAlarm/zlclient.exe
D:/Programmer/CursorXP/CursorXP.exe
D:/Programmer/SpeedFan/speedfan.exe
D:/Programmer/Norton AntiVirus/navapsvc.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/ZoneLabs/vsmon.exe
D:/Programmer/Norton AntiVirus/SAVScan.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Documents and Settings/tueN/Skrivebord/hijackthis.exe

R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://www.google.com/ie
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.google.com
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.google.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid;={SUB_CLSID}&pver;={SUB_PVER}&ar=home
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU/Software/Microsoft/Internet Explorer/SearchURL,(Default) = http://www.google.com/keyword/%s
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:/programmer/google/googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:/Programmer/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:/programmer/google/googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:/Programmer/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NvMcTray.dll,NvTaskbarInit
O4 - HKLM/../Run: [ccApp] “C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [Zone Labs Client] “D:/Programmer/Zone Labs/ZoneAlarm/zlclient.exe”
O4 - HKCU/../Run: [STYLEXP] C:/Programmer/TGTSoft/StyleXP/StyleXP.exe -Hide
O4 - HKCU/../Run: [CursorXP] D:/Programmer/CursorXP/CursorXP.exe -s
O4 - Startup: SpeedFan.lnk = D:/Programmer/SpeedFan/speedfan.exe
O8 - Extra context menu item: &Google; Search - res://C:/Programmer/Google/GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:/Programmer/Google/GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:/Programmer/Google/GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:/Programmer/Google/GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:/Programmer/Google/GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:/Programmer/ICQ/ICQ.exe
O9 - Extra ‘Tools’ menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:/Programmer/ICQ/ICQ.exe
O16 - DPF: {22D6F312-B0F6-11D0-4A00-000000000000} - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Redaktør
Antal indlæg: 3529

Deaktiver systemgendannelse. Hvis du ikke ved hvordan du gør det så kig her: http://www.spywarefri.dk/virus.htm#alle
Derefter skal du åbne HijackThis.
Du får herunder nogle filer som du skal fixe og det du skal gøre er, at sætte vinge ud for alle disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt, at det eneste vindue som er åbent er HijackThis vinduet. Husk også at lukke dette vindue (din Internet browser) når du har markeret filerne herunder. Nu må du fixe - Klik på <Fix cheked>.

Her er de filer, du skal fixe :
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://www.google.com/ie
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.google.com
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid;={SUB_CLSID}&pver;={SUB_PVER}&ar=home
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU/Software/Microsoft/Internet Explorer/SearchURL,(Default) = http://www.google.com/keyword/%s

Ikke noget alvorligt, men lad os lige se en ny log efter en genstart *S*

  tueN
Antal indlæg: 676

Ehm, det lyder sq godt nok mærkeligt det her.
Jeg åbner HJT igen, og alle de der filer er væk :s
Her er en ny log.

Logfile of HijackThis v1.98.1
Scan saved at 18:28:11, on 04-08-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Programmer/TGTSoft/StyleXP/StyleXPService.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/system32/spoolsv.exe
D:/Programmer/Zone Labs/ZoneAlarm/zlclient.exe
D:/PROGRA~1/ALWILS~1/Avast4/ashDisp.exe
D:/PROGRA~1/ALWILS~1/Avast4/ashmaisv.exe
D:/Programmer/CursorXP/CursorXP.exe
D:/Programmer/SpeedFan/speedfan.exe
D:/Programmer/Alwil Software/Avast4/aswUpdSv.exe
D:/Programmer/Alwil Software/Avast4/ashServ.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/ZoneLabs/vsmon.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Documents and Settings/tueN/Skrivebord/hijackthis.exe

R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.google.dk/
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:/programmer/google/googletoolbar1.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:/programmer/google/googletoolbar1.dll
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NvMcTray.dll,NvTaskbarInit
O4 - HKLM/../Run: [Zone Labs Client] “D:/Programmer/Zone Labs/ZoneAlarm/zlclient.exe”
O4 - HKLM/../Run: [avast!] D:/PROGRA~1/ALWILS~1/Avast4/ashDisp.exe
O4 - HKLM/../Run: [ashMaiSv] D:/PROGRA~1/ALWILS~1/Avast4/ashmaisv.exe
O4 - HKCU/../Run: [STYLEXP] C:/Programmer/TGTSoft/StyleXP/StyleXP.exe -Hide
O4 - HKCU/../Run: [CursorXP] D:/Programmer/CursorXP/CursorXP.exe -s
O4 - Startup: SpeedFan.lnk = D:/Programmer/SpeedFan/speedfan.exe
O8 - Extra context menu item: &Google; Search - res://C:/Programmer/Google/GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:/Programmer/Google/GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:/Programmer/Google/GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:/Programmer/Google/GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:/Programmer/Google/GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:/Programmer/ICQ/ICQ.exe
O9 - Extra ‘Tools’ menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:/Programmer/ICQ/ICQ.exe
O16 - DPF: {22D6F312-B0F6-11D0-4A00-000000000000} - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

 

Redaktør
Antal indlæg: 3529

Computere er og bliver nogle forunderlige skabninger - gad vide hvad de laver, når vi ikke er hjemme *GG*
Loggen er ren *S*

  tueN
Antal indlæg: 676

Haha =)

Redaktør
Antal indlæg: 3529

Jeg låser tråden. Får du brug for mere hjælp opretter du blot et nyt spørgsmål.
Fortsat god sommer :o)