Hjælp mig please
  big ben
Antal indlæg: 6

Hej
Har fået et problem xp home, kan ikke få lov at ændre i mine internet indstillinger. Har ikke ret til at ændre kontakt system admin. skriver den. Dette er ikke korrekt jeg er administrator, og laver jeg en ny konto må jeg godt, ved login kan jeg scanne en ipadresse med start 213.199.154.71 inden siden msn kommer op. Havde før tdc som start side, log ser således ud.

Logfile of HijackThis v1.97.5
Scan saved at 23:05:04, on 28-10-2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Programmer/Fælles filer/Symantec Shared/ccSetMgr.exe
C:/Programmer/Fælles filer/Symantec Shared/SNDSrvc.exe
C:/Programmer/Fælles filer/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/System32/brsvc01a.exe
C:/WINDOWS/System32/brss01a.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Fælles filer/Symantec Shared/ccProxy.exe
C:/Programmer/Norton Internet Security/Norton AntiVirus/navapsvc.exe
C:/Programmer/VeriSign/NAVI/naviagent.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/Programmer/Norton Internet Security/Norton AntiVirus/SAVScan.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/System32/MsPMSPSv.exe
C:/Programmer/Fælles filer/Symantec Shared/Security Center/SymWSC.exe
C:/WINDOWS/System32/HPZipm12.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/system32/RunDll32.exe
C:/Programmer/Browser Mouse/Browser Mouse/1.1/MOUSE32A.EXE
C:/Programmer/HP/hpcoretech/hpcmpmgr.exe
C:/Programmer/HP/HP Software Update/HPWuSchd2.exe
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/MSN Apps/Updater/01.02.3000.1001/da/msnappau.exe
C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe
C:/Programmer/Skype/Phone/Skype.exe
C:/Programmer/HP/Digital Imaging/bin/hpqtra08.exe
C:/Programmer/Messenger/msmsgs.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Documents and Settings/Ejer/Lokale indstillinger/Temp/HijackThis.exe

R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://g.msn.dk/0SEDADK/SAOS01
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.msn.dk
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.msn.dk
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:/Programmer/VeriSign/i-Nav/i-nav_4_2_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Reader/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:/Programmer/MSN Apps/ST/01.02.3000.1002/en-xu/stmain.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Programmer/Fælles filer/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:/Programmer/MSN Apps/MSN Toolbar/01.02.3000.1001/da/msntb.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Programmer/Norton Internet Security/Norton AntiVirus/NavShExt.dll
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:/Programmer/VeriSign/i-Nav/i-nav_4_2_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:/Programmer/MSN Apps/MSN Toolbar/01.02.3000.1001/da/msntb.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Programmer/Fælles filer/Symantec Shared/AdBlocking/NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Programmer/Norton Internet Security/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [SiSUSBRG] C:/WINDOWS/SiSUSBrg.exe
O4 - HKLM/../Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [LWBMOUSE] C:/Programmer/Browser Mouse/Browser Mouse/1.1/MOUSE32A.EXE
O4 - HKLM/../Run: [Tray Temperature] C:/PROGRA~1/AWS/MINIBUG.EXE 1
O4 - HKLM/../Run: [HP Component Manager] “C:/Programmer/HP/hpcoretech/hpcmpmgr.exe”
O4 - HKLM/../Run: [HP Software Update] “C:/Programmer/HP/HP Software Update/HPWuSchd2.exe”
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [msnappau] “C:/Programmer/MSN Apps/Updater/01.02.3000.1001/da/msnappau.exe”
O4 - HKLM/../Run: [ccApp] “C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [URLLSTCK.exe] C:/Programmer/Norton Internet Security/UrlLstCk.exe
O4 - HKLM/../Run: [Symantec NetDriver Monitor] C:/PROGRA~1/SYMNET~1/SNDMon.exe
O4 - HKLM/../Run: [NeroFilterCheck] C:/WINDOWS/system32/NeroCheck.exe
O4 - HKCU/../Run: [Skype] “C:/Programmer/Skype/Phone/Skype.exe” /nosplash /minimized
O4 - HKCU/../Run: [Symantec NetDriver Monitor] C:/PROGRA~1/SYMNET~1/SNDMon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:/Programmer/HP/Digital Imaging/bin/hpqtra08.exe
O4 - Global Startup: . = ?
O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/Restrictions present
O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/Control Panel present
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: i-Nav Hjælp (HKLM)
O9 - Extra ‘Tools’ menuitem: i-Nav Hjælp (HKLM)
O9 - Extra ‘Tools’ menuitem: i-Nav Indstillinger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O12 - Plugin for .pdf: C:/Programmer/Internet Explorer/PLUGINS/nppdf32.dll
O12 - Plugin for .spop: C:/Programmer/Internet Explorer/Plugins/NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37885.4191666667
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DC765522-D5BE-49C9-AF5F-8C715A44BA28} (MS Investor Ticker) - http://fdl.msn.com/public/investor/v9.5/ticker.cab

Administrator
Avatar
Antal indlæg: 55090

Nu skal jeg tjekke din log.
Den ipadresse 213.199.154.71 er legal nok.
http://emealogin.msn.com/pplogin.asp?strRS=http://213.199.154.71/Default.asp

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

Administrator
Avatar
Antal indlæg: 55090

Flyt Hijackthis til en mappe oprettet til formålet.

Hent denne scanner, den skal du bruge senere.
http://www.spywareinfo.dk/download/mwav.exe - Virusscanner.

Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, genstart.

O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/Restrictions present
O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/Control Panel present

———————————————————-
Så kører du engangsskanneren du hentede i starten - Aktiver det hele i opsætningen derinde, så den kan skanne alt igennem.
———————————————————-
Du skal også lige hente og installere programmet Ad-aware hvis du da ikke har det i forvejen. Opdater det straks efter installationen, og inden du kører en scanning med denne. Fjern alt hvad den finder. Programmet samt brugervejledning på dansk finder du her: http://www.spywarefri.dk/vaerktoj.htm#adaware
Følg også vejledningen her til udvidet søgning: http://www.spywarefri.dk/tipsogtricks.htm#adaware
———————————————————-
Genstart så skulle det være i orden igen.

Signatur

Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”

Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/

Nierne bomaye - You’ll never walk alone
qui potest, obligatur

  big ben
Antal indlæg: 6

Hej Fromsej

takker for hjælp, prøver det af..

Forsaat god aften/nat