FBJ_TS-support
den skriver “administratoren har fjernet muligheden for ændre i registreringsdatabasen
Administrator
Antal indlæg: 55090
Logfil fra Stens:
Logfile of HijackThis v1.97.7
Scan saved at 22:11:25, on 07-03-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/Explorer.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Fælles filer/Microsoft Shared/VS7Debug/mdm.exe
C:/Programmer/Fælles filer/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/SMSSkx.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Documents and Settings/Anders Stensgaard/Skrivebord/hijackthis.com
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=132047
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=132047
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.msn.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=132047
R1 - HKCU/Software/Microsoft/Windows/CurrentVersion/Internet Settings,ProxyOverride = localhost
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://www.google.dk/
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
F0 - system.ini: Shell=Explorer.exe SMSSkx.exe
F2 - REG:system.ini: Shell=Explorer.exe SMSSkx.exe
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:/Programmer/MyWay/myBar/1.bin/MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Programmer/Fælles filer/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Programmer/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Programmer/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &SearchBar; - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:/Programmer/MyWay/myBar/1.bin/MYBAR.DLL
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:/Programmer/ISTbar/istbar.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Programmer/Fælles filer/Symantec Shared/AdBlocking/NISShExt.dll
O4 - HKLM/../Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [zBrowser Launcher] C:/Programmer/Logitech/iTouch/iTouch.exe
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [FilterGate] C:/PROGRA~1/FILTER~1/filtergate.exe /ASK
O4 - HKLM/../Run: [ccApp] “C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [Advanced Tools Check] C:/PROGRA~1/NORTON~1/AdvTools/ADVCHK.EXE
O4 - HKLM/../Run: [BootWarn] C:/Programmer/Norton AntiVirus/BootWarn.exe /a
O4 - HKLM/../Run: [EM_EXEC] C:/PROGRA~1/Logitech/MOUSEW~1/SYSTEM/EM_EXEC.EXE
O4 - HKLM/../Run: [NeroFilterCheck] C:/WINDOWS/system32/NeroCheck.exe
O4 - HKLM/../Run: [IST Service] C:/Programmer/ISTsvc/istsvc.exe
O4 - HKLM/../Run: [msbb] C:/Programmer/180Solutions/msbb.exe
O4 - HKLM/../Run: [Power Scan] C:/Programmer/Power Scan/powerscan.exe
O4 - HKLM/../Run: [dqchsjow] C:/WINDOWS/System32/zgabziwd.exe
O4 - HKLM/../Run: [VGQIS] C:/WINDOWS/VGQIS.exe
O4 - HKLM/../Run: [EasyDates_no] C:/Program Files/GMSoft/Dialers/EasyDates_no/EasyDates_no.exe /dontdial
O4 - HKLM/../Run: [Service Host] C:/WINDOWS/SMSSkx.exe
O4 - HKLM/../Run: [IS CfgWiz] C:/Programmer/Fælles filer/Symantec Shared/cfgwiz.exe /GUID NIS /CMDLINE “REBOOT”
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [H/PC Connection Agent] “C:/Programmer/Microsoft ActiveSync/WCESCOMM.EXE”
O4 - HKCU/../Run: [AdsKiller2.0] C:/Programmer/AdsKiller2.0/AdsKiller.exe min
O4 - HKCU/../Run: [LDM] C:/Programmer/Logitech/Desktop Messenger/8876480/Program/BackWeb-8876480.exe
O4 - HKCU/../Run: [ClockSync] C:/Programmer/ClockSync/Sync.exe
O4 - Global Startup: GStartup.lnk = ?
O4 - Global Startup: LightSurf.lnk = C:/Programmer/LightSurf/Common/IconMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:/Programmer/Logitech/Desktop Messenger/8876480/Program/LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O4 - Global Startup: SECRETMAKER.lnk = C:/Programmer/SECRETMAKER/secretmaker.exe
O7 - HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/System, DisableRegedit=1
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra ‘Tools’ menuitem: Create Mobile Favorite… (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra ‘Tools’ menuitem: ICQ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:/Programmer/Internet Explorer/Plugins/NPDocBox.dll
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006_cracks.cab
O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) - http://www.skylinesoft.com/interactive/TerraExplorer/Install/TEInstallPlugIn.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.stellarhosting.dk/msrdp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://scanner.virus112.com/cabs/cssweb.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
Signatur
Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”
Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/
Nierne bomaye - You’ll never walk alone
qui potest, obligatur
Okay og hvad skal jeg så
?
Mvh Anders
Redaktør
Antal indlæg: 17644
Lige et øjeblik - nu er du blevet vant til hurtige svar, men nu skal jeg bruge et par minutter, så smut du bare ud og lav en kop kaffe
Signatur
Gode råd om sikkerhed….
hehe sorry
Okay det vil jeg gøre
Redaktør
Antal indlæg: 17644
Jeg tror vi skal tage det i par trin.
Kør en scanning med Hijackthis, så du kan se alle filer. Du får herunder nogle linier, som du skal fixe. Det, du skal gøre, er at sætte en vinge ud for alle disse linier. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på “Fix checked”. Efter fix skal du genstarte din computer.
Det er disse, som skal fixes:
F0 - system.ini: Shell=Explorer.exe SMSSkx.exe
F2 - REG:system.ini: Shell=Explorer.exe SMSSkx.exe
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:/Programmer/MyWay/myBar/1.bin/MYBAR.DLL
O3 - Toolbar: &SearchBar; - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:/Programmer/MyWay/myBar/1.bin/MYBAR.DLL
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:/Programmer/ISTbar/istbar.dll (file missing)
O4 - HKLM/../Run: [IST Service] C:/Programmer/ISTsvc/istsvc.exe
O4 - HKLM/../Run: [msbb] C:/Programmer/180Solutions/msbb.exe
O4 - HKLM/../Run: [Power Scan] C:/Programmer/Power Scan/powerscan.exe
O4 - HKLM/../Run: [dqchsjow] C:/WINDOWS/System32/zgabziwd.exe
O4 - HKLM/../Run: [VGQIS] C:/WINDOWS/VGQIS.exe
O4 - HKLM/../Run: [EasyDates_no] C:/Program Files/GMSoft/Dialers/EasyDates_no/EasyDates_no.exe /dontdial
O4 - HKLM/../Run: [Service Host] C:/WINDOWS/SMSSkx.exe
O4 - HKCU/../Run: [ClockSync] C:/Programmer/ClockSync/Sync.exe
O4 - Global Startup: GStartup.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O7 - HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/System, DisableRegedit=1
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006_cracks.cab
Genstart i SAFE MODE og slet følgende:
C:/Programmer/MyWay <<—hele mappen
C:/Programmer/ISTsvc <<—hele mappen
C:/Programmer/180Solutions <<—hele mappen
C:/Programmer/Power Scan <<—hele mappen
C:/WINDOWS/System32/zgabziwd.exe <<—fil
C:/WINDOWS/VGQIS.exe
C:/Program Files/GMSoft/Dialers <<—hele mappen
C:/WINDOWS/SMSSkx.exe <<—fil
C:/Programmer/ClockSync/Sync.exe <<—hele mappen
Se om du kan omdøbe Notepad.com/Notepad til Notepad.exe
Genstart i NORMAL MODE, kør HiJackThis, scan og læg en frisk log her (eller send den til fbjohansen(at)msn.com - og giv lyd fra dig når du har gjort det.
Signatur
Gode råd om sikkerhed….
Hej igen
Jeg kunne ikke slette C:/WINDOWS/SMSSkx.exe “adgang nægtet”
Og jeg kunne ikke finde C:/WINDOWS/VGQIS.EXE
Her er den nye log
Logfile of HijackThis v1.97.7
Scan saved at 23:05:22, on 07-03-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Programmer/Fælles filer/Symantec Shared/ccSetMgr.exe
C:/Programmer/Fælles filer/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/Explorer.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Fælles filer/Microsoft Shared/VS7Debug/mdm.exe
C:/Programmer/Norton AntiVirus/navapsvc.exe
C:/Programmer/Norton AntiVirus/AdvTools/NPROTECT.EXE
C:/WINDOWS/System32/nvsvc32.exe
C:/Programmer/Fælles filer/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/SMSSkx.exe
C:/Programmer/Norton AntiVirus/SAVScan.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Documents and Settings/Anders Stensgaard/Skrivebord/hijackthis.com
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=132047
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=132047
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.msn.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=132047
R1 - HKCU/Software/Microsoft/Windows/CurrentVersion/Internet Settings,ProxyOverride = localhost
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://www.google.dk/
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
F0 - system.ini: Shell=Explorer.exe SMSSkx.exe
F2 - REG:system.ini: Shell=Explorer.exe SMSSkx.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Programmer/Fælles filer/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Programmer/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Programmer/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Programmer/Fælles filer/Symantec Shared/AdBlocking/NISShExt.dll
O4 - HKLM/../Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [zBrowser Launcher] C:/Programmer/Logitech/iTouch/iTouch.exe
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [FilterGate] C:/PROGRA~1/FILTER~1/filtergate.exe /ASK
O4 - HKLM/../Run: [ccApp] “C:/Programmer/Fælles filer/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [Advanced Tools Check] C:/PROGRA~1/NORTON~1/AdvTools/ADVCHK.EXE
O4 - HKLM/../Run: [BootWarn] C:/Programmer/Norton AntiVirus/BootWarn.exe /a
O4 - HKLM/../Run: [EM_EXEC] C:/PROGRA~1/Logitech/MOUSEW~1/SYSTEM/EM_EXEC.EXE
O4 - HKLM/../Run: [NeroFilterCheck] C:/WINDOWS/system32/NeroCheck.exe
O4 - HKLM/../Run: [IS CfgWiz] C:/Programmer/Fælles filer/Symantec Shared/cfgwiz.exe /GUID NIS /CMDLINE “REBOOT”
O4 - HKLM/../Run: [Service Host] C:/WINDOWS/SMSSkx.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [H/PC Connection Agent] “C:/Programmer/Microsoft ActiveSync/WCESCOMM.EXE”
O4 - HKCU/../Run: [AdsKiller2.0] C:/Programmer/AdsKiller2.0/AdsKiller.exe min
O4 - HKCU/../Run: [LDM] C:/Programmer/Logitech/Desktop Messenger/8876480/Program/BackWeb-8876480.exe
O4 - Global Startup: LightSurf.lnk = C:/Programmer/LightSurf/Common/IconMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:/Programmer/Logitech/Desktop Messenger/8876480/Program/LDMConf.exe
O4 - Global Startup: SECRETMAKER.lnk = C:/Programmer/SECRETMAKER/secretmaker.exe
O7 - HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/System, DisableRegedit=1
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra ‘Tools’ menuitem: Create Mobile Favorite… (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra ‘Tools’ menuitem: ICQ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:/Programmer/Internet Explorer/Plugins/NPDocBox.dll
O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) - http://www.skylinesoft.com/interactive/TerraExplorer/Install/TEInstallPlugIn.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.stellarhosting.dk/msrdp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://scanner.virus112.com/cabs/cssweb.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
Nå jeg prøver at slette C:/WINDOWS/SMSSkx skriver den
“Det er ikke muligt at slette SMSSkx: Adgang nægtet.
Kontroller, at disken ikke er fuld eller skrivebeskyttet, og at filen ikke er i brug.”
Mvh Anders
Redaktør
Antal indlæg: 17644
Jeg går ud fra, at du var i fejlsikret tilstand ??
Det er en hård nyser den der fil, og det er den der laver al balladen. Klik Start -> Kør -> og skriv regedit . Naviger til HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/System, find DisableRegedit=1 og ret 1-tallet til et 0.
Brug tastekombinationen CTRL-ALT-DEL og kig i process fanebladet - kan du da finde SMSSkx? Hvis ja - højreklik på den og Afslut process.
Herefter: Naviger til C:/WINDOWS/SMSSkx.exe, højreklik på den, vælg egenskaber og fjern fluebenet i Skrivebeskyttet og klik OK. Prøv at slette filen nu.
Vi er ikke færdige, men det her er vigtigt at få fixet først.
Signatur
Gode råd om sikkerhed….
Øv, når jeg skriver “regedit” og trykker ok, kommer der en fejlmeddelse op der siger at windows ikke kan finde regedit
Redaktør
Antal indlæg: 17644
Bare fortsæt med CTRL-ALT-DEL ... osv.
Signatur
Gode råd om sikkerhed….
Jeg har afsluttet processen og filen er slettet
Redaktør
Antal indlæg: 17644
Det var rart. Genstart i fejlsikret tilstand, kør HiJackThis og fix følgende linier
F0 - system.ini: Shell=Explorer.exe SMSSkx.exe
F2 - REG:system.ini: Shell=Explorer.exe SMSSkx.exe
O4 - HKLM/../Run: [Service Host] C:/WINDOWS/SMSSkx.exe
O7 - HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/System, DisableRegedit=1
Genstart i normal mode, kør HiJackThis, scan og læg en frisk log.
Signatur
Gode råd om sikkerhed….
okay jeg skal lige høre, hvordan man starter i fejlsikret tilstand.
Når jeg trykker Start-Luk computer. Kan jeg kun vælge mellem
Stand by
Luk
Genstart
Der er ikke nogen genstart i fejsikrettilstand
Redaktør
Antal indlæg: 17644
Når du genstarter din PC skal du blot taste F8 en masse gange umiddelbart efter din PC er startet. Bare bliv ved indtil du får den mulighed. Hvis den spørger om hvor du vil boote fra, skal du blot trykke Enter og blive ved med at taste F8.
Signatur
Gode råd om sikkerhed….