On Thu, 7 Oct 2004 02:06:18 +0200, "Kim Larsen" <kl2607x@yahoo.dk>
wrote:
>"IzNoGoUd" <iznogoud@iznogoud.dk> skrev i en meddelelse
>news:ld78m0lhf821omq7frsnvsta1mvo6m2iej@4ax.com...
>> On Tue, 5 Oct 2004 20:46:13 +0200, "Kim Larsen" <kl2607x@yahoo.dk>
>> wrote:
>>
>> >Jeg er kommet dertil at jeg har opgivet indtil der kommer en ordentlig
>> >opdatering eller at ejeren af maskinen re-installerer den. Og det kommer
>nok
>> >ikke til at ske - såååhhh... slut med flere opdateringer på den maskine
>ved
>> >mindre at én eller anden kommer med et guldkorn
>>
>> Prøv at køre hijackthis.exe og kom med resultatet her.
>> Det er nok som andre har skrevet en ikke helt ren maskine.
>>
>>
http://209.133.47.12/~merijn/files/HijackThis.exe
>
>Her er resultatet, håber du kan bruge det til noget:
>
>Logfile of HijackThis v1.98.2
>Scan saved at 02:04:23, on 07-10-2004
>Platform: Windows XP SP1 (WinNT 5.01.2600)
>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>
>Running processes:
>C:\WINDOWS\System32\smss.exe
>C:\WINDOWS\system32\winlogon.exe
>C:\WINDOWS\system32\services.exe
>C:\WINDOWS\system32\lsass.exe
>C:\WINDOWS\system32\svchost.exe
>C:\WINDOWS\System32\svchost.exe
>C:\WINDOWS\system32\spoolsv.exe
>C:\WINDOWS\Explorer.EXE
>C:\Programmer\McAfee\McAfee VirusScan\Avsynmgr.exe
>C:\Programmer\Canon\MultiPASS4\MPSERVIC.EXE
>C:\WINDOWS\System32\nvsvc32.exe
>C:\WINDOWS\System32\svchost.exe
>C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
>C:\Programmer\Microsoft IntelliPoint\point32.exe
>C:\Programmer\Messenger Plus! 3\MsgPlus.exe
>C:\Programmer\Messenger\msmsgs.exe
>C:\Programmer\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
>C:\Programmer\McAfee\McAfee VirusScan\VsStat.exe
>C:\Programmer\McAfee\McAfee VirusScan\Vshwin32.exe
>C:\Programmer\Fælles filer\Network Associates\McShield\Mcshield.exe
>C:\Programmer\MSN Messenger\msnmsgr.exe
>C:\Programmer\McAfee\McAfee VirusScan\Avconsol.exe
>C:\Programmer\Outlook Express\msimn.exe
>C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
>C:\Programmer\Canon\MultiPASS4\MPDBMgr.exe
>C:\Documents and Settings\Kim\Lokale indstillinger\Temporary Internet
>Files\Content.IE5\0T6BC1MZ\HijackThis[1].exe
>
>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
>
http://search.scourweb.net/nph-search.cgi?partner=wesb1&look=sbar1_srchbtn
>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
>
http://search.scourweb.net/nph-search.cgi?partner=wesrch1&look=stmpl1&kw=
>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
>file:///E:/Startside/Startide.htm
>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
>
http://search.scourweb.net/nph-search.cgi?partner=wesrch1&look=stmpl1&kw=
>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
>
http://search.scourweb.net/nph-search.cgi?partner=wesb1&look=sbar1_srchbtn
>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
>
http://search.scourweb.net/nph-search.cgi?partner=wesrch1&look=stmpl1&kw=
>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
>
http://search.scourweb.net/nph-search.cgi?partner=wesrch1&look=stmpl1&kw=
>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
>
http://search.scourweb.net/nph-search.cgi?partner=wesrch1&look=stmpl1&kw=
>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
>
http://search.scourweb.net/nph-search.cgi?partner=wesrch1&look=stmpl1&kw=
>R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
>
http://search.scourweb.net/nph-search.cgi?partner=wesrch1&look=stmpl1&kw=
>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali
>A/S - Microsoft Internet Explorer
>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
>Hyperlinks
>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
>C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot -
>Search & Destroy\SDHelper.dll
>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
>C:\WINDOWS\System32\msdxm.ocx
>O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} -
>C:\Programmer\McAfee\McAfee VirusScan\VSCShellExtension.dll
>O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
>O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
>O4 - HKLM\..\Run: [TaskReg] C:\Programmer\Kazaa\My Shared Folder\Super Mario
>Bros 2 (2).exe
>O4 - HKLM\..\Run: [TkBellExe] C:\Programmer\Fælles
>filer\Real\Update_OB\realsched.exe -osboot
>O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft
>IntelliPoint\point32.exe"
>O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus!
>3\MsgPlus.exe"
>O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
>O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus!
>3\MsgPlus.exe" /WinStart
>O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor]
>"C:\Programmer\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe"
>/STARTMONITOR
>O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe"
>/background
>O4 - Global Startup: Adobe Gamma Loader.exe.lnk = ?
>O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft
>Office\Office\OSA9.EXE
>O8 - Extra context menu item: Åbn billede i &Microsoft PhotoDraw -
>res://C:\PROGRA~1\MICROS~2\Office\1030\phdintl.dll/phdContext.htm
>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
>C:\Programmer\Messenger\MSMSGS.EXE
>O9 - Extra 'Tools' menuitem: Windows Messenger -
>{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
>O16 - DPF: btcprinv -
http://www.supertel.se/download/btcprinv.cab
>O16 - DPF: Yahoo! Chess -
>
http://download.games.yahoo.com/games/clients/y/ct1_x.cab
>O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) -
>
http://www.meadroid.com/scriptx/ScriptX.cab
>O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) -
>
http://www.skylinesoft.com/interactive/TerraExplorer/Install/TEInstallPlugIn.cab
>O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -
>
http://www.cult3d.com/download/cult.cab
>O16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} (TurnTool Scene) -
>
http://www.turntool.com/ViewerInstall.exe
>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient
>Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer
>Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
>O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) -
>
https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
>O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
>
http://www.shockwave.com/content/zuma/popcaploader_v5.cab
>O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) -
>
https://netbank.danskebank.dk/netbank/activex/DanskeSikker.cab
Tak for det og så kan jeg sige dig at du skal have afinstalleret kazaa
jeg stoler ikke på det program så væk med det. Der kommer meget skidt
ind med det program!!!
Kør så spybot, adaware og virusscan prøv lige med:
http://housecall.trendmicro.com/housecall/start_corp.asp
og
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
Du har en del hijack programmer inde, som stjæler din startside i din
IE browser! kør dette lille program men du skal nok manuelt ind og
fjeren services som starter disse hijacker op!
http://209.133.47.12/~merijn/files/CWShredder.exe
Desuden har du et lille problem med canon printer softwaren som jeg
har beskrevet i en anden tråd, det er den der er dit største problem!
Følg instruktionerne om download, husk lige at vælge dansk.
http://support.microsoft.com/default.aspx?scid=kb;en-us;884020
Desuden skulle du lige rense lidt ud i dine filer som starter op fx.
behøver du måske ikke nerocheck.
God arbejdslyst
best regards IzNoGoUd a.k.a. Claes Nielsen, DK-5700 Svendborg, Denmark.
*
"All your base are belong to us"