Gå til innhold

Litt hjelp til Hijack-logg


Anbefalte innlegg

Skrevet (endret)

Jeg får opp dette hver gang jeg scanner, (og gjerne et par til) hva kommer det av? Hvorfor blir jeg aldri kvitt det? Bruker firefox som nettleser. Scanner 2-3 ganger i uka.

 

sad.jpg

Endret av Stine
Videoannonse
Annonse
Skrevet

Det der er vel stort sett trackingcookies, de vil derfor forsvinne om du gjør om en liten detalj i nettleseren din. I Firefox, gå til "tools->options->privacy->cookies->keep cookies" og velg "until i close Firefox". De vil da aldri bli igjen til neste gang du surfer og de mister da store deler av sin funksjon.

 

En annen liten detalj du kan være tjent med er å legge til et par stygge nettsteder inn i hostsfila, dette kan du blant annet gjøre via immuniser i spybot.

Skrevet
Det der er vel stort sett trackingcookies, de vil derfor forsvinne om du gjør om en liten detalj i nettleseren din. I Firefox, gå til "tools->options->privacy->cookies->keep cookies" og velg "until i close Firefox". De vil da aldri bli igjen til neste gang du surfer og de mister da store deler av sin funksjon.

 

En annen liten detalj du kan være tjent med er å legge til et par stygge nettsteder inn i hostsfila, dette kan du blant annet gjøre via immuniser i spybot.

Takk.

 

Jeg immuniserer hele tiden.

Skrevet (endret)

Du skulle vel ikke ha innstallert MSN+ ? Den kan legge igjen noen "morsomme" ting om du velger sponsa MSN+.

 

Uansett - forsøk housecall.trendmicro.com (virus og spyware scanner) og se hva den sier, forsøk også www.ccleaner.com og se hva den sier om ting i start-up menyen.

 

[edit]Url[/edit]

Endret av Grim Aramis
Skrevet (endret)

Logfile of HijackThis v1.99.1

Scan saved at 12:33:06, on 16.08.2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programfiler\TOSHIBA\Power Management\CeEPwrSvc.exe

C:\Programfiler\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe

C:\Programfiler\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Webroot\Spy Sweeper\WRSSSDK.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\igfxtray.exe

C:\WINDOWS\System32\hkcmd.exe

C:\Programfiler\Apoint2K\Apoint.exe

C:\Programfiler\TOSHIBA\Power Management\CePMTray.exe

C:\Programfiler\TOSHIBA\E-KEY\CeEKey.exe

C:\Programfiler\TOSHIBA\TouchPad\TPTray.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

C:\Programfiler\Microsoft AntiSpyware\gcasServ.exe

C:\Programfiler\MessengerPlus! 3\MsgPlus.exe

C:\Programfiler\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\MSN Messenger\msnmsgr.exe

C:\Programfiler\Apoint2K\Apntex.exe

C:\Programfiler\Microsoft AntiSpyware\gcasDtServ.exe

C:\Programfiler\Mozilla Firefox\firefox.exe

C:\Programfiler\Thumbs32\Thumbs.exe

C:\PROGRA~1\DVDREG~2\DVDRegionFree.exe

C:\Programfiler\Winamp\winamp.exe

 

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Popup Blocker - {593FA054-6BFB-4ce5-B87A-0A68DB7C0F08} - C:\WINDOWS\System32\EniroToolbar\PopupBlocker.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar1.dll

O3 - Toolbar: Eniro - {A3C4086C-097C-46b0-AFB0-76B5CC294233} - C:\WINDOWS\System32\EniroToolbar\Toolband.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar1.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [Apoint] C:\Programfiler\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [CeEPOWER] C:\Programfiler\TOSHIBA\Power Management\CePMTray.exe

O4 - HKLM\..\Run: [CPLDBL10] C:\Programfiler\EzButton\CPLDBL10.EXE

O4 - HKLM\..\Run: [CeEKEY] C:\Programfiler\TOSHIBA\E-KEY\CeEKey.exe

O4 - HKLM\..\Run: [TPNF] C:\Programfiler\TOSHIBA\TouchPad\TPTray.exe

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [DVD43] "C:\Programfiler\DVD Region+CSS Free\DVDRegionFree.exe" /hidden

O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programfiler\Logitech\Video\ISStart.exe

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

O4 - HKLM\..\Run: [gcasServ] "C:\Programfiler\Microsoft AntiSpyware\gcasServ.exe"

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programfiler\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [spySweeper] "C:\Programfiler\Webroot\Spy Sweeper\SpySweeper.exe" /startintray

O4 - HKLM\..\Run: [Zone Labs Client] C:\Programfiler\Zone Labs\ZoneAlarm\zlclient.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [simp] C:\Programfiler\Secway\SimpLite-MSN 2.1\SimpLite-MSN.exe

O4 - HKCU\..\Run: [TrickshotSetup.exe] C:\DOCUME~1\Kristine\SKRIVE~1\TRICKS~1.EXE /r

O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: &Google Search - res://c:\programfiler\google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: Backward Links - res://c:\programfiler\google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programfiler\google\GoogleToolbar1.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://c:\programfiler\google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Søk på Kvasir - res://C:\WINDOWS\System32\EniroToolbar\Toolband.dll/MENUSEARCH_NO.HTM

O8 - Extra context menu item: Translate into English - res://c:\programfiler\google\GoogleToolbar1.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {1D185838-009D-47C8-824B-B65B4854430E} (Installer Class) - http://quickfix2.chello.no/quickfix2/asp/chelloInstall.CAB

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www.ibm.com/pc/support/access/sdcco...ad/IbmEgath.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

O16 - DPF: {C58EFA10-2CC0-4C50-8C77-B326555EC1B7} (clsDefault Class) - http://quickfix2.chello.no/quickfix2/asp/LaunchApp.CAB

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab28578.cab

O20 - AppInit_DLLs: MsgPlusLoader.dll

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll

O23 - Service: .netrus - - (no file)

O23 - Service: Adobe LM Service - Unknown owner - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Programfiler\TOSHIBA\Power Management\CeEPwrSvc.exe

O23 - Service: DefWatch - Symantec Corporation - C:\Programfiler\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe

O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Programfiler\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe

O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Programfiler\Webroot\Spy Sweeper\WRSSSDK.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\Security Center\SymWSC.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Endret av Stine
Skrevet

Følgende bør du kunne krysse av for å fikse i HijackThis.

 

Hva er dette?

O4 - HKCU\..\Run: [TrickshotSetup.exe] C:\DOCUME~1\Kristine\SKRIVE~1\TRICKS~1.EXE /r

 

Trenger du egentlig både google toolbar og eniro - toolbarer er noe styggedom. Jeg stoler ikke på dem.

O2 - BHO: Popup Blocker - {593FA054-6BFB-4ce5-B87A-0A68DB7C0F08} - C:\WINDOWS\System32\EniroToolbar\PopupBlocker.dll

O3 - Toolbar: Eniro - {A3C4086C-097C-46b0-AFB0-76B5CC294233} - C:\WINDOWS\System32\EniroToolbar\Toolband.dll

O8 - Extra context menu item: Søk på Kvasir - res://C:\WINDOWS\System32\EniroToolbar\Toolband.dll/MENUSEARCH_NO.HTM

 

Søppel fra gammelt av:

O23 - Service: .netrus - - (no file)

 

Ikke godt å si ellers hva som gir deg popups..men prøv dette først.

Skrevet (endret)

Får ikke popups. Får det jeg postet i første posten. :)

Blah, som seff er borte...

 

 

Edit: O4 - HKCU\..\Run: [TrickshotSetup.exe] C:\DOCUME~1\Kristine\SKRIVE~1\TRICKS~1.EXE /r er et spill tror jeg.

Endret av Stine

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...