Guest idgadmin Posted November 20, 2004 Share Posted November 20, 2004 Logfile of HijackThis v1.98.1 Scan saved at 18:57:57, on 2004-11-20 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe C:\Program\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe C:\Program\Microsoft Hardware\Keyboard\type32.exe C:\Program\Messenger\msmsgs.exe C:\Program\AdDestroyer\AdDestroyer.exe C:\Program\VBouncer\VirtualBouncer.exe C:\Program\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe C:\Program\Delade filer\Microsoft Shared\VS7Debug\mdm.exe C:\Program\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\Avp32.exe C:\WINDOWS\System32\wuauclt.exe C:\Program\Internet Explorer\iexplore.exe C:\Documents and Settings\Modern\Mina dokument\Mina mottagna filer\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dn.se/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [OfficeGuard RegChecker] "C:\Program\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ogrc.exe" O4 - HKLM\..\Run: [AVPCC] "C:\Program\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait O4 - HKLM\..\Run: [intelliType] "C:\Program\Microsoft Hardware\Keyboard\type32.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background O4 - Startup: AdDestroyer.lnk = C:\Program\AdDestroyer\AdDestroyer.exe O4 - Startup: Virtual Bouncer.lnk = C:\Program\VBouncer\VirtualBouncer.exe O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=08684070fd49578d9cea50ae6b0acefcfbb84033807f5b0ac7f1263a2a3410a3530bb5d1d0c73631f955208ec57d9cb2ba04b99933536261:5384e68ecedbe601989f3130ba048162 O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1098294525046 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://install.spywarelabs.com/2506040513/BundleOuter2506040513.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{3AB53DC2-E7CF-4218-988B-28017DC961AD}: NameServer = 194.165.224.165 O17 - HKLM\System\CS1\Services\Tcpip\..\{3AB53DC2-E7CF-4218-988B-28017DC961AD}: NameServer = 194.165.224.165 O17 - HKLM\System\CS2\Services\Tcpip\..\{3AB53DC2-E7CF-4218-988B-28017DC961AD}: NameServer = 194.165.224.165 Link to comment Share on other sites More sharing options...
Zipp. Posted November 20, 2004 Share Posted November 20, 2004 Skapa en ny mapp på C:/ och placera HijackThis.exe dit så C:/HjT/HijackThis.exe Avsluta dom här processer C:\Program\AdDestroyer\AdDestroyer.exe C:\Program\VBouncer\VirtualBouncer.exe Sen avinstallera via Konrtollpanelen om det finns där AdDestroyer VBouncer Scanna med Hijack bocka i följande rader stäng Web-läsaren och alla andra öppna fönster och klicka FIX checked O4 - Startup: AdDestroyer.lnk = C:\Program\AdDestroyer\AdDestroyer.exe O4 - Startup: Virtual Bouncer.lnk = C:\Program\VBouncer\VirtualBouncer.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=08684070fd 49578d9cea50ae6b0acefcfbb84033807f5b0ac7f1263a2a3410a3530bb5d1d0c73631f955208ec57d9cb2ba04b99933536261 O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://install.spywarelabs.com/2506040513/BundleOuter2506040513.e xe Starta sen i felsäkert läge sök och ta bort om du hittar C:\Program\AdDestroyer\AdDestroyer.exe - ta bort AdDestroyer mappen C:\Program\VBouncer\VirtualBouncer.exe - ta bort VBouncer mappen Link to comment Share on other sites More sharing options...
Guest idgadmin Posted November 28, 2004 Share Posted November 28, 2004 tack så mycket.. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.