crusoe Skrevet 18. april 2004 Del Skrevet 18. april 2004 (endret) Nå har jeg kjørt "Spybot - Search & Destroy", "Ad-aware 6" og “The Cleaner” på maskinen min. Alle programmene har fjernet en del, men fortsatt blir startsiden tilbakestilt. Startsiden blir forandret fra online.no til denne adressen: mk:@MSITStore:C:\WINDOWS\start.chm::/start.html Nå har jeg lastet ned HijackThis og kjørt en scan: kan noen hjelpe meg med hva jeg kan slette? --------- Logfile of HijackThis v1.97.7 Scan saved at 10:36:14, on 17.04.04 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\PROGRAMFILER\AHEAD\INCD\INCD.EXE C:\WINDOWS\SYSTEM\QTTASK.EXE C:\WINDOWS\LOADQM.EXE C:\PROGRAMFILER\THE CLEANER\TCA.EXE C:\PROGRAMFILER\THE CLEANER\TCM.EXE C:\PROGRAMFILER\MSN MESSENGER\MSNMSGR.EXE C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE C:\WINDOWS\TWAIN_32\A4S2_600\WATCH.EXE C:\PROGRAMFILER\ULEAD SYSTEMS\ULEAD PHOTOIMPACT\ABMTSR.EXE C:\PROGRAMFILER\SPYWAREGUARD\SPYWAREGUARD\SGMAIN.EXE C:\PROGRAMFILER\MSCAN\MSOFFICE\PANEL.EXE C:\PROGRAMFILER\SPYWAREGUARD\SPYWAREGUARD\SGBHP.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE C:\PROGRAMFILER\FELLESFILER\REAL\UPDATE_OB\REALSCHED.EXE C:\PROGRAMFILER\HIJACKTHIS\HIJACKTHIS.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.online.no/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.online.no/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fra Online ADSL R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAMFILER\SPYWAREGUARD\SPYWAREGUARD\DLPROTECT.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe O4 - HKLM\..\Run: [systemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [inCD] C:\Programfiler\ahead\InCD\InCD.exe O4 - HKLM\..\Run: [uSSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1\SSAVER\USSSHREG.EXE /r O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [tcactive] C:\PROGRAMFILER\THE CLEANER\tca.exe O4 - HKLM\..\Run: [tcmonitor] C:\PROGRAMFILER\THE CLEANER\tcm.exe O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background O4 - Startup: Office Startup.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE O4 - Startup: Microsoft Find Fast.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE O4 - Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\A4S2_600\watch.exe O4 - Startup: TextBridge Instant Access OCR.lnk = C:\Program Files\TextBridge Classic\Bin\TBMenu.exe O4 - Startup: Album Fast Start.lnk = C:\Programfiler\Ulead Systems\Ulead PhotoImpact\ABMTSR.EXE O4 - Startup: SpywareGuard.lnk = C:\Programfiler\spywareguard\SpywareGuard\sgmain.exe O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.online.no/ O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB Endret 18. april 2004 av crusoe Lenke til kommentar
Crack Skrevet 18. april 2004 Del Skrevet 18. april 2004 (endret) ==== Slettet ==== Endret 24. mai 2006 av Crack Lenke til kommentar
crusoe Skrevet 18. april 2004 Forfatter Del Skrevet 18. april 2004 Den første delen av listen er vel bare en oversikt over "Running processes", og var vel kanskje ikke nødvendig å ta med. Den andre delen er litt mer interessant. Har slettet disse som jeg er ganske sikre på at er ulumskheter foreløpig: (men det var tydeligvis ikke nok) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå