Gå til innhold

"HijackThis" scan - hva kan jeg slette?


Anbefalte innlegg

Nå har jeg kjørt "Spybot - Search & Destroy", "Ad-aware 6" og “The Cleaner” på maskinen min. Alle programmene har fjernet en del, men fortsatt blir startsiden tilbakestilt.

 

Startsiden blir forandret fra online.no til denne adressen:

mk:@MSITStore:C:\WINDOWS\start.chm::/start.html

 

Nå har jeg lastet ned HijackThis og kjørt en scan:

kan noen hjelpe meg med hva jeg kan slette?

 

---------

 

Logfile of HijackThis v1.97.7

Scan saved at 10:36:14, on 17.04.04

Platform: Windows 98 SE (Win9x 4.10.2222A)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

 

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL

C:\WINDOWS\SYSTEM\MSGSRV32.EXE

C:\WINDOWS\SYSTEM\MPREXE.EXE

C:\WINDOWS\SYSTEM\MSTASK.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM\RNAAPP.EXE

C:\WINDOWS\SYSTEM\TAPISRV.EXE

C:\WINDOWS\TASKMON.EXE

C:\WINDOWS\SYSTEM\SYSTRAY.EXE

C:\PROGRAMFILER\AHEAD\INCD\INCD.EXE

C:\WINDOWS\SYSTEM\QTTASK.EXE

C:\WINDOWS\LOADQM.EXE

C:\PROGRAMFILER\THE CLEANER\TCA.EXE

C:\PROGRAMFILER\THE CLEANER\TCM.EXE

C:\PROGRAMFILER\MSN MESSENGER\MSNMSGR.EXE

C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE

C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE

C:\WINDOWS\TWAIN_32\A4S2_600\WATCH.EXE

C:\PROGRAMFILER\ULEAD SYSTEMS\ULEAD PHOTOIMPACT\ABMTSR.EXE

C:\PROGRAMFILER\SPYWAREGUARD\SPYWAREGUARD\SGMAIN.EXE

C:\PROGRAMFILER\MSCAN\MSOFFICE\PANEL.EXE

C:\PROGRAMFILER\SPYWAREGUARD\SPYWAREGUARD\SGBHP.EXE

C:\WINDOWS\SYSTEM\DDHELP.EXE

C:\WINDOWS\SYSTEM\SPOOL32.EXE

C:\WINDOWS\SYSTEM\PSTORES.EXE

C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE

C:\PROGRAMFILER\FELLESFILER\REAL\UPDATE_OB\REALSCHED.EXE

C:\PROGRAMFILER\HIJACKTHIS\HIJACKTHIS.EXE

 

 

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.online.no/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.online.no/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fra Online ADSL

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAMFILER\SPYWAREGUARD\SPYWAREGUARD\DLPROTECT.DLL

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX

O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun

O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe

O4 - HKLM\..\Run: [systemTray] SysTray.Exe

O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

O4 - HKLM\..\Run: [inCD] C:\Programfiler\ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [uSSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1\SSAVER\USSSHREG.EXE /r

O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime

O4 - HKLM\..\Run: [LoadQM] loadqm.exe

O4 - HKLM\..\Run: [tcactive] C:\PROGRAMFILER\THE CLEANER\tca.exe

O4 - HKLM\..\Run: [tcmonitor] C:\PROGRAMFILER\THE CLEANER\tcm.exe

O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - Startup: Office Startup.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE

O4 - Startup: Microsoft Find Fast.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE

O4 - Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\A4S2_600\watch.exe

O4 - Startup: TextBridge Instant Access OCR.lnk = C:\Program Files\TextBridge Classic\Bin\TBMenu.exe

O4 - Startup: Album Fast Start.lnk = C:\Programfiler\Ulead Systems\Ulead PhotoImpact\ABMTSR.EXE

O4 - Startup: SpywareGuard.lnk = C:\Programfiler\spywareguard\SpywareGuard\sgmain.exe

O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.online.no/

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab

O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB

Endret av crusoe
Lenke til kommentar
Videoannonse
Annonse

Den første delen av listen er vel bare en oversikt over "Running processes", og var vel kanskje ikke nødvendig å ta med. Den andre delen er litt mer interessant. Har slettet disse som jeg er ganske sikre på at er ulumskheter foreløpig:

(men det var tydeligvis ikke nok) :(

 

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...