![]() |
|
#1
| |||
| |||
| Okej, så jag har läst runt lite och det verkar som det finns olika lösningar. Jag kör regula Windows Vista. Ctrl Alt Del fungerar inte ... högerklicka fungerar inte. när jag söker efter taskmgr.exe det säger att det har inaktiverats av administratören. Vad kan jag göra? |
|
#2
| ||||||||||||
| ||||||||||||
| Vista är annorlunda till XP.
__________________
Högerklicka i Aktivitetsfältet och klicka sedan på Aktivitetshanteraren. Mitt System: Hybr! D
|
|
#3
| |||
| |||
| Jag klickade rätt aktivitetsfältet och det är nedtonade. Men jag sökte runt lite och jag hittade en sida med en direkt länk till min Reged och det gav mig varningar och då jag precis lämnat, för jag hade ingen aning om vad jag gjorde. Efteråt av nyfikenhet jag cheked aktivitetsfältet och det var nedtonade inte ut. Jag startade min dator (för att försäkra att det inte var en tillfällig sak) och av någon konstig anledning när skärmen för att logga in skulle komma upp ... det sa trycka Ctrl Alt Del för att logga in Jag förstår inte vad som hände . |
|
#4
| |||
| |||
| Här är min HijackThis logg C: \ Windows \ system32 \ taskeng.exe C: \ Windows \ system32 \ Dwm.exe C: \ Windows \ Explorer.EXE C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ Program Files \ HP \ QuickPlay \ QPService.exe C: \ Program Files \ HP \ HP Software Update \ hpwuSchd2.exe C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Knappar \ QLBCTRL.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe C: \ Program \ Java \ jre1.6.0 \ bin \ jusched.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ Program Files \ Comcast \ Desktop Doctor \ bin \ sprtcmd.exe C: \ Program Files \ Windows Sidebar \ sidebar.exe C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe C: \ WINDOWS \ System32 \ rundll32.exe C: \ WINDOWS \ ehome \ ehtray.exe C: \ Windows \ ehome \ ehmsas.exe C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe C: \ Program \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe C: \ Windows \ system32 \ wbem \ unsecapp.exe C: \ progra ~ 1 \ HEWLET ~ 1 \ Shared \ HPQTOA ~ 1.EXE C: \ Program Files \ Hewlett-Packard \ HP Advisor \ SSDK04.exe C: \ Program Files \ Internet Explorer \ Ieuser.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program \ Delade filer \ Microsoft Shared \ Windows Live \ WLLoginProxy.exe C: \ Windows \ system32 \ SearchFilterHost.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe C: \ Windows \ system32 \ Macromed \ Flash \ FlashUtil9b.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant = R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, CustomizeSearch = R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Window Title = Windows Internet Explorer som Comcast R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Settings, Proxyserver =: 0 R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName = R3 - URLSearchHook: AOLTBSearch Class - (EA756889-2338-43DB-8F07-D1CA6FB9C90D) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O1 - Hosts::: 1 localhost O2 - BHO: My Search BHO - (014DA6C1-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Download och Titelinformation Plugin för Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program \ Java \ jre1.6.0 \ bin \ ssv.dll O2 - BHO: AOL Toolbar Launcher - (7C554162-8CB7-45A4-B8F4-8EA1C75885F9) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O2 - BHO: (inget namn) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program \ Delade filer \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O2 - BHO: BDEX System - (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) - C: \ Windows \ blopenvxdt.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - c: \ program \ google \ googletoolbar1.dll O2 - BHO: FastRX - (E09962E7-A39E-4F60-8003-66D57BED27B7) - C: \ Windows \ system32 \ fastRX.dll (file missing) O3 - Toolbar: My Search Bar - (014DA6C9-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O3 - Toolbar: Veoh Browser Plug-in - (D0943516-5076-4020-A3B5-AEFAF26AB263) - C: \ Users \ Yasmany \ Desktop \ Veoh \ Plugins \ reg \ VeohTool bar.dll O3 - Toolbar: & Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - c: \ program \ google \ googletoolbar1.dll O3 - Toolbar: AIM Toolbar - (DE9C389F-3316-41A7-809B-AA305ED9D922) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O3 - Toolbar: The retnsrp - (CC304A4D-FC79-4CD3-9A67-46E3AF59319D) - C: \ Windows \ retnsrp.dll O4 - HKLM \ .. \ Run: [Windows Defender]% program% \ Windows Defender \ MSASCui.exe-hide O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [QPService] "C: \ Program Files \ HP \ QuickPlay \ QPService.exe" O4 - HKLM \ .. \ Run: [HP Software Update] C: \ Program Files \ Hp \ HP Software Update \ HPWuSchd2.exe O4 - HKLM \ .. \ Run: [QlbCtrl]% program% \ Hewlett-Packard \ HP Quick Launch Knappar \ QlbCtrl.exe / Start O4 - HKLM \ .. \ Run: [HP Health Check Scheduler] C: \ Program Files \ Hewlett-Packard \ HP Health Check \ HPHC_Scheduler.exe O4 - HKLM \ .. \ Run: [WAWifiMessage]% program% \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe O4 - HKLM \ .. \ Run: [hpWirelessAssistant]% program% \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program \ Java \ jre1.6.0 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [kpx] C: \ Windows \ system32 \ rundll32.exe C: \ Windows \ system32 \ fastRX.dll DllInitApp O4 - HKLM \ .. \ Run: [NvSvc] rundll32.exe C: \ Windows \ system32 \ nvsvc.dll, nvsvcStart O4 - HKLM \ .. \ Run: [NvCplDaemon] rundll32.exe C: \ Windows \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [NvMediaCenter] rundll32.exe C: \ Windows \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [SeekmoOE] C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe O4 - HKLM \ .. \ Run: [SeekmoSA] "C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ SeekmoSA.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program \ QuickTime \ QTTask.exe"-atboottime O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [Symantec pif AlertEng] "C: \ Program Files \ Common Files \ Symantec Shared \ pif \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe" / a / m " C: \ Program Files \ Common Files \ Symantec Shared \ pif \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ AlertEng.dll " O4 - HKLM \ .. \ Run: [ddoctorv2] "C: \ Program Files \ Comcast \ Desktop Doctor \ bin \ sprtcmd.exe" / P ddoctorv2 O4 - HKLM \ .. \ RunOnce: [Launcher]% WINDIR% \ SMINST \ launcher.exe O4 - HKCU \ .. \ Run: [Sidebar] C: \ Program Files \ Windows Sidebar \ sidebar.exe / autorun O4 - HKCU \ .. \ Run: [HPAdvisor] C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe O4 - HKCU \ .. \ Run: [Aim6] "C: \ Program Files \ AIM6 \ aim6.exe" / d locale = sv-SE ee: / / AOL / imApp O4 - HKCU \ .. \ Run: [ehTray.exe] C: \ Windows \ ehome \ ehTray.exe O4 - HKCU \ .. \ Run: [Veoh] "C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe" / VeohHide O4 - HKCU \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ MsnMsgr.Exe" / bakgrund O4 - HKCU \ .. \ Run: [SWG] C: \ Program \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe O4 - HKCU \ .. \ Run: [AdobeUpdater] C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe O4 - HKCU \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter O4 - HKUS \ S-1-5-19 \ .. \ Run: [Sidebar]% program% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-19 \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Sidebar]% program% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'NETWORK SERVICE') O4 - Startup: LimeWire On Startup.lnk = C: \ Program Files \ LimeWire \ LimeWire.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ AdobeCollabSync.exe O4 - Global Startup: HP Connections.lnk = C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe O8 - Extra sammanhang menyobjektet: & AOL Toolbar Search - C: \ Program Files \ AOL \ Syftet verktygsfältet 5.0 \ resurser \ sv-se \ Local \ search.html O8 - Extra sammanhang menyobjektet: E & xportera till Microsoft Excel - res: / / C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ EXCEL.EXE/3000 Ø9 - Extra button: (inget namn) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.6.0 \ bin \ ssv.dll Ø9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.6.0 \ bin \ ssv.dll Ø9 - Extra button: Skicka till OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ ONBttnIE.dll Ø9 - Extra 'Tools' MENUITEM: S & stopp för OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ ONBttnIE.dll Ø9 - Extra button: AIM Toolbar - (3369AF0D-62E9-4bda-8103-B4C75499B578) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll Ø9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: (48DD0448-9209-4F81-9F6D-D83562940134) (MySpace Uploader Control) -- http://lads.myspace.com/upload/MySpaceUploader1005.cab O16 - DPF: (5D6F45B3-9043-443D-a792-115447494D24) (UnoCtrl Class) -- http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab O16 - DPF: (67DABFBF-D0AB-41FA-9C46-CC0F21721616) (DivXBrowserPlugin Object) -- http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (MSN Games - Installer) -- http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: (BD393C14-72AD-4790-A095-76522973D6B8) (CBreakshotControl Class) -- http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: (DA758BB1-5F89-4465-975F-8D7179A4BCF3) (WheelofFortune Object) -- http://messenger.zone.msn.com/binary/WoF.cab57176.cab Ø21 - SSODL: leorop - (38CA8AE4-A78E-4111-8D0E-BDDF145A5040) - C: \ Windows \ leorop.dll Ø21 - SSODL: nopzet - (9543D4D7-3E5B-4B70-BB93-83AC9865627C) - C: \ Windows \ nopzet.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Knappar \ AddFiltr.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown ägaren - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown ägaren - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLSched.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - C: \ Program Files \ Hewlett-Packard \ HP Health Check \ hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ Shared \ hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Roxio \ Roxio MyDVD Basic v9 \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C: \ Program \ Norton AntiVirus \ isPwdSvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ progra ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ pif \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C: \ Program Files \ Common Files \ Roxio Shared \ 9.0 \ SharedCOM \ RoxMediaDB9.exe O23 - Service: SupportSoft Kedjekrans Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C: \ Program Files \ Comcast \ Desktop Doctor \ bin \ sprtsvc.exe O23 - Service: stllssvr - Microvision Development, Inc. - C: \ Program Files \ Common Files \ SureThing Shared \ stllssvr.exe O23 - Service: Symantec Core LC - Unknown ägaren - C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ AppCore \ AppSvc32.exe O23 - Service: synvinkel Manager Service - synvinkel Corporation - C: \ Program Files \ synvinkel \ Common \ ViewpointService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C: \ Windows \ System32 \ Drivers \ xaudio.exe |
|
#6
| |||
| |||
| Innan du sätter upp något jag vill påpeka att när jag gick att köra online scan det inte skulle låta mig ... Det sa något om att inte ha tillstånd. När jag tittade i min Lägg till / ta bort maskinvara Det är några av de saker jag hittade lite misstänksam eller att jag visste någonting om. MSXML 4.0 SP2 My Search Bar Movie Maker 5,0 Smart Video Codec v1.6 SUPERAntiSpyware log SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/05/2008 at 07:32 Application Version: 3.9.1008 Core Rules Database Version: 3374 Trace Rules Database Version: 1369 Scan type: Complete Scan Total Scan Time: 01:23:02 Memory ex skannade: 712 Memory hot upptäcks: 1 Registry ex skannade: 8.254 Registry hot upptäcks: 122 File ex skannade: 60.434 Arkiv hot upptäcktes: 12 Trojan.Net-MSV/VPS-Variant C: \ WINDOWS \ BLOPENVXDT.DLL C: \ WINDOWS \ BLOPENVXDT.DLL HKLM \ Software \ Classes \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ InprocServer32 HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ ProgID HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ Programmable HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ TypeLib HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ VersionIndependentProgID HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Exp lorer \ Browser Helper Objects \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) Adware.MyWay HKLM \ Software \ Classes \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) \ InprocServer32 HKCR \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) \ Programmable HKCR \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) \ TypeLib C: \ Program Files \ MYSEARCH \ BAR \ 1.BIN \ S4BAR.DLL HKLM \ Software \ Classes \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) \ InprocServer32 HKCR \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) \ Programmable HKCR \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) \ TypeLib HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Exp lorer \ Browser Helper Objects \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) HKLM \ Software \ Microsoft \ Internet Explorer \ Toolbar # (014DA6C9-189F-421a-88CD-07CFE51CFF10) HKCR \ TypeLib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) HKCR \ TypeLib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 HKCR \ TypeLib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ 0 HKCR \ TypeLib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ 0 \ win32 HKCR \ TypeLib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ FLAGS HKCR \ TypeLib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ HELPDIR HKU \ S-1-5-21-3682377349-2593316749-328379415-1000 \ Software \ Microsoft \ Internet Explorer \ Toolbar \ WebBrowser # (014DA6C9-189F-421a-88CD-07CFE51CFF10) Unclassified.Unknown Ursprung HKLM \ Software \ Classes \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ InprocServer32 HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ ProgID HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ Programmable HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ TypeLib HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ VersionIndependentProgID C: \ WINDOWS \ system32 \ FASTRX.DLL HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Exp lorer \ Browser Helper Objects \ (E09962E7-A39E-4F60-8003-66D57BED27B7) Adware.Tracking Cookie C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany@ar.atwola [2]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ atwola [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ doubleclick [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ adlegend [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ reklam [2]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ 2o7 [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ atdmt [2]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ Mediaplex [1]. Txt Adware.180solutions/Seekmo HKCR \ Seekmo.DesktopFlash HKCR \ Seekmo.DesktopFlash \ CLSID HKCR \ Seekmo.DesktopFlash \ rundning HKCR \ Seekmo.DesktopFlash.1 HKCR \ Seekmo.DesktopFlash.1 \ CLSID HKCR \ SeekmoAX.ClientDetector HKCR \ SeekmoAX.ClientDetector \ CLSID HKCR \ SeekmoAX.ClientDetector \ rundning HKCR \ SeekmoAX.ClientDetector.1 HKCR \ SeekmoAX.ClientDetector.1 \ CLSID HKCR \ SeekmoAX.UserProfiles HKCR \ SeekmoAX.UserProfiles \ CLSID HKCR \ SeekmoAX.UserProfiles \ rundning HKCR \ SeekmoAX.UserProfiles.1 HKCR \ SeekmoAX.UserProfiles.1 \ CLSID HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ Control HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ InprocServer32 HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ MiscStatus HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ MiscStatus \ 1 HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ ProgID HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ Programmable HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ ToolboxBitmap32 HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ TypeLib HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ Version HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ VersionIndependentProgID HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) # AppID HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ LocalServer32 HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ ProgID HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ Programmable HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ TypeLib HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ VersionIndependentProgID HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ InprocServer32 HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ ProgID HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ Programmable HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ TypeLib HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ VersionIndependentProgID HKCR \ TypeLib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) HKCR \ TypeLib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 HKCR \ TypeLib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ 0 HKCR \ TypeLib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ 0 \ win32 HKCR \ TypeLib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ FLAGS HKCR \ TypeLib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ HELPDIR HKCR \ TypeLib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) HKCR \ TypeLib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 HKCR \ TypeLib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ 0 HKCR \ TypeLib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ 0 \ win32 HKCR \ TypeLib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ FLAGS HKCR \ TypeLib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ HELPDIR HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ ProxyStubClsid HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ ProxyStubClsid32 HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ TypeLib HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ TypeLib # Version HKCR \ AppID \ SeekmoSA_df.exe HKCR \ AppID \ SeekmoSA_df.exe # AppID HKCR \ AppID \ (4A40E8FC-C7E4-4F57-9FA4-85DD77402897) HKU \ S-1-5-21-3682377349-2593316749-328379415-1000 \ Software \ seekmosa HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA # DisplayName HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA # DisplayIcon HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA # UninstallString HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA # DisplayVersion HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA # HelpLink HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA # Publisher HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ SeekmoSA # URLInfoAbout HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run # SeekmoOE [C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe] C: \ Users \ Yasmany \ AppData \ Roaming \ Seekmo Trojan.DNSChanger-Codec HKCR \ VAC.Video HKCR \ VAC.Video \ CLSID Trojan.Net-MSV/VPS HKCR \ MSVPS.MSVPSApp HKCR \ MSVPS.MSVPSApp \ CLSID HKCR \ MSVPS.MSVPSApp \ rundning Trojan.Net-MU/Gen HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ WebVideo HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ WebVideo # DisplayName HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uni nstall \ WebVideo # UninstallString HijackThis-logg Loggfil av Trend Micro HijackThis v2.0.2 Scan saved at 8:13:58, den 12/23/2007 Plattform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16575) Boot mode: Normal Kör processer: C: \ Windows \ system32 \ taskeng.exe C: \ Windows \ system32 \ Dwm.exe C: \ Windows \ Explorer.EXE C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ Program Files \ HP \ QuickPlay \ QPService.exe C: \ Program Files \ HP \ HP Software Update \ hpwuSchd2.exe C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Knappar \ QLBCTRL.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe C: \ Program \ Java \ jre1.6.0 \ bin \ jusched.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ Program Files \ Comcast \ Desktop Doctor \ bin \ sprtcmd.exe C: \ Program Files \ Windows Sidebar \ sidebar.exe C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe C: \ WINDOWS \ System32 \ rundll32.exe C: \ WINDOWS \ ehome \ ehtray.exe C: \ Windows \ ehome \ ehmsas.exe C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe C: \ Program \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe C: \ Windows \ system32 \ wbem \ unsecapp.exe C: \ progra ~ 1 \ HEWLET ~ 1 \ Shared \ HPQTOA ~ 1.EXE C: \ Program Files \ Hewlett-Packard \ HP Advisor \ SSDK04.exe C: \ Program Files \ Internet Explorer \ Ieuser.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program \ Delade filer \ Microsoft Shared \ Windows Live \ WLLoginProxy.exe C: \ Windows \ system32 \ SearchFilterHost.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe C: \ Windows \ system32 \ Macromed \ Flash \ FlashUtil9b.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant = R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, CustomizeSearch = R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Window Title = Windows Internet Explorer som Comcast R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Settings, Proxyserver =: 0 R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName = R3 - URLSearchHook: AOLTBSearch Class - (EA756889-2338-43DB-8F07-D1CA6FB9C90D) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O1 - Hosts::: 1 localhost O2 - BHO: My Search BHO - (014DA6C1-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Download och Titelinformation Plugin för Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program \ Java \ jre1.6.0 \ bin \ ssv.dll O2 - BHO: AOL Toolbar Launcher - (7C554162-8CB7-45A4-B8F4-8EA1C75885F9) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O2 - BHO: (inget namn) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program \ Delade filer \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O2 - BHO: BDEX System - (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) - C: \ Windows \ blopenvxdt.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - c: \ program \ google \ googletoolbar1.dll O2 - BHO: FastRX - (E09962E7-A39E-4F60-8003-66D57BED27B7) - C: \ Windows \ system32 \ fastRX.dll (file missing) O3 - Toolbar: My Search Bar - (014DA6C9-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O3 - Toolbar: Veoh Browser Plug-in - (D0943516-5076-4020-A3B5-AEFAF26AB263) - C: \ Users \ Yasmany \ Desktop \ Veoh \ Plugins \ reg \ VeohTool bar.dll O3 - Toolbar: & Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - c: \ program \ google \ googletoolbar1.dll O3 - Toolbar: AIM Toolbar - (DE9C389F-3316-41A7-809B-AA305ED9D922) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O3 - Toolbar: The retnsrp - (CC304A4D-FC79-4CD3-9A67-46E3AF59319D) - C: \ Windows \ retnsrp.dll O4 - HKLM \ .. \ Run: [Windows Defender]% program% \ Windows Defender \ MSASCui.exe-hide O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [QPService] "C: \ Program Files \ HP \ QuickPlay \ QPService.exe" O4 - HKLM \ .. \ Run: [HP Software Update] C: \ Program Files \ Hp \ HP Software Update \ HPWuSchd2.exe O4 - HKLM \ .. \ Run: [QlbCtrl]% program% \ Hewlett-Packard \ HP Quick Launch Knappar \ QlbCtrl.exe / Start O4 - HKLM \ .. \ Run: [HP Health Check Scheduler] C: \ Program Files \ Hewlett-Packard \ HP Health Check \ HPHC_Scheduler.exe O4 - HKLM \ .. \ Run: [WAWifiMessage]% program% \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe O4 - HKLM \ .. \ Run: [hpWirelessAssistant]% program% \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program \ Java \ jre1.6.0 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [kpx] C: \ Windows \ system32 \ rundll32.exe C: \ Windows \ system32 \ fastRX.dll DllInitApp O4 - HKLM \ .. \ Run: [NvSvc] rundll32.exe C: \ Windows \ system32 \ nvsvc.dll, nvsvcStart O4 - HKLM \ .. \ Run: [NvCplDaemon] rundll32.exe C: \ Windows \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [NvMediaCenter] rundll32.exe C: \ Windows \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [SeekmoOE] C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe O4 - HKLM \ .. \ Run: [SeekmoSA] "C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ SeekmoSA.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program \ QuickTime \ QTTask.exe"-atboottime O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [Symantec pif AlertEng] "C: \ Program Files \ Common Files \ Symantec Shared \ pif \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe" / a / m " C: \ Program Files \ Common Files \ Symantec Shared \ pif \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ AlertEng.dll " O4 - HKLM \ .. \ Run: [ddoctorv2] "C: \ Program Files \ Comcast \ Desktop Doctor \ bin \ sprtcmd.exe" / P ddoctorv2 O4 - HKLM \ .. \ RunOnce: [Launcher]% WINDIR% \ SMINST \ launcher.exe O4 - HKCU \ .. \ Run: [Sidebar] C: \ Program Files \ Windows Sidebar \ sidebar.exe / autorun O4 - HKCU \ .. \ Run: [HPAdvisor] C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe O4 - HKCU \ .. \ Run: [Aim6] "C: \ Program Files \ AIM6 \ aim6.exe" / d locale = sv-SE ee: / / AOL / imApp O4 - HKCU \ .. \ Run: [ehTray.exe] C: \ Windows \ ehome \ ehTray.exe O4 - HKCU \ .. \ Run: [Veoh] "C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe" / VeohHide O4 - HKCU \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ MsnMsgr.Exe" / bakgrund O4 - HKCU \ .. \ Run: [SWG] C: \ Program \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe O4 - HKCU \ .. \ Run: [AdobeUpdater] C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe O4 - HKCU \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter O4 - HKUS \ S-1-5-19 \ .. \ Run: [Sidebar]% program% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-19 \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Sidebar]% program% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'NETWORK SERVICE') O4 - Startup: LimeWire On Startup.lnk = C: \ Program Files \ LimeWire \ LimeWire.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ AdobeCollabSync.exe O4 - Global Startup: HP Connections.lnk = C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe O8 - Extra sammanhang menyobjektet: & AOL Toolbar Search - C: \ Program Files \ AOL \ Syftet verktygsfältet 5.0 \ resurser \ sv-se \ Local \ search.html O8 - Extra sammanhang menyobjektet: E & xportera till Microsoft Excel - res: / / C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ EXCEL.EXE/3000 Ø9 - Extra button: (inget namn) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.6.0 \ bin \ ssv.dll Ø9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program \ Java \ jre1.6.0 \ bin \ ssv.dll Ø9 - Extra button: Skicka till OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ ONBttnIE.dll Ø9 - Extra 'Tools' MENUITEM: S & stopp för OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ ONBttnIE.dll Ø9 - Extra button: AIM Toolbar - (3369AF0D-62E9-4bda-8103-B4C75499B578) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll Ø9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ progra ~ 1 \ mikro ~ 3 \ Office12 \ REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: (48DD0448-9209-4F81-9F6D-D83562940134) (MySpace Uploader Control) -- http://lads.myspace.com/upload/MySpaceUploader1005.cab O16 - DPF: (5D6F45B3-9043-443D-a792-115447494D24) (UnoCtrl Class) -- http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab O16 - DPF: (67DABFBF-D0AB-41FA-9C46-CC0F21721616) (DivXBrowserPlugin Object) -- http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (MSN Games - Installer) -- http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: (BD393C14-72AD-4790-A095-76522973D6B8) (CBreakshotControl Class) -- http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: (DA758BB1-5F89-4465-975F-8D7179A4BCF3) (WheelofFortune Object) -- http://messenger.zone.msn.com/binary/WoF.cab57176.cab Ø21 - SSODL: leorop - (38CA8AE4-A78E-4111-8D0E-BDDF145A5040) - C: \ Windows \ leorop.dll Ø21 - SSODL: nopzet - (9543D4D7-3E5B-4B70-BB93-83AC9865627C) - C: \ Windows \ nopzet.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Knappar \ AddFiltr.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown ägaren - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown ägaren - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLSched.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - C: \ Program Files \ Hewlett-Packard \ HP Health Check \ hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ Shared \ hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Roxio \ Roxio MyDVD Basic v9 \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C: \ Program \ Norton AntiVirus \ isPwdSvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ progra ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ pif \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C: \ Program Files \ Common Files \ Roxio Shared \ 9.0 \ SharedCOM \ RoxMediaDB9.exe O23 - Service: SupportSoft Kedjekrans Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C: \ Program Files \ Comcast \ Desktop Doctor \ bin \ sprtsvc.exe O23 - Service: stllssvr - Microvision Development, Inc. - C: \ Program Files \ Common Files \ SureThing Shared \ stllssvr.exe O23 - Service: Symantec Core LC - Unknown ägaren - C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ AppCore \ AppSvc32.exe O23 - Service: synvinkel Manager Service - synvinkel Corporation - C: \ Program Files \ synvinkel \ Common \ ViewpointService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C: \ Windows \ System32 \ Drivers \ xaudio.exe -- End of file - 13628 bytes |
|
#7
| |||
| |||
| Du kanske vill kopiera och klistra in dessa instruktioner i ett notepad fil. Då kan du har öppnat filen i felsäkert läge, så du kan följa instruktionerna lättare. Starta upp i felsäkert läge, enligt ditt vanliga användarnamn (INTE Administratörskontot). Se hur HÄR. I Utforskaren, sätta på "Visa alla filer och mappar, inklusive dolda och system". Se hur HÄR. Gå till Lägg till eller ta bort program i kontrollpanelen och avinstallera något att göra med (om det). MySearch bar Seekmo Synvinkel Stäng kontrollpanelen. Klicka på Start / Kör och skriv services.msc i rutan Kör och tryck på Enter. När fönstret öppnas maximera det. Dubbelklicka på följande tjänster (om det) Och välj stoppa om de kör. Ställ in startmetoden till funktionshindrade. Klicka på Verkställ / OK för varje tjänst du avaktivera. Synvinkel Manager Service Stäng fönstret Tjänster. Öppna Aktivitetshanteraren genom att hålla ner Ctrl och Alt-tangenterna och trycka på Delete-tangenten. Klicka på fliken Processer och slutet för (om det). ViewpointService.exe Launcher.exe SeekmoSA.exe OEAddOn.exe Stäng Aktivitetshanteraren. Kör HJT med något annat program (utom notepad). Klicka på scan-knappen. Har HJT fastställa följande, genom att placera ett kryss i den lilla rutan bredvid (om det). O2 - BHO: My Search BHO - (014DA6C1-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O2 - BHO: (inget namn) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O2 - BHO: BDEX System - (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) - C: \ Windows \ blopenvxdt.dll O2 - BHO: FastRX - (E09962E7-A39E-4F60-8003-66D57BED27B7) - C: \ Windows \ system32 \ fastRX.dll (file missing) O3 - Toolbar: My Search Bar - (014DA6C9-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O3 - Toolbar: The retnsrp - (CC304A4D-FC79-4CD3-9A67-46E3AF59319D) - C: \ Windows \ retnsrp.dll O4 - HKLM \ .. \ Run: [kpx] C: \ Windows \ system32 \ rundll32.exe C: \ Windows \ system32 \ fastRX.dll DllInitApp O4 - HKLM \ .. \ Run: [SeekmoOE] C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe O4 - HKLM \ .. \ Run: [SeekmoSA] "C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ SeekmoSA.exe" O4 - HKLM \ .. \ RunOnce: [Launcher]% WINDIR% \ SMINST \ launcher.exe Ø21 - SSODL: leorop - (38CA8AE4-A78E-4111-8D0E-BDDF145A5040) - C: \ Windows \ leorop.dll Ø21 - SSODL: nopzet - (9543D4D7-3E5B-4B70-BB93-83AC9865627C) - C: \ Windows \ nopzet.dll O23 - Service: synvinkel Manager Service - synvinkel Corporation - C: \ Program Files \ synvinkel \ Common \ ViewpointService.exe Klicka på filen kontrolleras knappen. Stäng HJT. Leta upp och ta bort följande bold filer eller mappar (om det). C: \ Program Files \Synvinkel<Stryk hela mappen. C: \ Windows \nopzet.dll C: \ Windows \leorop.dll % WINDIR% \ SMINST \Launcher.exe C: \ Program Files \Seekmo<Stryk hela mappen. C: \ Windows \ system32 \fastRX.dll C: \ Windows \retnsrp.dll C: \ Program Files \MySearch<Stryk hela mappen. C: \ Windows \blopenvxdt.dll Starta om i normalläge och rehide dina skyddade OS filer. Hämta combofix.exe på skrivbordet. Dubbelklicka på combofix.exe och följ anvisningarna. Ett fönster öppnas med en varning. Typ "1" (och Enter) för att starta fix. När genomsökningen är klar öppnas ett textfönster. Bifoga att logga in här tillsammans med en ny HJT logg. Varning - rör inte din mus / tangentbord tills genomsökningen har slutförts. Den scan att tillfälligt inaktivera ditt skrivbord, och om avbrytas får lämna skrivbordet funktionshindrade. Om detta inträffar ska du starta om för att återställa skrivbordet. Combofix automatiskt spara loggfilen C: \ combofix.txt Post den Combofix loggen samt en ny HJT logg. Regards Howard. |
|
#8
| |||
| |||
| Man jag har dålig timing. Jag har precis kommit på hur man kör online scan. Jag kör det just nu som vi pratar. Vill du fortfarande att jag ska göra som du sa. |
|
#9
| |||
| |||
| Glömma online scan för nu, följ bara instruktionerna jag har gett er. Regards Howard. |
|
#10
| |||
| |||
| När jag försöker köra ComboFix jag den blå fönstret, men då det står redo att köra, då Slut på minne eller åtkomstfel och då får jag en pop up som säger "Freeware genomförandet av reg.exe har slutat att fungera och det tvingar mig att stänga ner programmet. Vill du att jag ska posta HJT log? Jag ber om ursäkt för allt detta besvär. Vänta lite, jag vet inte hur, men nu är det arbetar jag ska köra det. |
![]() |
|
| Komihåglista |
Liknande Trådar | ||||
| Tråd | Thread Starter | Forum | Svar | Senaste Inlägg |
| Hjälp, kan inte komma åt mitt Task Manager | Raph78 | Windows-operativsystem | 5 | 23 juli 2009 02:45 |
| Task Manager inte stänga program | tbarber | Windows-operativsystem | 0 | 17 juni 2009 17:52 |
| Task Manager Processer .. | IsoldeAislinn | Windows-operativsystem | 9 | 25 sep 2008 19:26 |
| Kolla min arbetsuppgift direktör för mig plz:) | pete21 | General Software Chat | 5 | 9 juli 2008 06:05 |
| AnVir Task Manager | evilfantasy | General Software Chat | 0 | 28 mars 2008 14:40 |
| Thread Tools | |
| |