• Hmm, og der ligger ikke noget inden under tilføj/fjern ?


    Prøv at kør en Hijackthis og post reporten herinde, så må nogle jo kunne sige om noget forkert bliver startet :)

  • Logfile of HijackThis v1.99.1
    Scan saved at 11:10:36, on 02-08-2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
    C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmer\Norton AntiVirus\navapsvc.exe
    C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\wwSecure.exe
    C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
    C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmer\Logitech\SetPoint\KEM.exe
    C:\Programmer\Logitech\SetPoint\KHALMNPR.EXE
    C:\Programmer\valve\Steam.exe
    C:\Programmer\LimeWire\LimeWire.exe
    C:\Programmer\Internet Explorer\iexplore.exe
    C:\Documents and Settings\jonas\Dokumenter\Modtagne filer\hijackthis.exe
    C:\Programmer\Messenger\msmsgs.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\KEM.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O12 - Plugin for .mpeg: C:\Programmer\Internet Explorer\PLUGINS\npqtplugin3.dll
    O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/downl…sengersetupdownloader.cab
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Webroot Desktop Firewall Data Service (WebrootDesktopFirewallDataService) - Webroot Software, Inc. - C:\Programmer\Webroot\Desktop Firewall\WDFDataService.exe
    O23 - Service: Webroot Desktop Firewall (WebrootFirewall) - Unknown owner - C:\Programmer\Webroot\Desktop Firewall\FirewallNTService.exe
    O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe


    det var det...hvad for noget af det må jeg så slette...

  • Quote

    Oprindeligt indlæg af niller
    det hjalp desværre ikke
    :boxed:


    Husk at opdatere Spybot og når det er gjort, så skal du Immunize og husk at sætte hak ved Block bad pages silently. SpyBot skal køres i fejlsikret tilstand, prøv det efter update og Immunize.

  • hey.. hvis det kan hjælpe har jeg os haft det lort på min com..
    Jeg har fjernet det men kan ikke huske hvordan...


    Men faktisk at der er en uninstall til den..
    Men ellers er den altså abre til at slette...
    Du skal bare sørge for lige at trykke på Alt + Ctrl + delete og afbryde den ellers vil den ikke lade sig slette... det virkede ved min...

  • Et lille smut på google gav bl.a. disse svar: http://www.spywareguide.com/product_show.php?id=2195


    En anden side har en manuel måde, hvis man altså er inde i det med registreringsdatabasen (regedit):


    Manual Need2Find removal instructions:
    Attention! Before taking the following actions, please make your system and registry backup in case you make an error.


    Clean registry entries :
    HKEY_CLASSES_ROOT\need2findbar.settingsplugin
    HKEY_CLASSES_ROOT\need2findbar.settingsplugin.1
    HKEY_CLASSES_ROOT\need2findbar.toolbarplugin
    HKEY_CLASSES_ROOT\need2findbar.toolbarplugin.1


    (how to?) Removing registry items.
    You can remove registry items using RegEdit. Launch RegEdit by entering "regedit" in command line or find "regedit.exe" file in your WINDOWS directory. Browse the left menu to find unwanted registry items, use the right window to remove them by right-clicking on the item and choosing "Delete".


    Remove files:
    nd2fnbar.dll

    spy-sweeper gør det automatisk