Hinnavaatlus
:: Foorum
:: Uudised
:: Ärifoorumid
:: HV F1 ennustusvõistlus
:: Pangalink
:: Telekavad
:: HV toote otsing
|
|
autor |
|
kamilake
HV vaatleja
liitunud: 01.07.2004
|
02.08.2004 13:31:32
|
|
|
kas tervest pikast reast nii vähe mitte vajalikku?
aga seda O2 - BHO: (no name) - {6C669A73-4E8A-3B95-47DB-EC81D939CD23} - C:\PROGRA~1\REFLOV~1\axisstyle.dll
on ju mitu korda, või vaja fiksida ainult see ülal antud ?
|
|
tagasi üles |
|
 |
Tomek
HV kasutaja
liitunud: 07.11.2001
|
02.08.2004 13:43:57
|
|
|
Mis siin ikka haletseda - maha kõik.
|
|
Kommentaarid: 4 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
1 :: |
3 |
|
tagasi üles |
|
 |
kamilake
HV vaatleja
liitunud: 01.07.2004
|
02.08.2004 14:52:14
|
|
|
veel üks küsimus, et miks ma pean neid fiksima Spybotis? aga kui näiteks uue skänni teeksin ja siis sinna lihtsalt linnukesed ette?
|
|
tagasi üles |
|
 |
Märt.
HV Guru

liitunud: 17.01.2004
|
02.08.2004 16:49:06
|
|
|
Tomek kirjutas: |
O4 - HKLM\..\Run: [LDM] C:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe
|
Kas see pole mitte F-Secure jubin? Võib sel juhul vajalik olla.
_________________ Albert Einstein: "Vaid kaks asja on lõpmatud, universum ja inimlik rumalus, ja selles esimeses pole ma nii kindel." |
|
Kommentaarid: 29 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
23 |
|
tagasi üles |
|
 |
kamilake
HV vaatleja
liitunud: 01.07.2004
|
02.08.2004 17:10:52
|
|
|
f secure trial versiooni lasin juba maha, kuna aeg sai täis.
|
|
tagasi üles |
|
 |
Märt.
HV Guru

liitunud: 17.01.2004
|
02.08.2004 20:30:14
|
|
|
Võta maha siis.
_________________ Albert Einstein: "Vaid kaks asja on lõpmatud, universum ja inimlik rumalus, ja selles esimeses pole ma nii kindel." |
|
Kommentaarid: 29 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
23 |
|
tagasi üles |
|
 |
Tomek
HV kasutaja
liitunud: 07.11.2001
|
02.08.2004 21:46:51
|
|
|
Process File: backweb-8876480 or backweb-8876480.exe
Process Name: Logitech Desktop Messenger
Description: Comes with the software for Logitech products. Automatically checks for software upgrades and new products, services, and special offerings from Logitech.
Mis protsess see selline on? Oled kindel, et see peab töötama?
O4 - HKLM\..\Run: [RCServer] "C:\Program Files\Remote Control\RCServer.exe" -servicehelper
|
|
Kommentaarid: 4 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
1 :: |
3 |
|
tagasi üles |
|
 |
Badmad
HV kasutaja

liitunud: 01.08.2004
|
03.08.2004 10:31:03
|
|
|
mul umbes sama jama , vajaks abi :/ scannisin HijackThis iga aga ma ei tea missugust maha tõmmata , ehk saaks teilt abi.
Logfile of HijackThis v1.97.7
Scan saved at 10:16:07 AM, on 8/4/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\atlqc.exe
C:\WINDOWS\System32\wingrd32.exe
C:\Program Files\QuickTime\qttask.exe
C:\windows\system32\winexplor.exe
C:\WINDOWS\sdkxt32.exe
C:\Program Files\WindUpdates\WinUpdt.exe
C:\WINDOWS\System32\encyuo.exe
C:\Program Files\WindowsSA\omniscient.exe
C:\Program Files\CashBack\bin\cashback.exe
C:\Program Files\NaviSearch\bin\nls.exe
C:\Documents and Settings\Administrator\Application Data\hsec.exe
C:\WINDOWS\System32\qmyoeqv.exe
C:\Program Files\WindUpdates\WinKA.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
C:\WINDOWS\System32\notepad.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\unkii.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://unkii.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://unkii.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\unkii.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://unkii.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\unkii.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {66F47A0F-B4AA-B23E-011C-BD3F255CFC72} - C:\WINDOWS\system32\sdknj32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [winguard] wingrd32.exe
O4 - HKLM\..\Run: [winupd] C:\WINDOWS\System32\winupd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mysoft] C:\windows\system32\winexplor.exe
O4 - HKLM\..\Run: [WindUpdates] C:\Program Files\WindUpdates\WinUpdt.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\RunServices: [winguard] wingrd32.exe
O4 - HKCU\..\Run: [winguard] wingrd32.exe
O4 - HKCU\..\Run: [Osse] C:\Documents and Settings\Administrator\Application Data\hsec.exe
O4 - HKCU\..\Run: [Lok] C:\WINDOWS\System32\qmyoeqv.exe
O4 - HKLM\..\RunOnce: [atlqc.exe] C:\WINDOWS\system32\atlqc.exe
O4 - HKLM\..\RunOnce: [mfcdt.exe] C:\WINDOWS\system32\mfcdt.exe
O4 - HKLM\..\RunOnce: [sdkuo.exe] C:\WINDOWS\system32\sdkuo.exe
O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\iesc32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O13 - DefaultPrefix: http://www.microsoit.com/direct.php?url=
O13 - WWW Prefix: http://www.microsoit.com/direct.php?url=
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//cyberfreehost/main.chm::/testnewload.exe
O16 - DPF: {11010101-1001-1111-1000-110112345678} - ms-its:mhtml:file://c:\nosuch.mht!http://69.31.79.101/winsearchie32.chm::/winsearchie32.exe
O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://c:\nosuch.mht!http://www.terra.es/personal9/eroplis/rd/chm/files.chm::/file.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - link
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cab
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/en/filesharingctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
|
|
Kommentaarid: 29 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
27 |
|
tagasi üles |
|
 |
Siegfried
HV vaatleja
liitunud: 25.10.2003
|
03.08.2004 20:39:55
|
|
|
no see mediaticketsinstaller on raudne spy...
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
ja see ka:
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//cyberfreehost/main.chm::/testnewload.exe
muu kohta ei julge öelda kuigi ka see
O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://c:\nosuch.mht!http://www.terra.es/personal9/eroplis/rd/chm/files.chm::/file.exe
tundub kahtlane
|
|
tagasi üles |
|
 |
Badmad
HV kasutaja

liitunud: 01.08.2004
|
03.08.2004 22:50:35
|
|
|
Siegfried kirjutas: |
no see mediaticketsinstaller on raudne spy...
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
ja see ka:
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//cyberfreehost/main.chm::/testnewload.exe
muu kohta ei julge öelda kuigi ka see
O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://c:\nosuch.mht!http://www.terra.es/personal9/eroplis/rd/chm/files.chm::/file.exe
tundub kahtlane |
Tänan väga , põhilise asja sain maha kuigi IE homepage on ikka mingi kahtlane ja vahel viskab pop-uppe ette
|
|
Kommentaarid: 29 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
27 |
|
tagasi üles |
|
 |
-priit-
HV kasutaja

liitunud: 23.08.2003
|
03.08.2004 23:20:17
|
|
|
to Badmad:
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CashBack\bin\cashback.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\unkii.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://unkii.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://unkii.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\unkii.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://unkii.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\unkii.dll/sp.html#96676
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\iesc32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//cyberfreehost/main.chm::/testnewload.exe
O16 - DPF: {11010101-1001-1111-1000-110112345678} - ms-its:mhtml:file://c:\nosuch.mht!http://69.31.79.101/winsearchie32.chm::/winsearchie32.exe
O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://c:\nosuch.mht!http://www.terra.es/personal9/eroplis/rd/chm/files.chm::/file.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
|
|
Kommentaarid: 3 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
3 |
|
tagasi üles |
|
 |
|
lisa lemmikuks |
|
|
sa ei või postitada uusi teemasid siia foorumisse sa ei või vastata selle foorumi teemadele sa ei või muuta oma postitusi selles foorumis sa ei või kustutada oma postitusi selles foorumis sa ei või vastata küsitlustele selles foorumis sa ei saa lisada manuseid selles foorumis sa võid manuseid alla laadida selles foorumis
|
|