Najdi forum

Pozdravljeni,

ko odprem okence Zapiranje programa (ctrl+alt+del), zadnjih nekaj dni opažam tudi ta program, pa me zanima za kakšen program gre in ali ga lahko zbrišem.

Najlepša hvala za odgovor.

Ja spet so na delu špijoni. In to taki ta fejst zoprni. Ta je del FastWebFinderja.
Ampak pri temu trenutno ne pomagata niti Adware niti Spybot, ki smo ga zadnje čase tako hvalili, tu pride na pomoč Hijack This!

Najprej opozorilo : Ta program ni čistokrvni anti spy program, taka kot sta zgoraj našteta, zato je delo z njim bolj zahtevno in NIKAKOR ne smeš zbrisati vsega kar najde. !!!

No skratka najprej zapri vsa okna brskalnika, po inštalaciji oz odpakiranju, štartaj program in pritisni Scan.

Poišči če imaš karkoli od tega in jih izberi

R1 – HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.fastwebfinder.com/sp.php
R1 – HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.fastwebfinder.com/sp.php

O4 – HKLM\..\Run: [wordwsx] C:\WINDOWS\wordwsx.exe
O4 – HKCU\..\Run: [ld] C:\WINDOWS\ld.exe

O16 – DPF: {F3F193CC-8D90-4BEB-8EDA-3EA69BB624F0} (Downloader Class) – http://a2044.g.akamai.net/7/2044/7189/20030227212604/www.douwantit.com:80/web/download/dwnldr.cab

Pritisni Fix Checked in reštartaj čarunalo.
Po ponovnem zagonu iz windows direktorija zbriši
ld.exe
ld.rsf

sem si naložila ta program, sedaj pa ne vem, kaj od tega lahko zbrišem (so druge spletne strani):

R1 – HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchbar.linksummary.com/
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mp3hi-fi.com/cgi-bin/l/lnk.cgi?l=searchbar
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mp3hi-fi.com/cgi-bin/l/lnk.cgi?l=searchpage
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://med.over.net/forum/
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mp3hi-fi.com/cgi-bin/l/lnk.cgi?l=searchdef
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://med.over.net/forum
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mp3hi-fi.com/cgi-bin/l/lnk.cgi?l=searchass
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Povezave
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://searchbar.linksummary.com/
O2 – BHO: (no name) – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 – Toolbar: &Radio – {8E718888-423F-11D2-876E-00A0C9082467} – C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 – HKLM\..\Run: [internat.exe] internat.exe
O4 – HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 – HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 – HKLM\..\Run: [SystemTray] SysTray.Exe
O4 – HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 – HKLM\..\Run: [IOMON98.EXE] “C:\Program Files\Trend PC-cillin 98\IOMON98.EXE”
O4 – HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 – HKLM\..\Run: [WinampAgent] “C:\PROGRAM FILES\WINAMP\WINAMPa.exe”
O4 – HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 – HKLM\..\RunServices: [IOMON98.EXE] “C:\Program Files\Trend PC-cillin 98\IOMON98.EXE”
O4 – HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 – HKCU\..\Run: [TurboConnect] C:\PROGRA~1\RIZAL\NETACC~1\TurboConnect.exe 1
O4 – HKCU\..\Run: [ld] C:\WINDOWS\ld.exe
O4 – Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
O4 – Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 – Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 – Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 – Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O12 – Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 – Plugin for .au: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 – Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 – Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 – Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 – DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Zbriši tole
R1 – HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchbar.linksummary.com/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://searchbar.linksummary.com/
O4 – HKCU\..\Run: [ld] C:\WINDOWS\ld.exe

Reštartaj compi in nato iz windows direktorija zbriši datoteki

ld.exe
ld.rsf

Uspelo je. Najlepša hvala za pomoč.

Forum je zaprt za komentiranje.

New Report

Close