• 1
  • 2
2008-02-24, 01:29
  #1
Medlem
Tjenare!
Har ftt ngot virus som ploppar upp iexplore.exe d och d.
De laddar inte iexplore.exe helt men det r tillrckligt fr att ex. filmen jag tittar p ska tappa fokus. (bli tabbat)

ps. Det r novell p datorn. ds.
Citat:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Novell\XTAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program\Novell\ZENworks\nalntsrv.exe
C:\WINDOWS\system32\wsaccsvc.exe
C:\Program\Novell\ZENworks\RemoteManagement\RMAgen t\ZenRem32.exe
C:\WINDOWS\system32\svchost.exe
c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
c:\_integra\bin\ccmagent.exe
C:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
C:\Program\Novell\ZENworks\wm.exe
C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\wsaccsmp.exe
c:\_integra\bin\shstart.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program\Java\jre1.6.0_02\bin\jusched.exe
C:\Program\McAfee\Common Framework\UdaterUI.exe
C:\Program\McAfee\Common Framework\McTray.exe
C:\Program\A4Tech\Mouse\Amoumain.exe
C:\Program\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\Novell\ZENworks\NalAgent.exe
C:\Program\Novell\ZENworks\WMRUNDLL.EXE
C:\Program\MSN Messenger\usnsvc.exe
C:\Program\uTorrent\uTorrent.exe
C:\MPC\mplayerc.exe
C:\WINDOWS\system32\divxsm.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Lnkar
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\_inte gra\bin\shstart.exe
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: SecureLogin IESSO Browser Helper Object - {7DE7B623-A17E-4A0B-94BA-D1B3BA646792} - C:\Program\Novell\SecureLogin\iesso.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {801BF87E-A000-11D3-81FE-00902741DE09} - (no file)
O2 - BHO: (no name) - {C43D0B3C-6EFD-4FDD-B62E-8C4185999647} - C:\WINDOWS\system32\clbcat.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program\CyberLink\PowerDVD\DVDLauncher.exe "
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [WheelMouse] C:\Program\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program\Winamp\winampa.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\Program\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\Program\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program\Delade filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\RunOnce: [ICLaunch000] C:\DOCUME~1\joadav\LOKALA~1\Temp\_inst1.exe /B1 /DEL
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [StickerLite] C:\Program\MoRUN.net\Sticker Lite\sticker.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Reader\reader_sl.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program\Novell\ZENworks\NalView.exe
O4 - Global Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: msn_0802_upd232001.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...tml?p=ZJfox000
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sandviken.se
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1191885209421
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program\Bonjour\mDNSResponder.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: eBeam Device Service - Unknown owner - C:\Program\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program\Novell\ZENworks\nalntsrv.exe
O23 - Service: Novell Secure Workstation Service (Novell Secure Workstation) - Unknown owner - C:\WINDOWS\system32\wsaccsvc.exe
O23 - Service: Novell ZENworks Remote Management Agent (Remote Management Agent) - Novell, Inc. - C:\Program\Novell\ZENworks\RemoteManagement\RMAgen t\ZenRem32.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
O23 - Service: Symantec LiveState Agent for Windows (WControl) - On Technology Corporation - c:\_integra\bin\ccmagent.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Novell XTier Agent Services (XTAgent) - Novell, Inc. - C:\WINDOWS\System32\Novell\XTAgent.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, Inc. - C:\Program\Novell\ZENworks\wm.exe
Citera
2008-02-24, 09:42
  #2
Medlem
Paijters avatar
Ja, dr var en del visst.
Ladda upp den p www.hijackthis.de och googla p varje process som r markerad med ett kryss eller frgetecken. Drefter kan du googla p alla som inte r grnmarkerade och knda.

Hr har vi ngot:
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\Program\MYWEBS~1\bar\1.bin\mwsoemon.exe
http://www.sysinfo.org/startuplist.p...r=mwsoemon.exe
Citera
2008-02-24, 15:27
  #3
Medlem
927s avatar
dom hr raderna r antagligen malware s bocka fr dessa i hjt, klicka p knappen fix checked och ta bort dom markerade filerna (det r inte skert att alla finns. tm denna mapp helt C:\DOCUME~1\joadav\LOKALA~1\Temp\)

O2 - BHO: (no name) - {C43D0B3C-6EFD-4FDD-B62E-8C4185999647} - C:\WINDOWS\system32\clbcat.dll

O4 - HKLM\..\RunOnce: [ICLaunch000] C:\DOCUME~1\joadav\LOKALA~1\Temp\_inst1.exe /B1 /DEL

O4 - Global Startup: msn_0802_upd232001.exe

O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll

http://www.superantispyware.com/down...ntiSpyware.exe
installera >UPPDATERA superantispyware.
scan computer >vlj complete scan... >klicka p next >starta om (om det str s).
ppna superantispyware >preferences >statistics/logs >markera senaste loggen >view >kopiera in texten frn loggen hr (du radera ev cookies frn loggen du postar hr).

posta ven en ny HJT logg
Citera
2008-02-24, 15:58
  #4
Medlem
*UPPDATERING*
Om jag tar bort iexplore.exe s skapas det en ny senare...
Citera
2008-02-24, 18:49
  #5
Medlem
927s avatar
Citat:
Ursprungligen postat av JDaviK
*UPPDATERING*
Om jag tar bort iexplore.exe s skapas det en ny senare...

det beror antagligen p malware, har du gjort som jag skrev!?
Citera
2008-02-24, 23:32
  #6
Medlem
Joo, jag har gjort det du bad mig. Programmet tog bort MyWebSearch (vilket jag installerat sjlv). Men hittade inte felet. Fr det bara ploppar upp igen.

*EDIT* Har installerat och uppdaterat Nod32, ska se om jag hittar ngt.
Har ven installerat PeerGuardian 2 fr att blocka dumma sidor :P
__________________
Senast redigerad av JDaviK 2008-02-24 kl. 23:57.
Citera
2008-02-26, 10:15
  #7
Medlem
927s avatar
posta en ny HJT logg
Citera
2008-02-26, 13:43
  #8
Medlem
Del 1:
Citat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:36:39, on 2008-02-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Novell\XTAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program\Novell\ZENworks\nalntsrv.exe
C:\Program\Eset\nod32krn.exe
C:\WINDOWS\system32\wsaccsvc.exe
C:\Program\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\system32\wsaccsmp.exe
C:\WINDOWS\Explorer.EXE
c:\_integra\bin\shstart.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\uphclean\uphclean.exe
c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
c:\_integra\bin\ccmagent.exe
C:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
C:\Program\Novell\ZENworks\wm.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
C:\Program\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program\Java\jre1.6.0_02\bin\jusched.exe
C:\Program\McAfee\Common Framework\McTray.exe
C:\Program\A4Tech\Mouse\Amoumain.exe
C:\Program\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program\Eset\nod32kui.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Novell\ZENworks\NalAgent.exe
C:\Program\Novell\ZENworks\WMRUNDLL.EXE
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Trend Micro\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Lnkar
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\_inte gra\bin\shstart.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: SecureLogin IESSO Browser Helper Object - {7DE7B623-A17E-4A0B-94BA-D1B3BA646792} - C:\Program\Novell\SecureLogin\iesso.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program\CyberLink\PowerDVD\DVDLauncher.exe "
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [WheelMouse] C:\Program\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program\Winamp\winampa.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program\Delade filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [AVG7_CC] C:\Program\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SBCSTray] C:\Program\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [StickerLite] C:\Program\MoRUN.net\Sticker Lite\sticker.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJNST')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\Program\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Reader\reader_sl.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program\Novell\ZENworks\NalView.exe
O4 - Global Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: msn_0802_upd232001.exe
Citera
2008-02-26, 13:43
  #9
Medlem
Del 2:
Citat:
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sandviken.se
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1191885209421
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Unknown owner - C:\Program\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program\Novell\ZENworks\nalntsrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program\Eset\nod32krn.exe
O23 - Service: Novell Secure Workstation Service (Novell Secure Workstation) - Unknown owner - C:\WINDOWS\system32\wsaccsvc.exe
O23 - Service: Novell ZENworks Remote Management Agent (Remote Management Agent) - Novell, Inc. - C:\Program\Novell\ZENworks\RemoteManagement\RMAgen t\ZenRem32.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
O23 - Service: Symantec LiveState Agent for Windows (WControl) - On Technology Corporation - c:\_integra\bin\ccmagent.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Novell XTier Agent Services (XTAgent) - Novell, Inc. - C:\WINDOWS\System32\Novell\XTAgent.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, Inc. - C:\Program\Novell\ZENworks\wm.exe

--
End of file - 10136 byte
Citera
2008-02-26, 14:14
  #10
Medlem
927s avatar
gr en ny scan med hjt, bocka fr dessa:

O4 - Global Startup: msn_0802_upd232001.exe

O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll

klicka p knappen fix checked

stll in s dolda filer syns och ta bort dessa (om dom finns)
C:\WINDOWS\SYSTEM32\SWEvent.dll
C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll

nu har du ju tre antivirusprogram, det r inte bra.
tv mste du ta bort (mcafee)

vet du vad det hr r
c:\_inte gra\bin\shstart.exe
__________________
Senast redigerad av 927 2008-02-26 kl. 14:17.
Citera
2008-02-26, 21:36
  #11
Medlem
shstart.exe hr till ccmagent.exe och kom med datorn.
BootBoot kunde inte fixas med HiJackThis, men nr jag frskte ta bort filen ploppade AVG upp ska starta om datorn och kolla om allt str rtt till nu.

Sen om antivirusprogrammen: McAfee fljde med datorn och kan inte tas bort. Tog bort Nod32 nu fr att det tar mkt minne, ven om programmen inte har brkat :P

Kommer ter med resultatet.

Verkar vara fixat nu TACKAR !!!!
__________________
Senast redigerad av JDaviK 2008-02-26 kl. 21:47.
Citera
2008-02-26, 21:57
  #12
Medlem
klart att McAfee gr att ta bort, bara lite krngligt, tror det finns nerladdningsfil p deras hemsida som kan ta bort mcafee om inte annat sk p google, det var dr jag hittade den..
Citera
  • 1
  • 2

Skapa ett konto eller logga in för att kommentera

Du måste vara medlem för att kunna kommentera

Skapa ett konto

Det är enkelt att registrera ett nytt konto

Bli medlem

Logga in

Har du redan ett konto? Logga in här

Logga in