• 1
  • 2
2008-02-24, 01:29
  #1
Medlem
Tjenare!
Har fått något virus som ploppar upp iexplore.exe då och då.
De laddar inte iexplore.exe helt men det är tillräckligt för att ex. filmen jag tittar på ska tappa fokus. (bli tabbat)

ps. Det är novell på datorn. ds.
Citat:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Novell\XTAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program\Novell\ZENworks\nalntsrv.exe
C:\WINDOWS\system32\wsaccsvc.exe
C:\Program\Novell\ZENworks\RemoteManagement\RMAgen t\ZenRem32.exe
C:\WINDOWS\system32\svchost.exe
c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
c:\_integra\bin\ccmagent.exe
C:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
C:\Program\Novell\ZENworks\wm.exe
C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\wsaccsmp.exe
c:\_integra\bin\shstart.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program\Java\jre1.6.0_02\bin\jusched.exe
C:\Program\McAfee\Common Framework\UdaterUI.exe
C:\Program\McAfee\Common Framework\McTray.exe
C:\Program\A4Tech\Mouse\Amoumain.exe
C:\Program\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\Novell\ZENworks\NalAgent.exe
C:\Program\Novell\ZENworks\WMRUNDLL.EXE
C:\Program\MSN Messenger\usnsvc.exe
C:\Program\uTorrent\uTorrent.exe
C:\MPC\mplayerc.exe
C:\WINDOWS\system32\divxsm.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\_inte gra\bin\shstart.exe
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: SecureLogin IESSO Browser Helper Object - {7DE7B623-A17E-4A0B-94BA-D1B3BA646792} - C:\Program\Novell\SecureLogin\iesso.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {801BF87E-A000-11D3-81FE-00902741DE09} - (no file)
O2 - BHO: (no name) - {C43D0B3C-6EFD-4FDD-B62E-8C4185999647} - C:\WINDOWS\system32\clbcat.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program\CyberLink\PowerDVD\DVDLauncher.exe "
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [WheelMouse] C:\Program\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program\Winamp\winampa.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\Program\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\Program\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program\Delade filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\RunOnce: [ICLaunch000] C:\DOCUME~1\joadav\LOKALA~1\Temp\_inst1.exe /B1 /DEL
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [StickerLite] C:\Program\MoRUN.net\Sticker Lite\sticker.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Reader\reader_sl.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program\Novell\ZENworks\NalView.exe
O4 - Global Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: msn_0802_upd232001.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...tml?p=ZJfox000
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sandviken.se
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1191885209421
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program\Bonjour\mDNSResponder.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: eBeam Device Service - Unknown owner - C:\Program\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program\Novell\ZENworks\nalntsrv.exe
O23 - Service: Novell Secure Workstation Service (Novell Secure Workstation) - Unknown owner - C:\WINDOWS\system32\wsaccsvc.exe
O23 - Service: Novell ZENworks Remote Management Agent (Remote Management Agent) - Novell, Inc. - C:\Program\Novell\ZENworks\RemoteManagement\RMAgen t\ZenRem32.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
O23 - Service: Symantec LiveState Agent for Windows (WControl) - On Technology Corporation - c:\_integra\bin\ccmagent.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Novell XTier Agent Services (XTAgent) - Novell, Inc. - C:\WINDOWS\System32\Novell\XTAgent.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, Inc. - C:\Program\Novell\ZENworks\wm.exe
Citera
2008-02-24, 09:42
  #2
Medlem
Paijters avatar
Ja, där var en del visst.
Ladda upp den på www.hijackthis.de och googla på varje process som är markerad med ett kryss eller frågetecken. Därefter kan du googla på alla som inte är grönmarkerade och kända.

Här har vi något:
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\Program\MYWEBS~1\bar\1.bin\mwsoemon.exe
http://www.sysinfo.org/startuplist.p...r=mwsoemon.exe
Citera
2008-02-24, 15:27
  #3
Medlem
927s avatar
dom här raderna är antagligen malware så bocka för dessa i hjt, klicka på knappen fix checked och ta bort dom markerade filerna (det är inte säkert att alla finns. töm denna mapp helt C:\DOCUME~1\joadav\LOKALA~1\Temp\)

O2 - BHO: (no name) - {C43D0B3C-6EFD-4FDD-B62E-8C4185999647} - C:\WINDOWS\system32\clbcat.dll

O4 - HKLM\..\RunOnce: [ICLaunch000] C:\DOCUME~1\joadav\LOKALA~1\Temp\_inst1.exe /B1 /DEL

O4 - Global Startup: msn_0802_upd232001.exe

O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll

http://www.superantispyware.com/down...ntiSpyware.exe
installera >UPPDATERA superantispyware.
scan computer >välj complete scan... >klicka på next >starta om (om det står så).
öppna superantispyware >preferences >statistics/logs >markera senaste loggen >view >kopiera in texten från loggen här (du radera ev cookies från loggen du postar här).

posta även en ny HJT logg
Citera
2008-02-24, 15:58
  #4
Medlem
*UPPDATERING*
Om jag tar bort iexplore.exe så skapas det en ny senare...
Citera
2008-02-24, 18:49
  #5
Medlem
927s avatar
Citat:
Ursprungligen postat av JDaviK
*UPPDATERING*
Om jag tar bort iexplore.exe så skapas det en ny senare...

det beror antagligen på malware, har du gjort som jag skrev!?
Citera
2008-02-24, 23:32
  #6
Medlem
Joo, jag har gjort det du bad mig. Programmet tog bort MyWebSearch (vilket jag installerat själv). Men hittade inte felet. För det bara ploppar upp igen.

*EDIT* Har installerat och uppdaterat Nod32, ska se om jag hittar ngt.
Har även installerat PeerGuardian 2 för att blocka dumma sidor :P
__________________
Senast redigerad av JDaviK 2008-02-24 kl. 23:57.
Citera
2008-02-26, 10:15
  #7
Medlem
927s avatar
posta en ny HJT logg
Citera
2008-02-26, 13:43
  #8
Medlem
Del 1:
Citat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:36:39, on 2008-02-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Novell\XTAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program\Novell\ZENworks\nalntsrv.exe
C:\Program\Eset\nod32krn.exe
C:\WINDOWS\system32\wsaccsvc.exe
C:\Program\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\system32\wsaccsmp.exe
C:\WINDOWS\Explorer.EXE
c:\_integra\bin\shstart.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\uphclean\uphclean.exe
c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
c:\_integra\bin\ccmagent.exe
C:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
C:\Program\Novell\ZENworks\wm.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
C:\Program\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program\Java\jre1.6.0_02\bin\jusched.exe
C:\Program\McAfee\Common Framework\McTray.exe
C:\Program\A4Tech\Mouse\Amoumain.exe
C:\Program\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program\Eset\nod32kui.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Novell\ZENworks\NalAgent.exe
C:\Program\Novell\ZENworks\WMRUNDLL.EXE
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Trend Micro\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\_inte gra\bin\shstart.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: SecureLogin IESSO Browser Helper Object - {7DE7B623-A17E-4A0B-94BA-D1B3BA646792} - C:\Program\Novell\SecureLogin\iesso.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program\CyberLink\PowerDVD\DVDLauncher.exe "
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [WheelMouse] C:\Program\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program\Winamp\winampa.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program\Delade filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [AVG7_CC] C:\Program\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SBCSTray] C:\Program\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [StickerLite] C:\Program\MoRUN.net\Sticker Lite\sticker.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\Program\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Reader\reader_sl.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program\Novell\ZENworks\NalView.exe
O4 - Global Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Global Startup: msn_0802_upd232001.exe
Citera
2008-02-26, 13:43
  #9
Medlem
Del 2:
Citat:
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sandviken.se
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1191885209421
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Unknown owner - C:\Program\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program\Novell\ZENworks\nalntsrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program\Eset\nod32krn.exe
O23 - Service: Novell Secure Workstation Service (Novell Secure Workstation) - Unknown owner - C:\WINDOWS\system32\wsaccsvc.exe
O23 - Service: Novell ZENworks Remote Management Agent (Remote Management Agent) - Novell, Inc. - C:\Program\Novell\ZENworks\RemoteManagement\RMAgen t\ZenRem32.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.0.61\bin\Apache.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
O23 - Service: Symantec LiveState Agent for Windows (WControl) - On Technology Corporation - c:\_integra\bin\ccmagent.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Novell XTier Agent Services (XTAgent) - Novell, Inc. - C:\WINDOWS\System32\Novell\XTAgent.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, Inc. - C:\Program\Novell\ZENworks\wm.exe

--
End of file - 10136 byte
Citera
2008-02-26, 14:14
  #10
Medlem
927s avatar
gör en ny scan med hjt, bocka för dessa:

O4 - Global Startup: msn_0802_upd232001.exe

O20 - Winlogon Notify: wsacclcm - C:\WINDOWS\SYSTEM32\SWEvent.dll
O21 - SSODL: BootBoot - {d69afe5a-fbf2-451b-b6e0-95d027442482} - C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll

klicka på knappen fix checked

ställ in så dolda filer syns och ta bort dessa (om dom finns)
C:\WINDOWS\SYSTEM32\SWEvent.dll
C:\WINDOWS\Installer\{d69afe5a-fbf2-451b-b6e0-95d027442482}\BootBoot.dll

nu har du ju tre antivirusprogram, det är inte bra.
två måste du ta bort (mcafee)

vet du vad det här är
c:\_inte gra\bin\shstart.exe
__________________
Senast redigerad av 927 2008-02-26 kl. 14:17.
Citera
2008-02-26, 21:36
  #11
Medlem
shstart.exe hör till ccmagent.exe och kom med datorn.
BootBoot kunde inte fixas med HiJackThis, men när jag försökte ta bort filen ploppade AVG upp ska starta om datorn och kolla om allt står rätt till nu.

Sen om antivirusprogrammen: McAfee följde med datorn och kan inte tas bort. Tog bort Nod32 nu för att det tar mkt minne, även om programmen inte har bråkat :P

Kommer åter med resultatet.

Verkar vara fixat nu TACKAR !!!!
__________________
Senast redigerad av JDaviK 2008-02-26 kl. 21:47.
Citera
2008-02-26, 21:57
  #12
Medlem
klart att McAfee går att ta bort, bara lite krångligt, tror det finns nerladdningsfil på deras hemsida som kan ta bort mcafee om inte annat sök på google, det var där jag hittade den..
Citera
  • 1
  • 2

Skapa ett konto eller logga in för att kommentera

Du måste vara medlem för att kunna kommentera

Skapa ett konto

Det är enkelt att registrera ett nytt konto

Bli medlem

Logga in

Har du redan ett konto? Logga in här

Logga in