2008-03-03, 10:33
#1
Tjenare.. jag har fått ett virus på min dator och skulle uppskatta om nån kunde hjälpa mig. mitt f-secure hittade det men kunde inte ta bort det. det heter Backdoor.Win32.Bifrose.ee om det hjälper er nått.
Tack på förhand!
Logfile of HijackThis v1.99.1
Scan saved at 10:34:19, on 2008-03-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FSMB32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FCH32.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\BACKWEB\7836882\PROGRAM\FSBWSYS. EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\BACKWEB\7836882\PROGRAM\FSPEX.EX E
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FAMEH32.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSQH.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSGK32.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSRW.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\FWES\PROGRAM\FSDFWD.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSSM32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSAV32.EXE
C:\PROGRAM\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\PROGRAM\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FSM32.EXE
C:\PROGRAM\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM\HI-SPEED USB-TO-IDE WIN98 DRIVER\IO2507MON.EXE
C:\WINDOWS\IOMBG.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\FSGUI\FSGUIDLL.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-SPYWARE\FSAW.EXE
C:\PROGRAM\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRAM\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\RAR$EX13.339\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsidan.telia.se/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://se.msn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = proxy1.telia.com:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = login1.telia.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [IO2507MON] C:\Program\Hi-Speed USB-to-IDE Win98 Driver\IO2507Mon.exe
O4 - HKLM\..\Run: [IOMBG] C:\WINDOWS\IOMBG.EXE
O4 - HKLM\..\RunServices: [HC Reminder] hc.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKCU\..\Run: [Eraser] C:\PROGRAM\ERASER\ERASER.EXE -hide
O4 - HKCU\..\RunServices: [Eraser] C:\PROGRAM\ERASER\ERASER.EXE -hide
O4 - Global Startup: Telias säkerhetstjänster.lnk = C:\Program\Telia\Telias Sakerhetstjanster\backweb\7836882\Program\fspex.ex e
O8 - Extra context menu item: &Blockera detta popup-fönster - C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\BITCOMET\BITCOMET.EXE/AddLink.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\BITCOMET\BITCOMET.EXE/AddAllLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\BITCOMET\BITCOMET.EXE/AddVideo.htm
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: IE-sköld - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-SPYWARE\IESHIELD.DLL
O9 - Extra 'Tools' menuitem: IE-sköld... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-SPYWARE\IESHIELD.DLL
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = telia.com
Scan saved at 10:34:19, on 2008-03-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FSMB32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FCH32.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\BACKWEB\7836882\PROGRAM\FSBWSYS. EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\BACKWEB\7836882\PROGRAM\FSPEX.EX E
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FAMEH32.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSQH.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSGK32.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSRW.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\FWES\PROGRAM\FSDFWD.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSSM32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-VIRUS\FSAV32.EXE
C:\PROGRAM\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\PROGRAM\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\COMMON\FSM32.EXE
C:\PROGRAM\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM\HI-SPEED USB-TO-IDE WIN98 DRIVER\IO2507MON.EXE
C:\WINDOWS\IOMBG.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\FSGUI\FSGUIDLL.EXE
C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-SPYWARE\FSAW.EXE
C:\PROGRAM\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRAM\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\RAR$EX13.339\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsidan.telia.se/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://se.msn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = proxy1.telia.com:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = login1.telia.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [IO2507MON] C:\Program\Hi-Speed USB-to-IDE Win98 Driver\IO2507Mon.exe
O4 - HKLM\..\Run: [IOMBG] C:\WINDOWS\IOMBG.EXE
O4 - HKLM\..\RunServices: [HC Reminder] hc.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKCU\..\Run: [Eraser] C:\PROGRAM\ERASER\ERASER.EXE -hide
O4 - HKCU\..\RunServices: [Eraser] C:\PROGRAM\ERASER\ERASER.EXE -hide
O4 - Global Startup: Telias säkerhetstjänster.lnk = C:\Program\Telia\Telias Sakerhetstjanster\backweb\7836882\Program\fspex.ex e
O8 - Extra context menu item: &Blockera detta popup-fönster - C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\BITCOMET\BITCOMET.EXE/AddLink.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\BITCOMET\BITCOMET.EXE/AddAllLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\BITCOMET\BITCOMET.EXE/AddVideo.htm
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: IE-sköld - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-SPYWARE\IESHIELD.DLL
O9 - Extra 'Tools' menuitem: IE-sköld... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\PROGRAM\TELIA\TELIAS SAKERHETSTJANSTER\ANTI-SPYWARE\IESHIELD.DLL
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = telia.com
Tack på förhand!