2008-07-03, 21:56
  #13
Medlem
Frottefiltens avatar
Kan ni översätta till svenska tack alltså det i den där länken en postade!
Citera
2008-07-03, 22:04
  #14
Medlem
Ladda ner HijackThis.exe och scanna datorn med det.
Skicka hit loggen sen så tar vi en titt hur den ser ut.

http://download.bleepingcomputer.com...HiJackThis.exe
Citera
2008-07-03, 23:17
  #15
Medlem
Frottefiltens avatar
Citat:
Ursprungligen postat av tzipp
Ladda ner HijackThis.exe och scanna datorn med det.
Skicka hit loggen sen så tar vi en titt hur den ser ut.

http://download.bleepingcomputer.com...HiJackThis.exe


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:15:18, on 2008-07-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Java\jre1.6.0_06\bin\jusched.exe
C:\Program\F-Secure Internet Security\Common\FSM32.EXE
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\Program\iTunes\iTunesHelper.exe
C:\Program\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program\BREDBA~1\BACKUP~1\DESKTO~1.EXE
C:\Program\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\WINDOWS\emMON.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Free Download Manager\fdm.exe
C:\Program\Windows Live\Messenger\MsnMsgr.Exe
C:\Program\ATI Technologies\ATI.ACE\CLI.exe
C:\Program\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Bonjour\mDNSResponder.exe
C:\Program\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program\F-Secure Internet Security\Common\FSMA32.EXE
C:\WINDOWS\system32\PSIService.exe
C:\Program\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program\Trend Micro\RUBotted\TMRUBotted.exe
C:\Program\F-Secure Internet Security\Common\FCH32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program\iPod\bin\iPodService.exe
C:\Program\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program\F-Secure Internet Security\FSAUA\program\fsaua.exe
C:\Program\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program\F-Secure Internet Security\FSAUA\program\fsus.exe
C:\Program\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\Program\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Outlook Express\msimn.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\iTunes\iTunes.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\distnoted.exe
C:\Documents and Settings\XXX\Skrivbord\HiJackThis.exe
C:\Documents and Settings\XXX\Skrivbord\HiJackThis(3).exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aftonbladet.se/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Länkhjälp till Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program\Windows Live Toolbar\msntb.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program\Free Download Manager\iefdm2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Backup - För säkerhets skullTray] C:\Program\BREDBA~1\BACKUP~1\DESKTO~1.EXE
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [emMON] emMON.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Blogga detta - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blogga detta i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program\F-Secure Internet Security\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Installer restarter (FSIHS) - Unknown owner - C:\DOCUME~1\ANNA~1\LOKALA~1\Temp\Installer\0000000 1\bootstrap\fsihs.exe (file missing)
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program\Trend Micro\RUBotted\TMRUBotted.exe

--
End of file - 8786 bytes
Citera
2008-07-03, 23:22
  #16
Medlem
Ladda ner ComboFix till Skrivbordet:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Dra ur internetanslutningen och stäng av alla program du ser inklusive antivirusprogram, antispionprogram och brandvägg, alternativt starta om datorn i felsäkert läge.
Kör ComboFix och följ anvisningarna som visas.

VIKTIGT! Klicka inte på ComboFix-fönstret med musen när den körs annars kan den hänga upp sig.

När den är färdig så ska en logg komma upp, bifoga den till ditt svar. Kontrollera att antivirusprogram och brandvägg är igång innan du ansluter till internet.


Om du får problem med att komma ut på internet:
Kontrollpanelen - Nätverksanslutningar
högerklicka på din internetanslutning och välj Reparera och/eller starta om datorn

tittar till imorn = läggdags
Citera
2008-07-07, 09:17
  #17
Medlem
Frottefiltens avatar
Får upp meddelanden nu att det är farliga kod i vissa temp filer. Man att filerna tas bort hmmm trodde viruset var borta ur datan men antagligen inte
Citera
2008-07-07, 13:20
  #18
Medlem
Kör Combo + skicka loggen som kommer ut.
Citera
2008-07-07, 18:16
  #19
Medlem
Frottefiltens avatar
Citat:
Ursprungligen postat av tzipp
Kör Combo + skicka loggen som kommer ut.


kommer ej ut nån logg!
Citera
2008-07-07, 19:23
  #20
Medlem
Titta på C:\ om du ser den
Citera
2008-07-07, 22:28
  #21
Medlem
Frottefiltens avatar
Jag tog bort det med Trojan remower sen hade jag lite tracking cookies också som jag tog bort med spyware fighter!
__________________
Senast redigerad av Frottefilten 2008-07-07 kl. 22:51.
Citera
2008-07-07, 22:59
  #22
Medlem
927s avatar
det är den här filen du ska kolla efter C:\ComboFix.txt
Citera
2008-07-08, 11:12
  #23
Medlem
Frottefiltens avatar
ComboFix 08-07-05.1 - U 2008-07-07 18:18:28.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1053.18.572 [GMT 2:00]
Running from: C:\Documents and Settings\U\Skrivbord\ComboFix.exe
* Resident AV is active


[color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.

((((((((((((((((((((((((( Files Created from 2008-06-07 to 2008-07-07 )))))))))))))))))))))))))))))))
Citera
2008-07-08, 11:14
  #24
Medlem
Frottefiltens avatar
.
del 2

.



2008-07-04 23:54 . 2008-07-04 23:54 718,558 --a------ C:\mmm_socialmediakit.zip
2008-07-04 23:47 . 2008-07-04 23:47 103,126 --a------ C:\wallpaper6_800x600.jpg
2008-07-02 12:15 . 2008-07-02 21:53 24 --a------ C:\WINDOWS\cdplayer.ini
2008-06-28 10:04 . 2008-06-28 10:04 63,918 --a------ C:\WINDOWS\system32\{72ab498d-74d8-0a49-a2b0-848865f6bf6f}.dll-uninst.exe
2008-06-28 09:52 . 2008-06-28 09:52 0 --a------ C:\WINDOWS\system32\htXTj72B.exe.a_a
2008-06-28 09:51 . 2008-06-28 09:51 29,760 --a------ C:\WINDOWS\system32\htXTj72B.exe
2008-06-16 15:17 . 2008-06-16 15:17 268 --ah----- C:\sqmdata10.sqm
2008-06-16 15:17 . 2008-06-16 15:17 244 --ah----- C:\sqmnoopt10.sqm
2008-06-16 15:16 . 2006-02-17 14:53 671,859 --a------ C:\WINDOWS\system32\NSEncore.dll
2008-06-16 15:16 . 2005-06-08 01:32 192,512 --a------ C:\WINDOWS\system32\NSM4AEnc.dll
2008-06-16 15:12 . 2008-06-16 15:12 268 --ah----- C:\sqmdata09.sqm
2008-06-16 15:12 . 2008-06-16 15:12 244 --ah----- C:\sqmnoopt09.sqm
2008-06-16 15:08 . 2008-06-16 15:08 <KAT> d-------- C:\Program\EMUSB2.0
2008-06-16 15:08 . 2008-06-16 15:08 <KAT> d-------- C:\Program\eMPIA
2008-06-16 15:06 . 2008-06-16 15:06 268 --ah----- C:\sqmdata08.sqm
2008-06-16 15:06 . 2008-06-16 15:06 244 --ah----- C:\sqmnoopt08.sqm
2008-06-16 08:50 . 2008-06-16 08:50 268 --ah----- C:\sqmdata07.sqm
2008-06-16 08:50 . 2008-06-16 08:50 244 --ah----- C:\sqmnoopt07.sqm
2008-06-16 08:23 . 2008-06-16 08:23 <KAT> d-------- C:\Program\Trend Micro
2008-06-16 08:23 . 2007-11-27 22:51 35,216 --a------ C:\WINDOWS\system32\drivers\TMPassthru.sys
2008-06-16 08:22 . 2008-06-16 08:22 <KAT> d-------- C:\Documents and Settings\U\Application Data\InstallShield
2008-06-15 23:23 . 2008-06-15 23:23 268 --ah----- C:\sqmdata06.sqm
2008-06-15 23:23 . 2008-06-15 23:23 244 --ah----- C:\sqmnoopt06.sqm
2008-06-15 23:21 . 2008-06-15 23:21 268 --ah----- C:\sqmdata05.sqm
2008-06-15 23:21 . 2008-06-15 23:21 244 --ah----- C:\sqmnoopt05.sqm
2008-06-15 21:43 . 2008-06-15 21:43 268 --ah----- C:\sqmdata04.sqm
2008-06-15 21:43 . 2008-06-15 21:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-15 21:40 . 2007-02-05 11:15 18,432 --a------ C:\WINDOWS\system32\drivers\Achernar.sys
2008-06-15 21:39 . 2001-11-12 10:44 122,880 --a------ C:\WINDOWS\system32\Nsvideo.dll
2008-06-15 21:24 . 2008-06-15 21:24 268 --ah----- C:\sqmdata03.sqm
2008-06-15 21:24 . 2008-06-15 21:24 244 --ah----- C:\sqmnoopt03.sqm
2008-06-15 21:05 . 2008-06-15 21:05 268 --ah----- C:\sqmdata02.sqm
2008-06-15 21:05 . 2008-06-15 21:05 244 --ah----- C:\sqmnoopt02.sqm
2008-06-15 20:23 . 2008-06-15 20:23 268 --ah----- C:\sqmdata01.sqm
2008-06-15 20:23 . 2008-06-15 20:23 244 --ah----- C:\sqmnoopt01.sqm
2008-06-14 22:18 . 2008-06-14 22:18 <KAT> d-------- C:\Documents and Settings\U\Application Data\TransRender
2008-06-14 22:18 . 2008-06-24 21:52 <KAT> d-------- C:\Documents and Settings\U\Application Data\Temporary
2008-06-14 22:18 . 2008-06-14 22:18 <KAT> d-------- C:\Documents and Settings\U\Application Data\Samsung
2008-06-14 22:18 . 2008-06-14 22:18 <KAT> d-------- C:\Documents and Settings\U\Application Data\ConvertTemp
2008-06-14 22:12 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-06-14 22:11 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-06-14 22:09 . 2005-12-22 12:24 137,884 --a------ C:\WINDOWS\system32\drivers\sscdmdm.sys
2008-06-14 22:09 . 2005-12-22 12:24 80,272 --a------ C:\WINDOWS\system32\drivers\sscdbus.sys
2008-06-14 22:09 . 2005-12-22 12:24 11,877 --a------ C:\WINDOWS\system32\drivers\sscdcmnt.sys
2008-06-14 22:09 . 2005-12-22 12:24 11,877 --a------ C:\WINDOWS\system32\drivers\sscdcm.sys
2008-06-14 22:09 . 2005-12-22 12:24 11,188 --a------ C:\WINDOWS\system32\drivers\sscdwhnt.sys
2008-06-14 22:09 . 2005-12-22 12:24 11,188 --a------ C:\WINDOWS\system32\drivers\sscdwh.sys
2008-06-14 22:09 . 2005-12-22 12:24 10,864 --a------ C:\WINDOWS\system32\drivers\sscdmdfl.sys
2008-06-14 22:08 . 2008-06-14 22:12 <KAT> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-06-14 22:08 . 2008-06-14 22:08 <KAT> d-------- C:\Program\Samsung
2008-06-14 22:08 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico

.
Citera

Skapa ett konto eller logga in för att kommentera

Du måste vara medlem för att kunna kommentera

Skapa ett konto

Det är enkelt att registrera ett nytt konto

Bli medlem

Logga in

Har du redan ett konto? Logga in här

Logga in