Gå til innhold
Trenger du hjelp med PCen? Still spørsmål her! ×

Hjelp med virus!


Anbefalte innlegg

Skrevet

Hei jeg lurte på om noen "nerder" her inne kunne hjulpet meg litt xD

 

Har akkurat tatt en HJT, og har loggen her;)

 

Logfile of Trend Micro HijackThis v2.0.0 (BETA)

Scan saved at 18:26:37, on 01.09.2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe

C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

C:\Programfiler\Hewlett-Packard\Shared\hpqwmiex.exe

C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

C:\Programfiler\HP\QuickPlay\QPService.exe

C:\Programfiler\Hp\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\RunDLL32.exe

C:\Programfiler\Google\Gmail Notifier\gnotify.exe

C:\WINDOWS\system32\RunDll32.exe

C:\Programfiler\Razer\DeathAdder\razerhid.exe

C:\windows\system32\ljdsregq.exe

C:\Programfiler\MSN Messenger\MsnMsgr.Exe

C:\Programfiler\WIDCOMM\Bluetooth-programvare\BTTray.exe

C:\WINDOWS\system32\qwinkmdt.exe

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\Logitech\SetPoint\SetPoint.exe

C:\Documents and Settings\JulanSåklart\Start-meny\Programmer\Oppstart\MSN-SongText.exe

C:\Programfiler\Razer\DeathAdder\razertra.exe

C:\Programfiler\Razer\DeathAdder\razerofa.exe

C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe

C:\Programfiler\Fellesfiler\Logitech\khalshared\KHALMNPR.EXE

C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE

C:\Programfiler\HP\Digital Imaging\bin\hpqimzone.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Documents and Settings\JulanSåklart\Skrivebord\HiJackThis_v2.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...ilion&pf=laptop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...ilion&pf=laptop

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar2.dll

O2 - BHO: (no name) - {E271F4E9-D46E-4C7A-8608-AFDD4A87E582} - C:\WINDOWS\system32\urqnnkl.dll

O2 - BHO: (no name) - {FC0D5BD2-AE7F-46F5-8019-7F4D3CF6736F} - C:\WINDOWS\system32\awvtu.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar2.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [QPService] "C:\Programfiler\HP\QuickPlay\QPService.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Cpqset] C:\Programfiler\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe

O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Programfiler\Google\Gmail Notifier\gnotify.exe

O4 - HKLM\..\Run: [sbUsb AudCtrl] RunDll32 sbusbdll.dll,RCMonitor

O4 - HKLM\..\Run: [DeathAdder] C:\Programfiler\Razer\DeathAdder\razerhid.exe

O4 - HKLM\..\Run: [{F0-04-46-6A-ZN}] C:\windows\system32\ljdsregq.exe OLI001

O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\qwinkmdt.exe OLI001

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: MSN-SongText.exe

O4 - Startup: RocketDock.lnk = ?

O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe

O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinkmdt.exe

O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe

O4 - Startup: UberIcon.lnk = ?

O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: HP Photosmart Premier Hurtigstart.lnk = C:\Programfiler\Hp\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech SetPoint.lnk = ?

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: Send til &Bluetooth - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie_ctx.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{099FC8FD-96D2-4DC2-A723-29B55C640B4B}: NameServer = 192.168.1.1

O17 - HKLM\System\CCS\Services\Tcpip\..\{72700D34-CFB2-41F2-AD9F-3BE6F41061F9}: NameServer = 192.168.1.1

O17 - HKLM\System\CS1\Services\Tcpip\..\{099FC8FD-96D2-4DC2-A723-29B55C640B4B}: NameServer = 192.168.1.1

O17 - HKLM\System\CS2\Services\Tcpip\..\{099FC8FD-96D2-4DC2-A723-29B55C640B4B}: NameServer = 192.168.1.1

O20 - Winlogon Notify: awvtu - C:\WINDOWS\system32\awvtu.dll

O20 - Winlogon Notify: urqnnkl - C:\WINDOWS\SYSTEM32\urqnnkl.dll

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programfiler\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Programfiler\Fellesfiler\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 8428 bytes

 

Problemet er manglende "admin-rettigheter", kan ikke trykke slå av, bare Logg av. Og masse pop-ups.. Hjelp! :D

MVh effectiv

Videoannonse
Annonse
Skrevet

Du har fått noe grums, ja, så vi gjør følgende:

 

Start HJT, velg "Do a system scan only", sett merke framfor følgende linjer og klikk 'Fix checked':

O2 - BHO: (no name) - {E271F4E9-D46E-4C7A-8608-AFDD4A87E582} - C:\WINDOWS\system32\urqnnkl.dll

O2 - BHO: (no name) - {FC0D5BD2-AE7F-46F5-8019-7F4D3CF6736F} - C:\WINDOWS\system32\awvtu.dll

O4 - HKLM\..\Run: [{F0-04-46-6A-ZN}] C:\windows\system32\ljdsregq.exe OLI001

O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\qwinkmdt.exe OLI001

O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe

O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinkmdt.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O20 - Winlogon Notify: awvtu - C:\WINDOWS\system32\awvtu.dll

O20 - Winlogon Notify: urqnnkl - C:\WINDOWS\SYSTEM32\urqnnkl.dll

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Når combofix er ferdig:

Last ned SAS, installer, oppdater og kjør en full (Complete) scan.

 

Post loggfilen fra combofix (vanligvis c:\combofix.txt), SAS (preferences->statistics/logs) + ny hjt-logg.

Skrevet

Bare så de er nevnt, så er det IKKE nødvendig å reformatere for å kvitte seg med alle virus. Om du bare reinstallerer windows på nytt så vil alle virus bli inaktive. Dvs. virusfilene kan potensiellt fremdeles ligge på harddisken (avhengig av hvor de installeres til, hele windows katalogen blir overskrevet), men de vil ikke bli automatisk kjørt av systemet på noen måte, så i praksis får du samme resultat som ved reformatering + reinstallasjon.

 

Så slipper du å miste alle filene dine (selv om diverse progammer må installeres på nytt igjen selv om filene ligger på harddisken).

 

-Stigma

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...