Effectiv Skrevet 1. september 2007 Skrevet 1. september 2007 Hei jeg lurte på om noen "nerder" her inne kunne hjulpet meg litt xD Har akkurat tatt en HJT, og har loggen her;) Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 18:26:37, on 01.09.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Programfiler\Hewlett-Packard\Shared\hpqwmiex.exe C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe C:\Programfiler\HP\QuickPlay\QPService.exe C:\Programfiler\Hp\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\RunDLL32.exe C:\Programfiler\Google\Gmail Notifier\gnotify.exe C:\WINDOWS\system32\RunDll32.exe C:\Programfiler\Razer\DeathAdder\razerhid.exe C:\windows\system32\ljdsregq.exe C:\Programfiler\MSN Messenger\MsnMsgr.Exe C:\Programfiler\WIDCOMM\Bluetooth-programvare\BTTray.exe C:\WINDOWS\system32\qwinkmdt.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Logitech\SetPoint\SetPoint.exe C:\Documents and Settings\JulanSåklart\Start-meny\Programmer\Oppstart\MSN-SongText.exe C:\Programfiler\Razer\DeathAdder\razertra.exe C:\Programfiler\Razer\DeathAdder\razerofa.exe C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe C:\Programfiler\Fellesfiler\Logitech\khalshared\KHALMNPR.EXE C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE C:\Programfiler\HP\Digital Imaging\bin\hpqimzone.exe C:\WINDOWS\system32\wuauclt.exe C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Documents and Settings\JulanSåklart\Skrivebord\HiJackThis_v2.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...ilion&pf=laptop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...ilion&pf=laptop R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar2.dll O2 - BHO: (no name) - {E271F4E9-D46E-4C7A-8608-AFDD4A87E582} - C:\WINDOWS\system32\urqnnkl.dll O2 - BHO: (no name) - {FC0D5BD2-AE7F-46F5-8019-7F4D3CF6736F} - C:\WINDOWS\system32\awvtu.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar2.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QPService] "C:\Programfiler\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Cpqset] C:\Programfiler\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Programfiler\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [sbUsb AudCtrl] RunDll32 sbusbdll.dll,RCMonitor O4 - HKLM\..\Run: [DeathAdder] C:\Programfiler\Razer\DeathAdder\razerhid.exe O4 - HKLM\..\Run: [{F0-04-46-6A-ZN}] C:\windows\system32\ljdsregq.exe OLI001 O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\qwinkmdt.exe OLI001 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: MSN-SongText.exe O4 - Startup: RocketDock.lnk = ? O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinkmdt.exe O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe O4 - Startup: UberIcon.lnk = ? O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: HP Photosmart Premier Hurtigstart.lnk = C:\Programfiler\Hp\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Logitech SetPoint.lnk = ? O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: Send til &Bluetooth - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie_ctx.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{099FC8FD-96D2-4DC2-A723-29B55C640B4B}: NameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{72700D34-CFB2-41F2-AD9F-3BE6F41061F9}: NameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{099FC8FD-96D2-4DC2-A723-29B55C640B4B}: NameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{099FC8FD-96D2-4DC2-A723-29B55C640B4B}: NameServer = 192.168.1.1 O20 - Winlogon Notify: awvtu - C:\WINDOWS\system32\awvtu.dll O20 - Winlogon Notify: urqnnkl - C:\WINDOWS\SYSTEM32\urqnnkl.dll O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programfiler\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Programfiler\Fellesfiler\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 8428 bytes Problemet er manglende "admin-rettigheter", kan ikke trykke slå av, bare Logg av. Og masse pop-ups.. Hjelp! MVh effectiv
snippsat Skrevet 1. september 2007 Skrevet 1. september 2007 (endret) Les her så poster du der. https://www.diskusjon.no/index.php?showtopic=691246 Du kan lime in HJT loggen her. http://www.hijackthis.de/en#anl Endret 1. september 2007 av SNIPPSAT
norbat Skrevet 1. september 2007 Skrevet 1. september 2007 Du har fått noe grums, ja, så vi gjør følgende: Start HJT, velg "Do a system scan only", sett merke framfor følgende linjer og klikk 'Fix checked': O2 - BHO: (no name) - {E271F4E9-D46E-4C7A-8608-AFDD4A87E582} - C:\WINDOWS\system32\urqnnkl.dll O2 - BHO: (no name) - {FC0D5BD2-AE7F-46F5-8019-7F4D3CF6736F} - C:\WINDOWS\system32\awvtu.dll O4 - HKLM\..\Run: [{F0-04-46-6A-ZN}] C:\windows\system32\ljdsregq.exe OLI001 O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\qwinkmdt.exe OLI001 O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinkmdt.exe O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O20 - Winlogon Notify: awvtu - C:\WINDOWS\system32\awvtu.dll O20 - Winlogon Notify: urqnnkl - C:\WINDOWS\SYSTEM32\urqnnkl.dll Hent Combofix, og legg det på skrivebordet Kjør combofix.exe, og følg veiledningen. Du må ikke klikke på vinduet mens programmet kjører. Når combofix er ferdig: Last ned SAS, installer, oppdater og kjør en full (Complete) scan. Post loggfilen fra combofix (vanligvis c:\combofix.txt), SAS (preferences->statistics/logs) + ny hjt-logg.
Effectiv Skrevet 1. september 2007 Forfatter Skrevet 1. september 2007 Glem det jeg ble så sint at jeg reformaterte
norbat Skrevet 1. september 2007 Skrevet 1. september 2007 Ok, men det var ikke all verden du hadde Men en reinstallering i ny og ned gjør bare godt.
Stigma Skrevet 1. september 2007 Skrevet 1. september 2007 Bare så de er nevnt, så er det IKKE nødvendig å reformatere for å kvitte seg med alle virus. Om du bare reinstallerer windows på nytt så vil alle virus bli inaktive. Dvs. virusfilene kan potensiellt fremdeles ligge på harddisken (avhengig av hvor de installeres til, hele windows katalogen blir overskrevet), men de vil ikke bli automatisk kjørt av systemet på noen måte, så i praksis får du samme resultat som ved reformatering + reinstallasjon. Så slipper du å miste alle filene dine (selv om diverse progammer må installeres på nytt igjen selv om filene ligger på harddisken). -Stigma
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå