Snabbare, snyggare, effektivare och mer socialt är kännetecknen efter att forumet uppgraderats till den senaste versionen under dagen 9/5. Mer information om forumuppgraderingen.

Jump to content

  • Log in with Facebook Log in with Twitter Logga in via Google      Logga in   
  • Registrera konto


- - - - -

Hjälp! Antivirus 2009


Den här tråden har arkiverats. Det innebär att du inte längre kan svara på inlägg i tråden. Vänligen starta en ny tråd vid behov.
6 svar i den här tråden

#1 fnork

fnork
  • Medlem
  • Pip
  • 4 inlägg

Skrivet 04 januari 2009 - 21:48

Hej! Drabbades bara för någon dag sen av det besvärliga "Antivirus 2009" som poppar upp när jag har Firefox uppe. Programmet påstår sig vara ett antivirusprogram men är egentligen av vad jag läst ett virus. Har försökt med alla möjliga anti-virusprogram för att få bort det, men inget verkar hjälpa, och jag hamnade till slut på den här sidan och har försökt följa instruktionerna och har nedan kopierat min Loggfil. Hoppas på att få nån form av hjälp!

mvh Martin





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:42:51, on 2009-01-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32csrss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:NormanNpmbinELOGSVC.EXE
C:NormanNpmBinZanda.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:ProgramDelade filerSymantec SharedccSvcHst.exe
C:WINDOWSsystem32spoolsv.exe
C:ProgramNetropaMultimedia Keyboardnhksrv.exe
C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:ProgramBonjourmDNSResponder.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32CNAB4RPK.EXE
C:WINDOWSSOUNDMAN.EXE
C:ProgramFSCWireless Wheel MouseMOUSE32A.EXE
C:ProgramNetropaMultimedia KeyboardMMKeybd.exe
C:ProgramMessengerPlus! 3MsgPlus.exe
C:ProgramAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe
C:ProgramJavajre1.6.0_01binjusched.exe
C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe
C:ProgramDelade filerSymantec SharedccApp.exe
C:ProgramMicrosoft IntelliType Proitype.exe
C:ProgramMicrosoft IntelliPointipoint.exe
C:ProgramSearch SettingsSearchSettings.exe
C:ProgramQuickTimeQTTask.exe
C:ProgramiTunesiTunesHelper.exe
C:WINDOWSsystem32rundll32.exe
C:NormanNpmbinZLH.EXE
C:WINDOWSsystem32ctfmon.exe
C:ProgramMessengerMsmsgs.exe
C:ProgramNetropaMultimedia KeyboardTrayMon.exe
C:ProgramNetropaOnscreen DisplayOSD.exe
C:ProgramNetropaInetKbInetkb.exe
C:NormanNpmbinNJEEVES.EXE
C:Last.fmLastFMHelper.exe
C:NormannsebinNSESVC.EXE
C:ProgramiPodbiniPodService.exe
C:WINDOWSSystem32alg.exe
C:NormanNvcbinnvcoas.exe
C:NormanNvcBINNIP.EXE
C:NormanNvcBINNVCSCHED.EXE
C:NormanNvcbincclaw.exe
C:ProgramMozilla Firefoxfirefox.exe
C:WINDOWSexplorer.exe
C:ProgramTrend MicroHijackThisHijackThis.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32wbemwmiprvse.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://search.imesh....ex.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.imesh....ex.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.imesh....ex.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.imesh....ex.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:ProgramBearShare applicationsBearShare MediaBarMediaBar.dll (file missing)
R3 - URLSearchHook: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:ProgramiMesh applicationsiMesh mediabarMediaBar.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:ProgramYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgramAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:ProgramDelade filerSymantec SharedcoSharedBrowser1.5NppBho.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:ProgramAskBarDisbarbinaskBar.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:ProgramFlashGetjccatch.dll
O2 - BHO: (no name) - {498b333e-a702-434c-9515-849713fbbfb8} - C:WINDOWSsystem32gopapodu.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:MYDOWN~1SPYBOT~1SDHelper.dll
O2 - BHO: XBTP01621 - {54B62CEF-8A07-4d3c-A2EF-DDF184264374} - C:ProgramIMESHA~1IMESHM~1MediaBar.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:ProgramSPYWAR~1toolsiesdsg.dll
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:ProgramDealiokb125Dealio.dll
O2 - BHO: (no name) - {6E94FA35-698C-3A56-A54C-67E33B9EAAB8} - C:WINDOWSsystem32ixtnflgl.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_01binssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:ProgramDelade filerMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Softonic English Toolbar - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:ProgramSoftonic_EnglishtbSoft.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programgooglegoogletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:ProgramGoogleGoogleToolbarNotifier3.1.807.1746swg.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:ProgramSearch Settingskb125SearchSettings.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:ProgramFlashGetgetflash.dll
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:ProgramBEARSH~1BEARSH~2MediaBar.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:ProgramYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:ProgramiMesh applicationsiMesh mediabarMediaBar.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:ProgramBearShare applicationsBearShare MediaBarMediaBar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programgooglegoogletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:ProgramDelade filerSymantec SharedcoSharedBrowser1.5UIBHO.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:ProgramFlashGetfgiebar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:ProgramDealiokb125Dealio.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:ProgramAskBarDisbarbinaskBar.dll
O3 - Toolbar: Softonic English Toolbar - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:ProgramSoftonic_EnglishtbSoft.dll
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [LWBMOUSE] C:ProgramFSCWireless Wheel MouseMOUSE32A.EXE
O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:ProgramNetropaMultimedia KeyboardMMKeybd.exe
O4 - HKLM..Run: [MessengerPlus3] "C:ProgramMessengerPlus! 3MsgPlus.exe"
O4 - HKLM..Run: [Adobe Photo Downloader] "C:ProgramAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:ProgramJavajre1.6.0_01binjusched.exe"
O4 - HKLM..Run: [Google Desktop Search] "C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe" /startup
O4 - HKLM..Run: [ccApp] "C:ProgramDelade filerSymantec SharedccApp.exe"
O4 - HKLM..Run: [itype] "C:ProgramMicrosoft IntelliType Proitype.exe"
O4 - HKLM..Run: [IntelliPoint] "C:ProgramMicrosoft IntelliPointipoint.exe"
O4 - HKLM..Run: [au] C:ProgramDealioDealioAU.exe
O4 - HKLM..Run: [SearchSettings] C:ProgramSearch SettingsSearchSettings.exe
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" /a /m "C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [QuickTime Task] "C:ProgramQuickTimeQTTask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:ProgramiTunesiTunesHelper.exe"
O4 - HKLM..Run: [piletofetu] Rundll32.exe "C:WINDOWSsystem32fagunake.dll",s
O4 - HKLM..Run: [c241ce41] rundll32.exe "C:WINDOWSsystem32manuhavi.dll",b
O4 - HKLM..Run: [Norman ZANDA] "C:NormanNpmbinZLH.EXE" /LOAD /SPLASH
O4 - HKLM..Run: [CPMc172fddd] Rundll32.exe "c:windowssystem32nevoputo.dll",a
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:ProgramMessengerMsmsgs.exe" /background
O4 - HKCU..Run: [Free Download Manager] C:ProgramFree Download Managerfdm.exe -autorun
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUSS-1-5-19..Run: [piletofetu] Rundll32.exe "C:WINDOWSsystem32fagunake.dll",s (User 'LOKAL TJÄNST')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:ProgramDelade filerAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:ProgramAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: Last.fm Helper.lnk = C:Last.fmLastFMHelper.exe
O8 - Extra context menu item: &Windows Live Search - res://C:ProgramWindows Live Toolbarmsntb.dll/search.htm
O8 - Extra context menu item: Compare Prices with &Dealio - C:Documents and SettingsMartinApplication DataDealiokb125resDealioSearch.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download All by FlashGet - C:ProgramFlashGetjc_all.htm
O8 - Extra context menu item: Download Image with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download URL in selection with Download Manager - tbr:iemenudownsel
O8 - Extra context menu item: Download URL with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download using FlashGet - C:ProgramFlashGetjc_link.htm
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_01binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_01binssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:ProgramFlashGetflashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:ProgramFlashGetflashget.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:ProgramDealiokb125Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:ProgramDealiokb125Dealio.dll
O9 - Extra button: @c:ProgramMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:ProgramMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: @c:ProgramMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:ProgramMessengermsmsgs.exe
O16 - DPF: {00C1329F-D6C9-46A2-8C3F-23F50977F0A5} (SMUpdateAX Class) - http://www.liquidlab...et/SetupInf.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://lnknsr03.gbgsd.se/qp2.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://lnknsr05.gbgsd.se/iNotes6W.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSKYPE4~1.DLL
O20 - AppInit_DLLs: C:ProgramGoogleGOOGLE~1GOEC62~1.DLL C:WINDOWSsystem32jahasike.dll c:windowssystem32nevoputo.dll c:windowssystem32topapope.dll c:windowssystem32zuhuwuro.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:windowssystem32zuhuwuro.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:windowssystem32zuhuwuro.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:ProgramDelade filerSymantec SharedVAScannercomHost.exe
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:NormanNpmbinELOGSVC.EXE
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:ProgramGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:ProgramSymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:ProgramNetropaMultimedia Keyboardnhksrv.exe
O23 - Service: Norman NJeeves - Norman ASA - C:NormanNpmbinNJEEVES.EXE
O23 - Service: Norman ZANDA - Norman ASA - C:NormanNpmBinZanda.exe
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:NormannsebinNSESVC.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:NormanNvcbinnvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:NormanNvcBINNVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:ProgramSpyware DoctorpctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:ProgramSpyware DoctorpctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:ProgramDelade filerSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:WINDOWSsystem32UTSCSI.EXE

--
End of file - 15727 bytes

Det här inlägget har redigerats av Malou: 24 januari 2009 - 20:45
Tråden/Ämnet är låst:



ANNONS:
  • Inte din sorts mobil? Jämför priser på fler hos

#2 Malou

Malou
  • Gäster

Skrivet 04 januari 2009 - 21:57

Hej fnork!

Vi skall göra vad vi kan för att hjälpa  ;)

Ser att du har två skyddsprogram installerade (Symantec och Norman). Avinstallera det du inte använder. Det är aldrig bra att använda/installera flera antivirusprogram på samma gång och som ligger och kör. Bäddat för konflikter.
Är det du som har installerat Yahoo Toolbar?

Döp även om filen HiJack This.exe enligt instruktionerna
=> Trend Micro HiJack This (Nerladdning/Instruktioner):

Vidare:

Skriv ut nedanstående eller kopiera det till ett textdokument och spara det till skrivbordet:
Läs/Följ instruktionerna noga:


Hämta hem Malwarebytes Anti-Malware:
http://www.malwarebytes.org/index.php

1: Spara installationsfilen till skrivbordet
2: För att påbörja installationen dubbelklicka på mbam-setup.exe
3: Bocka för nedanstående
Uppdatera Malwarebytes' Anti-Malware
Starta Malwarebytes' Anti-Malware

4: Klicka på Slutför
Om där finns uppdateringar kommer dessa att installeras.

Då ovanstående är gjort gå vidare med nedanstående procedur:

1: När programmet startar så välj Utför snabb scanning
2: Klicka på knappen Scanna
3: Scanningen kommer nu att ta en stund
3: När programmet scannat klart klicka Ok och sedan Visa resultat
4: Bocka för allt och klicka på Remove Selected
5: Då borttagningen är klar kommer en textfil i Anteckningar att öppnas upp med en logg. Kopiera/klistra in den loggan hit till din tråd.
6: Gör en ny TM HJT-logga kopiera in den hit så får vi se hur den ser ut.
7: Berätta/Tala om hur datorn mår och om där kvarstår problem

MVH/Malou

#3 fnork

fnork
  • Medlem
  • Pip
  • 4 inlägg

Skrivet 05 januari 2009 - 12:49

Hej! Tack för hjälpen, har följt dina instruktioner, nu återstår att se om datorn funkar bättre än innan... Ska avinstallera ett av anti-virus-programmen snart. Fick scanna datorn ett antal gånger (det tog för lång tid för att göra allt på en gång), så här är tre loggfiler från Malwarebytes:



Malwarebytes' Anti-Malware 1.32
Databasversion: 1617
Windows 5.1.2600 Service Pack 2

2009-01-05 12:39:59
mbam-log-2009-01-05 (12-39-59).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 64672
Förfluten tid: 19 minute(s), 15 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 4
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 15

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftcontim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftdslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftrdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicescore (Rootkit.Agent) -> Quarantined and deleted successfully.

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:WINDOWSsystem32makatulo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32pazewaju.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32yudukoke.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32zazuporo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32k1E68Hp8.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:WINDOWSTemp22m5SlI0.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSTempP8oEGx57.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSTempTE2hunO7.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSTempN0400vIr.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:WINDOWSsystem32i4C02Fn2.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:WINDOWSsystem32WCiuro7L.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:WINDOWSsystem32ClickToFindandFixErrors_Intl.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:WINDOWSsystem32ClickToFindandFixErrors_RON_Intl.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:WINDOWSsystem32ClickToFindandFixErrors_US.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:WINDOWSsystem32driverscore.cache.dsk (Rootkit.Agent) -> Quarantined and deleted successfully.





Loggfil 2:



Malwarebytes' Anti-Malware 1.32
Databasversion: 1617
Windows 5.1.2600 Service Pack 2

2009-01-05 12:15:47
mbam-log-2009-01-05 (12-15-47).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 4200
Förfluten tid: 47 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 8
Infekterade registernycklar: 3
Infekterade registervärden: 4
Infekterade registerdataposter: 11
Infekterade mappar: 0
Infekterade filer: 8

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
C:WINDOWSsystem32jahasike.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32semehine.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32gopapodu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32fagunake.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32niwezufa.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32zuhuwuro.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32topapope.dll (Trojan.Vundo) -> Delete on reboot.
c:WINDOWSsystem32nevoputo.dll (Trojan.Vundo) -> Delete on reboot.

Infekterade registernycklar:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{498b333e-a702-434c-9515-849713fbbfb8} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOTCLSID{498b333e-a702-434c-9515-849713fbbfb8} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOTCLSID{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Infekterade registervärden:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuncpmc172fddd (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunpiletofetu (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadssodl (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Infekterade registerdataposter:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: c:windowssystem32jahasike.dll -> Delete on reboot.
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLSANotification Packages (Trojan.Vundo.H) -> Data: c:windowssystem32jahasike.dll  -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: system32jahasike.dll -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: c:windowssystem32niwezufa.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: system32niwezufa.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: c:windowssystem32zuhuwuro.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: system32zuhuwuro.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: c:windowssystem32topapope.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: system32topapope.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: c:windowssystem32nevoputo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: system32nevoputo.dll -> Quarantined and deleted successfully.

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
c:WINDOWSsystem32zuhuwuro.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32fagunake.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32gopapodu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32jahasike.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32semehine.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32niwezufa.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32topapope.dll (Trojan.Vundo) -> Delete on reboot.
c:WINDOWSsystem32nevoputo.dll (Trojan.Vundo) -> Delete on reboot.



Loggfil 3:


Malwarebytes' Anti-Malware 1.32
Databasversion: 1617
Windows 5.1.2600 Service Pack 2

2009-01-05 12:12:54
mbam-log-2009-01-05 (12-12-54).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 19850
Förfluten tid: 31 minute(s), 29 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 8
Infekterade registernycklar: 16
Infekterade registervärden: 9
Infekterade registerdataposter: 11
Infekterade mappar: 0
Infekterade filer: 18

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
C:WINDOWSsystem32semehine.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32jahasike.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32gopapodu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32fagunake.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32niwezufa.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32zuhuwuro.dll (Trojan.Vundo) -> Delete on reboot.
c:WINDOWSsystem32topapope.dll (Trojan.Vundo) -> Delete on reboot.
c:WINDOWSsystem32nevoputo.dll (Trojan.Vundo) -> Delete on reboot.

Infekterade registernycklar:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{498b333e-a702-434c-9515-849713fbbfb8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{498b333e-a702-434c-9515-849713fbbfb8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{6e94fa35-698c-3a56-a54c-67e33b9eaab8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{6e94fa35-698c-3a56-a54c-67e33b9eaab8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionExtStats{498b333e-a702-434c-9515-849713fbbfb8} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTxbtb01621.ietoolbar (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypeLib{625a04f1-dbbb-4a6f-94cf-7e8430c97d98} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionExtStats{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{54b62cef-8a07-4d3c-a2ef-ddf184264374} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionExtStats{54b62cef-8a07-4d3c-a2ef-ddf184264374} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{54b62cef-8a07-4d3c-a2ef-ddf184264374} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTxbtb01621.ietoolbar.1 (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTxbtb01621.xbtb01621 (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTxbtb01621.xbtb01621.1 (Adware.SoftMate) -> Quarantined and deleted successfully.

Infekterade registervärden:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunc241ce41 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunpiletofetu (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuncpmc172fddd (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadssodl (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerURLSearchHooks{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerToolbarWebBrowser{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerToolbarShellBrowser{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.

Infekterade registerdataposter:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: c:windowssystem32jahasike.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLSANotification Packages (Trojan.Vundo.H) -> Data: c:windowssystem32jahasike.dll  -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: system32jahasike.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: c:windowssystem32niwezufa.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: system32niwezufa.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: c:windowssystem32zuhuwuro.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: system32zuhuwuro.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: c:windowssystem32topapope.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: system32topapope.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: c:windowssystem32nevoputo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo) -> Data: system32nevoputo.dll -> Quarantined and deleted successfully.

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:WINDOWSsystem32gizoroda.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32adorozig.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32lewowesa.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32asewowel.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32manuhavi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32ivahunam.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32pewafahu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32uhafawep.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32semehine.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32enihemes.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32fagunake.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32niwezufa.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32gopapodu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32jahasike.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32zuhuwuro.dll (Trojan.Vundo) -> Delete on reboot.
c:WINDOWSsystem32topapope.dll (Trojan.Vundo) -> Delete on reboot.
c:WINDOWSsystem32nevoputo.dll (Trojan.Vundo) -> Delete on reboot.
C:ProgramiMesh applicationsiMesh mediabarMediaBar.dll (Adware.SoftMate) -> Quarantined and deleted successfully.

#4 fnork

fnork
  • Medlem
  • Pip
  • 4 inlägg

Skrivet 05 januari 2009 - 12:50

Här är en loggfil från TM HJT:




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:44:08, on 2009-01-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32csrss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:NormanNpmbinELOGSVC.EXE
C:NormanNpmBinZanda.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:ProgramDelade filerSymantec SharedccSvcHst.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:ProgramNetropaMultimedia Keyboardnhksrv.exe
C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:ProgramBonjourmDNSResponder.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32CNAB4RPK.EXE
C:NormanNpmbinNJEEVES.EXE
C:WINDOWSSOUNDMAN.EXE
C:ProgramFSCWireless Wheel MouseMOUSE32A.EXE
C:ProgramNetropaMultimedia KeyboardMMKeybd.exe
C:ProgramMessengerPlus! 3MsgPlus.exe
C:NormannsebinNSESVC.EXE
C:ProgramAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe
C:WINDOWSSystem32alg.exe
C:ProgramJavajre1.6.0_01binjusched.exe
C:ProgramNetropaMultimedia KeyboardTrayMon.exe
C:ProgramNetropaOnscreen DisplayOSD.exe
C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe
C:ProgramNetropaInetKbInetkb.exe
C:ProgramDelade filerSymantec SharedccApp.exe
C:ProgramMicrosoft IntelliType Proitype.exe
C:ProgramMicrosoft IntelliPointipoint.exe
C:ProgramSearch SettingsSearchSettings.exe
C:ProgramQuickTimeQTTask.exe
C:ProgramiTunesiTunesHelper.exe
C:NormanNpmbinZLH.EXE
C:WINDOWSsystem32ctfmon.exe
C:ProgramMessengerMsmsgs.exe
C:WINDOWSSystem32svchost.exe
C:ProgramAdobeAcrobat 7.0Readerreader_sl.exe
C:Last.fmLastFMHelper.exe
C:ProgramiPodbiniPodService.exe
C:WINDOWSsystem32wbemwmiprvse.exe
C:NormanNvcBINNVCSCHED.EXE
C:NormanNvcbinnvcoas.exe
C:NormanNvcBINNIP.EXE
C:NormanNvcbincclaw.exe
C:ProgramMozilla Firefoxfirefox.exe
C:ProgramTrend MicroHijackThisHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://search.imesh....ex.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.imesh....ex.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.imesh....ex.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.imesh....ex.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:ProgramBearShare applicationsBearShare MediaBarMediaBar.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgramAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:ProgramDelade filerSymantec SharedcoSharedBrowser1.5NppBho.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:ProgramAskBarDisbarbinaskBar.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:ProgramFlashGetjccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:MYDOWN~1SPYBOT~1SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:ProgramSPYWAR~1toolsiesdsg.dll
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:ProgramDealiokb125Dealio.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_01binssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:ProgramDelade filerMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Softonic English Toolbar - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:ProgramSoftonic_EnglishtbSoft.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programgooglegoogletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:ProgramGoogleGoogleToolbarNotifier3.1.807.1746swg.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:ProgramSearch Settingskb125SearchSettings.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:ProgramFlashGetgetflash.dll
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:ProgramBEARSH~1BEARSH~2MediaBar.dll (file missing)
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:ProgramBearShare applicationsBearShare MediaBarMediaBar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programgooglegoogletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:ProgramDelade filerSymantec SharedcoSharedBrowser1.5UIBHO.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:ProgramFlashGetfgiebar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:ProgramDealiokb125Dealio.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:ProgramAskBarDisbarbinaskBar.dll
O3 - Toolbar: Softonic English Toolbar - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:ProgramSoftonic_EnglishtbSoft.dll
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [LWBMOUSE] C:ProgramFSCWireless Wheel MouseMOUSE32A.EXE
O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:ProgramNetropaMultimedia KeyboardMMKeybd.exe
O4 - HKLM..Run: [MessengerPlus3] "C:ProgramMessengerPlus! 3MsgPlus.exe"
O4 - HKLM..Run: [Adobe Photo Downloader] "C:ProgramAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:ProgramJavajre1.6.0_01binjusched.exe"
O4 - HKLM..Run: [Google Desktop Search] "C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe" /startup
O4 - HKLM..Run: [ccApp] "C:ProgramDelade filerSymantec SharedccApp.exe"
O4 - HKLM..Run: [itype] "C:ProgramMicrosoft IntelliType Proitype.exe"
O4 - HKLM..Run: [IntelliPoint] "C:ProgramMicrosoft IntelliPointipoint.exe"
O4 - HKLM..Run: [au] C:ProgramDealioDealioAU.exe
O4 - HKLM..Run: [SearchSettings] C:ProgramSearch SettingsSearchSettings.exe
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" /a /m "C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [QuickTime Task] "C:ProgramQuickTimeQTTask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:ProgramiTunesiTunesHelper.exe"
O4 - HKLM..Run: [Norman ZANDA] "C:NormanNpmbinZLH.EXE" /LOAD /SPLASH
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:ProgramMessengerMsmsgs.exe" /background
O4 - HKCU..Run: [Free Download Manager] C:ProgramFree Download Managerfdm.exe -autorun
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUSS-1-5-19..Run: [piletofetu] Rundll32.exe "C:WINDOWSsystem32fagunake.dll",s (User 'LOKAL TJÄNST')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:ProgramDelade filerAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:ProgramAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: Last.fm Helper.lnk = C:Last.fmLastFMHelper.exe
O8 - Extra context menu item: &Windows Live Search - res://C:ProgramWindows Live Toolbarmsntb.dll/search.htm
O8 - Extra context menu item: Compare Prices with &Dealio - C:Documents and SettingsMartinApplication DataDealiokb125resDealioSearch.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download All by FlashGet - C:ProgramFlashGetjc_all.htm
O8 - Extra context menu item: Download Image with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download URL in selection with Download Manager - tbr:iemenudownsel
O8 - Extra context menu item: Download URL with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download using FlashGet - C:ProgramFlashGetjc_link.htm
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_01binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_01binssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:ProgramFlashGetflashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:ProgramFlashGetflashget.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:ProgramDealiokb125Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:ProgramDealiokb125Dealio.dll
O9 - Extra button: @c:ProgramMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:ProgramMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: @c:ProgramMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:ProgramMessengermsmsgs.exe
O16 - DPF: {00C1329F-D6C9-46A2-8C3F-23F50977F0A5} (SMUpdateAX Class) - http://www.liquidlab...et/SetupInf.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://lnknsr03.gbgsd.se/qp2.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://lnknsr05.gbgsd.se/iNotes6W.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSKYPE4~1.DLL
O20 - AppInit_DLLs: C:ProgramGoogleGOOGLE~1GOEC62~1.DLL         ,   
O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:ProgramDelade filerSymantec SharedVAScannercomHost.exe
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:NormanNpmbinELOGSVC.EXE
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:ProgramGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:ProgramSymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:ProgramDelade filerSymantec SharedccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:ProgramNetropaMultimedia Keyboardnhksrv.exe
O23 - Service: Norman NJeeves - Norman ASA - C:NormanNpmbinNJEEVES.EXE
O23 - Service: Norman ZANDA - Norman ASA - C:NormanNpmBinZanda.exe
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:NormannsebinNSESVC.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:NormanNvcbinnvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:NormanNvcBINNVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:ProgramSpyware DoctorpctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:ProgramSpyware DoctorpctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:ProgramDelade filerSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:WINDOWSsystem32UTSCSI.EXE

--
End of file - 14316 bytes

#5 Malou

Malou
  • Gäster

Skrivet 05 januari 2009 - 13:13

Hej fnork!

Citat

(det tog för lång tid för att göra allt på en gång), så här är tre loggfiler från Malwarebytes:
Man skall inte göra allt på en och samma gång  ;) utan en scanning åt gången  ;)

Du har lagt in tre loggar från Malwarebytes' Anti-Malware det räcker med den allra första scanner-loggan samt den sista scanner-loggan  ;)

För att få en bättre överblick så gör nedanstående procedur och kopiera in endast en logga från varje scanner verktyg  ;) Utifrån de nya loggarna du kopierar in går vi vidare  ;)

1: Starta om datorn
2: Uppdatera Malwarebytes' Anti-Malware
3: Starta programmet => välj Utför snabb scanning
4: Klicka på knappen Scanna
5: Scanningen kommer nu att ta en stund
6: När programmet scannat klart klicka Ok och sedan Visa resultat
7: Bocka för allt och klicka på Remove Selected
8: Då borttagningen är klar kommer en textfil i Anteckningar att öppnas upp med en logg. Kopiera/klistra in den loggan hit till din tråd.
9: Gör en ny TM HJT-logga kopiera in den hit så får vi se hur den ser ut.
10: Berätta/Tala om hur datorn mår och om där kvarstår problem

MVH/Malou

#6 fnork

fnork
  • Medlem
  • Pip
  • 4 inlägg

Skrivet 05 januari 2009 - 23:57

Tack för hjälpen :) Nu ser det ju mycket bättre ut efter den senaste scanningen:

Malwarebytes' Anti-Malware 1.32
Databasversion: 1618
Windows 5.1.2600 Service Pack 2

2009-01-05 23:10:05
mbam-log-2009-01-05 (23-10-05).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 64366
Förfluten tid: 18 minute(s), 24 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 0

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
(Inga illasinnade poster hittades)

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
(Inga illasinnade poster hittades)




Här är en TM HJT-logga:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54:41, on 2009-01-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32csrss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:NormanNpmbinELOGSVC.EXE
C:NormanNpmBinZanda.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:ProgramNetropaMultimedia Keyboardnhksrv.exe
C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:ProgramBonjourmDNSResponder.exe
C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32CNAB4RPK.EXE
C:NormanNpmbinNJEEVES.EXE
C:WINDOWSSystem32alg.exe
C:NormannsebinNSESVC.EXE
C:NormanNvcBINNVCSCHED.EXE
C:NormanNvcbinnvcoas.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSOUNDMAN.EXE
C:ProgramFSCWireless Wheel MouseMOUSE32A.EXE
C:ProgramNetropaMultimedia KeyboardMMKeybd.exe
C:ProgramMessengerPlus! 3MsgPlus.exe
C:ProgramAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe
C:ProgramJavajre1.6.0_01binjusched.exe
C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe
C:ProgramNetropaMultimedia KeyboardTrayMon.exe
C:ProgramMicrosoft IntelliType Proitype.exe
C:ProgramNetropaOnscreen DisplayOSD.exe
C:ProgramNetropaInetKbInetkb.exe
C:ProgramMicrosoft IntelliPointipoint.exe
C:ProgramSearch SettingsSearchSettings.exe
C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
C:ProgramQuickTimeQTTask.exe
C:ProgramiTunesiTunesHelper.exe
C:NormanNpmbinZLH.EXE
C:WINDOWSsystem32ctfmon.exe
C:NormanNvcBINNIP.EXE
C:ProgramMessengerMsmsgs.exe
C:NormanNvcbincclaw.exe
C:Last.fmLastFMHelper.exe
C:WINDOWSSystem32svchost.exe
C:ProgramiPodbiniPodService.exe
C:ProgramMalwarebytes' Anti-Malwarembam.exe
C:ProgramMozilla Firefoxfirefox.exe
C:ProgramMSN Messengerusnsvc.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:ProgramTrend MicroHijackThisHijackThis.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:WINDOWSsystem32wbemwmiprvse.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://search.imesh....ex.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.imesh....ex.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.imesh....ex.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:ProgramBearShare applicationsBearShare MediaBarMediaBar.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgramAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:ProgramAskBarDisbarbinaskBar.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:ProgramFlashGetjccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:MYDOWN~1SPYBOT~1SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:ProgramSPYWAR~1toolsiesdsg.dll
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:ProgramDealiokb125Dealio.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgramJavajre1.6.0_01binssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:ProgramDelade filerMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Softonic English Toolbar - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:ProgramSoftonic_EnglishtbSoft.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programgooglegoogletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:ProgramGoogleGoogleToolbarNotifier3.1.807.1746swg.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:ProgramSearch Settingskb125SearchSettings.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:ProgramFlashGetgetflash.dll
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C:ProgramBEARSH~1BEARSH~2MediaBar.dll (file missing)
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:ProgramBearShare applicationsBearShare MediaBarMediaBar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programgooglegoogletoolbar4.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:ProgramFlashGetfgiebar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:ProgramDealiokb125Dealio.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:ProgramAskBarDisbarbinaskBar.dll
O3 - Toolbar: Softonic English Toolbar - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:ProgramSoftonic_EnglishtbSoft.dll
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [LWBMOUSE] C:ProgramFSCWireless Wheel MouseMOUSE32A.EXE
O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:ProgramNetropaMultimedia KeyboardMMKeybd.exe
O4 - HKLM..Run: [MessengerPlus3] "C:ProgramMessengerPlus! 3MsgPlus.exe"
O4 - HKLM..Run: [Adobe Photo Downloader] "C:ProgramAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:ProgramJavajre1.6.0_01binjusched.exe"
O4 - HKLM..Run: [Google Desktop Search] "C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe" /startup
O4 - HKLM..Run: [itype] "C:ProgramMicrosoft IntelliType Proitype.exe"
O4 - HKLM..Run: [IntelliPoint] "C:ProgramMicrosoft IntelliPointipoint.exe"
O4 - HKLM..Run: [au] C:ProgramDealioDealioAU.exe
O4 - HKLM..Run: [SearchSettings] C:ProgramSearch SettingsSearchSettings.exe
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" /a /m "C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [QuickTime Task] "C:ProgramQuickTimeQTTask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:ProgramiTunesiTunesHelper.exe"
O4 - HKLM..Run: [Norman ZANDA] "C:NormanNpmbinZLH.EXE" /LOAD /SPLASH
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:ProgramMessengerMsmsgs.exe" /background
O4 - HKCU..Run: [Free Download Manager] C:ProgramFree Download Managerfdm.exe -autorun
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUSS-1-5-19..Run: [piletofetu] Rundll32.exe "C:WINDOWSsystem32fagunake.dll",s (User 'LOKAL TJÄNST')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUSS-1-5-21-2862596491-1884698460-4128294431-1011..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe (User 'Christina Malmgren')
O4 - HKUSS-1-5-21-2862596491-1884698460-4128294431-1011..Run: [IpWins] C:ProgramIpwindowsipwins.exe (User 'Christina Malmgren')
O4 - HKUSS-1-5-21-2862596491-1884698460-4128294431-1011..Run: [BitTorrent DNA] "C:ProgramDNAbtdna.exe" (User 'Christina Malmgren')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:ProgramDelade filerAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:ProgramAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: Last.fm Helper.lnk = C:Last.fmLastFMHelper.exe
O8 - Extra context menu item: &Windows Live Search - res://C:ProgramWindows Live Toolbarmsntb.dll/search.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:WINDOWSsystem32GPhotos.scr/200
O8 - Extra context menu item: Compare Prices with &Dealio - C:Documents and SettingsMartinApplication DataDealiokb125resDealioSearch.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download All by FlashGet - C:ProgramFlashGetjc_all.htm
O8 - Extra context menu item: Download Image with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download URL in selection with Download Manager - tbr:iemenudownsel
O8 - Extra context menu item: Download URL with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download using FlashGet - C:ProgramFlashGetjc_link.htm
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:ProgramMICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_01binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.6.0_01binssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:ProgramMICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:ProgramFlashGetflashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:ProgramFlashGetflashget.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:ProgramDealiokb125Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:ProgramDealiokb125Dealio.dll
O9 - Extra button: @c:ProgramMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:ProgramMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: @c:ProgramMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:ProgramMessengermsmsgs.exe
O16 - DPF: {00C1329F-D6C9-46A2-8C3F-23F50977F0A5} (SMUpdateAX Class) - http://www.liquidlab...et/SetupInf.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://lnknsr03.gbgsd.se/qp2.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://lnknsr05.gbgsd.se/iNotes6W.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:ProgramDELADE~1SkypeSKYPE4~1.DLL
O20 - AppInit_DLLs: C:ProgramGoogleGOOGLE~1GOEC62~1.DLL         ,   
O23 - Service: Apple Mobile Device - Apple Inc. - C:ProgramDelade filerAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:ProgramBonjourmDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:ProgramDelade filerSymantec SharedccSvcHst.exe (file missing)
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:NormanNpmbinELOGSVC.EXE
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:ProgramGoogleGoogle Desktop SearchGoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:ProgramGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgramDelade filerInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:ProgramiPodbiniPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:ProgramSymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:ProgramDelade filerSymantec SharedccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:ProgramDelade filerSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:ProgramNetropaMultimedia Keyboardnhksrv.exe
O23 - Service: Norman NJeeves - Norman ASA - C:NormanNpmbinNJEEVES.EXE
O23 - Service: Norman ZANDA - Norman ASA - C:NormanNpmBinZanda.exe
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:NormannsebinNSESVC.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:NormanNvcbinnvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:NormanNvcBINNVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:ProgramSpyware DoctorpctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:ProgramSpyware DoctorpctsSvc.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:WINDOWSsystem32UTSCSI.EXE

--
End of file - 14090 bytes




Har än så länge inga som helst problem med datorn, Antivirus 2009 är försvunnet och det är bara nån enstaka gång som t ex Internet Explorer startas av sig självt och det öppnas nån reklamrelaterad ruta...

#7 Malou

Malou
  • Gäster

Skrivet 06 januari 2009 - 00:20

Hej fnork!

Varsegod!

ser att du inte har döpt om filen som jag bad om tidigare
C:ProgramTrend MicroHijackThisHijackThis.exe
Gå in på nedanstående sida och följ instruktionen om hur du döper om filen
=> Trend Micro HiJack This (Nerladdning/Instruktioner):

*******************************************************************
Härligt att höra att datorn mår bättre.
Malwarebytes' Anti-Malware ser strålande ren och fin ut  ;)

Är det du som har installerat alla nedanstående Toolbares och är det verkligen nödvändigt att ha alla dessa?
gFlash
BearShare MediaBar
AskBar
DealioBHO
Softonic English Toolbar
XBTP02634
Ask Toolbar
Softonic English Toolbar
skall titta närmare på de ovanstående för att se om de är lämpliga att ha.

Dessa båda nedanstående bör du avinstallera.
AskBar
Ask Toolbar

Ser att du har => MessengerPlus3 <= installerat. Är det installerat med eller utan sponsorprogrammen?

Och hur är det med skyddsprogrammen Symantec och Norman?
Du har inte åtgärdat med att avinstallera det du inte använder.

Återkom med en ny TM HJT-logga (filen skall vara omdöpt). Samt återkom med svar på mina ovanstående frågor så vi kan gå vidare med rensningsprocedurerna.

MVH/Malou