virus! joblisten minimeres og forsvinder
Jeg har et problem med at min jobliste bliver minimeret lige så snart jeg starter den op. Når jeg så trykker på ikonet nede i bunden, forsvinder den helt. Jeg har Norton Antivirus 2004 og den har ikke fundet noget.Jeg har også været udsat for at skærmen bliver helt blå, og der står at den må genstarte pga. noget med "bad - cool - ???".
jeg har kørt en "e-scan" og den finder nogle forskellige fejl bla.: ISEAKA.exe - jauvcc.exe + nogle andre. Jeg smider lige en logfil fra e-scan:
File C:\WINDOWS\System32\ISEAKA.EXE infected by "Backdoor.Win32.Spyboter.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\ISEAKA.EXE infected by "Backdoor.Win32.Spyboter.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\ISEAKA.EXE infected by "Backdoor.Win32.Spyboter.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\iseaka.exe infected by "Backdoor.Win32.Spyboter.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jauvcc.exe infected by "Backdoor.Win32.Spyboter.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\msnmgr16.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Thomas og Charlotte\Lokale indstillinger\Application Data\IM\Identities\{15247E13-6C46-4797-B44B-20805ACAE757}\Message Store\Attachments\cover71.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Thomas og Charlotte\Lokale indstillinger\Temp\lesdi.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Thomas og Charlotte\Lokale indstillinger\Temp\shqskji.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\iseaka.exe infected by "Backdoor.Win32.Spyboter.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\jauvcc.exe infected by "Backdoor.Win32.Spyboter.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\msnmgr16.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
Jeg har også kørt hijackthis. Her smider jeg også lige en logfil:
Logfile of HijackThis v1.98.2
Scan saved at 14:39:12, on 15-11-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\WINDOWS\System32\RUNDLL32.EXE
F:\Programmer\PowerDVD\PDVDServ.exe
F:\Programmer\iTouch\iTouch.exe
C:\WINDOWS\System32\ISEAKA.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
F:\Programmer\WinTV\Ir.exe
C:\Programmer\VIA\RAID\raid_tool.exe
F:\Programmer\Office 2003\OFFICE11\ONENOTEM.EXE
F:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wuauclt.exe
c:\programmer\internet explorer\iexplore.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\DOCUME~1\THOMAS~1\LOKALE~1\Temp\mwavscan.com
C:\DOCUME~1\THOMAS~1\LOKALE~1\Temp\kavss.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Thomas og Charlotte\Skrivebord\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - f:\programmer\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [Smapp] C:\Programmer\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] F:\Programmer\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [zBrowser Launcher] F:\Programmer\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Windows Config] ISEAKA.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] F:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\RunOnce: [Windows Config] ISEAKA.EXE
O4 - Startup: Hurtig start af Microsoft Office OneNote 2003.lnk = F:\Programmer\Office 2003\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: AutoStart IR.lnk = F:\Programmer\WinTV\Ir.exe
O4 - Global Startup: Hurtig start af Microsoft Office OneNote 2003.lnk = F:\Programmer\Office 2003\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmer\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - F:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://F:\PROGRA~1\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
Håber der er en dygtig ekspert der kan hjælpe.
På forhånd tak!!!
