En ny logfil til hijackthis har jeg virus ?
Har lige fået hjælp til min logfil hvor der var virus.men det hele blev vist ikke fjernet første gang, da det samme problem viste sig igen dagen efter.
der er et program som bruger alt min cpu "SGBHP".exe
jeg for også en meddelse fra mit spyware prg at ... prøver at ændre start siden til C:\WINDOWS\system32\msblank.html
håber der nogle der kan hjælpe!
Min log ser sådan ud
Logfile of HijackThis v1.99.1
Scan saved at 16:56:56, on 03-09-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NPFSVICE.EXE
C:\WINDOWS\Explorer.EXE
E:\Internetprg\Norman internet control v5.50\bin\ZANDA.EXE
E:\musikprg\MusicMatch 7.1\mm_tray.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
E:\Internetprg\Norman internet control v5.50\bin\ZLH.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
E:\Musikprg\Ipod\itunes\iTunesHelper.exe
C:\WINDOWS\System32\popcorn72.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
E:\Internetprg\Norman internet control v5.50\bin\NJEEVES.EXE
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\nvcoas.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
E:\Musikprg\Ipod\bin\iPodService.exe
E:\Internetprg\SpywareGuard\sgmain.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\Nvc\BIN\nipsvc.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NVCSCHED.EXE
C:\Programmer\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
E:\Internetprg\SpywareGuard\sgbhp.exe
E:\Internetprg\Norman internet control v5.50\Nvc\BIN\NIP.EXE
E:\Internetprg\Norman internet control v5.50\Nvc\bin\cclaw.exe
E:\Internetprg\Norman internet control v5.50\Npf\BIN\npfmsg2.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Martin\Skrivebord\hjt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\System32\msblank.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - E:\Internetprg\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [MMTray] e:\musikprg\MusicMatch 7.1\mm_tray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Norman ZANDA] E:\Internetprg\Norman internet control v5.50\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [LaunchList] E:\Filmprg\Pinnacle PCTV deluxe 1.5\LaunchList.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Musikprg\Ipod\itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\popcorn72.exe rundll.dll,LoadMouseProfile
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: SpywareGuard.lnk = E:\Internetprg\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Kontorprg\MS Office 2000 pro\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://E:\KONTOR~1\MSOFFI~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030523/qtinstall.info.apple.com/drakken/dk/win/QuickTimeInstaller.exe
O16 - DPF: {5A447319-0EA2-447B-A063-A5F849B097D0} (ScanZillaLE Class) - https://www.stopzilla.com/scanner/binaries/SZScanLE.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094126590274
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EE2BF0A-5760-4BDC-82F5-0B2286211DC6}: NameServer = 195.95.218.34,85.255.112.7
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC13E763-6094-4336-B2EB-1DF159A5EDD4}: NameServer = 195.95.218.34,85.255.112.7
O17 - HKLM\System\CS2\Services\Tcpip\..\{8EE2BF0A-5760-4BDC-82F5-0B2286211DC6}: NameServer = 195.95.218.34,85.255.112.7
O17 - HKLM\System\CS3\Services\Tcpip\..\{8EE2BF0A-5760-4BDC-82F5-0B2286211DC6}: NameServer = 195.95.218.34,85.255.112.7
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Musikprg\Ipod\bin\iPodService.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - E:\Internetprg\Norman internet control v5.50\bin\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown owner - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown owner - E:\Internetprg\Norman internet control v5.50\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
