Bærbar infected med virus
Harjsa Herinde.Jeg har fået min fars bærbar med hjem da den ifølge ham skulle være inficeret af virus. Han har ikke haft installeret noget antivirus program før han koblede den på nettet, så det er nok der det er gået galt.
Jeg har lavet en hijackthis log, som jeg håber på i kan fortælle mig om er ren eller ej, da jeg selv har forsøgt at rense den.
Håber i kan hjælpe.
Loggen:
Logfile of HijackThis v1.99.1
Scan saved at 17:23:52, on 10/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\nusser\LOKALE~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\nusser\LOKALE~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {155BAF91-6B27-A330-2AC2-4532D8BCE638} - sysconf16.dll (file missing)
O2 - BHO: (no name) - {501E429B-EBDA-4EB9-BD82-E75FA8F66E65} - C:\WINDOWS\System32\ndlk.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {580F9B4B-E533-4B1C-B25D-2E23B3F6F1B7} - C:\WINDOWS\System32\msclq.dll
O2 - BHO: (no name) - {C39DD35E-00E8-44C2-AFA5-B917B8A524EA} - C:\WINDOWS\System32\msclq.dll
O3 - Toolbar: (no name) - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - (no file)
O4 - HKLM\..\Run: [sp2ctr] c:\windows\system32\sp2ctr.exe /nocomm
O4 - HKLM\..\Run: [sp2chk.exe] sp2chk.exe
O4 - HKLM\..\Run: [SYSTRAV] stuffmon.exe
O4 - HKLM\..\Run: [xxtoolbar] MNTP.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\nusser\LOKALE~1\Temp\se.dll,DllInstall
O4 - HKLM\..\Run: [msevnt] c:\windows\system32\msevnt.exe /nocomm
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WareOut] "C:\Programmer\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [bnui] DCC_send.exe
O4 - HKCU\..\Run: [RtlFindVal] trycrt.exe
O4 - HKCU\..\Run: [driver64] NukeSpan.exe
O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\MSMSGS.EXE" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.63.219.181.7
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://69.50.166.212/counter/new/x.chm::/update.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117050229108
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C5EEFC2-23D9-48AE-86C0-C16C8FF90147}: NameServer = 69.50.188.180,195.225.176.31
O17 - HKLM\System\CS1\Services\Tcpip\..\{4C5EEFC2-23D9-48AE-86C0-C16C8FF90147}: NameServer = 69.50.188.180,195.225.176.31
O18 - Filter: text/html - {BC585154-3FA5-45FC-9F11-2CC349A88C19} - C:\WINDOWS\System32\ndlk.dll
O18 - Filter: text/plain - {BC585154-3FA5-45FC-9F11-2CC349A88C19} - C:\WINDOWS\System32\ndlk.dll
