Avatar billede Slettet bruger
11. januar 2006 - 11:35 Der er 3 kommentarer og
1 løsning

Hijackthis log

Hej!

Er der nogen som kan tjekke denne HijackThis log?

------
Logfile of HijackThis v1.99.1
Scan saved at 11:33:47, on 11-01-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Programmer\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe
C:\Programmer\Panda Software\Panda Administrator 3\Scheduler\pavsched.exe
C:\Programmer\Panda Software\Panda Administrator 3\Pav_Agent\pagentwd.exe
C:\Programmer\Fælles filer\Panda Software\PavShld\pavprsrv.exe
C:\Programmer\Panda Software\AVTC\PavSrv51.exe
C:\Programmer\Panda Software\AVTC\PSKMsSvc.exe
C:\Programmer\Panda Software\AVTC\AVENGINE.EXE
C:\Programmer\Panda Software\AVTC\PsImSvc.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Panda Software\AVTC\WebProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Programmer\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Programmer\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
\HERA\netlogon\pcounter\WBALANCE.EXE
C:\Programmer\Panda Software\AVTC\ClShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\apifz32.exe
C:\Programmer\Panda Software\AVTC\SRVLOAD.EXE
C:\Programmer\Panda Software\AVTC\WebProxy.exe
C:\Documents and Settings\DELIU\Lokale indstillinger\Temporary Internet Files\Content.IE5\8VOZQNE7\hijackthis[1].exe
C:\Programmer\ewido anti-malware\ewidoguard.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\Programmer\ewido anti-malware\securitysuite.exe
C:\WINDOWS\javawx.exe
C:\Programmer\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {21C98520-4F7A-2066-F1EA-C39290DEFC87} - C:\WINDOWS\system32\atlsh.dll (file missing)
O2 - BHO: Class - {849E652D-E279-49D1-44C6-6C7123362280} - C:\WINDOWS\d3sr32.dll (file missing)
O2 - BHO: Class - {A963E875-BD23-4A38-7CEC-B5840D7C5CF0} - C:\WINDOWS\system32\addvr32.dll (file missing)
O2 - BHO: Class - {D4AC8A5F-A479-B347-A77F-9FA40E14594C} - C:\WINDOWS\system32\addww32.dll (file missing)
O2 - BHO: Class - {D909FA9D-7AE6-6B2A-B820-22D8EBB261F2} - C:\WINDOWS\atldt.dll (file missing)
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Programmer\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [appwo32.exe] C:\WINDOWS\appwo32.exe
O4 - HKLM\..\Run: [5.tmp] C:\DOCUME~1\DELIU\LOKALE~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [6.tmp] C:\DOCUME~1\DELIU\LOKALE~1\Temp\6.tmp.exe
O4 - HKLM\..\Run: [6.tmp.exe] C:\DOCUME~1\DELIU\LOKALE~1\Temp\6.tmp.exe
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\DELIU\LOKALE~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [netcl32.exe] C:\WINDOWS\system32\netcl32.exe
O4 - HKLM\..\Run: [syshm32.exe] C:\WINDOWS\syshm32.exe
O4 - HKLM\..\Run: [ieeh.exe] C:\WINDOWS\system32\ieeh.exe
O4 - HKLM\..\Run: [nthp.exe] C:\WINDOWS\nthp.exe
O4 - HKLM\..\Run: [sysjt32.exe] C:\WINDOWS\sysjt32.exe
O4 - HKLM\..\Run: [ntio32.exe] C:\WINDOWS\system32\ntio32.exe
O4 - HKLM\..\Run: [addcr.exe] C:\WINDOWS\addcr.exe
O4 - HKLM\..\Run: [ntxr.exe] C:\WINDOWS\ntxr.exe
O4 - HKLM\..\Run: [netix.exe] C:\WINDOWS\system32\netix.exe
O4 - HKLM\..\Run: [javarn.exe] C:\WINDOWS\javarn.exe
O4 - HKLM\..\Run: [addqg32.exe] C:\WINDOWS\addqg32.exe
O4 - HKLM\..\Run: [crng.exe] C:\WINDOWS\crng.exe
O4 - HKLM\..\Run: [iefp.exe] C:\WINDOWS\iefp.exe
O4 - HKLM\..\Run: [addgv32.exe] C:\WINDOWS\addgv32.exe
O4 - HKLM\..\Run: [javawe.exe] C:\WINDOWS\system32\javawe.exe
O4 - HKLM\..\Run: [apiqn.exe] C:\WINDOWS\system32\apiqn.exe
O4 - HKLM\..\Run: [iedr.exe] C:\WINDOWS\system32\iedr.exe
O4 - HKLM\..\Run: [nthm32.exe] C:\WINDOWS\nthm32.exe
O4 - HKLM\..\Run: [appql32.exe] C:\WINDOWS\appql32.exe
O4 - HKLM\..\Run: [iezv.exe] C:\WINDOWS\system32\iezv.exe
O4 - HKLM\..\Run: [winjn.exe] C:\WINDOWS\winjn.exe
O4 - HKLM\..\Run: [mspu.exe] C:\WINDOWS\system32\mspu.exe
O4 - HKLM\..\Run: [apiog.exe] C:\WINDOWS\apiog.exe
O4 - HKLM\..\Run: [addrp.exe] C:\WINDOWS\system32\addrp.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmer\Panda Software\AVTC\ClShield.exe"
O4 - HKLM\..\Run: [cril32.exe] C:\WINDOWS\system32\cril32.exe
O4 - HKLM\..\Run: [winpn32.exe] C:\WINDOWS\winpn32.exe
O4 - HKLM\..\Run: [winwk32.exe] C:\WINDOWS\system32\winwk32.exe
O4 - HKLM\..\Run: [javalk.exe] C:\WINDOWS\system32\javalk.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: @C:\Programmer\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Programmer\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/dk/win/QuickTimeFullInstaller.exe
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = fmts.lan
O17 - HKLM\Software\..\Telephony: DomainName = fmts.lan
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = fmts.lan
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = fmts.lan
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Panda AdminSecure Communications Agent (PAVAGENTE) - Panda Software - C:\Programmer\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe
O23 - Service: Panda AdminSecure Scheduler (PavAtScheduler) - Panda Software - C:\Programmer\Panda Software\Panda Administrator 3\Scheduler\pavsched.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Programmer\Fælles filer\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda Antivirus Report Service (PavReport) - Panda Software - C:\Programmer\Panda Software\Panda Administrator 3\PavReport\PavReport.exe
O23 - Service: Panda Antivirus Service (PavSrv) - Panda Software - C:\Programmer\Panda Software\AVTC\PavSrv51.exe
O23 - Service: Panda AntiSpam Engine (PMShellSrv) - PANDA SOFTWARE - C:\Programmer\Panda Software\AVTC\PSKMsSvc.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Panda IManager Service (PsImSvc) - Panda Software Internacional - C:\Programmer\Panda Software\AVTC\PsImSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
Avatar billede kalp Novice
11. januar 2006 - 11:40 #1
det gør jeg da lige
Avatar billede kalp Novice
11. januar 2006 - 11:52 #2
Download og gem denne scanner på skrivebordet. (Vi skal bruge den senere)
http://www.spywareinfo.dk/download/mwav.exe

Download Ewido (Installer og opdater programmet, men vent med et scanne til jeg siger til!)
http://shop.element5.com/product.html?productid=531168

Genstart i Fejlsikret tilstand ved at taste F8 under opstart.

Lav en fuld scan med Ewido nu!

Slet indholdet af denne mappe

C:\DOCUME~1\DELIU\LOKALE~1\Temp\

Kør HijackThis, scan og sæt et flueben ud for disse linjer - luk øvrige programvinduer. Dobbelt tjeck alt kom med!. Klik herefter "Fix checked" i hijackthis:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcvud.dll/sp.html#88449%resultposition.net
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {21C98520-4F7A-2066-F1EA-C39290DEFC87} - C:\WINDOWS\system32\atlsh.dll (file missing)   
O2 - BHO: Class - {849E652D-E279-49D1-44C6-6C7123362280} - C:\WINDOWS\d3sr32.dll (file missing)
O2 - BHO: Class - {A963E875-BD23-4A38-7CEC-B5840D7C5CF0} - C:\WINDOWS\system32\addvr32.dll (file missing)
O2 - BHO: Class - {D4AC8A5F-A479-B347-A77F-9FA40E14594C} - C:\WINDOWS\system32\addww32.dll (file missing) 
O2 - BHO: Class - {D909FA9D-7AE6-6B2A-B820-22D8EBB261F2} - C:\WINDOWS\atldt.dll (file missing)
O4 - HKLM\..\Run: [appwo32.exe] C:\WINDOWS\appwo32.exe
O4 - HKLM\..\Run: [5.tmp] C:\DOCUME~1\DELIU\LOKALE~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [6.tmp] C:\DOCUME~1\DELIU\LOKALE~1\Temp\6.tmp.exe   
O4 - HKLM\..\Run: [6.tmp.exe] C:\DOCUME~1\DELIU\LOKALE~1\Temp\6.tmp.exe   
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\DELIU\LOKALE~1\Temp\5.tmp.exe   
O4 - HKLM\..\Run: [netcl32.exe] C:\WINDOWS\system32\netcl32.exe ´
O4 - HKLM\..\Run: [syshm32.exe] C:\WINDOWS\syshm32.exe
O4 - HKLM\..\Run: [ieeh.exe] C:\WINDOWS\system32\ieeh.exe
O4 - HKLM\..\Run: [nthp.exe] C:\WINDOWS\nthp.exe
O4 - HKLM\..\Run: [sysjt32.exe] C:\WINDOWS\sysjt32.exe
O4 - HKLM\..\Run: [ntio32.exe] C:\WINDOWS\system32\ntio32.exe
O4 - HKLM\..\Run: [addcr.exe] C:\WINDOWS\addcr.exe
O4 - HKLM\..\Run: [ntxr.exe] C:\WINDOWS\ntxr.exe
O4 - HKLM\..\Run: [netix.exe] C:\WINDOWS\system32\netix.exe
O4 - HKLM\..\Run: [javarn.exe] C:\WINDOWS\javarn.exe
O4 - HKLM\..\Run: [addqg32.exe] C:\WINDOWS\addqg32.exe
O4 - HKLM\..\Run: [crng.exe] C:\WINDOWS\crng.exe
O4 - HKLM\..\Run: [iefp.exe] C:\WINDOWS\iefp.exe
O4 - HKLM\..\Run: [addgv32.exe] C:\WINDOWS\addgv32.exe
O4 - HKLM\..\Run: [javawe.exe] C:\WINDOWS\system32\javawe.exe
O4 - HKLM\..\Run: [apiqn.exe] C:\WINDOWS\system32\apiqn.exe
O4 - HKLM\..\Run: [iedr.exe] C:\WINDOWS\system32\iedr.exe
O4 - HKLM\..\Run: [nthm32.exe] C:\WINDOWS\nthm32.exe
O4 - HKLM\..\Run: [appql32.exe] C:\WINDOWS\appql32.exe
O4 - HKLM\..\Run: [iezv.exe] C:\WINDOWS\system32\iezv.exe
O4 - HKLM\..\Run: [winjn.exe] C:\WINDOWS\winjn.exe
O4 - HKLM\..\Run: [mspu.exe] C:\WINDOWS\system32\mspu.exe
O4 - HKLM\..\Run: [apiog.exe] C:\WINDOWS\apiog.exe
O4 - HKLM\..\Run: [addrp.exe] C:\WINDOWS\system32\addrp.exe
O4 - HKLM\..\Run: [cril32.exe] C:\WINDOWS\system32\cril32.exe
O4 - HKLM\..\Run: [winpn32.exe] C:\WINDOWS\winpn32.exe
O4 - HKLM\..\Run: [winwk32.exe] C:\WINDOWS\system32\winwk32.exe
O4 - HKLM\..\Run: [javalk.exe] C:\WINDOWS\system32\javalk.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe

------------------------------------------------------------------------------------

Højreklik på windows start knappen (helt nede i venstre hjørne af din skærm) og vælge "Stifinder", klik på Funktioner->Mappeindstillinger->Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

Find og slet (Kig godt efter!!.. Det du ikke finder har hijackthis muligvis selv kunne slette!)

Filerne

C:\WINDOWS\apifz32.exe
C:\WINDOWS\system32\netcl32.exe
C:\WINDOWS\system32\atlsh.dll
C:\WINDOWS\appwo32.exe
C:\WINDOWS\atldt.dll
C:\WINDOWS\system32\addww32.dll
C:\WINDOWS\system32\addvr32.dll
C:\WINDOWS\d3sr32.dll
C:\WINDOWS\syshm32.exe
C:\WINDOWS\system32\ieeh.exe
C:\WINDOWS\nthp.exe
C:\WINDOWS\system32\jcvud.dll
C:\WINDOWS\sysjt32.exe
C:\WINDOWS\system32\ntio32.exe
C:\WINDOWS\addcr.exe
C:\WINDOWS\ntxr.exe
C:\WINDOWS\system32\netix.exe
C:\WINDOWS\javarn.exe
C:\WINDOWS\addqg32.exe
C:\winstall.exe
C:\WINDOWS\crng.exe
C:\WINDOWS\iefp.exe
C:\WINDOWS\addgv32.exe
C:\WINDOWS\system32\javawe.exe
C:\WINDOWS\system32\apiqn.exe
C:\WINDOWS\system32\iedr.exe
C:\WINDOWS\nthm32.exe
C:\WINDOWS\appql32.exe
C:\WINDOWS\system32\iezv.exe
C:\WINDOWS\winjn.exe
C:\WINDOWS\system32\mspu.exe
C:\WINDOWS\apiog.exe
C:\WINDOWS\system32\addrp.exe
C:\WINDOWS\system32\cril32.exe
C:\WINDOWS\winpn32.exe
C:\WINDOWS\system32\winwk32.exe
C:\WINDOWS\system32\javalk.exe

Gå herefter i Start -> Programmer -> Tilbehør -> Systemværktøjer -> Diskoprydning og slet temp-filer, temporary internet files og papirkurv.

Klik på mwav.exe som du hentede, programmet pakker sig selv ud og starter.
Sæt flueben i følgende:
Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende:
All local drives og Scan all files

Genstart normalt og kopir en ny hijackthis log herind så jeg kan se om vi fik fjernet det hele eller om noget skulle være blevet overset:)
Avatar billede Slettet bruger
11. januar 2006 - 12:22 #3
Logfile of HijackThis v1.99.1
Scan saved at 12:21:34, on 11-01-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Programmer\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe
C:\Programmer\Panda Software\Panda Administrator 3\Scheduler\pavsched.exe
C:\Programmer\Panda Software\Panda Administrator 3\Pav_Agent\pagentwd.exe
C:\Programmer\Fælles filer\Panda Software\PavShld\pavprsrv.exe
C:\Programmer\Panda Software\AVTC\PavSrv51.exe
C:\Programmer\Panda Software\AVTC\PSKMsSvc.exe
C:\Programmer\Panda Software\AVTC\AVENGINE.EXE
C:\Programmer\Panda Software\AVTC\PsImSvc.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Panda Software\AVTC\WebProxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Programmer\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\wuauclt.exe
\HERA\netlogon\pcounter\WBALANCE.EXE
C:\Programmer\Panda Software\AVTC\ClShield.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Programmer\Panda Software\AVTC\SRVLOAD.EXE
C:\Programmer\Panda Software\AVTC\WebProxy.exe
C:\Documents and Settings\DELIU\Lokale indstillinger\Temporary Internet Files\Content.IE5\8VOZQNE7\hijackthis[1].exe
C:\Programmer\ewido anti-malware\ewidoguard.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\Programmer\ewido anti-malware\securitysuite.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Panda Software\Panda Administrator 3\PavReport\PavReport.exe
C:\WINDOWS\javawx.exe
C:\Programmer\Kaspersky\mwavscan.com
C:\Programmer\Kaspersky\kavss.exe
C:\WINDOWS\netja32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {7347ADCC-D3E9-4012-5AD0-05413D9B9276} - C:\WINDOWS\sysqv32.dll
O4 - HKLM\..\Run: [javawx.exe] C:\WINDOWS\javawx.exe
O4 - HKLM\..\RunOnce: [netja32.exe] C:\WINDOWS\netja32.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: @C:\Programmer\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Programmer\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/dk/win/QuickTimeFullInstaller.exe
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = fmts.lan
O17 - HKLM\Software\..\Telephony: DomainName = fmts.lan
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = fmts.lan
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = fmts.lan
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Programmer\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Panda AdminSecure Communications Agent (PAVAGENTE) - Panda Software - C:\Programmer\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe
O23 - Service: Panda AdminSecure Scheduler (PavAtScheduler) - Panda Software - C:\Programmer\Panda Software\Panda Administrator 3\Scheduler\pavsched.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Programmer\Fælles filer\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda Antivirus Report Service (PavReport) - Panda Software - C:\Programmer\Panda Software\Panda Administrator 3\PavReport\PavReport.exe
O23 - Service: Panda Antivirus Service (PavSrv) - Panda Software - C:\Programmer\Panda Software\AVTC\PavSrv51.exe
O23 - Service: Panda AntiSpam Engine (PMShellSrv) - PANDA SOFTWARE - C:\Programmer\Panda Software\AVTC\PSKMsSvc.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Panda IManager Service (PsImSvc) - Panda Software Internacional - C:\Programmer\Panda Software\AVTC\PsImSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
Avatar billede kalp Novice
11. januar 2006 - 12:48 #4
Download og gem denne scanner på skrivebordet. Du skal ikke aktivere den endnu.
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Genstart i Fejlsikret tilstand ved at taste F8 under opstart.

Start drweb-cureit.exe nu.

Kør HijackThis, scan og sæt et flueben ud for disse linjer - luk øvrige programvinduer. Dobbelt tjeck alt kom med!. Klik herefter "Fix checked" i hijackthis:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\omhck.dll/sp.html#88449%resultposition.net
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {7347ADCC-D3E9-4012-5AD0-05413D9B9276} - C:\WINDOWS\sysqv32.dll
O4 - HKLM\..\Run: [javawx.exe] C:\WINDOWS\javawx.exe
O4 - HKLM\..\RunOnce: [netja32.exe] C:\WINDOWS\netja32.exe

Find og slet (Kig godt efter!!.. Det du ikke finder har hijackthis muligvis selv kunne slette!)

Filerne

C:\WINDOWS\javawx.exe
C:\WINDOWS\netja32.exe
C:\WINDOWS\omhck.dll
C:\WINDOWS\sysqv32.dll

Genstart normalt og kopir en ny hijackthis log herind så jeg kan se om vi fik fjernet det hele eller om noget skulle være blevet overset:)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester

IT-JOB

Netcompany A/S

Test Consultant

Forsvarsministeriets Materiel- og Indkøbsstyrelse

Cyberdivisionen søger IT-supporter til lokal IT i Slagelse

Csis Security Group A/S

Sales Executive

Nextway Software A/S

Product Configuration Specialist