mindre egenkapital

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Sikkerhed

Register


 Default 

Jeg tror, jeg har en virus




Reply
 
Thread Tools
  #1  
Old 31. marts 2008, 10:52
Medlem Gruppen
 
Default Jeg tror, jeg har en virus

OK, så jeg synes at have samlet op eller anden form for malware, der har slået den mulighed for at ændre automatiske opdateringer, der forlader dem permanantly slukket.

Log af HJT:

Logfile af Trend Micro HijackThis v2.0.2
Scan gemt kl 18:45:43 den 31/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Kørende processer:
C: \ WINDOWS.NEW \ System32 \ smss.exe
C: \ WINDOWS.NEW \ system32 \ Winlogon.exe
C: \ WINDOWS.NEW \ system32 \ Services.exe
C: \ WINDOWS.NEW \ system32 \ Lsass.exe
C: \ WINDOWS.NEW \ system32 \ Svchost.exe
C: \ Programmer \ Windows Defender \ MsMpEng.exe
C: \ WINDOWS.NEW \ System32 \ Svchost.exe
C: \ Programmer \ forude \ inCD \ InCD \ InCDsrv.exe
C: \ WINDOWS.NEW \ system32 \ Svchost.exe
C: \ Programmer \ Common Files \ Symantec Shared \ ccSvcHst.exe
C: \ Programmer \ Common Files \ Symantec Shared \ ccProxy.exe
C: \ Programmer \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe
C: \ WINDOWS.NEW \ system32 \ Spoolsv.exe
C: \ Programmer \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Programmer \ Bonjour \ mDNSResponder.exe
C: \ WINDOWS.NEW \ System32 \ Svchost.exe
C: \ Programmer \ Common Files \ Microsoft Shared \ VS7Debug \ mdm.exe
C: \ WINDOWS.NEW \ system32 \ nvsvc32.exe
C: \ WINDOWS.NEW \ System32 \ HPZipm12.exe
C: \ Programmer \ Dantz \ bakspejlet \ retrorun.exe
C: \ PROGRA ~ 1 \ Dantz \ RETROS ~ 1 \ wdsvc.exe
C: \ WINDOWS.NEW \ System32 \ Svchost.exe
C: \ Programmer \ Microsoft \ UPHCS \ uphclean.exe
C: \ WINDOWS.NEW \ System32 \ Ltmoh.exe
C: \ WINDOWS.NEW \ system32 \ taskswitch.exe
C: \ Programmer \ lg_fwupdate \ fwupdate.exe
C: \ Programmer \ SiteAdvisor \ 6021 \ SiteAdv.exe
C: \ Programmer \ Windows Defender \ MSASCui.exe
C: \ Programmer \ forude \ inCD \ InCD \ InCD.exe
C: \ Programmer \ Common Files \ Symantec Shared \ ccSvcHst.exe
C: \ Programmer \ Java \ jre1.6.0_05 \ bin \ jusched.exe
C: \ Programmer \ iTunes \ iTunesHelper.exe
C: \ Programmer \ Unlocker \ UnlockerAssistant.exe
C: \ WINDOWS.NEW \ system32 \ Ctfmon.exe
C: \ Programmer \ Spybot - Search & Destroy \ TeaTimer.exe
C: \ Programmer \ Windows Media Player \ WMPNSCFG.exe
C: \ Programmer \ NETGEAR \ GA311 \ GA311.exe
C: \ Programmer \ NETGEAR \ WPN111 \ wpn111.exe
C: \ Programmer \ Nikon \ PictureProject \ NkbMonitor.exe
C: \ Programmer \ iPod \ bin \ iPodService.exe
C: \ WINDOWS.NEW \ explorer.exe
C: \ Programmer \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
C: \ WINDOWS.NEW \ system32 \ wuauclt.exe
C: \ Programmer \ Common Files \ Microsoft Shared \ Windows Live \ WLLoginProxy.exe
C: \ Programmer \ Trend Micro \ HijackThis \ HijackThis.exe
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.google.co.uk/ig?hl=en
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Settings, ProxyOverride = *. lokale
O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Programmer \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: (no name) - (089FD14D-132B-48FC-8861-0048AE113215) - C: \ Programmer \ SiteAdvisor \ 6066 \ SiteAdv.dll
O2 - BHO: RealPlayer Download og Record Plugin for Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Programmer \ Real \ RealPlayer \ rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - (602ADB0E-4AFF-4217-8AA1-95DAC4DFA408) - C: \ Programmer \ Common Files \ Symantec Shared \ coShared \ Browser \ 2.0 \ coIEPlg.dll
O2 - BHO: Symantec Tyverisikrings Forebyggelse - (6D53EC84-6AAE-4787-AEEE-F4628F01010C) - C: \ PROGRA ~ 1 \ FÆLLES ~ 1 \ SYMANT ~ 1 \ IDS \ IPSBHO.dll
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Programmer \ Java \ jre1.6.0_05 \ bin \ ssv.dll
O2 - BHO: FoxyTunes Toolbar Helper - (784D8FBC-4165-4D88-90FB-62907ACDD045) - C: \ Programmer \ FoxyTunes \ ForInternetExplorer \ komponenter \ IE \ FoxyTunesForIE.dll
O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Programmer \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - c: \ program files \ google \ googletoolbar3.dll
O2 - BHO: Windows Live Toolbar Helper - (BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Programmer \ Windows Live Toolbar \ msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - (0BF43445-2F28-4351-9252-17FE6E806AA0) - C: \ Programmer \ SiteAdvisor \ 6066 \ SiteAdv.dll
O3 - Toolbar: Gotuit Toolbar - (3f59a812-9c30-4ecd-938d-dd73e7c6497d) - (no file)
O3 - Toolbar: FoxyTunes Toolbar - (1D1901C3-F72A-46F3-9DBB-0AAA0DEEF6DF) - C: \ Programmer \ FoxyTunes \ ForInternetExplorer \ komponenter \ IE \ FoxyTunesForIE.dll
O3 - Toolbar: & Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - c: \ program files \ google \ googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - (BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Programmer \ Windows Live Toolbar \ msntb.dll
O3 - Toolbar: Vis Norton Toolbar - (7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA) - C: \ Programmer \ Common Files \ Symantec Shared \ coShared \ Browser \ 2.0 \ CoIEPlg.dll
O4 - HKLM \ .. \ Run: [LtMoh] C: \ WINDOWS.NEW \ System32 \ Ltmoh.exe
O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS.NEW \ system32 \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [CoolSwitch] C: \ WINDOWS.NEW \ system32 \ taskswitch.exe
O4 - HKLM \ .. \ Run: [LGODDFU] "C: \ Programmer \ lg_fwupdate \ fwupdate.exe" blrun
O4 - HKLM \ .. \ Run: [SiteAdvisor] "C: \ Programmer \ SiteAdvisor \ 6021 \ SiteAdv.exe"
O4 - HKLM \ .. \ Run: [Windows Defender] "C: \ Programmer \ Windows Defender \ MSASCui.exe"-hide
O4 - HKLM \ .. \ Run: [InCD] "C: \ Programmer \ forude \ inCD \ InCD \ InCD.exe"
O4 - HKLM \ .. \ Run: [ccApp] "C: \ Programmer \ Common Files \ Symantec Shared \ ccApp.exe"
O4 - HKLM \ .. \ Run: [osCheck] "C: \ Programmer \ Norton Internet Security \ osCheck.exe"
O4 - HKLM \ .. \ Run: [NvCplDaemon] rundll32.exe C: \ WINDOWS.NEW \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ Run: [NvMediaCenter] rundll32.exe C: \ WINDOWS.NEW \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Programmer \ Java \ jre1.6.0_05 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Programmer \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Programmer \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [UnlockerAssistant] "C: \ Programmer \ Unlocker \ UnlockerAssistant.exe"
O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ system32 \ Ctfmon.exe
O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Programmer \ Spybot - Search & Destroy \ TeaTimer.exe
O4 - HKCU \ .. \ Run: [WMPNSCFG] C: \ Programmer \ Windows Media Player \ WMPNSCFG.exe
O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ Ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ Ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ Ctfmon.exe (User 'SYSTEM')
O4 - HKUS \ S-1-5-18 \ .. \ RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS.NEW \ System32 \ Ctfmon.exe (User 'Default user')
O4 - HKUS \. DEFAULT \ .. \ RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: GA311 Smart Wizard Utility.lnk = C: \ Programmer \ NETGEAR \ GA311 \ GA311.exe
O4 - Global Startup: HP instant support.lnk = C: \ Programmer \ Hewlett-Packard \ HP Instant Support DI \ Bin \ matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C: \ Programmer \ Microsoft Office \ Office10 \ OSA.EXE
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk =?
O4 - Global Startup: NkbMonitor.exe.lnk = C: \ Programmer \ Nikon \ PictureProject \ NkbMonitor.exe
O8 - Extra sammenhæng menupunktet: & ieSpell Options - res: / / C: \ Programmer \ ieSpell \ iespell.dll / SPELLOPTION.HTM
O8 - Extra sammenhæng menupunktet: & Windows Live Search - res: / / C: \ Programmer \ Windows Live Toolbar \ msntb.dll / search.htm
O8 - Extra sammenhæng menupunkt: Check & Spelling - res: / / C: \ Programmer \ ieSpell \ iespell.dll / SPELLCHECK.HTM
O8 - Extra sammenhæng menupunkt: Download alle med Free Download Manager -- file: / / C: \ Programmer Files \ Free Download Manager \ dlall.htm
O8 - Extra sammenhæng menupunkt: Download valgte med Free Download Manager -- file: / / C: \ Programmer Files \ Free Download Manager \ dlselected.htm
O8 - Extra sammenhæng menupunkt: Download med Free Download Manager -- file: / / C: \ Programmer Files \ Free Download Manager \ dllink.htm
O8 - Extra sammenhæng menupunktet: E & ksporter til Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ mikroer ~ 2 \ Office10 \ EXCEL.EXE/3000
O8 - Extra sammenhæng menupunkt: opslag på Merriam Webster -- file: / / C: \ Programmer Files \ ieSpell \ Merriam Webster.HTM
O8 - Extra sammenhæng menupunkt: opslag på Wikipedia -- file: / / C: \ Programmer Files \ ieSpell \ wikipedia.HTM
O9 - Ekstra knap: Video Detect - (0028E570-E86D-4ceb-A108-76158C18DEF3) - C: \ Programmer \ videodetect \ videodetect.dll
O9 - Extra 'Tools' MENUITEM: Video Detect - (0028E570-E86D-4ceb-A108-76158C18DEF3) - C: \ Programmer \ videodetect \ videodetect.dll
O9 - Extra knappen: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Programmer \ Java \ jre1.6.0_05 \ bin \ ssv.dll
O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Programmer \ Java \ jre1.6.0_05 \ bin \ ssv.dll
O9 - Ekstra knap: ieSpell - (0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8) - C: \ Programmer \ ieSpell \ iespell.dll
O9 - Extra 'Tools' MENUITEM: ieSpell - (0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8) - C: \ Programmer \ ieSpell \ iespell.dll
O9 - Extra knappen: (no name) - (1606D6F9-9D3B-4aea-A025-ED5B2FD488E7) - C: \ Programmer \ ieSpell \ iespell.dll
O9 - Extra 'Tools' MENUITEM: ieSpell Options - (1606D6F9-9D3B-4aea-A025-ED5B2FD488E7) - C: \ Programmer \ ieSpell \ iespell.dll
O9 - Ekstra knap: dvs billede Downloader - (8F05069A-4BC5-4175-8B19-76A413464C90) - C: \ PROGRA ~ 1 \ IE_PIC ~ 1 \ \ iedownloader.exe
O9 - Ekstra knap: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) - res: / / C: \ Programmer \ BitComet \ tools \ BitCometBHO_1.2.1.2.dll/206 (filen mangler)
O9 - Extra knappen: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O9 - Extra 'Tools' MENUITEM: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O9 - Extra knappen: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS.NEW \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS.NEW \ Network Diagnostic \ xpnetdiag.exe
O9 - Ekstra knap: @ C: \ Programmer \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Programmer \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' MENUITEM: @ C: \ Programmer \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Programmer \ Messenger \ msmsgs.exe
O10 - Ukendt fil i Winsock LSP: c: \ windows.new \ system32 \ nwprovau.dll
O16 - DPF: (01010E00-5E80-11D8-9E86-0007E96C65AE) (SupportSoft SmartIssue) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: (01012101-5E80-11D8-9E86-0007E96C65AE) (SupportSoft Script Runner Class) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: (05D44720-58E3-49E6-BDF6-D00330E511D3) (StagingUI Object) -- http://zone.msn.com/binFrameWork/v10...I.cab46479.cab
O16 - DPF: (0742B9EF-8C83-41CA-BFBA-830A59E23533) (Microsoft Data Collection Control) -- https: / / support.microsoft.com / OAS / ActiveX / MSDcode.cab
O16 - DPF: (1F2F4C9E-6F09-47BC-970D-3C54734667FE) -- http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: (2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B) (DownloadManager Control) -- http://dlmanager.akamaitools.com.edg...ex-2.0.6.0.cab
O16 - DPF: (2BC66F54-93A8-11D3-BEB6-00105AA9B6AE) (Symantec AntiVirus scanner) -- http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: (2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5) (Microsoft Data Collection Control) -- https: / / support.microsoft.com / OAS / ActiveX / odc.cab
O16 - DPF: (3451DEDE-631F-421C-8127-FD793AFC6CC8) (ActiveDataInfo klasse) -- http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: (34F12AFD-E9B5-492A-85D2-40FA4535BE83) (AxProdInfoCtl klasse) -- http://www.symantec.com/techsupp/act...a/nprdtinf.cab
O16 - DPF: (3BB54395-5982-4788-8AF4-B5388FFDD0D8) -- http://zone.msn.com/BinFrameWork/v10...y.cab32846.cab
O16 - DPF: (44990200-3C9D-426D-81DF-AAB636FA4345) (Symantec SmartIssue) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: (44990301-3C9D-426D-81DF-AAB636FA4345) (Symantec Script Runner Class) -- http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: (5736C456-EA94-4AAC-BB08-917ABDD035B3) -- http://zone.msn.com/binframework/v10...t.cab32846.cab
O16 - DPF: (5ED80217-570B-4DA9-BF44-BE107C0EC166) (Windows Live Safety Center Base Module) -- http://cdn.scan.onecare.live.com/res...scbase8300.cab
O16 - DPF: (644E432F-49D3-41A1-8DD5-E099162EEEC5) (Symantec RuFSI Utility Class) -- http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: (67A5F8DC-1A4B-4D66-9F24-A704AD929EEE) (System Requirements Lab) -- http://www.nvidia.com/content/Driver...sysreqlab2.cab
O16 - DPF: (6A344D34-5231-452A-8A57-D064AC9B7862) (Symantec Download Manager) -- https: / / webdl.symantec.com / ActiveX / symdlmgr.cab
O16 - DPF: (6B75345B-AA36-438A-BBE6-4078B4C6984D) (HpProductDetection klasse) -- http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
O16 - DPF: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) (MUWebControl Class) -- http://update.microsoft.com/microsof...?1125163370105
O16 - DPF: (AB86CE53-AC9F-449F-9399-D8ABCA09EC09) -- https: / / h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
O16 - DPF: (B3E22EA2-A579-11D2-847A-00C04F7605B6) -- file: / / E: \ 0000C5DD \ wpxfp01a \ Common \ e. .. kode \ odweb.cab
O16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (ZoneIntro Class) -- http://cdn2.zone.msn.com/binFramewor...o.cab34246.cab
O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab
O16 - DPF: (CE28D5D2-60CF-4C7D-9FE8-0F47A3308078) (ActiveDataInfo klasse) -- http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: (D1E7CBDA-E60E-4970-A01C-37301EF7BF98) (Measurement Services Client v.3.11) -- http://advisor.futuremark.com/global/msc311.cab
O16 - DPF: (DA2AA6CF-5C7A-4B71-BC3B-C771BB369937) (StadiumProxy klasse) -- http://zone.msn.com/binframework/v10...y.cab41227.cab
O16 - DPF: (E7D2588A-7FB5-47DC-8830-832605661009) (Live Collaboration) -- http://livenj01.rightnowtech.com/556.../java/RntX.cab
O16 - DPF: (E8F628B5-259A-4734-97EE-BA914D7BE941) (Driver Agent ActiveX Control) -- http://plugin.driveragent.com/files/driveragent.cab
O16 - DPF: (EB387D2F-E27B-4D36-979E-847D1036C65D) (QDiagHUpdateObj klasse) -- http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O16 - DPF: (FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1) (DownloadManager Control) -- http://dlm.tools.akamai.com/dlmanage...ex-2.2.1.6.cab
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ PROGRA ~ 1 \ FÆLLES ~ 1 \ Skype \ SKYPE4 ~ 1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C: \ Programmer \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C: \ Programmer \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C: \ Programmer \ Bonjour \ mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Programmer \ Common Files \ Symantec Shared \ ccSvcHst.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C: \ Programmer \ Common Files \ Symantec Shared \ ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Programmer \ Common Files \ Symantec Shared \ ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C: \ Programmer \ Common Files \ Symantec Shared \ ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C: \ Programmer \ Common Files \ Symantec Shared \ VAScanner \ comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C: \ Programmer \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe
O23 - Service: InstallDriver Tabel Manager (IDriverT) - Macrovision Corporation - C: \ Programmer \ Common Files \ InstallShield \ Driver \ 1150 \ Intel 32 \ IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C: \ Programmer \ forude \ inCD \ InCD \ InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C: \ Programmer \ iPod \ bin \ iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C: \ Programmer \ Symantec \ LiveUpdate \ LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C: \ Programmer \ Common Files \ Symantec Shared \ ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS.NEW \ system32 \ nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C: \ WINDOWS.NEW \ System32 \ HPZipm12.exe
O23 - Service: bakspejlet Launcher (RetroLauncher) - Dantz Development Corporation - C: \ Programmer \ Dantz \ bakspejlet \ retrorun.exe
O23 - Service: bakspejlet WD Service (RetroWDSvc) - Dantz Development Corporation - C: \ PROGRA ~ 1 \ Dantz \ RETROS ~ 1 \ wdsvc.exe
O23 - Service: Symantec Core LC - Unknown ejer - C: \ Programmer \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
--
End of file - 17835 bytes
  #2  
Old 31. marts 2008, 10:54
Bandlyst Gruppen
 
Default Jeg tror, jeg har en virus

WAW nu Thats en mursten af tekst
__________________

Mit system: SAALEDES MACHINE!

Processor (s):
Intel Core 2 Quad Q6600 Pro "Energi
Bundkort:
Asus Maximus Extreme Intel X38
RAM Hukommelse:
OCZ 4GB (2x2GB) PC2-8000C5
Grafikkort (r):
EVGA GeForce 8800 Ultra SuperClocke
Lydkort:
Creative SB0670 X-FI PCI SOUND Blas
Harddisk (e):
Seagate Barracuda ES.2 1TB SATA-II
Optisk drev (r):
Sag / PSU:
Dell XPS
Køling:
Arctic Køling Freezer 64 Pro varmefylder
Network / Internet:
AOL
Monitor (s):
19 "LCD 1080/1920p
Operating System (s):
xp
  #3  
Old 31. marts 2008, 11:04
Redaktør Gruppen
 
Default Jeg tror, jeg har en virus

Jeg kan ikke se nogen malware i loggen.

Har Hijackthis fastsætte disse poster.
  • O3 - Toolbar: Gotuit Toolbar - (3f59a812-9c30-4ecd-938d-dd73e7c6497d) - (no file)
  • O9 - Ekstra knap: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) - res: / / C: \ Programmer \ BitComet \ tools \ BitCometBHO_1.2.1.2.dll/206 (filen mangler)
  • O16 - DPF: (FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1) (DownloadManager Control) -- http://dlm.tools.akamai.com/dlmanage...ex-2.2.1.6.cab
Prøv her Hjælp med Windows Updates

Lad mig vide, hvordan du får den, kan vi altid køre flere scanninger for at sikre sig.
__________________

  #4  
Old 31. marts 2008, 11:23
Medlem Gruppen
 
Default Jeg tror, jeg har en virus

Jeg kunne ikke finde noget der, der hjælper ... tak for linket, selv om.

Jeg har vedhæftet et skærmbillede, der viser bare, hvad jeg mener - håber det er i brug.
Attached Thumbnails
I think I Have a Virus-untitled.jpg  
  #5  
Old 31. marts 2008, 11:29
Redaktør Gruppen
 
Default Jeg tror, jeg har en virus

Er du logget på som administrator?
__________________

  #6  
Old 31. marts 2008, 11:33
Medlem Gruppen
 
Default Jeg tror, jeg har en virus

Yup .. det var det første, jeg kontrolleres, tænker, at det havde fået ændret. Det er det samme på den anden admin konto, så godt.
  #7  
Old 31. marts 2008, 11:43
Redaktør Gruppen
 
Default Jeg tror, jeg har en virus

Har du nogen sikkerhed programmer installeret, der kan få det slået fra. xp-Antispy?

Du kan gå til den registreringsdatabasenøgle og ændre standardværdien og genaktivere dem manuelt.

Gå til Start> Kør type regedit og klik OK
Find nøglen:
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ au
I højre rude, skal du kigge efter en nøgle kaldes noautoupdate
Ændre værdien fra 1 til en 0

Genstart og se om det har ændret sig.
__________________

  #8  
Old 31. marts 2008, 11:44
Redaktør Gruppen
 
Default Jeg tror, jeg har en virus

Beklager, men bare kørte på tværs af denne.

Gå til http://www.kellys-korner-xp.com/xp.htm gå til tweaks sektion og få den tweak kaldet "Windows Update grå - Gendan."
__________________

  #9  
Old 31. marts 2008, 11:53
Medlem Gruppen
 
Default Jeg tror, jeg har en virus

Det er godt, tak en million evilfantasy! Det ser ud, som den mindreårige infektion jeg havde var som ikke er relateret til dette.

Endnu en gang cheers.
  #10  
Old 31. marts 2008, 12:01
Redaktør Gruppen
 
Default Jeg tror, jeg har en virus

Intet problem.
__________________

Reply

Register
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Computer Juice.

Annoncenetværk baseret på bytteøkonomi ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd SEO ved vBSEO © 2009, websteds egnethed til webcrawling, Inc.