Gå til innhold

"oppgavebehandling" kommer ikke frem


Anbefalte innlegg

Videoannonse
Annonse

tok en rask scan på hijackthis:

 

Logfile of HijackThis v1.99.1

Scan saved at 19:15:54, on 13.04.2006

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\RUNDLL32.EXE

C:\Programfiler\VIAudioi\SBADeck\ADeck.exe

C:\Programfiler\Winamp\winampa.exe

C:\Programfiler\DAEMON Tools\daemon.exe

C:\Programfiler\iTunes\iTunesHelper.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe

C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe

C:\Programfiler\outlook\outlook.exe

C:\windows\mousepad11.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Programfiler\Messenger\msmsgs.exe

C:\Programfiler\MSN Messenger\MsnMsgr.Exe

C:\PROGRA~1\FELLES~1\qwww\qwwwm.exe

C:\Programfiler\WinZip\WZQKPICK.EXE

C:\PROGRA~1\FELLES~1\qwww\qwwwa.exe

C:\Programfiler\Fellesfiler\Windows\services32.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\Øystein\Skrivebord\HijackThis.exe

C:\WINDOWS\System32\wuauclt.exe

C:\WINDOWS\System32\wuauclt.exe

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Programfiler\Toolbar888\ToolBar888.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AudioDeck] C:\Programfiler\VIAudioi\SBADeck\ADeck.exe 1

O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\winampa.exe

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [bearShare] "C:\Programfiler\BearShare\BearShare.exe" /pause

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [outlook] C:\Programfiler\outlook\outlook.exe /auto

O4 - HKLM\..\Run: [winlog] winlog.exe

O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard11.exe

O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad11.exe

O4 - HKLM\..\Run: [newname] C:\windows\newname11.exe

O4 - HKLM\..\RunServices: [winlog] winlog.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MECA] C:\Programfiler\Meca\\Meca.exe

O4 - HKCU\..\Run: [ares] "C:\Programfiler\Ares\Ares.exe" -h

O4 - HKCU\..\Run: [services32] C:\Programfiler\Fellesfiler\Windows\mc-110-12-0000140.exe

O4 - HKCU\..\Run: [qwww] C:\PROGRA~1\FELLES~1\qwww\qwwwm.exe

O4 - Startup: Adobe Gamma.lnk = C:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\fp6s03j7e.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Lenke til kommentar

Her var det mange programmer som trygt kan fjernes fra oppstarten!

 

Start | Kjør | msconfig [enter]

 

Kategorien helt til høyre lister opp hvilke programmer som startes ved innlogging.

 

Fjern haken ved:

 

C:\Programfiler\iTunes\iTunesHelper.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe

C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe

C:\PROGRA~1\FELLES~1\qwww\qwwwm.exe <-- usikker på denne, finner ikke noe på Google

C:\Programfiler\WinZip\WZQKPICK.EXE

C:\PROGRA~1\FELLES~1\qwww\qwwwa.exe

C:\Programfiler\Fellesfiler\Windows\services32.exe <--" services32.exe is registered as a downloader. This process usually comes bundled with a virus or spyware and it’s main role is to do nothing other than download other viruses/spyware to your computer. It is a registered security risk and should be removed immediately."

C:\Programfiler\iPod\bin\iPodService.exe

[/color][/color]

 

Ang. Oppgavebehandling: Prøv kombinasjonen Control+Shift+Escape.

Lenke til kommentar

C:\Programfiler\Fellesfiler\Windows\services32.exe <- W32/Rbot-MB Orm.

 

Fjern:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

 

O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Programfiler\Toolbar888\ToolBar888.dll

 

Er litt usikker på disse:

O4 - HKCU\..\Run: [services32] C:\Programfiler\Fellesfiler\Windows\mc-110-12-0000140.exe

 

O4 - HKCU\..\Run: [qwww] C:\PROGRA~1\FELLES~1\qwww\qwwwm.exe

 

Fjern dem hvis du ikke kjenner de igjen

 

Fjern:

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

 

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

Lenke til kommentar

Skaff deg et antivirusprogram!

 

Anbefaler deg å gå igjennom alle flereogtjue punktene her:

http://www.wilderssecurity.com/showthread.php?t=50662

Det er ting her som ikke lar seg fjerne med kun HJT.

Dersom du gjør som i linken tenker jeg det går bra. Det du ikke må gjøre er å gi deg halvveis, for da kommer svineriet tilbake. Det eneste er at punkt 13 kan du gjøre mer elegant med Crapcleaner (google ccleaner) eller Cleanup (google, stevengould)

 

Skaff deg et antivirusprogram! (jada, jeg har sagt det før) AVG og AVAST! er begge gratis; dersom du gjør som de sier i linken plukker du ned Ewido, som har en gratisdel etter 14 dager.

 

Forresten bør denne flyttes til Sikkerhet.

 

Bernt K

Endret av berxter
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...