Gå til innhold
Trenger du hjelp med PCen? Still spørsmål her! ×

Sliter med virus/spy..


Anbefalte innlegg

Hello, jeg har kjøpt meg ny pc og det ser ut som det hilser ALT av virus og spyware velkommen..

 

hardware: MSI diamond hovedkort, 3 x 512mb ram, AMD3800+ x2

 

kjører windows xp med sp1 og 2, har KJØPT Ewido anti malware som jeg kjører støtt og stadig, og kjører Bitdefender 9 professional plus..

 

men likavel strømmer problemene inn.. bitdefender virker som et bra programm men jeg har mista mye av tilliten til det.. ja jeg har firewall oppe..

 

noen forslag?

 

når jeg starter I-net Explorer kommer denne siden opp: http://www.safetyuptodate.com/

 

og jeg kommer meg heller ikke vekk fra den..

 

virker som pc'en blir mer og mer sliten etter hver gang jeg fjerner virus..

Endret av MysticoN
Lenke til kommentar
Videoannonse
Annonse

Anbefaler deg å spörre i sikkerhets delen.

Er det noen prosesser på listen som du er usikker på ta et google sök og sjekk hva det er, fjern unödvendige program og ta spyware/anti virus scan.

Jeg ville formatert disken, fordi det kommer nok ligge igjen litt söppel som gjör pcn treger etter du har fjernet virus/spyware.

Lenke til kommentar
jeg kan se en STOR feil, og det er at du har 61 prosesser kjørende!!

 

Men jeg anbefaler deg å reinstallere, skaffe deg AdAware, SpyBot Search & Destroy og Ccleaner og et nytt virusprogram og ny brannmur!

6160249[/snapback]

 

takker for svar.. bruker sp2 brannmuren no.. hvilken anti virus prog anbefaler du da?

siden jeg no har 3 anti spy prog så burde jeg no få fjernet mesteparten av spy ganske fort..

Endret av MysticoN
Lenke til kommentar

fra windows task manager:

alg.exe : This program provides optional utilities like the Windows Firewall and ICS. If you're not using either one of them then you should not be seeing this program run.

 

ATKKBservice.exe:

ATKKBService.exe is a process installed alongside ASUS Keyboards and provides additional configuration options for these devices. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems.

 

bdmcon.exe, bdagent.exe, bdoesrv.exe, bdss.exe og bdwitch.exe :

Bit defender helps protect the PC from virus infections.

 

csrss.exe

This is the user-mode portion of the Win32 subsystem (with Win32.sys being the kernel-mode portion). Csrss stands for client/server run-time subsystem and is an essential subsystem that must be running at all times. Csrss is responsible for console windows, creating and/or deleting threads, and some parts of the 16-bit virtual MS-DOS environment.

 

CTsysvol.exe

Creative Labs audio devices and handles the volume

 

isass.exe

isass.exe is registered as the Optix.Pro virus which carries in it's payload, the ability to disable firewalls and local security protections, and a backdoor capability.

:O

 

svchost.exe

har 4stk av denne.. 2 på system, 2 på network service og en på local service.

 

wdfmgr.exe, wuauclt.exe og xcommsvr.exe

fant ikke noe jeg skjønte meg på om denne..

 

 

ok.. så det er vertfall isass.exe som ikke hører hjemme på min pc.. tenkte å poste alt men orka ikke ettersom at jeg kjente igjen en del uten å google for det.. skal prøve å kjøre NOD32 no. som dere sikker skjønner så er jeg vel ikke den som har MEST peiling på slikt^^

 

takker for alle svar. men håper enda på flere

Lenke til kommentar
Du har da ikke isass. Du har en helt alminnelig og godartet lsass! LSASS (unnskyld den store skrifta).

Hvorfor ikke HijackThis?

 

Bernt K

6164910[/snapback]

 

noe for det erfarende øye.

 

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Opera\Opera.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Creative\SBAudigy\Surround

 

Mixer\CTSysVol.exe

C:\WINDOWS\system32\Rundll32.exe

C:\WINDOWS\ATKKBService.exe

C:\Program Files\Razer\razerhid.exe

C:\Program

 

Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\ewido

 

anti-malware\ewidoctrl.exe

C:\Program Files\MSI\Live Update

 

3\LMonitor.exe

C:\Program Files\ewido

 

anti-malware\ewidoguard.exe

C:\Program Files\Winamp\winampa.exe

C:\Program

 

Files\Softwin\BitDefender9\bdoesrv.exe

C:\program

 

files\softwin\bitdefender9\bdnagent.exe

C:\program

 

files\softwin\bitdefender9\bdswitch.exe

C:\Program Files\Eset\nod32kui.exe

C:\Program Files\Eset\nod32krn.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\Program Files\MSI\DigiCell\DigiCell.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Common

 

Files\Softwin\BitDefender

 

Communicator\xcommsvr.exe

C:\Program Files\Razer\razertra.exe

C:\Program Files\Razer\razerofa.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Common

 

Files\Softwin\BitDefender Update

 

Service\livesrv.exe

C:\Program Files\Common

 

Files\Softwin\BitDefender Scan

 

Server\bdss.exe

C:\Program

 

Files\Softwin\BitDefender9\vsserv.exe

c:\program

 

files\softwin\bitdefender9\bdmcon.exe

C:\Program Files\Opera\Opera.exe

C:\Program Files\WinRAR\WinRAR.exe

C:\DOCUME~1\THEREA~1\LOCALS~1\Temp\Rar$EX00.5

 

62\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet

 

Explorer\Main,Start Page =

 

http://www.skandiabanken.no/

R1 - HKCU\Software\Microsoft\Internet

 

Connection Wizard,ShellNext =

 

http://windowsupdate.microsoft.com/

O2 - BHO: Yahoo! Toolbar Helper -

 

{02478D38-C3F9-4EFB-9B51-7695ECA05670} -

 

C:\Program

 

Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: (no name) -

 

{53707962-6F74-2D53-2644-206D7942484F} -

 

C:\Program Files\Spybot - Search &

 

Destroy\SDHelper.dll

O2 - BHO: Nothing -

 

{f79fd28e-36ee-4989-aa61-9dd8e30a82fa} -

 

C:\WINDOWS\system32\hp98E7.tmp

O3 - Toolbar: Yahoo! Toolbar -

 

{EF99BD32-C1FB-11D2-892F-0090271D4F88} -

 

C:\Program

 

Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

 

C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter]

 

RUNDLL32.EXE

 

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarIni

 

t

O4 - HKLM\..\Run: [CTSysVol] C:\Program

 

Files\Creative\SBAudigy\Surround

 

Mixer\CTSysVol.exe /r

O4 - HKLM\..\Run: [P17Helper] Rundll32

 

P17.dll,P17Helper

O4 - HKLM\..\Run: [updReg]

 

C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [razer] C:\Program

 

Files\Razer\razerhid.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched]

 

C:\Program

 

Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [LiveMonitor] C:\Program

 

Files\MSI\Live Update 3\LMonitor.exe

O4 - HKLM\..\Run: [WinampAgent] C:\Program

 

Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [bDMCon] "C:\Program

 

Files\Softwin\BitDefender9\bdmcon.exe"

O4 - HKLM\..\Run: [bDOESRV] "C:\Program

 

Files\Softwin\BitDefender9\bdoesrv.exe"

O4 - HKLM\..\Run: [bDNewsAgent] "c:\program

 

files\softwin\bitdefender9\bdnagent.exe"

O4 - HKLM\..\Run: [bDSwitchAgent] "c:\program

 

files\softwin\bitdefender9\bdswitch.exe"

O4 - HKLM\..\Run: [nod32kui] "C:\Program

 

Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program

 

Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - Startup: DigiCell.lnk = C:\Program

 

Files\MSI\DigiCell\DigiCell.exe

O9 - Extra button: (no name) -

 

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

 

C:\Program

 

Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

O9 - Extra 'Tools' menuitem: Sun Java Console

 

- {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

 

C:\Program

 

Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

O9 - Extra button: Messenger -

 

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

 

C:\Program Files\Messenger\msmsgs.exe (file

 

missing)

O9 - Extra 'Tools' menuitem: Windows

 

Messenger -

 

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

 

C:\Program Files\Messenger\msmsgs.exe (file

 

missing)

O16 - DPF:

 

{6414512B-B978-451D-A0D8-FCFDF33E833C}

 

(WUWebControl Class) -

 

http://update.microsoft.com/windowsupdate/v6/

 

V5Controls/en/x86/client/wuweb_site.cab?11476

 

99990409

O18 - Protocol: msnim -

 

{828030A1-22C1-4009-854F-8E305202313F} -

 

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file

 

missing)

O23 - Service: ATK Keyboard Service

 

(ATKKeyboardService) - ASUSTeK COMPUTER INC.

 

- C:\WINDOWS\ATKKBService.exe

O23 - Service: BitDefender Scan Server (bdss)

 

- Unknown owner - C:\Program Files\Common

 

Files\Softwin\BitDefender Scan

 

Server\bdss.exe" /service (file missing)

O23 - Service: ewido security suite control -

 

ewido networks - C:\Program Files\ewido

 

anti-malware\ewidoctrl.exe

O23 - Service: ewido security suite guard -

 

ewido networks - C:\Program Files\ewido

 

anti-malware\ewidoguard.exe

O23 - Service: BitDefender Desktop Update

 

Service (LIVESRV) - Unknown owner -

 

C:\Program Files\Common

 

Files\Softwin\BitDefender Update

 

Service\livesrv.exe" /service (file missing)

O23 - Service: NOD32 Kernel Service

 

(NOD32krn) - Eset - C:\Program

 

Files\Eset\nod32krn.exe

O23 - Service: NVIDIA Display Driver Service

 

(NVSvc) - NVIDIA Corporation -

 

C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: BitDefender Virus Shield

 

(VSSERV) - Unknown owner - C:\Program

 

Files\Softwin\BitDefender9\vsserv.exe"

 

/service (file missing)

O23 - Service: BitDefender Communicator

 

(XCOMM) - Unknown owner - C:\Program

 

Files\Common Files\Softwin\BitDefender

 

Communicator\xcommsvr.exe" /service (file

 

missing)

Endret av MysticoN
Lenke til kommentar

Det var et sant mareritt å lese denne loggen; hvordan du har fått til denne formateringen skjønner ikke jeg.. :cool:

 

Du har fått deg en SmitFraudvariant (Spyfalcon), men den er ganske grei å bli kvitt:

Medisinen finner du her.

 

Når du har fikset den, vennligst gi oss tilbakemelding.

 

Bernt K

Endret av berxter
Lenke til kommentar

Logfile of HijackThis v1.99.1

Scan saved at 15:58:34, on 24.05.2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

C:\WINDOWS\system32\Rundll32.exe

C:\Program Files\Razer\razerhid.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\MSI\Live Update 3\LMonitor.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Softwin\BitDefender9\bdmcon.exe

C:\Program Files\Softwin\BitDefender9\bdoesrv.exe

C:\Program Files\Softwin\BitDefender9\bdnagent.exe

C:\Program Files\Softwin\BitDefender9\bdswitch.exe

C:\Program Files\Eset\nod32kui.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\Program Files\MSI\DigiCell\DigiCell.exe

C:\WINDOWS\ATKKBService.exe

C:\Program Files\ewido anti-malware\ewidoctrl.exe

C:\Program Files\ewido anti-malware\ewidoguard.exe

C:\Program Files\Eset\nod32krn.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

C:\Program Files\Opera\Opera.exe

C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe

C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe

C:\Program Files\Softwin\BitDefender9\vsserv.exe

C:\Program Files\Razer\razertra.exe

C:\Program Files\Razer\razerofa.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\The Real MysticoN\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r

O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper

O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe

O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender9\bdmcon.exe"

O4 - HKLM\..\Run: [bDOESRV] "C:\Program Files\Softwin\BitDefender9\bdoesrv.exe"

O4 - HKLM\..\Run: [bDNewsAgent] "C:\Program Files\Softwin\BitDefender9\bdnagent.exe"

O4 - HKLM\..\Run: [bDSwitchAgent] "C:\Program Files\Softwin\BitDefender9\bdswitch.exe"

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - Startup: DigiCell.lnk = C:\Program Files\MSI\DigiCell\DigiCell.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1147699990409

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe

O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)

O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe

O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe

O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)

O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

 

sån ser det ut no. vist det har blitt noe bedre da..

 

btw takker for all hjelpen du har gitt meg Bernt K.

Lenke til kommentar

Heisann! Loggen din ser fin og rein ut, og gratulerer med det!

 

En liten ting, jeg ser du kjører med Nod32, BitDefender og Ewido samtidig. Ewido kan du godt la gå sammen med en av de andre, da den er laget for det, men BitDefender og NOD går ikke nødvendigvis så godt sammen. Du trenger ikke å avinstallere ett av dem, men fjerne ett av dem fra autostarten, ihvertfall. Du riksikerer ellers at de kommer i konflikt med hverandre, rapporterer hverandres karantenefoldere og mulig annet grums.

 

Nå når du har rein maskin anbefaler jeg at du stopper System Restore, rebooter og setter den på igjen. Dersom du er i tvil om hvordan det best gjøres, les her:

http://bertk.mvps.org/html/disablesr.html

 

Du bør også kjøre en runde med ccleaner (google) for å fjerne gammelt skrap.

 

Bernt K

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...