Gå til innhold

Hjelp! Fjerne spyware reklame!


Anbefalte innlegg

Pcen min har installert masse spyware reklame og det har gjort hele pcen min helt klikk! det legger seg som en gul trekant nede på startlinja osv...

 

Her er loggen fra Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:06:02, on 19.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Programfiler\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\WINDOWS\system32\perfs.exe

C:\WINDOWS\system32\routing.exe

C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programfiler\Telenor\Online Start\Telenor.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe

C:\Programfiler\iTunes\iTunesHelper.exe

C:\Programfiler\Telenor\Online Start\Telenor .exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched .exe

C:\WINDOWS\lsass.exe

C:\Programfiler\iTunes\iTunesHelper .exe

C:\Programfiler\Creative\SBLive\Diagnostics\diagent.exe

C:\WINDOWS\avp.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\mgrs.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched .exe

C:\WINDOWS\lsass .exe

C:\WINDOWS\avp .exe

C:\Programfiler\Creative\SBLive\Diagnostics\diagent .exe

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\Programfiler\iTunes\iTunes.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe

F2 - REG:system.ini: UserInit=userinit.exe,

O4 - HKLM\..\Run: [MSN] C:\DOCUME~1

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [diagent] C:\Programfiler\Creative\SBLive\Diagnostics\diagent.exe startup

O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [Telenor Online Start] "C:\Programfiler\Telenor\Online Start\Telenor.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask .exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [adsnwm] C:\WINDOWS\system32\adsnwm.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Winupdate Engine] C:\WINDOWS\system32\wupeng.exe

O4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass .exe

O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe

O4 - HKLM\..\Run: [smgr] mgrs.exe

O4 - HKLM\..\Run: [ghudofmr] regsvr32 /u "C:\Documents and Settings\All Users\Programdata\ghudofmr.dll"

O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Programfiler\BitTorrent_DNA\dna.exe"

O4 - HKCU\..\Run: [steam] C:\Programfiler\Valve\Steam\Steam.exe -silent

O4 - HKCU\..\Run: [AdobeUpdater] C:\Programfiler\Fellesfiler\Adobe\Updater5\AdobeUpdater.exe

O4 - HKCU\..\Run: [spoolsv] C:\WINDOWS\system32\spoolvs.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Startup: findfast .exe

O4 - Startup: findfast.exe

O4 - Global Startup: autorun.exe

O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O16 - DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} (Panasonic Network Camera) - http://208.0.229.84/SysCamInst.cab

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://mallcam.uta.edu/kxhcm10.ocx

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://193.69.140.39/activex/AMC.cab

O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (BL_Camera) - http://67.154.21.186:8002/bl_camera.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://129.57.20.46:1497/activex/AxisCamControl.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: perfmons Service (perfmons) - Unknown owner - C:\WINDOWS\system32\perfs.exe

O23 - Service: Routing Service (Routing) - Unknown owner - C:\WINDOWS\system32\routing.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

 

--

End of file - 7624 bytes

Lenke til kommentar
Videoannonse
Annonse

Jeg har forresten prøvd å slette de før. men når jeg rebooter så har alt installert seg på nytt!!!! Aner ikke hvor mange ganger jeg har brukt adaware eller fjernet de manuellt, men det er mange ganger :( Håper noen kan tyde loggen :)

Lenke til kommentar

OIII! jeg ble skremt nå hvor mye virus du har ;O

 

åpne hijackthis og scan og fjern merkede linjer:

 

C:\WINDOWS\system32\perfs.exe

 

C:\WINDOWS\system32\routing.exe

 

C:\WINDOWS\lsass.exe

 

C:\WINDOWS\avp.exe

 

C:\Programfiler\Java\jre1.6.0_03\bin\jusched .exe

 

C:\WINDOWS\avp .exe

 

C:\Programfiler\Creative\SBLive\Diagnostics\diagent .exe

 

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe

 

F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe

 

F2 - REG:system.ini: UserInit=userinit.exe

 

O4 - HKLM\..\Run: [MSN] C:\DOCUME~1

 

O4 - HKLM\..\Run: [adsnwm] C:\WINDOWS\system32\adsnwm.exe

 

O4 - HKLM\..\Run: [Winupdate Engine] C:\WINDOWS\system32\wupeng.exe

 

O4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass .exe

 

O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe

 

O4 - HKLM\..\Run: [smgr] mgrs.exe

 

O4 - HKLM\..\Run: [ghudofmr] regsvr32 /u "C:\Documents and Settings\All Users\Programdata\ghudofmr.dll"

 

O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exe

 

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

 

O4 - HKCU\..\Run: [spoolsv] C:\WINDOWS\system32\spoolvs.exe

 

- Startup: findfast .exe

 

O4 - Startup: findfast.exe

 

O4 - Global Startup: autorun.exe

 

O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

 

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

 

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe (file missing)

 

O16 - DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} (Panasonic Network Camera) - http://208.0.229.84/SysCamInst.cab

 

O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (BL_Camera) - http://67.154.21.186:8002/bl_camera.cab

 

O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll

 

O23 - Service: perfmons Service (perfmons) - Unknown owner - C:\WINDOWS\system32\perfs.exe

 

O23 - Service: Routing Service (Routing) - Unknown owner - C:\WINDOWS\system32\routing.exe

 

 

 

 

etter at du har fjernet det så kan du poste en logg fra hijackthis =)

Endret av Danielsm
Lenke til kommentar

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:52:12, on 19.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Programfiler\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\WINDOWS\system32\perfs.exe

C:\WINDOWS\system32\routing.exe

C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programfiler\Telenor\Online Start\Telenor.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe

C:\Programfiler\iTunes\iTunesHelper.exe

C:\Programfiler\Telenor\Online Start\Telenor .exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched .exe

C:\Programfiler\iTunes\iTunesHelper .exe

C:\Programfiler\Creative\SBLive\Diagnostics\diagent.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Programfiler\Java\jre1.6.0_03\bin\jusched .exe

C:\Programfiler\Creative\SBLive\Diagnostics\diagent .exe

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\Programfiler\iTunes\iTunes.exe

C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programfiler\Macromedia\Flash 8\Flash.exe

C:\Programfiler\Internet Explorer\iexplore.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [diagent] C:\Programfiler\Creative\SBLive\Diagnostics\diagent.exe startup

O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [Telenor Online Start] "C:\Programfiler\Telenor\Online Start\Telenor.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask .exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Programfiler\BitTorrent_DNA\dna.exe"

O4 - HKCU\..\Run: [steam] C:\Programfiler\Valve\Steam\Steam.exe -silent

O4 - HKCU\..\Run: [AdobeUpdater] C:\Programfiler\Fellesfiler\Adobe\Updater5\AdobeUpdater.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://mallcam.uta.edu/kxhcm10.ocx

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://193.69.140.39/activex/AMC.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://129.57.20.46:1497/activex/AxisCamControl.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programfiler\Fellesfiler\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe

O23 - Service: perfmons Service (perfmons) - Unknown owner - C:\WINDOWS\system32\perfs.exe

O23 - Service: Routing Service (Routing) - Unknown owner - C:\WINDOWS\system32\routing.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

 

--

End of file - 6206 bytes

 

 

Fant ikke disse :S

C:\WINDOWS\system32\perfs.exe

 

C:\WINDOWS\system32\routing.exe

 

C:\WINDOWS\lsass.exe

 

C:\WINDOWS\avp.exe

 

C:\Programfiler\Java\jre1.6.0_03\bin\jusched .exe

 

C:\WINDOWS\avp .exe

 

C:\Programfiler\Creative\SBLive\Diagnostics\diagent .exe

Lenke til kommentar

fjern disse linjene:

 

C:\WINDOWS\system32\routing.exe

 

C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

 

F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe

 

O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll

 

O23 - Service: perfmons Service (perfmons) - Unknown owner - C:\WINDOWS\system32\perfs.exe

 

O23 - Service: Routing Service (Routing) - Unknown owner - C:\WINDOWS\system32\routing.exe

Lenke til kommentar

Hmm. Når jeg trykker "fix checked" så blir de slettet. Men når jeg scanner på nytt er alle der igjen :S eller, bare de 5 siste.

 

Her er neste log hvis det hjelper:

 

  Vis skjult innhold

 

 

Forresten. Tusen Tusen takk for at du ser på saken ;) Trekanten nede i hjørnet er borte alt! :D håper bare det ikke kommer tilbake når jeg starter maskinen på nytt :o

Lenke til kommentar

Nå har alt spyware reklame + enda mer kommet tilbake :( Hver gang jeg tok nytt scan så var alle filene der på nytt selv om jeg sletta de for 1 minutt sia.

 

Tror nok det har noe med at jeg ikke fikk slettet alt på en gang, slik at f.eks en fil fungerte som "seed" til resten eller noe.

Men jeg skal laster ned combofix nå og håper på det beste :)

Lenke til kommentar

Her er ComboFix loggen ;) Tusen takk for at dere hjelper meg ! :D

ComboFix:

 

  Vis skjult innhold

 

Lenke til kommentar

Gå til nettstedet http://virusscan.jotti.org/, og last opp følgende fil for sjekk: C:\WINDOWS\system32\drivers\bnswoltk.dat

(Du må mulig slå på "Hvis skjulte filer og mapper" for å se filen - kontrollpanel->mappealt.->vis)

 

Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt.

Dra deretter fila over Combofix-iconet. Combofix vil starte igjen. Post loggen.

File::

C:\WINDOWS\system32\confms.dll

C:\Documents and Settings\Adrian\Programdata\Anti-Virus-Pro.com

C:\Documents and Settings\Adrian\Programdata\EasySpywareCleaner.com

C:\WINDOWS\system32\drvboj.dll

 

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{670B0F96-B386-4FF5-9793-DED3F81A8CF9}]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxyyax]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineil32]

Lenke til kommentar

Den siden fungerer jo aldri :p

 

"Status: The server is extremely busy at the moment, please wait (retrying in 6 seconds)...

 

finnes det en annen side/måte du kan gjøre det på?

Er det farlig om jeg sletter filen?

Endret av Chizzo
Lenke til kommentar
  norbat skrev:
Ta og rename file til bnswoltk.dat.vir. Om alt kjører normalt og ingen feilmeldinger etc. så kan fila slettes senere en gang. Når du bytter filendelse så vil den bli uvirksom.

Fikk opp feilmelding hvor det stod at filen var i bruk eller skrivebeskyttet.

Lenke til kommentar
  Chizzo skrev:
  norbat skrev:
Ta og rename file til bnswoltk.dat.vir. Om alt kjører normalt og ingen feilmeldinger etc. så kan fila slettes senere en gang. Når du bytter filendelse så vil den bli uvirksom.

Fikk opp feilmelding hvor det stod at filen var i bruk eller skrivebeskyttet.

 

Prøv å starte opp PC-en i sikkermodus ved å tappe f8 ved oppstart, og deretter endre filnavnet derfra.

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...