Hjälp med skit på dator / av Frobler

  • 10 svar
Hjälp med skit på dator
2008-05-17 kl 02:29

Har just tagit bort massa skit på datorn med verkar som det ligger kvar några.. (är nte så jätte haj på det här)
har kört S&D, super antispyware, Ad aware och Nod32
här är hi jack loggen

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 18:48:33, on 2008-05-16
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program\Eset\nod32kui.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vsnpstd.exe
C:\Program\Razer\razerhid.exe
C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Razer\razerofa.exe
C:\Documents and Settings\Frobl3r\Mina dokument\Mina mottagna filer\spy virus progra\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blocket.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: {1045f161-d37d-7829-73d4-8bcc7d2856c0} - {0c6582d7-ccb8-4d37-9287-d73d161f5401} - (no file)
O2 - BHO: (no name) - {1833F38F-BB28-403A-9C71-181E6DA0D359} - (no file)
O2 - BHO: (no name) - {22A1DDB8-91F2-47E0-B380-205921ECE08F} - (no file)
O2 - BHO: (no name) - {2FA02E15-D6C8-4FD7-8EC8-082EEE86FE90} - (no file)
O2 - BHO: (no name) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - (no file)
O2 - BHO: (no name) - {49FE9BEE-9910-4213-B112-AD264329F30D} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CFA72AD-6980-402E-967C-44C1F32A3C31} - (no file)
O2 - BHO: (no name) - {70AB0A8B-8A8A-496F-A339-4CD2F3352991} - (no file)
O2 - BHO: (no name) - {73708D49-7481-4015-A692-733CD5CBB18F} - (no file)
O2 - BHO: (no name) - {74C432F4-DA6B-47F6-83B3-2E8E8B459C31} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {A13287B5-18E9-42FF-AC32-D074C4F43BAC} - (no file)
O2 - BHO: (no name) - {A5586ABB-2000-4B55-9CE7-DA5151B959C0} - (no file)
O2 - BHO: (no name) - {ade01199-e7f9-4c49-a37a-51674d248575} - (no file)
O2 - BHO: (no name) - {B1749382-ACE8-42DD-83C5-7CD8B520C32B} - (no file)
O2 - BHO: (no name) - {BAE684F5-B8BE-4F4C-B4A1-E471E7E9F7BF} - (no file)
O2 - BHO: (no name) - {BBA8B635-7289-4D95-890D-1B30736F85BF} - (no file)
O2 - BHO: (no name) - {BD240D1B-1BDA-4CB6-9DB6-E6AB1243B23A} - (no file)
O2 - BHO: (no name) - {C557838A-5D4B-4AA4-978E-9FFD4A9CBBEC} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [razer] C:\Program\Razer\razerhid.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [60f5aec6] rundll32.exe "C:\WINDOWS\system32\lirdbbtf.dll",b
O4 - HKLM\..\Run: [BM63c69d5a] Rundll32.exe "C:\WINDOWS\system32\eendjtbt.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/
V5Controls/en/x86/client/wuweb_site.cab?120023990
1907

O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/fl
ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{0C1E804F-7CFD-
461C-849E-6434225BD8D5}: NameServer = 213.199.96.131,80.88.97.142
O17 - HKLM\System\CS1\Services\Tcpip\..\{0C1E804F-7CFD-
461C-849E-6434225BD8D5}: NameServer = 213.199.96.131,80.88.97.142
O17 - HKLM\System\CS4\Services\Tcpip\..\{0C1E804F-7CFD-
461C-849E-6434225BD8D5}: NameServer = 213.199.96.131,80.88.97.142

2008-05-17 kl 04:15

[url]http://www.malwarebytes.org/mbam/program/mba
m-setup.exe
[/url]
installera programmet och klicka på scanna när du ser den knappen.
klicka på ok >show results >remove selected,starta om.
gör en ny scan med MBAM, posta den loggen och en HJT logg

2008-05-17 kl 12:58

Får inte igång MBAM.. står bara så här

Run time error 372
Faild to load control `Image list´ from COMCTL32.OCX
your version of COMCLT32.OCX may be out of date
Make sure you are using the version of the control that was provided whit your application.

Vad menas med det... vad gör jag för att fixa det?? :O

2008-05-17 kl 13:49

filen finns att hämta här
http://www.ascentive.com/support/new/support_dll.
phtml?dllname=COMCTL32.OCX


sök efter filen på datorn, kolla vilken version du har jämfört med den som finns på länken. jag har vers 6.0.81.5

2008-05-18 kl 14:09

här kommer MBAM loggen:

Malwarebytes' Anti-Malware 1.12
Databasversion: 758

Skanningstyp: Fullständig skanning (C:\|E:\|G:\|)
Antal skannade objekt: 83873
Förfluten tid: 57 minute(s), 56 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 0

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
(Inga illasinnade poster hittades)

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
(Inga illasinnade poster hittades)

Här är Hi jack loggen:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 14:06:49, on 2008-05-18
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program\Eset\nod32kui.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vsnpstd.exe
C:\Program\Razer\razerhid.exe
C:\Program\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Razer\razerofa.exe
C:\Documents and Settings\Frobl3r\Mina dokument\Mina mottagna filer\spy virus progra\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blocket.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: {1045f161-d37d-7829-73d4-8bcc7d2856c0} - {0c6582d7-ccb8-4d37-9287-d73d161f5401} - (no file)
O2 - BHO: (no name) - {1833F38F-BB28-403A-9C71-181E6DA0D359} - (no file)
O2 - BHO: (no name) - {22A1DDB8-91F2-47E0-B380-205921ECE08F} - (no file)
O2 - BHO: (no name) - {2FA02E15-D6C8-4FD7-8EC8-082EEE86FE90} - (no file)
O2 - BHO: (no name) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - (no file)
O2 - BHO: (no name) - {49FE9BEE-9910-4213-B112-AD264329F30D} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CFA72AD-6980-402E-967C-44C1F32A3C31} - (no file)
O2 - BHO: (no name) - {70AB0A8B-8A8A-496F-A339-4CD2F3352991} - (no file)
O2 - BHO: (no name) - {73708D49-7481-4015-A692-733CD5CBB18F} - (no file)
O2 - BHO: (no name) - {74C432F4-DA6B-47F6-83B3-2E8E8B459C31} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {A13287B5-18E9-42FF-AC32-D074C4F43BAC} - (no file)
O2 - BHO: (no name) - {A5586ABB-2000-4B55-9CE7-DA5151B959C0} - (no file)
O2 - BHO: (no name) - {ade01199-e7f9-4c49-a37a-51674d248575} - (no file)
O2 - BHO: (no name) - {B1749382-ACE8-42DD-83C5-7CD8B520C32B} - (no file)
O2 - BHO: (no name) - {BAE684F5-B8BE-4F4C-B4A1-E471E7E9F7BF} - (no file)
O2 - BHO: (no name) - {BBA8B635-7289-4D95-890D-1B30736F85BF} - (no file)
O2 - BHO: (no name) - {BD240D1B-1BDA-4CB6-9DB6-E6AB1243B23A} - (no file)
O2 - BHO: (no name) - {C557838A-5D4B-4AA4-978E-9FFD4A9CBBEC} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [razer] C:\Program\Razer\razerhid.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/
V5Controls/en/x86/client/wuweb_site.cab?120023990
1907

O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/fl
ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{0C1E804F-7CFD-
461C-849E-6434225BD8D5}: NameServer = 213.199.96.131,80.88.97.142
O17 - HKLM\System\CS1\Services\Tcpip\..\{0C1E804F-7CFD-
461C-849E-6434225BD8D5}: NameServer = 213.199.96.131,80.88.97.142
O17 - HKLM\System\CS4\Services\Tcpip\..\{0C1E804F-7CFD-
461C-849E-6434225BD8D5}: NameServer = 213.199.96.131,80.88.97.142
O20 - Winlogon Notify: !SASWinLogon - C:\Program\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: mljkhif - C:\WINDOWS\
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program\Eset\nod32krn.exe

--
End of file - 7009 bytes

2008-05-18 kl 16:23

nu ser det mycket bättre ut, du kan bocka för och fixa alla dessa rader i HJT loggen
O2 - BHO: (no name) - {BAE684F5-B8BE-4F4C-B4A1-E471E7E9F7BF} - (no file)

får du inte bort dom så måste du inaktivera funktionen teatimer i spybot

2008-05-18 kl 18:02

får inte bort dom..
Hur stänger jag av tea timmer?
eller ska jag ta bort S&D helt.. och bara köra med super anti spyware?

2008-05-18 kl 20:57

du måste välja advanced mode i spybot för att komma åt teatimer

2008-05-18 kl 22:53

aaa.. ok då är jag med...
tack för hjälpen i alla fall..

2008-05-18 kl 23:17

fick bort no name filerna å stängt av tea timer nu ....

  • 10 svar
Avatar

Inte inloggad

Logga in Bli medlem

Läs mer

  • Senaste
  • Mest läst
  • Mest kommenterat

Kom in i diskussionen

Detta innehåll är skapat av PC Hemmas besökare

Logga in som administratör

1 kommentar

Markus: Hur gör jag om man har glömt vad man tog för första lösenord till proffesional?

Forum

Detta innehåll är skapat av PC Hemmas medlemmar.

Tester

  • Senaste
  • Mest läst
  • Mest kommenterat

Artikelkommentarer


Egmont logo
© Egmont Tidskrifter