Giftig virus/orm
En giftig orm har besat min computer, og kan simpelhen ikke komme har virkelig prøvet alt og den bliver bare sidene! Har hentet div. anti virus programmer men der er intet der tager den.Der kommer nu et vindue frem, som fortæller at computeren genstartet om et minut - pga. en virus ved navn lsass.exe (mener det var sådan).
Men efter en anden virus scan fik jeg afvide at en virus med navn "Backdoor.Win32.SdBot.aad" også er på computeren..
Har virkelig brug for HJÆLP! :)
Logfile of HijackThis v1.99.1
Scan saved at 21:03:06, on 11-04-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\CTsvcCDA.exe
D:\WINDOWS\winpad.exe
D:\VIRUSfighter\Bin\Zanda.exe
D:\Programmer\Spyware Doctor\sdhelp.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\msnid
D:\VIRUSfighter\Nvc\bin\nvcoas.exe
D:\VIRUSfighter\bin\NJEEVES.EXE
D:\VIRUSfighter\Nvc\BIN\NVCSCHED.EXE
D:\VIRUSfighter\Nvc\BIN\nipsvc.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
D:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\dinsp.exe
D:\Programmer\Java\jre1.5.0_03\bin\jusched.exe
D:\VIRUSfighter\bin\ZLH.EXE
D:\WINDOWS\System32\ctfmon.exe
D:\VIRUSfighter\Nvc\BIN\NIP.EXE
D:\VIRUSfighter\Nvc\bin\cclaw.exe
D:\PROGRA~1\SPYWAR~1\swdoctor.exe
D:\Programmer\PC Tools AntiVirus\PCTAV.exe
D:\Programmer\PC Tools AntiVirus\ScanningProcess.exe
D:\Programmer\Windows Media Player\wmplayer.exe
D:\VIRUSfighter\bin\NREN.EXE
D:\Programmer\TrojanHunter 4.5\THGuard.exe
D:\DOCUME~1\Mathias\LOKALE~1\Temp\mexe.com
D:\DOCUME~1\Mathias\LOKALE~1\Temp\kavss.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Documents and Settings\Mathias\Dokumenter\hjt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CTSysVol] D:\Programmer\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ATIPTA] D:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [asdgs] C:\dinsp.exe
O4 - HKLM\..\Run: [Windows Ocx Service] winocx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Programmer\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Norman ZANDA] D:\VIRUSfighter\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [THGuard] "D:\Programmer\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [Windows Ocx Service] winocx.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows Ocx Service] winocx.exe
O4 - HKCU\..\Run: [a-squared] "D:\Programmer\a-squared\a2guard.exe"
O4 - HKCU\..\RunServices: [Windows Ocx Service] winocx.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1144770917890
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.hssyd.dk/media/msrdp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Word Process (msproc) - Unknown owner - D:\WINDOWS\winpad.exe (file missing)
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - D:\VIRUSfighter\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - D:\VIRUSfighter\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - D:\VIRUSfighter\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - D:\VIRUSfighter\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - D:\VIRUSfighter\Nvc\BIN\NVCSCHED.EXE
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Programmer\Spyware Doctor\sdhelp.exe