Har fått värsta virusattacken - hjälp!|Felsökning|Forum|Nordichardware

   

Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
Lost password?
The forums are currently locked and only available for read only access
sp_Feed sp_TopicIcon
Har fått värsta virusattacken - hjälp!
Dave123
Nu vet jag hur man gör inlägg!
Medlem
Forum Posts: 46
Member Since:
March 11, 2005
sp_UserOfflineSmall Offline
1
May 17, 2005 - 4:58 pm
sp_Permalink sp_Print

Har fått en massa virus. Det har lagts till en massa favoriter, startsidan har ändrat på sig, det bildas länkar på vanlig text och NOD32 som jag har poppar upp en massa virusvarningar hela tiden så fort jag startar upp Explorer.
Har försökt rensa i felsäkert läge osv. Jag som precis köpt NOD32, trodde den skulle skydda någorlunda bra i alla fall, men icke.

Jag har tydligen fått Win32/Agent.NAB trojan och Win32/TrojanDownloader.Agent.BQ trojan.

Säg inte att jag ska byta till Firefox för min dator gillar inte det programmet, hehe!

Jag klistrar in en HijackThis logg också.

Snälla hjälp mig att få bort detta elände!
Tack på förhand!

Logfile of HijackThis v1.99.1
Scan saved at 18:32:37, on 2005-05-17
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:ProgramSygateSPFsmc.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32RUNDLL32.EXE
C:ProgramEsetnod32kui.exe
C:ProgramDelade filerRealUpdate_OBrealsched.exe
C:WINDOWSSystem32CTHELPER.EXE
C:ProgramJavajre1.5.0_02binjusched.exe
C:ProgramPersonalbinPersonal.exe
C:ProgramEsetnod32krn.exe
C:WINDOWSSystem32nvsvc32.exe
C:ProgramInternet Exploreriexplore.exe
C:Documents and SettingsLichterSkrivbordHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWShnrci.dll/sp.html#83556
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWShnrci.dll/sp.html#83556
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = about :blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = res://C:WINDOWShnrci.dll/sp.html#83556
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWShnrci.dll/sp.html#83556
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWShnrci.dll/sp.html#83556
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWShnrci.dll/sp.html#83556
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Länkar
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgramAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: Class - {FBD510D7-7593-FDD3-1C34-C5FEB77E69B3} - C:WINDOWSsystem32mfcvn.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [SmcService] C:ProgramSygateSPFsmc.exe -startgui
O4 - HKLM..Run: [nod32kui] "C:ProgramEsetnod32kui.exe" /WAITSERVICE
O4 - HKLM..Run: [SBDrvDet] C:ProgramCreativeSB Drive DetSBDrvDet.exe /r
O4 - HKLM..Run: [TkBellExe] "C:ProgramDelade filerRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [iTunesHelper] "C:ProgramiTunesiTunesHelper.exe"
O4 - HKLM..Run: [QuickTime Task] "C:ProgramQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [SunJavaUpdateSched] C:ProgramJavajre1.5.0_02binjusched.exe
O4 - HKLM..Run: [iexplore.exe] C:ProgramInternet Exploreriexplore.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:ProgramDelade filerAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:ProgramAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: Personal.lnk = C:ProgramPersonalbinPersonal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.5.0_02binnpjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgramJavajre1.5.0_02binnpjpi150_02.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/11a25af...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...b?1115839857983
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:WINDOWSsystem32appbx32.exe (file missing)
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:ProgramiPodbiniPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:ProgramEsetnod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:ProgramSygateSPFsmc.exe

EDIT: Vill bara tillägga att användaren "Dave23" här på forumet inte är jag, hehe!

Avatar
gilgamesh
Member
Medlem
Forum Posts: 2883
Member Since:
February 28, 2005
sp_UserOfflineSmall Offline
892395
May 17, 2005 - 5:07 pm
sp_Permalink sp_Print

formatera om!... ;)... 🙁

Isaku
Almost a full-blooded keyboard-warrior
Medlem
Forum Posts: 244
Member Since:
October 23, 2002
sp_UserOfflineSmall Offline
892398
May 17, 2005 - 5:08 pm
sp_Permalink sp_Print

Om inte NOD funkar kan du ju prova med AntiVir som är helt gratis, finns på http://www.free-av.com.
Din loggfil verkar okay, inget suspekt vad jag kan se..

Avatar
Jalle64
Member
Medlem
Forum Posts: 6913
Member Since:
April 13, 2004
sp_UserOfflineSmall Offline
892455
May 17, 2005 - 7:03 pm
sp_Permalink sp_Print

Töm internetcachen 😛

MoparPower
Kommer du hit ofta?
Medlem
Forum Posts: 1613
Member Since:
October 31, 2003
sp_UserOfflineSmall Offline
892475
May 17, 2005 - 7:26 pm
sp_Permalink sp_Print

(och installera FF) wink

Dave123
Nu vet jag hur man gör inlägg!
Medlem
Forum Posts: 46
Member Since:
March 11, 2005
sp_UserOfflineSmall Offline
892517
May 17, 2005 - 8:00 pm
sp_Permalink sp_Print

Så roliga ni är, hehe!
Det var mycket hjälp man fick! :p

Fixade det själv! Tack ändå!

Forum Timezone: Europe/Stockholm
Most Users Ever Online: 1030
Currently Online:
Guest(s) 17
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Andreas Galistel: 16287
Jonas Klar: 15897
ilg@dd: 10810
Nyhet: 10607
Mind: 10550
Ctrl: 10355
Gueno: 9881
Guest: 9344
Snorch: 8881
Callister: 8468
Newest Members:
PetrbonFU PetrbonFU
Karine Bembry
Dolores Mcdaniels
Anibal McLeish
Francisca Alt
Alfie Everhart
Lester Huitt
Orlando Jorgensen
Mikki Lundgren
Dakota Kozlowski
Forum Stats:
Groups: 11
Forums: 59
Topics: 146630
Posts: 1300967

 

Member Stats:
Guest Posters: 2
Members: 79425
Moderators: 0
Admins: 11
Administrators: nordicadmin, Henrik Berntsson, Anton Karmehed, Carl Holmberg, Joel Oscarsson, Mikael Linnér, Mikael Schwartz, Andreas Paulsson, Nickebjrk, Mattias Pettersson, EmxL