I början av Januari 2014 låstes Whoa och du kan alltså ej logga in eller skriva något nytt i forumen. Innehåll i forum osv kommer finnas tillgängligt. Läs Mer »

svchost.exe infekterat (w32.welchia.b.worm)

Hobby & Fritid - Datorer & Teknik

   

2004-04-08 21:59

svchost.exe infekterat (w32.welchia.b.worm)

jag ladda ner Hijack This sen men har ingen aning vilka jag ska våga ta bort,, snälla nån hjälp mig (har windows XP proffesional)



Logfile of HijackThis v1.97.7
Scan saved at 22:01:41, on 2004-04-08
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Vanliga filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\drivers\svchost.exe< br> C:\Program\Vanliga filer\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\sysconf.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\Messenger\msmsgs.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Documents and Settings\Standard\Lokala inställningar\Temp\Temporär katalog 1 för hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login1.telia.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1053,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: SysTray.Exe
O4 - HKLM\..\Run: "C:\Program\Vanliga filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: "C:\Program\Vanliga filer\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: enbiei.exe
O4 - HKLM\..\Run: sysconf.exe
O4 - HKLM\..\RunServices: sysconf.exe
O4 - HKCU\..\Run: C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: "C:\Program\Messenger\msmsgs.exe&qu ot; /background
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shock wave/cabs/director/sw.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberlink.com/winxp/CheckDV D.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CA B/x86/unicode/iuctl.CAB?38084.4648263889
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shock wave/cabs/flash/swflash.cab



OK,,,, kommer viruset försvinna efter de??? eller nån som har ett bättre sätt hur man tar bort den???+

/DESPERAAAAAT"


HATAR XP

S-O-L-I-D(Situationer-och-livet-i-dag)
WWW.SOUNDCLICK.COM/SOLIDP