<!--QuoteBegin-Sulle+5 Sep 2004, 19:28:44--><div class='quotetop'>QUOTE(Sulle @ 5 Sep 2004, 19:28:44)</div><div class='quotemain'><!--QuoteEBegin-->Kör ner hijackthis och kopiera hela loggen hit så ska vi nog fixa ditt problem
<a href="
http://www.spychecker.com/download/down ... kthis.html" target="_blank">
http://www.spychecker.com/download/down ... is.html</a>
testa även att köra de här programmet från symantec som sägs ska ta bort den.
<a href="
http://securityresponse.symantec.com/av ... xKorgo.exe" target="_blank">
http://securityresponse.symantec.com/av ... rgo.exe</a>
kör hem den, sedan stänger du av system restore i win xp och kör fixen.
angående namnet korgo så kallar symantec den för korgo men det är Worm.Win32.Padobot.n
följ instruktionerna här, ganska viktigt. Med tanke på att du måste patcha ditt xp etc.....
<a href="
http://securityresponse.symantec.com/av ... rgo.s.html" target="_blank">
http://securityresponse.symantec.com/av ... uoteEEnd-->
Logfile of HijackThis v1.97.7
Scan saved at 22:09:40, on 2004-09-05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\LennartFranzén\LFConnectionKeeper\lfck.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\WINDOWS\System32\setver32.exe
C:\WINDOWS\System32\navsw.exe
C:\WINDOWS\System32\winupdate.exe
C:\WINDOWS\System32\msmscc.exe
C:\WINDOWS\System32\ntfs16.exe
C:\Program\mozilla.org\Mozilla\mozilla.exe
C:\Documents and Settings\Andreas\Skrivbord\[Virusskydd, Adawares m.m]\nytt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="
http://www.google.se/" target="_blank">
http://www.google.se/</a>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: (no name) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program\FlashFXP\IEFlash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Windows secure] setver32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Norton SpySweeper AutoUpdate] navsw.exe
O4 - HKLM\..\Run: [mssoul] C:\WINDOWS\System32\msmscc.exe
O4 - HKLM\..\Run: [NTFS16] ntfs16.exe
O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\Run: [msupdates] msupdt.exe
O4 - HKLM\..\Run: [Win32 USB2 Driver] winupdate.exe
O4 - HKLM\..\Run: [Windows backup] systems.exe
O4 - HKLM\..\Run: [System Uptime Server] sysentry32.exe
O4 - HKLM\..\Run: [mswkork Service] msework.exe
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKLM\..\RunServices: [NTFS16] ntfs16.exe
O4 - HKLM\..\RunServices: [Windows secure] setver32.exe
O4 - HKLM\..\RunServices: [Norton SpySweeper AutoUpdate] navsw.exe
O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\RunServices: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\RunServices: [msupdates] msupdt.exe
O4 - HKLM\..\RunServices: [Win32 USB2 Driver] winupdate.exe
O4 - HKLM\..\RunServices: [Windows backup] systems.exe
O4 - HKLM\..\RunServices: [System Uptime Server] sysentry32.exe
O4 - HKLM\..\RunServices: [mswkork Service] msework.exe
O4 - HKCU\..\Run: [mssoul] C:\WINDOWS\System32\msmscc.exe
O4 - HKCU\..\Run: [Windows secure] setver32.exe
O4 - HKCU\..\Run: [NTFS16] ntfs16.exe
O4 - HKCU\..\Run: [Norton SpySweeper AutoUpdate] navsw.exe
O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKCU\..\Run: [Win32 USB2 Driver] winupdate.exe
O4 - HKCU\..\Run: [mswkork Service] msework.exe
O4 - HKLM\..\RunOnce: [Windows secure] setver32.exe
O4 - HKLM\..\RunOnce: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\RunOnce: [Norton SpySweeper AutoUpdate] navsw.exe
O4 - HKLM\..\RunOnce: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\RunOnce: [Win32 USB2 Driver] winupdate.exe
O4 - HKCU\..\RunOnce: [Windows secure] setver32.exe
O4 - HKCU\..\RunOnce: [Norton SpySweeper AutoUpdate] navsw.exe
O4 - HKCU\..\RunOnce: [Win32 System Spool] spoolsvc.exe
O4 - HKCU\..\RunOnce: [Win32 Configuration] videosd32.exe
O4 - HKCU\..\RunOnce: [Win32 USB2 Driver] winupdate.exe
O9 - Extra 'Tools' menuitem: Sun Java-konsol (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Broken Internet access because of LSP provider 'avsda.dll' missing
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - <a href="
http://public.windupdates.com/get_file. ... 665a3ccb43" target="_blank">
http://public.windupdates.com/get_file. ... a3ccb43</a>
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - <a href="
http://software-dl.real.com/252c99933c6 ... xIE601.cab" target="_blank">
http://software-dl.real.com/252c99933c6 ... 601.cab</a>
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href="
http://download.macromedia.com/pub/shoc ... wflash.cab" target="_blank">
http://download.macromedia.com/pub/shoc ... ash.cab</a>