1. Tämä sivusto käyttää keksejä (cookie). Jatkamalla sivuston käyttämistä hyväksyt keksien käyttämisen. Lue lisää.

mikä on csharpshel

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi eva02 16.05.2008.

Viestiketjun tila:
Viestiketju on suljettu.
  1. eva02

    eva02 Member

    Liittynyt:
    26.10.2005
    Viestejä:
    17
    Kiitokset:
    0
    Pisteet:
    11
    mikä on csharpshel
    msconfig:illa näen että tollanen käynistyy koneen käynnistyessä
    "C:\Windows\System32\csharpshell.exe"
    voikohan sen poistaa




    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:51:09, on 16.5.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    D:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    d:\Program Files\a-squared Free\a2service.exe
    d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    d:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
    d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsgk32st.exe
    d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\FSGK32.EXE
    d:\Program Files\Sonera Internet Tietoturva\backweb\4436233\program\fsbwsys.exe
    d:\Program Files\Sonera Internet Tietoturva\Common\FSMA32.EXE
    d:\Program Files\Sonera Internet Tietoturva\Common\FSMB32.EXE
    d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fssm32.exe
    C:\WINDOWS\system32\nvsvc32.exe
    d:\Program Files\Sonera Internet Tietoturva\Common\FCH32.EXE
    d:\PROGRA~1\SPYWAR~1\sp_rsser.exe
    d:\Program Files\Sonera Internet Tietoturva\Common\FAMEH32.EXE
    C:\WINDOWS\System32\svchost.exe
    d:\Program Files\ThreatFire\TFService.exe
    d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsrw.exe
    C:\WINDOWS\system32\wdfmgr.exe
    d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    d:\Program Files\Sonera Internet Tietoturva\FWES\Program\fsdfwd.exe
    C:\WINDOWS\System32\alg.exe
    d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsav32.exe
    C:\WINDOWS\Explorer.EXE
    D:\Program Files\Sonera Internet Tietoturva\Common\FSM32.EXE
    d:\PROGRA~1\SONERA~1\ANTI-S~1\fsaw.exe
    D:\Program Files\Sonera Internet Tietoturva\FSGUI\ispnews.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    D:\Program Files\ThreatFire\TFTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    d:\Program Files\Sonera Internet Tietoturva\FSGUI\fsguidll.exe
    D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    D:\PROGRA~1\FIRE\FIREFOX.EXE
    D:\Program Files\Sonera Internet Tietoturva\backweb\4436233\Program\fspex.exe
    d:\Program Files\Everest Labs\Spydefense\sdc.exe
    D:\Program Files\fire\firefox.exe
    D:\Program Files\foobar2000\foobar2000.exe
    D:\Program Files3\BitComet\BitComet.exe
    D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files3\BitComet\tools\BitCometBHO_1.2.2.28.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {6FE4B40D-80B2-4247-B8B0-86D6659660E6} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {AE402173-05B5-408D-B757-B0833B6A0DB1} - (no file)
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: (no name) - {C7D8C2CD-F5A9-4B58-8F06-DA83153F6DD4} - (no file)
    O2 - BHO: {eff701a6-6787-4b4a-91b4-58541813041d} - {d1403181-4585-4b19-a4b4-78766a107ffe} - (no file)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [F-Secure Manager] "d:\Program Files\Sonera Internet Tietoturva\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "d:\Program Files\Sonera Internet Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "d:\Program Files\Sonera Internet Tietoturva\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [News Service] "d:\Program Files\Sonera Internet Tietoturva\FSGUI\ispnews.exe"
    O4 - HKLM\..\Run: [swcpshell] C:\Windows\System32\csharpshell.exe
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [ThreatFire] d:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\RunServices: [Winpower] "C:\Program Files\UpsPilot\Winpower.exe"
    O4 - HKCU\..\Run: [csharpshell] C:\Windows\System32\csharpshell.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: AutorunsDisabled
    O4 - Global Startup: AutorunsDisabled
    O4 - Global Startup: Sonera Tietoturva.lnk = D:\Program Files\Sonera Internet Tietoturva\backweb\4436233\Program\fspex.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files3\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files3\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files3\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: &Estä tämä kohoikkuna - d:\Program Files\Sonera Internet Tietoturva\Anti-Spyware\blockpopups.htm
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Avaa uuteen etuvälilehteen - res://C:\Program Files\Windows Live Toolbar\Components\fi-fi\msntabres.dll.mui/230?aa946b597d1344619a0fa5b4fa7a357b
    O8 - Extra context menu item: Avaa uuteen taustavälilehteen - res://C:\Program Files\Windows Live Toolbar\Components\fi-fi\msntabres.dll.mui/229?aa946b597d1344619a0fa5b4fa7a357b
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Lisää tämä blogiin - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Lisää tämä blogiin tuotteessa Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - d:\Program Files\Sonera Internet Tietoturva\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - d:\Program Files\Sonera Internet Tietoturva\Anti-Spyware\ieshield.dll
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://D:\Program Files3\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: rqRHbCrq - C:\WINDOWS\
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - d:\Program Files\a-squared Free\a2service.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Sonera Tietoturva (BackWeb Client - 4436233) - Sonera Tietoturva - d:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - d:\Program Files\Sonera Internet Tietoturva\backweb\4436233\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - d:\Program Files\Sonera Internet Tietoturva\FWES\Program\fsdfwd.exe
    O23 - Service: FSMA - F-Secure Corporation - d:\Program Files\Sonera Internet Tietoturva\Common\FSMA32.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Route Access Protocol Graphics (RAPG) - Unknown owner - C:\Program Files\Intel\SVCH0ST.exe (file missing)
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - d:\PROGRA~1\SPYWAR~1\sp_rsser.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: ThreatFire - PC Tools - d:\Program Files\ThreatFire\TFService.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    --
    End of file - 10885 bytes
     
  2.  
Viestiketjun tila:
Viestiketju on suljettu.

Jaa tämä sivu