rr_a » 27 Des 2009, 14:03
og MGTool kan du hente her: - har ikke prøvd dette men majorgeeks forumet hevder det virker....
"PC infected? HTML:Iframe-inf detected on every website
--------------------------------------------------------------------------------
You have some infected system files. Let's do this:
It is a very bad idea to allow all users to have admin. privileges. Once malware gets into the system, it has free reign.
Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
Quote:
O4 - HKUS\S-1-5-18\..\Run: [vxrhkeje.exe] C:\WINDOWS\vxrhkeje.exe (User 'SYSTEM')
After clicking Fix, exit HJT.
Use windows explorer to find and delete ( if there ):
C:\WINDOWS\vxrhkeje.exe
C:\Documents and Settings\Scott Kelley\ixnric.exe
Now we need to replace these:
Quote:
c:\windows\system32\userinit.exe . . . is infected!!
c:\windows\system32\svchost.exe . . . is infected!!
c:\windows\system32\spoolsv.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
Go to each of these and copy then paste:
C:\WINDOWS\ServicePackFiles\i386\userinit.exe --> to c:\windows\system32\
C:\WINDOWS\ServicePackFiles\i386\svchost.exe --> to c:\windows\system32\
C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe --> to c:\windows\system32\
C:\WINDOWS\ServicePackFiles\i386\explorer.exe --> to c:\windows\
You will first have to open task manager and end the spoolsv process.
Let me know if you have any problems with doing this.
If not, then re-run ComboFix and attach the new log."