Gaobot/Windows lukker programmer endnu en gang
Endnu en forespørgelse på en XP inficeret med (måske) Gaobot.Jeg har set de andre tråde om, hvordan man skal installere Spybot og opdatere det – Check!
Jeg har scannet min maskine med den opdaterede Spybot, fixet de ting den kunne fixe og genstartet den – Check!
Ingen nye bots fundet.
Jeg har installeret HiJackThis, scannet min computer og savet Logfilen, som jeg så præsentere her!
Logfile of HijackThis v1.97.7
Scan saved at 22:40:10, on 20-01-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\System32\Ati2evxx.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\Explorer.EXE
H:\Programmer\Messenger\msmsgs.exe
H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_AICN03.EXE
H:\WINDOWS\System32\esoh123.exe
H:\Programmer\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
H:\Programmer\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
H:\Programmer\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
H:\Programmer\Spybot - Search & Destroy\SpybotSD.exe
C:\Back-up\Spy\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsc.discovery.com/news/news.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - H:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SCANINICIO] "H:\Programmer\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "H:\Programmer\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [esoh] esoh123.exe
O4 - HKLM\..\RunServices: [esoh] esoh123.exe
O4 - HKCU\..\Run: [MSMSGS] "H:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus COLOR 480SXU] H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_AICN03.EXE /P25 "EPSON Stylus COLOR 480SXU" /O6 "USB001" /M "Stylus COLOR 480SXU"
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38005.6219675926
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Hvilke filer skal slettes?
MVH
WormHeart
