Avatar billede Slettet bruger
13. marts 2005 - 17:55 Der er 6 kommentarer og
1 løsning

Check lige denne Hijackthislog!

Check lige den her hijackthislog!
Dette er min kusines computer som hun har haft problemer med. F.eks. har hun problemer med reklamer, hijacking af IE, og spyware som prøver at ringe op. Jeg har prøvet at deaktivere alt skidtet via msconfig. CWShredder fandt intet og Spybot og Ad-Aware finder altid noget og sletter det, men det generer af sig selv.

Loggen:
Logfile of HijackThis v1.99.1
Scan saved at 17:37:00, on 13-03-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pd7.exe
C:\Program Files\Media Pass\MediaPassK.exe
C:\WINDOWS\luoos.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Program Files\Media Pass\MediaPass.exe
C:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe
C:\Programmer\ISTsvc\istsvc.exe
C:\WINDOWS\inetdata\services.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\inetdata\explorer.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\dstart.exe
C:\Documents and Settings\ch@anett\Dokumenter\Internet Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://letgohome.com/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://letgohome.com/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://letgohome.com/hp.htm?id=9
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search-paga.com/10039/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://letgohome.com/hp.htm?id=9
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F3 - REG:win.ini: run=C:\WINDOWS\inetdata\services.exe
O1 - Hosts: 69.50.164.77 google.com www.google.com
O2 - BHO: (no name) - {0F9561D0-03B2-44a3-89A6-E95E417CBA25} - C:\WINDOWS\cerbmod.dll
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - C:\WINDOWS\sasetup.dll
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.3000.1001\da\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.3000.1001\da\msntb.dll
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O4 - HKLM\..\Run: [printer] C:\WINDOWS\bstart.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Programmer\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe
O4 - HKLM\..\Run: [VTBbv] C:\WINDOWS\luoos.exe
O4 - HKLM\..\Run: [absl] C:\WINDOWS\absl.exe
O4 - HKLM\..\Run: [kutlF44J] C:\WINDOWS\luoos.exe
O4 - HKLM\..\Run: [<°‡@¡±§Tlçÿ[Ì…*9ÀÌC:\Programmer\ISTsvc\istsvc.exe] C:\WINDOWS\luoos.exe
O4 - HKLM\..\Run: [IST Service] C:\Programmer\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
O4 - Global Startup: Microsoft Office.hta
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {D9ED79BB-5D8E-4E90-8E0F-22D18270E0C0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D9ED79BB-5D8E-4E90-8E0F-22D18270E0C0} - (no file) (HKCU)
O16 - DPF: {0A9C6BE0-C69C-191C-0CD3-5DCC3E421626} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {0DCC337F-A690-5E93-EE76-200F7AD88FD5} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {12C2B12A-6D1E-2712-8B4A-41B47D4FEB3A} - http://69.50.182.94/1/rdgDK994.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {23A1E1A7-1417-26EB-5354-001827E2B3C6} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {24F8054D-1F09-6B67-7673-07EF11AA7550} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {37F558E1-AD11-552B-9216-0DE64D27A9AE} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {3E2D8495-9230-7FD7-5DDB-07047362B934} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {4C4B02E8-9F0D-3EF8-841B-4A5B6A5A766E} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5BA42FE8-1FDB-3FBA-26D7-25A2422E8569} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {5CC67D01-0B9E-2A29-E22B-32A96BB1C498} - http://69.50.182.94/1/rdgDK994.exe
O16 - DPF: {5F21F19D-877D-3D87-455C-1CE17BF06C7E} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {6410F6DC-8C7D-5035-A3E7-41D81DA4D444} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {68DC4038-56BB-14E2-CB5E-11264B97DCEA} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B32CA9B-806E-2EDD-E2C1-364C6B11EB64} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} - http://www.globalphon.com/dialer/internazionale_ver4.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C56CE781-A6FC-4706-8B32-6EB4622155DF} (MediaConnect Control) - http://plugin.euro-infomedia.com/mpv0.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O20 - AppInit_DLLs: 2v59ldmtc8mtulll.dll.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Tak på forhånd!!
Svar hurtigst muligt, t ak
Avatar billede arlet Juniormester
13. marts 2005 - 18:02 #1
tjekker den nu
Avatar billede arlet Juniormester
13. marts 2005 - 18:06 #2
Du skal nu til at i gang med at fixe:

Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.
Dobbelttjek, så alt kommer med.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://letgohome.com/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://letgohome.com/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://letgohome.com/hp.htm?id=9
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search-paga.com/10039/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://letgohome.com/hp.htm?id=9

F3 - REG:win.ini: run=C:\WINDOWS\inetdata\services.exe

O1 - Hosts: 69.50.164.77 google.com www.google.com

O2 - BHO: (no name) - {0F9561D0-03B2-44a3-89A6-E95E417CBA25} - C:\WINDOWS\cerbmod.dll
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - C:\WINDOWS\sasetup.dll
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)

O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
O4 - HKLM\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O4 - HKLM\..\Run: [printer] C:\WINDOWS\bstart.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe
O4 - HKLM\..\Run: [VTBbv] C:\WINDOWS\luoos.exe
O4 - HKLM\..\Run: [absl] C:\WINDOWS\absl.exe
O4 - HKLM\..\Run: [kutlF44J] C:\WINDOWS\luoos.exe
O4 - HKLM\..\Run: [<°‡@¡±§Tlçÿ[Ì…*9ÀÌC:\Programmer\ISTsvc\istsvc.exe] C:\WINDOWS\luoos.exe
O4 - HKLM\..\Run: [IST Service] C:\Programmer\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe

O9 - Extra button: Microsoft AntiSpyware helper - {D9ED79BB-5D8E-4E90-8E0F-22D18270E0C0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D9ED79BB-5D8E-4E90-8E0F-22D18270E0C0} - (no file) (HKCU)

O16 - DPF: {0A9C6BE0-C69C-191C-0CD3-5DCC3E421626} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {0DCC337F-A690-5E93-EE76-200F7AD88FD5} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {12C2B12A-6D1E-2712-8B4A-41B47D4FEB3A} - http://69.50.182.94/1/rdgDK994.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {23A1E1A7-1417-26EB-5354-001827E2B3C6} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {24F8054D-1F09-6B67-7673-07EF11AA7550} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {37F558E1-AD11-552B-9216-0DE64D27A9AE} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {3E2D8495-9230-7FD7-5DDB-07047362B934} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {4C4B02E8-9F0D-3EF8-841B-4A5B6A5A766E} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {5BA42FE8-1FDB-3FBA-26D7-25A2422E8569} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {5CC67D01-0B9E-2A29-E22B-32A96BB1C498} - http://69.50.182.94/1/rdgDK994.exe
O16 - DPF: {5F21F19D-877D-3D87-455C-1CE17BF06C7E} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {6410F6DC-8C7D-5035-A3E7-41D81DA4D444} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {68DC4038-56BB-14E2-CB5E-11264B97DCEA} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {7B32CA9B-806E-2EDD-E2C1-364C6B11EB64} - http://69.50.182.94/1/rdgDK896.exe
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} - http://www.globalphon.com/dialer/internazionale_ver4.CAB

O20 - AppInit_DLLs: 2v59ldmtc8mtulll.dll.dll

--------------------------------------------------------------------

Åbn en tilfældig mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

--------------------------------------------------------------------

Find og slet manuelt i fejlsikret(f8 ved opstart):


C:\WINDOWS\system32\pd7.exe
C:\WINDOWS\luoos.exe
C:\Program Files\Media Pass<-hele mappen
C:\Programmer\ISTsvc<-hele mappen
C:\WINDOWS\inetdata<-hele mappen


------------------------------------------------

Hent og kør spybot herfra: http://www.arlet.dk/spywarescanner.htm
scan hele computeren og slet alt hvad den finder

----------------------------------------------------------

Hent og kør denne scanner fra Kaspersky : http://www.spywareinfo.dk/download/mwav.exe
Sæt flueben i følgende: Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende: All local drives og Scan all files
Og så trykker du på Scan Clean

----------------------------------------------------------

Derefter genstarter du og sender en ny log herind, for at se om vi har fået den helt ren.
Avatar billede Slettet bruger
13. marts 2005 - 18:12 #3
Tusind tak for hjælpen! Vil nu gå igang med at fixe.
Avatar billede majsmarken Nybegynder
13. marts 2005 - 20:03 #4
<arlet>: Du ved så meget - har du noget på denne: http://www.eksperten.dk/spm/596825
(Undskyld "spam"...)
Avatar billede Slettet bruger
13. marts 2005 - 20:04 #5
Gjorde som der blev sagt, og her er loggen:

Logfile of HijackThis v1.99.1
Scan saved at 20:03:14, on 13-03-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe
C:\Documents and Settings\ch@anett\Dokumenter\Internet Downloads\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.3000.1001\da\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.3000.1001\da\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C56CE781-A6FC-4706-8B32-6EB4622155DF} (MediaConnect Control) - http://plugin.euro-infomedia.com/mpv0.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Har deaktiveret systemgendannelse og aktiveret den igen efter genstart!
Avatar billede arlet Juniormester
13. marts 2005 - 20:54 #6
Majsmarken-> Nej desværre..

joniz->
Så er din log ren.

For at beskytte dig mod snavs har jeg lavet en sikkerhedspakke,
som du kan hente her : www.arlet.dk/pakke.htm
Avatar billede Slettet bruger
14. marts 2005 - 15:10 #7
OK, tusind tak! :D

Men har selv en lille sikkerhedspakke som jeg har fået samlet hen vejen (igennem de sidste par år). Bl.a. Spybot, Ad-Aware, MS AntiSpyware, SpywareBlaster, SpywareGuard, Spydoctor og engang SpySweeper men den udløb! osv osv ..

Ellers mange tak!
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester