Avatar billede flemming_a Nybegynder
27. april 2005 - 17:02 Der er 4 kommentarer og
1 løsning

hjt log

Logfile of HijackThis v1.99.1
Scan saved at 16:57:44, on 27/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\WAFFLEz\mlg1.exe
C:\WINDOWS\System32\raxfivoa.exe
C:\WINDOWS\mmups.exe
C:\WINDOWS\suploads.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\D-Tools\daemon.exe
C:\s.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msnmessag.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\System32\packager.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\WinRAR\WinRAR.exe
C:\DOCUME~1\Martin\LOKALE~1\Temp\Rar$EX06.437\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.irutnwiyczfjhtkavu.com/opOS47OQt5zXoQakWQ1q2F1ZlS6WsjF5Vfm1vnFCbw6mSlg1Pz8lKj/U9rI2Qvci.jpg
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.habbohotel.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
F3 - REG:win.ini: load=C:\Programmer\WAFFLEz\mlg1.exe
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll
O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Programmer\Hotbar\bin\4.4.5.0\HbHostIE.dll
O2 - BHO: (no name) - {B6A19E69-CFD7-4779-00F0-28D1546F55FC} - C:\DOCUME~1\Martin\APPLIC~1\DEFYNO~1\Does Corn.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {ED626BCF-5209-4321-56C9-333790BACD30} - C:\DOCUME~1\Martin\APPLIC~1\DEFYNO~1\Does Corn.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Programmer\Hotbar\bin\4.4.5.0\HbHostIE.dll
O3 - Toolbar: TaskMates Toolbar - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - C:\Program Files\TaskMates\taskmates.dll (file missing)
O4 - HKLM\..\Run: [vihsnl] C:\WINDOWS\System32\raxfivoa.exe
O4 - HKLM\..\Run: [mediamotor.exe] C:\WINDOWS\mmups.exe
O4 - HKLM\..\Run: [loads.exe] C:\WINDOWS\suploads.exe
O4 - HKLM\..\Run: [Fgkzdar] C:\Program Files\Vmvmdzr\Mkxahz.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [axis close manager tool] C:\Documents and Settings\All Users\Application Data\List Bleh Axis Close\MeetTest.exe
O4 - HKLM\..\Run: [MSN Messages] msnmessag.exe
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler V1.39.12R] C:\s.exe
O4 - HKLM\..\RunServices: [MSN Messages] msnmessag.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ace trans] C:\DOCUME~1\Martin\APPLIC~1\COALUS~1\Bin Start Team.exe
O4 - HKCU\..\Run: [MSN Messages] msnmessag.exe
O4 - HKCU\..\RunServices: [MSN Messages] msnmessag.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {0556834E-F56C-4545-8FAD-4F0ED25999BE} (Jackie Control) - http://www.6jackpot.com/dialup/jackie.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=cc06fae0c5ce5e53c21bbcb067bafa2669a8f3cc9bf62eb65f31f229f0bf3037e6b6c7de8b77c1691c31a7a022e9d947db95c2df87b2028996eb59cfdba645:ad6c8f07bb920312228695168af3c74a
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {C56CE781-A6FC-4706-8B32-6EB4622155DF} (MediaConnect Control) - http://plugin.euro-infomedia.com/mpv0.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://scanner.virus112.com/cabs/cssweb.cab
O16 - DPF: {D22AC3EF-B7D8-11D5-A281-005056BF0101} (plug Class) - http://www.gxplugin.com/loader/dll/gxbplug.dll
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/diamond.cab
O16 - DPF: {E154E3CC-0C3A-4101-91D8-6B4876F0FD64} (PrintScreen Class) - http://www.myemo.com/my_picture/Flash2Image.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
Avatar billede levich Nybegynder
27. april 2005 - 17:14 #1
jeg ser på den
Avatar billede levich Nybegynder
27. april 2005 - 17:35 #2
Du har en masser "skrammel" på din computer, bl.a. har du fået virus via MSN Messenger. SE her: http://castlecops.com/postp520892.html. Men det kan godt fjernes.

(1)
Deaktiver systemgendannelse, ved at Højreklikke på "Denne Computer" på skrivebordet -> egenskaber -> Systemgendannelse -> sæt flueben i "Deaktiver systemgendannelse" -> Klik OK.

(2)
Hent scannereren http://www.spywareinfo.dk/download/mwav.exe, som vi skal bruge senere.

(3)
Genstart computeren i fejlsikret tilstand (tryk F8 når Windows starter op), og fix følgende linjer med HijackThis:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.irutnwiyczfjhtkavu.com/opOS47OQt5zXoQakWQ1q2F1ZlS6WsjF5Vfm1vnFCbw6mSlg1Pz8lKj/U9rI2Qvci.jpg
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
F3 - REG:win.ini: load=C:\Programmer\WAFFLEz\mlg1.exe
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll
O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Programmer\Hotbar\bin\4.4.5.0\HbHostIE.dll
O2 - BHO: (no name) - {B6A19E69-CFD7-4779-00F0-28D1546F55FC} - C:\DOCUME~1\Martin\APPLIC~1\DEFYNO~1\Does Corn.exe
O2 - BHO: (no name) - {ED626BCF-5209-4321-56C9-333790BACD30} - C:\DOCUME~1\Martin\APPLIC~1\DEFYNO~1\Does Corn.exe
O3 - Toolbar: &Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Programmer\Hotbar\bin\4.4.5.0\HbHostIE.dll
O3 - Toolbar: TaskMates Toolbar - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - C:\Program Files\TaskMates\taskmates.dll (file missing)
O4 - HKLM\..\Run: [vihsnl] C:\WINDOWS\System32\raxfivoa.exe
O4 - HKLM\..\Run: [mediamotor.exe] C:\WINDOWS\mmups.exe
O4 - HKLM\..\Run: [loads.exe] C:\WINDOWS\suploads.exe
O4 - HKLM\..\Run: [Fgkzdar] C:\Program Files\Vmvmdzr\Mkxahz.exe
O4 - HKLM\..\Run: [axis close manager tool] C:\Documents and Settings\All Users\Application Data\List Bleh Axis Close\MeetTest.exe
O4 - HKLM\..\Run: [MSN Messages] msnmessag.exe
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler V1.39.12R] C:\s.exe
O4 - HKLM\..\RunServices: [MSN Messages] msnmessag.exe
O4 - HKCU\..\Run: [ace trans] C:\DOCUME~1\Martin\APPLIC~1\COALUS~1\Bin Start Team.exe
O4 - HKCU\..\Run: [MSN Messages] msnmessag.exe
O4 - HKCU\..\RunServices: [MSN Messages] msnmessag.exe
O16 - DPF: {0556834E-F56C-4545-8FAD-4F0ED25999BE} (Jackie Control) - http://www.6jackpot.com/dialup/jackie.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=cc06fae0c5ce5e53c21bbcb067bafa2669a8f3cc9bf62eb65f31f229f0bf3037e6b6c7de8b77c1691c31a7a022e9d947db95c2df87b2028996eb59cfdba645:ad6c8f07bb920312228695168af3c74a
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {C56CE781-A6FC-4706-8B32-6EB4622155DF} (MediaConnect Control) - http://plugin.euro-infomedia.com/mpv0.cab
O16 - DPF: {D22AC3EF-B7D8-11D5-A281-005056BF0101} (plug Class) - http://www.gxplugin.com/loader/dll/gxbplug.dll
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/diamond.cab
O16 - DPF: {E154E3CC-0C3A-4101-91D8-6B4876F0FD64} (PrintScreen Class) - http://www.myemo.com/my_picture/Flash2Image.cab

BEMÆRK:
Kender du www.habbohotel.dk. Hvis ikke så fix også linjen:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.habbohotel.dk/

Kunder du www.errorguard. Hvis ikke så fix også linjen:
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab

Åbn en tilfældig mappe, i menuen klik på Funktioner -> Mappeindstillinger -> Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

søg efter og slet følgende filer:
C:\WINDOWS\ceres.dll
C:\DOCUME~1\Martin\APPLIC~1\DEFYNO~1\Does Corn.exe
C:\DOCUME~1\Martin\APPLIC~1\DEFYNO~1\Does Corn.exe
C:\WINDOWS\System32\raxfivoa.exe
C:\WINDOWS\mmups.exe
C:\WINDOWS\suploads.exe
C:\Documents and Settings\All Users\Application Data\List Bleh Axis Close\MeetTest.exe
msnmessag.exe
C:\s.exe
C:\DOCUME~1\Martin\APPLIC~1\COALUS~1\Bin Start Team.exe

... og følgende mapper:
C:\Programmer\WAFFLEz\
C:\Programmer\Hotbar\
C:\Program Files\TaskMates\
C:\Program Files\Vmvmdzr\

(4)
Start -> programmer -> tilbehør -> systemværktøjer -> diskoprydning -> Slet Temporary internet files, papirkurv og midlertidige filer.

(5)
Kør scanneret mwav.exe, og sæt flueben i følgende:
Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende: All local drives og Scan all files.
Tryk på Scan Clean
Scanningen kan godt tage et par timer.

(6)
Genstart computeren normalt. Lav en ny log med HijackThis, og send den herind.

(7)
Når vi er helt færdige, så husk at aktiver systemgendannelse igen.
Avatar billede flemming_a Nybegynder
27. april 2005 - 18:47 #3
det er ikke min pc så svar tager nok lidt tid
Avatar billede flemming_a Nybegynder
27. april 2005 - 18:47 #4
smid lige et svar med samme
Avatar billede levich Nybegynder
27. april 2005 - 21:38 #5
svar
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester