Avatar billede jackie18 Mester
21. maj 2005 - 13:27 Der er 8 kommentarer og
1 løsning

Trojan Horse

Hejsa jeg har lagt mærke til at jeg er blivet smittet af denne irriterende virus Trojan Horse..jeg har også lagt mærke til at jeg har mistet nogle data, tror det skyldes den her virus..

er her nogen som kan hjælpe mig med at fjerne den så den ikke kommer igen??

på forhånd tak.
Avatar billede arlet Juniormester
21. maj 2005 - 13:37 #1
Hent og kør denne meget effektive scanner fra Kaspersky : http://www.spywareinfo.dk/download/mwav.exe
Sæt flueben i følgende: Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende: All local drives og Scan all files
Og så trykker du på Scan Clean
Det tager lidt over en time at scanne


Hent derefter denne scanner:
Ewido kan du downloade her: http://www.ewido.net/en/download/
Klik på Download now. Installer og kør Ewido. Opdater straks efter installationen programmet, (men lad være med at scanne endnu).
Genstart i fejlsikret tilstand. Du skal klikke på f8 tasten under genstarten (ca. lige når der er talt ram), og så vælge fejlsikret tilstand. Er du i tvivl, så klik bare på f8 flere gange. Kør nu en fuld scanning med Ewido. Programmet laver en lille log, som du skal kopiere herind sammen med en hijackthis log taget efter du har kørt Ewido

genstart og så vil jeg gerne se en hijackthis: http://www.arlet.dk/hjt.htm
Avatar billede jackie18 Mester
21. maj 2005 - 13:44 #2
ok prøver dettte..tak:-)
Avatar billede jackie18 Mester
22. maj 2005 - 00:10 #3
Ok her er rapporten fra ewido.

ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            00:03:26, 22-05-2005
+ Report-Checksum:        FC305620

+ Date of database:        21-05-2005
+ Version of scan engine:    v3.0

+ Duration:                72 min
+ Scanned Files:            106974
+ Speed:                24.48 Files/Second
+ Infected files:            37
+ Removed files:            37
+ Files put in quarantine:        37
+ Files that could not be opened:    0
+ Files that could not be cleaned:    0

+ Binder:        Yes
+ Crypter:        Yes
+ Archives:        Yes

+ Scanned items:
    C:\
    D:\
    E:\
    G:\

+ Scan result:
    C:\WINDOWS\NDNuninstall4_85.exe -> Spyware.NewDotNet -> Cleaned with backup
    C:\WINDOWS\mxTarget.dll.mwt -> Spyware.BiSpy.f -> Cleaned with backup
    C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet -> Cleaned with backup
    C:\WINDOWS\webhdll.dll_tobedeleted -> Spyware.WebHancer -> Cleaned with backup
    C:\Documents and Settings\All Users\Dokumenter\install.exe.mwt -> Backdoor.Robobot.x -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Skrivebord\HijackThis\backups\backup-20050329-232946-916.dll -> Spyware.Azesearch.b -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@perf.overture[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@hb.lycos[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@zedo[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@geocities[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@a.as-us.falkag[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@as1.falkag[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@realmedia[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@burstnet[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@image.masterstats[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@gostats[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@cz9.clickzs[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@cz11.clickzs[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@server.iad.liveperson[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@mediaplex[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@targetnet[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@servedby.advertising[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@ehg-eline.hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Documents and Settings\Khaled Abou Chaker\Cookies\khaled abou chaker@ehg-guba.hitbox[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
    C:\Programmer\whInstall\WhAgent.exe -> Spyware.WebHancer.320 -> Cleaned with backup
    C:\Programmer\whInstall\WhSurvey.exe -> Spyware.WebHancer -> Cleaned with backup
    C:\Programmer\whInstall\Webhdll.dll -> Spyware.WebHancer -> Cleaned with backup
    C:\System Volume Information\_restore{79DBB899-3B8B-4F9F-B035-1FD4A261D9D5}\RP1\A0000051.dll -> Spyware.Azesearch.b -> Cleaned with backup
    C:\System Volume Information\_restore{79DBB899-3B8B-4F9F-B035-1FD4A261D9D5}\RP41\A0002715.exe.mwt -> Backdoor.Robobot.x -> Cleaned with backup
    C:\System Volume Information\_restore{79DBB899-3B8B-4F9F-B035-1FD4A261D9D5}\RP43\A0002892.exe.mwt -> Backdoor.Robobot.x -> Cleaned with backup
    C:\System Volume Information\_restore{79DBB899-3B8B-4F9F-B035-1FD4A261D9D5}\RP44\A0002920.exe.mwt -> Backdoor.Robobot.x -> Cleaned with backup
    C:\System Volume Information\_restore{79DBB899-3B8B-4F9F-B035-1FD4A261D9D5}\RP48\A0003150.exe.mwt -> Backdoor.Robobot.x -> Cleaned with backup
    E:\Programmer 2\hijackthis\backups\backup-20050101-150646-434.dll -> Spyware.Neon.a -> Cleaned with backup
    E:\Programmer 2\hijackthis\backups\backup-20050101-150646-915.dll -> Spyware.Neon.a -> Cleaned with backup


::Report End




og her er hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 00:09:27, on 22-05-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\Java\jre1.5.0_02\bin\jusched.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Khaled Abou Chaker\Skrivebord\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.signon.stofanet.dk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

???
Avatar billede arlet Juniormester
22. maj 2005 - 11:51 #4
Så er din computer ren igen .

Efter sådan en tur er det altid en god ide og rydde op i dine systemgendannelses filerne.
Deaktiver systemgendannelse ( http://www.arlet.dk/systemgendannelsen.htm ) - genstart din computer - aktiver systemgendannelse.

Generel oprydning: http://www.arlet.dk/oprydning.htm

For at beskytte dig mod snavs har jeg lavet en sikkerhedspakke,
som du kan hente her : www.arlet.dk/pakke.htm
Avatar billede jackie18 Mester
22. maj 2005 - 13:54 #5
tusind tak for hjælpen arlet!!!
Dvs fremover så¨kan der ikke komme nogen ind og hacke på min pc?
Avatar billede arlet Juniormester
22. maj 2005 - 14:16 #6
Man kan aldrig sikre sig 100%

Men med de programmer fra sikkerhedsopakken og specielt en firewall rækker et lang stykke hen af vejen
Avatar billede jackie18 Mester
22. maj 2005 - 16:57 #7
ok, dvs jeg skal hverdag begynder at køre de programmer du anbefaldte mig eller hva?
Avatar billede arlet Juniormester
22. maj 2005 - 17:06 #8
Nej. Når de er installeret, så passer de sig selv.. De skal opdateres en gang i mellem, men ellers ligger de bare i baggrunden..
Avatar billede jackie18 Mester
22. maj 2005 - 17:13 #9
ok tak for hjælpen:-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester