Avatar billede shorty-on Nybegynder
05. juni 2005 - 14:30 Der er 4 kommentarer

HIjack THIS Clean

Jeg har en Hijack this Folder jeg skal have cleaned det er en kunde PC Nogen som kan hjælpe


Logfile of HijackThis v1.99.1
Scan saved at 14:22:21, on 05-06-2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Utimaco\SafeGuard Easy\SgeCtl.exe
C:\WINDOWS\System32\SgLogPlayer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Programmer\Utimaco\SafeGuard Easy\Ecview.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Utimaco\SafeGuard Easy\WKSCFGSRV.EXE
C:\Documents and Settings\Shorty\Skrivebord\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ya-hoo.biz/?a=2&b=dorki
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yapsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ya-hoo.biz/?a=2&b=dorki
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {8A61A09C-9E57-EC3D-1885-07C0C023D4B2} - MsNetHelper.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 69.64.35.177 auto.search.msn.com
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programmer\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\ayscg.dll
O2 - BHO: (no name) - {6FE95A2B-4827-FD9C-969B-91CD039B792E} - C:\WINDOWS\System32\zfrtrein.dll
O2 - BHO: (no name) - {9650A656-34FE-2FED-F151-357E9746019C} - C:\WINDOWS\System32\btmjlwod.dll
O2 - BHO: Internet Explorer Hot Fix - {9F7E4E23-6EF9-41C7-AF30-36260BA52D29} - C:\WINDOWS\System32\ozkej.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: (no name) - {B33176B5-B8B7-4351-9D1A-98281C95C552} - C:\WINDOWS\System32\shimengd.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: (no name) - {000277A3-7D84-406a-9799-D12A81594693} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programmer\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\ayscg.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EdWizard] C:\Programmer\Utimaco\SafeGuard Easy\EdWizard.exe as
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SgeEcView] C:\Programmer\Utimaco\SafeGuard Easy\Ecview.exe
O4 - HKLM\..\RunServices: [Adware Defence] Msoft32.exe
O4 - HKLM\..\RunServices: [Andware Defence] Zsoft32.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [gabber] ___.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029YYUS_ZNxmk142XXUS
O8 - Extra context menu item: Backward Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://195.95.218.82/users/zoom/web/axe/x.chm::/update.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971CanadaInc/ie/bridge-c9.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://www.toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{35650DC5-363A-4F94-90BA-07779F36C92D}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\Tcpip\..\{9363A8B5-0D7C-4D29-AEDB-EE74F05A6AE8}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB25E2D6-FE8E-4BCB-8765-0B072CB8EFD0}: NameServer = 69.50.184.84,195.225.176.37
O20 - Winlogon Notify: avpx32 - C:\WINDOWS\SYSTEM32\avpx32.dll
O20 - Winlogon Notify: NotLog - C:\WINDOWS\SYSTEM32\SGLogEx.dll
O20 - Winlogon Notify: SGLogNotification - C:\WINDOWS\SYSTEM32\SGLogNotification.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\Programmer\Utimaco\SafeGuard Easy\SgeCtl.exe
O23 - Service: SafeGuard SGLOG  Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINDOWS\System32\SgLogPlayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede majsmarken Nybegynder
05. juni 2005 - 17:41 #1
Avatar billede majsmarken Nybegynder
05. juni 2005 - 17:42 #2
Ka' de dog ikke snart lære det - samme plade:

Du har ikke opdateret dit Windows XP til ServicePack2 (SP2).
[1Klik.dk: Ubeskyttede pc’er holder i 20 minutter]:
http://1klik.dk/news_1klik/nyhed_32992.html

Det er ikke så godt, for så er du ikke sikret mod mange af de vira, der suser rundt på nettet og kigger efter uopdaterede maskiner.

Du kan hente SP2 her som 'løs' fil (~280Mb):
http://intern.sdu.dk/it-service/tjenester/ftphotel/ftpindhold/
Download/copy til et passende medie.
Afbryd fra det 'farlige' internet (stikket fysisk UD).
Instaler SP2 pakken.
Når det er så gået godt og efter en genstart eller to - først DA tilslut internettet igen og gå i start ->programmer ->Windowsupdate og lade din maskine scanne for nyeste opdateringer. Installer dem du får anbefalet.

Good Luck... men først når putter er erklæret 'ren' ...
Hvilket jeg vil lade andre eksperten om at bedømme - men der er rigeligt!!!

(Tja - hvis du ikke får dette gennemført ses vi nok snart igen...i virus kategorien?)

----
Avatar billede majsmarken Nybegynder
05. juni 2005 - 17:43 #3
PS: pt. modtager vi ikke automatisk E-mail fra Eksperten - derfor minimum af (retur)support...
Avatar billede kalp Novice
06. juni 2005 - 18:22 #4
Download og gem denne scanner på skrivebordet. (Vi skal bruge den senere)
http://www.spywareinfo.dk/download/mwav.exe

Genstart i Fejlsikret tilstand ved at taste F8 under opstart.

Kør HijackThis, scan og sæt et flueben ud for disse linjer - luk øvrige programvinduer. Dobbelt tjeck alt kom med!. Klik herefter "Fix checked" i hijackthis:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ya-hoo.biz/?a=2&b=dorki
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yapsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ya-hoo.biz/?a=2&b=dorki
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://ya-hoo.biz/?a=2&b=dorki
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {8A61A09C-9E57-EC3D-1885-07C0C023D4B2} - MsNetHelper.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 69.64.35.177 auto.search.msn.com
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\ayscg.dll
O2 - BHO: (no name) - {6FE95A2B-4827-FD9C-969B-91CD039B792E} - C:\WINDOWS\System32\zfrtrein.dll
O2 - BHO: (no name) - {9650A656-34FE-2FED-F151-357E9746019C} - C:\WINDOWS\System32\btmjlwod.dll
O2 - BHO: Internet Explorer Hot Fix - {9F7E4E23-6EF9-41C7-AF30-36260BA52D29} - C:\WINDOWS\System32\ozkej.dll
O2 - BHO: (no name) - {B33176B5-B8B7-4351-9D1A-98281C95C552} - C:\WINDOWS\System32\shimengd.dll
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file) 
O3 - Toolbar: (no name) - {000277A3-7D84-406a-9799-D12A81594693} - (no file) 
- Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\ayscg.dll
O4 - HKLM\..\RunServices: [Adware Defence] Msoft32.exe
O4 - HKLM\..\RunServices: [Andware Defence] Zsoft32.exe
O4 - HKCU\..\Run: [gabber] ___.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029YYUS_ZNxmk142XXUS
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://195.95.218.82/users/zoom/web/axe/x.chm::/update.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971CanadaInc/ie/bridge-c9.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{35650DC5-363A-4F94-90BA-07779F36C92D}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\Tcpip\..\{35650DC5-363A-4F94-90BA-07779F36C92D}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\Tcpip\..\{35650DC5-363A-4F94-90BA-07779F36C92D}: NameServer = 69.50.184.84,195.225.176.37

Upload disse filer

C:\WINDOWS\System32\SgLogPlayer.exe
C:\WINDOWS\SYSTEM32\SGLogNotification.dll

til disse to sider
http://www.kaspersky.com/scanforvirus
http://virusscan.jotti.org/

siger de det er snavs? så slet dem. og fortæl mig lige hvilke den siger er snavs til sidst.

Gå herefter i Start -> Programmer -> Tilbehør -> Systemværktøjer -> Diskoprydning og slet temp-filer, temporary internet files og papirkurv.

Klik på mwav.exe som du hentede, programmet pakker sig selv ud og starter.
Sæt flueben i følgende:
Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende:
All local drives og Scan all files

Genstart normalt og kopir en ny log herind så jeg kan se om vi fik ramt på det hele eller om noget er blevet overset:)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester