Avatar billede aloes7 Nybegynder
10. december 2005 - 22:34 Der er 7 kommentarer og
1 løsning

cydoor.topicks.a

Når jeg scanner finder jeg"cydoor.topicks.a" MWTI e-scan skriver at den er fjernet,men når jeg laver en ny scanning er den der igen,hvad skal jeg gøre??
CJ
Avatar billede fromsej Praktikant
10. december 2005 - 22:40 #1
Følg vejledningen i denne artikel:
http://exp.dk/artikler/755
Avatar billede aloes7 Nybegynder
11. december 2005 - 00:39 #2
Resultat af de i vejledning foreskrevne tiltag:

Logfile of HijackThis v1.99.1
Scan saved at 23:34:09, on 10-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\Option\GlobeTrotter Mobility Manager\MobilityManager.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Option\GlobeTrotter Mobility Manager\VirtualWirelessDevice.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Avant Browser\avant.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\C-J\Local Settings\Temporary Internet Files\Content.IE5\QXA543ON\hijackthis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: GlobeTrotter Mobility Manager.lnk = C:\Program Files\Option\GlobeTrotter Mobility Manager\MobilityManager.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Bloker alle billeder fra den samme server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Marker forekomster af ord på denne side - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Open In New Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O8 - Extra context menu item: Søg på ord - C:\Program Files\Avant Browser\Search.htm
O8 - Extra context menu item: Tilføj til Ad Blocker - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Åbn alle links på denne side... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Åbn i ny Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{028952CF-C395-48EA-A1FD-6569C77779AA}: NameServer = 194.65.100.117
O17 - HKLM\System\CS1\Services\Tcpip\..\{028952CF-C395-48EA-A1FD-6569C77779AA}: NameServer = 194.65.100.117
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

DR WEB:
-----------------------------------------------------------------------------
Estatísticas
-----------------------------------------------------------------------------
Objectos verificados: 94
Objectos infectados encontrados: 0
Objectos com modificações encontrados: 0
Objectos suspeitos encontrados: 0
Programas Adware encontrados: 0
Programas Dialer encontrados: 0
Programas Joke encontrados: 0
Programas Riskware encontrados: 0
Programas Hacktool encontrados: 0
Objectos curados: 0
Objectos eliminados: 0
Objectos renomeados: 0
Objectos movidos: 0
Objectos ignorados: 0
Velocidade de verificação: 2413 Kb/s
Tempo de verificação: 00:00:14

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:  23:18:25, 10-12-2005
+ Report-Checksum:  4BCFB45E

+ Scan result:

No infected objects found.


::Report End
Avatar billede fromsej Praktikant
11. december 2005 - 13:21 #3
Logfilerne er rene.
Hvor finder MTWI (Mwav) Cydoor henne?
Avatar billede aloes7 Nybegynder
11. december 2005 - 14:38 #4
Her er bæstet!

Sat Dec 10 20:36:29 2005 => Offending file found: C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\symantec\COMMON~1\settings.dat
Sat Dec 10 20:36:29 2005 => System found infected with cydoor.topicks.a Spyware/Adware (settings.dat)! Action taken: Entries Removed.
Sat Dec 10 20:36:29 2005 => Object "cydoor.topicks.a Spyware/Adware" found in File System! Action Taken: Entries Removed.


Sat Dec 10 20:36:31 2005 => ***** Scanning Registry for errors created because of Adware/Spyware *****
Sat Dec 10 20:36:49 2005 => Clearing Temporary sub-folders as Spyware/Adware found in system...
Sat Dec 10 20:37:05 2005 => Please Wait Exiting Application...

Sat Dec 10 20:37:07 2005 => Total Objects Scanned: 22569
Sat Dec 10 20:37:07 2005 => Total Virus(es) Found: 1
Sat Dec 10 20:37:07 2005 => Total Disinfected Files: 0
Sat Dec 10 20:37:07 2005 => Total Files Renamed: 0
Sat Dec 10 20:37:07 2005 => Total Deleted Objects: 1
Avatar billede fromsej Praktikant
11. december 2005 - 16:06 #5
Det lyder mystisk.
Prøv at kopiere Settings.dat i den mappe, så kan du uploade kopien hos Jotti, jeg tror ikke du får lov at uploade den originale, jeg ved det dog ikke 100%.
http://virusscan.jotti.org/
Lad os høre resultatet.
Avatar billede aloes7 Nybegynder
15. december 2005 - 17:25 #6
Jeg er ikke nogen ørn til det her,jeg kan ikke få uploadningen til at gå i hak,vil du venligst lukke,så kan vi begynde forfra,foreløbig TAK!
C-J
Avatar billede aloes7 Nybegynder
13. januar 2006 - 16:08 #7
Jeg er blevet af med Cyador,jeg må tilstå jeg er ikke helt klar over hvilken af scannerne der fik has på den.Jeg takker og vil gerne af med mine point-tak! C-J.
Avatar billede fromsej Praktikant
13. januar 2006 - 16:26 #8
Der kommer da et svar så.*S*
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester