SPYAXE 3.0 spyware
Hej!Jeg er også blevet invaderet af det lort håber der er noget hjælp at hente :)
På forhånd 1.000 TAK!
Chris Sørensen
Logs:
-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 20487
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 9
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 2
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 11
Objects moved: 0
Objects ignored: 0
Scan speed: 1878 Kb/s
Scan time: 00:11:49
-----------------------------------------------------------------------------
---------------------------------------------------------
ewido security suite - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 23:26:51, 11-12-2005
+ Rapport-Checksum: 950F942F
+ Scanningsresultat:
F:\WINDOWS\system32\ld5709.tmp -> Downloader.Zlob.cj : Renset med backup
F:\WINDOWS\system32\mssearchnet.exe -> Downloader.Zlob.cm : Renset med backup
::Rapport slut
Logfile of HijackThis v1.99.1
Scan saved at 23:41:46, on 11-12-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\System32\Ati2evxx.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\Ati2evxx.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
F:\Programmer\ewido\security suite\ewidoctrl.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\nvctrl.exe
F:\Programmer\Internet Explorer\IEXPLORE.EXE
F:\Documents and Settings\Chris Sørensen\Skrivebord\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: HomepageBHO - {1ca480cd-c0e5-4548-874e-b85b17905b3a} - F:\WINDOWS\System32\hp514C.tmp
O4 - HKLM\..\Run: [SpyAxe] F:\Programmer\SpyAxe\spyaxe.exe /h
O4 - HKCU\..\Run: [msnmsgr] "F:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - F:\Programmer\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ewido security suite control - ewido networks - F:\Programmer\ewido\security suite\ewidoctrl.exe
Det var alt jeg fik af logs, håber det er nok til at jeg kan blive fri for det SpyAxe fis...
