Avatar billede h-hansen Nybegynder
14. oktober 2006 - 12:44 Der er 11 kommentarer og
2 løsninger

Hijackthis-log

Min søns PC er blevet umådeligt sløv, og jeg har scannet den med diverse virus og spywarescannere, uden den helt store succes. I joblisten studsede jeg over en proces "VcDebugOnce.exe" - den ligger højt i CPU-brug(?) - ofte på 99.
Dette er iøvrigt mit debutspørgsmål her på Eksperten, hvor jeg tidligere har fundet mange nyttige råd.
Jeg medsender en log fra Hijackthis, og håber der er nogle lyse hoveder der kan hjælpe:

Logfile of HijackThis v1.99.1
Scan saved at 12:23:58, on 14-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.EXE
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\LVComS.exe
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\WINDOWS\System32\svchost.exe
c:\docume~1\s-pirit\applic~1\holebl~1\VcDebugOnce.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\S-PiriT\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LanguageShortcut] C:\Programmer\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [twobluedogbrowse] C:\Documents and Settings\All Users\Application Data\obj list two blue\poll chin.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [More ping] C:\DOCUME~1\S-PiriT\APPLIC~1\HOLEBL~1\BoltMp3.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase969.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154709481171
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winrzf32 - winrzf32.dll (file missing)
O21 - SSODL: died - {7fa55359-7223-410f-bc82-efb3e3ded07f} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede ejvindh Ekspert
16. oktober 2006 - 00:28 #1
-- Hent NoLop.exe og gem den på skrivebordet:
http://www.spywareedge.net/nolop/NoLop.exe

Kør programmet. Tryk på "Search and Destroy"-knappen. Hvis den finder noget, bliver du bedt om at trykke på Reboot-knappen. Dette skal du så gøre.

Efter genstarten har NoLop.exe lavet en log-fil, der ligger her: C:\NoLop.txt
Kopiér indholdet af denne fil herind.

-- Hent S!Ri's SmitfraudFix.zip og pak det ud til dit Skrivebord.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Programmet pakker sig ud i en mappe, der hedder SmitfraudFix.

NB: Filen "process.exe" som ligger i dette værktøj bliver af visse antivirus-programmer identificeret som "RiskTool". Det har dog ikke noget på sig!

-- Hent AVG Anti-Spyware herfra (14 dages version af plus-versionen)
http://www.spywarefri.dk/downloads1.htm
Installer og opdater programmet, men vent med at scanne.

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Åbn mappen SmitfraudFix som du fik på Skrivebordet, og dobbeltklik på SmitfraudFix.cmd og tast 2 - svar ja til at rense (y=yes). Lad programmet gennemføre en rensning. Det vil også checke om systemfilen wininet.dll er inficeret. Hvis den er det, vil du blive bedt om tilladelse til at erstatte den med en anden. Her skal du vælge "Yes", ved at taste "y".

Programmet bliver muligvis nødt til at genstarte undervejs. Herefter vil der dukke en liste med resultaterne af rensningen op . Kopiér denne liste ind i tråden.

-- Kør en fuld scanning med AVG Anti-Spyware, og tillad programmet at fixe de ting, som det finder. Programmet laver en lille log, som du skal kopiere herind.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked (nogle af linierne er muligvis allerede forsvundet).

O4 - HKLM\..\Run: [twobluedogbrowse] C:\Documents and Settings\All Users\Application Data\obj list two blue\poll chin.exe
O4 - HKCU\..\Run: [More ping] C:\DOCUME~1\S-PiriT\APPLIC~1\HOLEBL~1\BoltMp3.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
O20 - Winlogon Notify: winrzf32 - winrzf32.dll (file missing)
O21 - SSODL: died - {7fa55359-7223-410f-bc82-efb3e3ded07f} - (no file)

-- Genstart og læg en frisk Hijackthislog herind, sammen med loggen fra AVG Anti-Spyware og loggen fra SmitfraudFix (C:\rapport.txt) og loggen fra Nolop.
Avatar billede h-hansen Nybegynder
16. oktober 2006 - 11:40 #2
Hej ejvindh. Tak for den meget udførlige vejledning. Min søn kom i tanker om noget han havde installeret for nylig - "netpumper" eller noget i den stil(?). Han fik det afinstalleret igen, og den meget livlige proces VcDebugOnce.exe er nu ude igen, og maskinen opfører sig tilsyneladende normalt. Men jeg vil alligevel følge din vejledning, for det er bestemt ikke utænkeligt er der er andet rod på hans maskine - på trods af fars moralprædikener og manen til forsigtighed og omtanke. Jeg vender tilbage med logfilerne så snart jeg har dem.
Avatar billede ejvindh Ekspert
16. oktober 2006 - 12:16 #3
Ja, jeg synes i hvert fald vejledningen skal følges alligevel, idet der var 2 forskellige infektioner på computeren. Og man kan som regel ikke helt stole på at en afinstaller fjerner det hele ;-)
Avatar billede h-hansen Nybegynder
16. oktober 2006 - 21:41 #4
Så blev der endelig tis til at komme i gang. Her er først loggen fra NoLop
(Jeg fortsætter nu med SmitfraudFix):

NoLop! Log by Skate_Punk_21

Fix running from: C:\Documents and Settings\S-PiriT\Skrivebord
[16-10-2006]
[21:33:51]

---Infection Files Found/Removed---
C:\WINDOWS\tasks\A8DB874D91300085.job

Beginning Removal...
Rebooting...

Beginning Removal...
Rebooting...
Removing Lop's Leftover Files/Folders...
Editing Registry...
**Fix Complete!**

---Listing AppData sub directories---

C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Aol
C:\Documents and Settings\All Users\Application Data\Aol Downloads
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Autodesk
C:\Documents and Settings\All Users\Application Data\Avg7
C:\Documents and Settings\All Users\Application Data\Cyberlink
C:\Documents and Settings\All Users\Application Data\Grisoft
C:\Documents and Settings\All Users\Application Data\Messenger Plus!
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Obj List Two Blue
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\Default User\Application Data\Microsoft
C:\Documents and Settings\Localservice\Application Data\Avg7  -- EMPTY Directory
C:\Documents and Settings\Localservice\Application Data\Microsoft
C:\Documents and Settings\Networkservice\Application Data\Microsoft
C:\Documents and Settings\S-pirit\Application Data\Apple Computer
C:\Documents and Settings\S-pirit\Application Data\Ati
C:\Documents and Settings\S-pirit\Application Data\Autodesk
C:\Documents and Settings\S-pirit\Application Data\Avg7  -- EMPTY Directory
C:\Documents and Settings\S-pirit\Application Data\Azureus
C:\Documents and Settings\S-pirit\Application Data\Cyberlink
C:\Documents and Settings\S-pirit\Application Data\Dvdcss
C:\Documents and Settings\S-pirit\Application Data\Google
C:\Documents and Settings\S-pirit\Application Data\Hole Bleh Aim
C:\Documents and Settings\S-pirit\Application Data\Identities
C:\Documents and Settings\S-pirit\Application Data\Lavasoft
C:\Documents and Settings\S-pirit\Application Data\Leadertech
C:\Documents and Settings\S-pirit\Application Data\Macromedia
C:\Documents and Settings\S-pirit\Application Data\Microsoft
C:\Documents and Settings\S-pirit\Application Data\Mozilla
C:\Documents and Settings\S-pirit\Application Data\Netpumper
C:\Documents and Settings\S-pirit\Application Data\Sun
C:\Documents and Settings\S-pirit\Application Data\Superantispyware.com
C:\Documents and Settings\S-pirit\Application Data\Teamspeak2
C:\Documents and Settings\S-pirit\Application Data\Ventrilo
C:\Documents and Settings\S-pirit\Application Data\Vlc
Avatar billede h-hansen Nybegynder
16. oktober 2006 - 22:06 #5
En log mere:

SmitFraudFix v2.110

Scan done at 21:57:37,93, 16-10-2006
Run from C:\Documents and Settings\S-PiriT\Skrivebord\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
Avatar billede h-hansen Nybegynder
16. oktober 2006 - 22:35 #6
...endnu en:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:    22:34:47 16-10-2006

+ Scan result:   



C:\System Volume Information\_restore{2A826694-F31D-4A33-BD7C-52B953076027}\RP269\A0099082.exe -> Adware.SaveNow : Ignored.
HKU\S-1-5-21-515967899-507921405-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F6FE2C2-6040-4645-9053-7F689AFFE176} -> Adware.VirusBlast : Ignored.
:mozilla.65:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
:mozilla.89:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.90:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.7:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.8:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.45:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.46:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.47:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.48:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.40:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@bluestreak[2].txt -> TrackingCookie.Bluestreak : Ignored.
:mozilla.91:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Clickhype : Ignored.
:mozilla.92:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Clickhype : Ignored.
:mozilla.109:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.19:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.13:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.122:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Revenue : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@revenue[2].txt -> TrackingCookie.Revenue : Ignored.
:mozilla.83:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignored.
:mozilla.84:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignored.
:mozilla.51:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.52:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.87:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.88:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.58:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.59:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.60:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.61:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.62:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.63:C:\Documents and Settings\S-PiriT\Application Data\Mozilla\Firefox\Profiles\94l8bm1f.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
C:\Documents and Settings\S-PiriT\Cookies\s-pirit@zedo[1].txt -> TrackingCookie.Zedo : Ignored.


::Report end
Avatar billede h-hansen Nybegynder
16. oktober 2006 - 22:49 #7
En frisk log fra HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 22:48:45, on 16-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.EXE
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Windows NT\Tilbehør\WORDPAD.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\Windows Defender\MSASCui.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Programmer\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Documents and Settings\S-PiriT\Skrivebord\hijackthis.exe
C:\Programmer\Windows Media Player\wmplayer.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LanguageShortcut] C:\Programmer\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [twobluedogbrowse] C:\Documents and Settings\All Users\Application Data\obj list two blue\About extra.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase969.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154709481171
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede ejvindh Ekspert
17. oktober 2006 - 11:58 #8
Det hjalp lidt, men der er stadig Lop-infektion i loggen. Og dette skyldes sandsynligvis at han har installeret Messenger+ uden at sige nejtak til sponsorprogrammet. Derfor vil jeg anbefale at afinstallere Messenger+. Evt. kan han bagefter geninstallere det, men så huske at sige nej, når han bliver spurgt om han vil have sponsor-programmet med.

Slet derefter følgende mapper:
C:\Documents and Settings\All Users\Application Data\Messenger Plus!
C:\Documents and Settings\All Users\Application Data\Obj List Two Blue
C:\Documents and Settings\S-pirit\Application Data\Hole Bleh Aim
C:\Documents and Settings\S-pirit\Application Data\Netpumper

Kør Hijackthis, marker følgende linie, og klik på Fix checked:
O4 - HKLM\..\Run: [twobluedogbrowse] C:\Documents and Settings\All Users\Application Data\obj list two blue\About extra.exe

Derudover vil jeg også anbefale dig at køre AVG antispyware igen. Men denne gang skal du give programmet lov til at fixe de ting, som det finder.

Genstart så computeren, og lav en ny log med Hijackthis som du lægger herind til check.
Avatar billede h-hansen Nybegynder
17. oktober 2006 - 13:07 #9
Her er så en frisk log:

Logfile of HijackThis v1.99.1
Scan saved at 13:07:42, on 17-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\ATI Technologies\ATI.ACE\CLI.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\Windows Defender\MSASCui.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\Programmer\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\S-PiriT\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Programmer\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LanguageShortcut] C:\Programmer\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase969.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154709481171
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmer\CyberLink\Shared files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Avatar billede ejvindh Ekspert
17. oktober 2006 - 13:19 #10
Så er loggen ren :-)

For at gøre arbejdet helt færdig:
Det kan være en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse (http://www.spywarefri.dk/virusscannere.htm#alle) - genstart din computer - aktiver systemgendannelse.
Og så kan det også være en god ide at skjule dine systemfiler og -mapper igen, så du ikke ved en fejl kommer til at slette en vigtig fil. Det gør du samme sted, hvor du satte det til at vise alle filer, denne gang vælger du bare: Vis ikke skjulte filer og mapper.

Det kan også være en god ide at få renset ud i dine midlertidige filer. Det kan gøres på en hurtig og nem måde med denne fil
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------

For at forhindre gentagelser, vil jeg anbefale dig at lægge nogle små programmer ind, som forhindrer spyware i at komme ind i første omgang. Du finder links og gode råd her:
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at han læser disse artikler om hvordan han kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414
http://www.ejvindh.net/viewtopic.php?t=37
Avatar billede h-hansen Nybegynder
17. oktober 2006 - 14:13 #11
Jeg er meget taknemmelig for hjælpen, og vil forsøge at stramme op på sikkerheden her ;-)
Avatar billede h-hansen Nybegynder
17. oktober 2006 - 14:20 #12
Jeg skal også lige give dig nogle point jo, prøver lige igen...
Avatar billede ejvindh Ekspert
17. oktober 2006 - 17:32 #13
Du er velkommen. Og jeg har modtaget point for tråden :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester