Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Software \ Generel software
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

HijackThis - rimlig meget bruge for hjælp...

Af Gigabruger Acidzpy | 11-07-2004 16:15 | 1320 visninger | 12 svar, hop til seneste
Hej Kan I hjælpe mig med denne log? -------------------------------------------------------- Logfile of HijackThis v1.97.7 Scan saved at 4:11:26 PM, on 7/11/2004 Platform: Windows 2000 SP3 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINNTSystem32smss.exe C:WINNTsystem32winlogon.exe C:WINNTsystem32services.exe C:WINNTsystem32lsass.exe C:WINNTsystem32svchost.exe C:WINNTsystem32spoolsv.exe C:ProgrammerFælles filerSymantec SharedccEvtMgr.exe C:ProgrammerNorton Personal FirewallNISUM.EXE C:ProgrammerNorton Personal FirewallccPxySvc.exe C:WINNTSYSTEM32DNTUS26.EXE C:WINNTSYSTEM32DWRCS.EXE C:WINNTSystem32svchost.exe c:winntsystem32quservFireDaemon.EXE c:winntsystem32quservwindows.exe C:Program indstallNortom-anti avapsvc.exe c:winntsystem32driversetcfiredaemon.exe c:winntsystem32driversetcsvchost.exe C:Program indstallNortom-antiAdvToolsNPROTECT.EXE C:WINNTsystem32 vsvc32.exe C:WINNTsystem32 egsvc.exe C:WINNTSystem32 _server.exe C:WINNTsystem32MSTask.exe C:WINNTsystem32driversetc undll32.exe C:ProgrammerAnalog DevicesSoundMAXSMAgent.exe C:WINNTsystem32stisvc.exe C:WINNTSystem32WBEMWinMgmt.exe C:ProgrammerTDC InternetWrOS.EXE C:WINNTSystem32mspmspsv.exe C:WINNTsystem32svchost.exe C:WINNTExplorer.EXE C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe C:ProgrammerAnalog DevicesSoundMAXsmax4.exe C:Program indstallDeemondaemon.exe C:ProgrammerFælles filerSymantec SharedccApp.exe C:ProgrammerTDC InternetWinPPPoverEthernet.exe C:winntfontssystem.exe C:ProgrammerMessenger Plus! 2MsgPlus.exe C:program indstallprobeAsusProb.exe C:WINNTsystem32qttask.exe C:ProgrammerLogitechMouseWaresystemem_exec.exe C:WINNTsystem32wuauclt.exe C:ProgrammerMSN Messengermsnmsgr.exe C:Program indstallDC++DCPlusPlus.exe C:ProgrammerInternet Exploreriexplore.exe C:ProgrammerACE Mega CoDecS PackSystemSRealMediaUpdate_OB ealsched.exe C:Program indstallhijackthis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://searchweb2.com[...] R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.hol.dk[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://tdconline.dk[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer leveret af TDC Internet R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program indstallNortom-antiNavShExt.dll O2 - BHO: (no name) - {CCCB814A-611C-9365-4B88-10697F105645} - C:PROGRA~1WEBLOG~1DATASETUP.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program indstallNortom-antiNavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx O3 - Toolbar: DriveSite - {BE8ACB20-1EBD-7A4E-AF12-57EAF9A87534} - C:PROGRA~1WEBLOG~1DATASETUP.dll O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINNTsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [SoundMAXPnP] C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe O4 - HKLM..Run: [SoundMAX] "C:ProgrammerAnalog DevicesSoundMAXsmax4.exe" /tray O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program indstallDeemondaemon.exe" -lang 1033 O4 - HKLM..Run: [ccApp] "C:ProgrammerFælles filerSymantec SharedccApp.exe" O4 - HKLM..Run: [ccRegVfy] "C:ProgrammerFælles filerSymantec SharedccRegVfy.exe" O4 - HKLM..Run: [Advanced Tools Check] C:PROGRA~2NORTOM~1AdvToolsADVCHK.EXE O4 - HKLM..Run: [WinPoET] C:ProgrammerTDC InternetWinPPPoverEthernet.exe O4 - HKLM..Run: [Mirabilis ICQ] C:Program indstallICQICQNet.exe O4 - HKLM..Run: [scanreg] "C:WINNTp0six.exe " O4 - HKLM..Run: [AcrobatAgent] C:WINNTsystem32AdobeAcrobatAcrobatAGT.exe O4 - HKLM..Run: [system.exe] c:winntfontssystem.exe O4 - HKLM..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" O4 - HKLM..Run: [ERYC] C:WINNTERYC.exe O4 - HKLM..Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM..Run: [NeroFilterCheck] C:WINNTsystem32NeroCheck.exe O4 - HKLM..Run: [NeroCheck] C:WINNTsystem32NeroCheck.exe O4 - HKLM..Run: [ASUS Probe] c:program indstallprobeAsusProb.exe O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINNTsystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [QuickTime Task] "C:WINNTsystem32qttask.exe" -atboottime O4 - HKLM..Run: [TkBellExe] "C:ProgrammerACE Mega CoDecS PackSystemSRealMediaUpdate_OB ealsched.exe" -osboot O4 - HKCU..Run: [SpySweeper] C:ProgrammerWebrootSpy SweeperSpySweeper.exe /0 O4 - HKCU..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" /WinStart O4 - HKCU..Run: [Steam] "c:programmersteamsteam.exe" -silent O4 - HKCU..Run: [Symantec NetDriver Monitor] C:PROGRA~1SymantecLIVEUP~1SNDMon.EXE O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background O4 - Startup: PeerGuardian.lnk = C:ProgrammerPeerGuardian_1.99pr7PeerGuardian_1.99b_pr7.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:ProgrammerLogitechDesktop Messenger8876480ProgramLDMConf.exe O9 - Extra button: ICQ Pro (HKLM) O9 - Extra 'Tools' menuitem: ICQ (HKLM) O9 - Extra button: Real.com (HKLM) O14 - IERESET.INF: START_PAGE_URL=http://tdconline.dk[...] O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com[...] O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com[...] O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com[...] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com[...] O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com[...] O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://216.65.38.226[...] O17 - HKLMSystemCCSServicesTcpip..{8C97D71E-2374-4D31-9938-9AEF142E8228}: NameServer = 193.162.153.164 194.239.134.83
--
+Manga+ | [Ma]Trunks
#1
Steffan
Junior Supporter
11-07-2004 16:19

Rapporter til Admin
Er noet nemmere at hjælpe hvis du lige skriver hvad dit problem er, er det din startside i IE eller?
--
Online Tutorials - http://www.pcfreek.dk[...] Portfolio - http://www.web-grafik.dk[...]
#2
Acidzpy
Gigabruger
11-07-2004 16:32

Rapporter til Admin
vil gerne vide om der er noget der ikke skal være der?
--
+Manga+ | [Ma]Trunks
#3
jyk
Junior Nørd
11-07-2004 16:40

Rapporter til Admin
Kan ikke lige udpege noget snavs i den log!
--
- There is something rotten in the State of Denmark -
#4
Armageddon
Moderator
11-07-2004 17:17

Rapporter til Admin
Hejsa, der er godt meget lort i den log :( Kør en ny scanning med HJT og sæt flueben ved disse: R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://searchweb2.com[...] O2 - BHO: (no name) - {CCCB814A-611C-9365-4B88-10697F105645} - C:PROGRA~1WEBLOG~1DATASETUP.dll O3 - Toolbar: DriveSite - {BE8ACB20-1EBD-7A4E-AF12-57EAF9A87534} - C:PROGRA~1WEBLOG~1DATASETUP.dll O4 - HKLM..Run: [scanreg] "C:WINNTp0six.exe " O4 - HKLM..Run: [AcrobatAgent] C:WINNTsystem32AdobeAcrobatAcrobatAGT.exe O4 - HKLM..Run: [system.exe] c:winntfontssystem.exe O4 - HKLM..Run: [ERYC] C:WINNTERYC.exe O4 - HKLM..Run: [NeroFilterCheck] C:WINNTsystem32NeroCheck.exe O4 - HKLM..Run: [NeroCheck] C:WINNTsystem32NeroCheck.exe O4 - HKLM..Run: [QuickTime Task] "C:WINNTsystem32qttask.exe" -atboottime O4 - HKLM..Run: [TkBellExe] "C:ProgrammerACE Mega CoDecS PackSystemSRealMediaUpdate_OB ealsched.exe" -osboot O4 - Global Startup: Logitech Desktop Messenger.lnk = C:ProgrammerLogitechDesktop Messenger8876480ProgramLDMConf.exe O9 - Extra button: Real.com (HKLM) O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://216.65.38.226[...] Luk alle øvrige programvinduer så kun HJT er åben. Klik på ”Fix checked”. Luk programmet og genstart i fejlsikret tilstand (tryk F8 efter POST skærmen). Find og slet disse: C:\WINNT\SYSTEM32\DNTUS26.EXE C:\WINNT\SYSTEM32\DWRCS.EXE c:\winnt\system32\quserv\FireDaemon.EXE c:\winnt\system32\quserv\windows.exe c:\winnt\system32\drivers\etc\firedaemon.exe c:\winnt\system32\drivers\etc\svchost.exe C:\WINNT\system32\drivers\etc\rundll32.exe C:\winnt\fonts\system.exe C:\WINNT\p0six.exe C:PROGRA~1WEBLOG~1DATASETUP.dll C:\WINNT\ERYC.exe Genstart normalt. Kør en ny scanning med HJT og smid loggen herind til kontrol.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]
#5
MSB.dk
Elite Supporter
11-07-2004 17:45

Rapporter til Admin
#4 HVordan kan du sådan umiddelbart lige se hvilke ting der skal fjernes ?
--
Abit IC7-G | Intel P4 C 3.2Ghz | Leadtek FX5900 | WD Raptor 36.7Gb | WD 2000JD Sata 200Gb | 1Gb Elixir Pc3200 | ThermalRight SLK 947-U | Logitech Z-560 THX | Samsung SyncMaster 1100DF 21"
#6
Acidzpy
Gigabruger
11-07-2004 18:02

Rapporter til Admin
1.000tak for hælpen! her er den nye log.. : ------------- Logfile of HijackThis v1.97.7 Scan saved at 5:58:40 PM, on 7/11/2004 Platform: Windows 2000 SP3 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINNTSystem32smss.exe C:WINNTsystem32winlogon.exe C:WINNTsystem32services.exe C:WINNTsystem32lsass.exe C:WINNTsystem32svchost.exe C:WINNTsystem32spoolsv.exe C:ProgrammerFælles filerSymantec SharedccEvtMgr.exe C:ProgrammerNorton Personal FirewallNISUM.EXE C:ProgrammerNorton Personal FirewallccPxySvc.exe C:WINNTSystem32svchost.exe C:Program indstallNortom-anti avapsvc.exe C:Program indstallNortom-antiAdvToolsNPROTECT.EXE C:WINNTsystem32 vsvc32.exe C:WINNTsystem32 egsvc.exe C:WINNTSystem32 _server.exe C:WINNTsystem32MSTask.exe C:ProgrammerAnalog DevicesSoundMAXSMAgent.exe C:WINNTsystem32stisvc.exe C:WINNTSystem32WBEMWinMgmt.exe C:ProgrammerTDC InternetWrOS.EXE C:WINNTSystem32mspmspsv.exe C:WINNTsystem32svchost.exe C:WINNTExplorer.EXE C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe C:ProgrammerAnalog DevicesSoundMAXsmax4.exe C:Program indstallDeemondaemon.exe C:ProgrammerFælles filerSymantec SharedccApp.exe C:ProgrammerTDC InternetWinPPPoverEthernet.exe C:ProgrammerMessenger Plus! 2MsgPlus.exe C:program indstallprobeAsusProb.exe C:ProgrammerWebrootSpy SweeperSpySweeper.exe C:ProgrammerLogitechMouseWaresystemem_exec.exe C:ProgrammerPeerGuardian_1.99pr7PeerGuardian_1.99b_pr7.exe C:ProgrammerInternet ExplorerIEXPLORE.EXE C:ProgrammerMSN Messengermsnmsgr.exe C:WINNTsystem32wuauclt.exe C:Program indstallICQICQ.exe C:Program indstallhijackthis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.hol.dk[...] R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.hol.dk[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://tdconline.dk[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer leveret af TDC Internet R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program indstallNortom-antiNavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program indstallNortom-antiNavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINNTsystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [SoundMAXPnP] C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe O4 - HKLM..Run: [SoundMAX] "C:ProgrammerAnalog DevicesSoundMAXsmax4.exe" /tray O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program indstallDeemondaemon.exe" -lang 1033 O4 - HKLM..Run: [ccApp] "C:ProgrammerFælles filerSymantec SharedccApp.exe" O4 - HKLM..Run: [ccRegVfy] "C:ProgrammerFælles filerSymantec SharedccRegVfy.exe" O4 - HKLM..Run: [Advanced Tools Check] C:PROGRA~2NORTOM~1AdvToolsADVCHK.EXE O4 - HKLM..Run: [WinPoET] C:ProgrammerTDC InternetWinPPPoverEthernet.exe O4 - HKLM..Run: [Mirabilis ICQ] C:Program indstallICQICQNet.exe O4 - HKLM..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" O4 - HKLM..Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM..Run: [ASUS Probe] c:program indstallprobeAsusProb.exe O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINNTsystem32NvMcTray.dll,NvTaskbarInit O4 - HKCU..Run: [SpySweeper] C:ProgrammerWebrootSpy SweeperSpySweeper.exe /0 O4 - HKCU..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" /WinStart O4 - HKCU..Run: [Steam] "c:programmersteamsteam.exe" -silent O4 - HKCU..Run: [Symantec NetDriver Monitor] C:PROGRA~1SymantecLIVEUP~1SNDMon.EXE O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background O4 - HKCU..RunOnce: [ICQ] C:Program indstallICQICQ.exe -trayboot O4 - Startup: PeerGuardian.lnk = C:ProgrammerPeerGuardian_1.99pr7PeerGuardian_1.99b_pr7.exe O9 - Extra button: ICQ Pro (HKLM) O9 - Extra 'Tools' menuitem: ICQ (HKLM) O14 - IERESET.INF: START_PAGE_URL=http://tdconline.dk[...] O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com[...] O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com[...] O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com[...] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com[...] O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com[...] O17 - HKLMSystemCCSServicesTcpip..{8C97D71E-2374-4D31-9938-9AEF142E8228}: NameServer = 193.162.153.164 194.239.134.83
--
+Manga+ | [Ma]Trunks
#7
Armageddon
Moderator
11-07-2004 18:03

Rapporter til Admin
#5 Fordi jeg analyserer hver en stump i loggen - derfor tager det tid at komme med svar.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]
#8
Armageddon
Moderator
11-07-2004 18:10

Rapporter til Admin
#6 Så er loggen dejlig ren. Jeg vil anbefale dig at opdatere systemet til SP4 og eventuelle kritiske opdateringer via Windows update.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]
#9
MSB.dk
Elite Supporter
11-07-2004 18:54

Rapporter til Admin
#8 Hvordan ved du så hvilke filer der skal fjernes ??
--
Abit IC7-G | Intel P4 C 3.2Ghz | Leadtek FX5900 | WD Raptor 36.7Gb | WD 2000JD Sata 200Gb | 1Gb Elixir Pc3200 | ThermalRight SLK 947-U | Logitech Z-560 THX | Samsung SyncMaster 1100DF 21"
#10
Knutz
Nørd Aspirant
11-07-2004 19:35

Rapporter til Admin
#9 ved at researche hver fil der ser mistænksom ud... her er google til stor hjælp!
--
Jahh.. Så kan du lære det! MSN: [email protected]
#11
MSB.dk
Elite Supporter
11-07-2004 23:37

Rapporter til Admin
#10 Ok, troede man skulle kæde dem sammen med hver enkelt proces man har kørende
--
Abit IC7-G | Intel P4 C 3.2Ghz | Leadtek FX5900 | WD Raptor 36.7Gb | WD 2000JD Sata 200Gb | 1Gb Elixir Pc3200 | ThermalRight SLK 947-U | Logitech Z-560 THX | Samsung SyncMaster 1100DF 21"
#12
Armageddon
Moderator
12-07-2004 06:47

Rapporter til Admin
#11 Ikke nødvendigvis, men jeg analyserer både processer og de øvrige data i loggen og kan ofte se et mønster.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]

Opret svar til indlægget: HijackThis - rimlig meget bruge for hjælp...

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning