Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Software \ Sikkerhed
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

Her kommer en HJT log :)

Af Elitebruger GoA_GaRtNeR | 15-06-2004 19:52 | 908 visninger | 3 svar, hop til seneste
ja så er vi på den igen, har fået brugeren til at køre ad aware og spy bot men der er stadig nogle ting som ikke bliver eller ikke kan fjernes ( blandt andet newdotnet ) af de to programmer jeg har givet ham en røvfuld for brug af p2p puuha fy fy skamme :) here we go ! mamma mia Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32spoolsv.exe C:WINDOWSExplorer.EXE C:Program FilesD-Toolsdaemon.exe C:WINDOWSSM1BG.EXE C:Program FilesMicrosoft IntelliPointpoint32.exe C:Program FilesCommon FilesSymantec SharedccApp.exe C:Program FilesNorton SystemWorksNorton GhostGhostStartTrayApp.exe C:WINDOWSSystem32 undll32.exe C:Program FilesMessenger Plus! 3MsgPlus.exe C:Program FilesWinampwinampa.exe C:WINDOWSSystem32RUNDLL32.EXE C:WINDOWSSystem32ctfmon.exe C:Program FilesSkypePhoneSkype.exe C:program filessteamsteam.exe C:Program FilesCommon FilesSymantec SharedccProxy.exe C:Program FilesCommon FilesSymantec SharedccSetMgr.exe C:PROGRA~1NORTON~3NORTON~3GHOSTS~2.EXE C:Program FilesNorton Internet Security ProfessionalNorton AntiVirus avapsvc.exe C:PROGRA~1NORTON~3NORTON~1NPROTECT.EXE C:WINDOWSSystem32 vsvc32.exe C:PROGRA~1NORTON~3NORTON~1SPEEDD~1NOPDB.EXE C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusSAVScan.exe C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe C:Program FilesVentriloVentrilo.exe C:Documents and SettingsUserMy DocumentsModtagne filerhjt.exe C:Program FilesMessengermsmsgs.exe R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchweb2.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://searchweb2.com[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://searchweb2.com[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchweb2.com[...] R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://searchweb2.com[...] O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:Program FilesSpybot - Search & DestroySDHelper.dll O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll O2 - BHO: (no name) - {AC2E9B22-50FF-226B-575B-58764FD9EBD1} - C:PROGRA~1STUPID~1math play.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusNavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusNavShExt.dll O3 - Toolbar: Bore Cdrom - {CFA36639-9115-8D23-588D-2104ED297E95} - C:PROGRA~1STUPID~1math play.dll O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe" -lang 1033 O4 - HKLM..Run: [SM1BG] C:WINDOWSSM1BG.EXE O4 - HKLM..Run: [IntelliPoint] "C:Program FilesMicrosoft IntelliPointpoint32.exe" O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe" O4 - HKLM..Run: [URLLSTCK.exe] C:Program FilesNorton Internet Security ProfessionalUrlLstCk.exe O4 - HKLM..Run: [Advanced Tools Check] C:PROGRA~1NORTON~4NORTON~1AdvToolsADVCHK.EXE O4 - HKLM..Run: [GhostStartTrayApp] C:Program FilesNorton SystemWorksNorton GhostGhostStartTrayApp.exe O4 - HKLM..Run: [AcctMgr] C:Program FilesNorton SystemWorksPassword ManagerAcctMgr.exe /startup O4 - HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART O4 - HKLM..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe" O4 - HKLM..Run: [Surfdeaf] C:PROGRA~1MORE NEW DOWNLOADAudioslowlogo.exe O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [anvshell] anvshell.exe O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup -s O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized O4 - HKCU..Run: [Steam] "c:program filessteamsteam.exe" -silent O4 - HKCU..Run: [Norton SystemWorks] C:Program FilesCommon FilesSymantec SharedCfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA} O4 - HKCU..Run: [Symantec NetDriver Monitor] C:PROGRA~1SymantecLIVEUP~1SNDMon.EXE O4 - HKCU..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe" /WinStart O4 - HKCU..Run: [ASUS SmartDoctor] C:Program FilesASUSSmartDoctor\SmartDoctor.exe /start O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background O4 - HKLM..RunOnce: [Ad-aware] "C:PROGRA~1LavasoftAD-AWA~1Ad-aware.exe" "+b1" O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com[...] O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com[...] O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com[...] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com[...] O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com[...] O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com[...] O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com[...]
--
P4c 3.0GHz|Asus p4c800e-deluxe|1GB Geil ultra plat. pc4000 dual|BBA Ati radeon 9800XT|320GB maxtor sata raid0|Audigy 2 ZS|SP-94 120MM papst
#1
Kim In Chul
Monsterbruger
15-06-2004 20:05

Rapporter til Admin
Hej du har en gang lort... Start med at deaktivere systemgendannelsen, download så disse programmer: http://members.shaw.ca[...] http://cexx.org[...] Kør dem og kør så en ny Hijackthis... Sæt flueben ud for: R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchweb2.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://searchweb2.com[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://searchweb2.com[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchweb2.com[...] R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://searchweb2.com[...] O2 - BHO: (no name) - {AC2E9B22-50FF-226B-575B-58764FD9EBD1} - C:PROGRA~1STUPID~1math play.dll O3 - Toolbar: Bore Cdrom - {CFA36639-9115-8D23-588D-2104ED297E95} - C:PROGRA~1STUPID~1math play.dll O4 - HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART O4 - HKLM..Run: [Surfdeaf] C:PROGRA~1MORE NEW DOWNLOADAudioslowlogo.exe O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup -s Genstart så computeren i fejlsikret tilstand og find og slet: C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART (Hele p2p mappen skal væk) C:PROGRA~1MORE NEW DOWNLOADAudioslowlogo.exe (hvis den ligger i en seperat mappe så slet den) C:PROGRA~1STUPID~1math play.dll (hvis den ligger i en seperat mappe så slet den) //Kim In Chul P. S New.net er noget djævelskab.... få Armageddon til at kigge helt på det... Send en log til kontrol
--
#2
Kim In Chul
Monsterbruger
15-06-2004 20:12

Rapporter til Admin
tillæg til #1 O4 - HKLM..Run: [SM1BG] C:WINDOWSSM1BG.EXE = USB driver for downloading from within Napster to portable MP3 players. Is it required to run at startup or can it be run manually? Tjaerh, du bestemmer vel selv om den skal væk;) fy bab!
--
#3
Armageddon
Moderator
15-06-2004 20:13

Rapporter til Admin
Hejsa, Der er et par småting som lige skal fixes. Start med at deaktivere systemgendannelse. Højreklik på "Denne Computer" på skrivebordet, vælg egenskaber og fanebladet "Systemgendannelse" og sæt flueben i "Deaktiver systemgendannelse". Klik ok og genstart. Kør en ny scanning med HJT og sæt flueben ved disse: R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchweb2.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://searchweb2.com[...] R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://searchweb2.com[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com[...] R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchweb2.com[...] R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://searchweb2.com[...] O2 - BHO: (no name) - {AC2E9B22-50FF-226B-575B-58764FD9EBD1} - C:PROGRA~1STUPID~1math play.dll O3 - Toolbar: Bore Cdrom - {CFA36639-9115-8D23-588D-2104ED297E95} - C:PROGRA~1STUPID~1math play.dll O4 - HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART O4 - HKLM..Run: [Surfdeaf] C:PROGRA~1MORE NEW DOWNLOADAudioslowlogo.exe O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup -s O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - Luk alle øvrige programvinduer så kun HJT er åben. Klik på ”Fix checked”. Luk programmet og genstart i fejlsikret tilstand (tryk F8 efter POST skærmen). Find og slet denne: C:\PROGRA~1\STUPID~1\math play.dll C:\WINDOWS\System32\P2P Networking\P2P Networking.exe C:\PROGRA~1\MORE NEW DOWNLOAD\Audioslowlogo.exe C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL Genstart normalt. Kør en ny scanning med HJT og smid loggen herind til kontrol.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]

Opret svar til indlægget: Her kommer en HJT log :)

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning