Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Software \ Sikkerhed
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

Tjek vens HJT-logfil

Af Ultra Supporter ?? | 22-12-2004 14:03 | 1013 visninger | 3 svar, hop til seneste
hej, vil i tjekke en logfil for min ven? Logfile of HijackThis v1.99.0 Scan saved at 13:59:26, on 22-12-2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32spoolsv.exe C:PROGRA~1NORTON~1NORTON~1 avapw32.exe C:WINDOWSSystem32MMTray.exe C:WINDOWSSystem32MMTray2k.exe C:WINDOWSSystem32MMTrayLSI.exe C:WINDOWSSystem32qttask.exe C:PROGRA~1GrisoftAVG6avgcc32.exe C:ProgrammerWinampwinampa.exe C:ProgrammerBearShareBearShare.exe C:ProgrammerBearShareBearShare.exe C:ProgrammerMessenger Plus! 3MsgPlus.exe C:ProgrammerMSN AppsUpdater1.02.3000.1001damsnappau.exe C:WINDOWSSystem32 undll32.exe C:ProgrammerSkypePhoneSkype.exe C:ProgrammerNorton SystemWorksNorton CleanSweepcsinsmnt.exe C:ProgrammerInternet Exploreriexplore.exe c:progra~1intern~1iexplore.exe C:PROGRA~1GrisoftAVG6avgserv.exe C:ProgrammerNorton SystemWorksNorton UtilitiesNPROTECT.EXE C:WINDOWSSystem32 vsvc32.exe C:PROGRA~1NORTON~1SPEEDD~1 opdb.exe C:WINDOWSsystem32 tvdm.exe C:ProgrammerInternet Exploreriexplore.exe C:ProgrammerMSN Messengermsnmsgr.exe C:ProgrammerWinampwinamp.exe C:WINDOWSexplorer.exe C:Documents and SettingsThora Samsø FastDokumenterModtagne filerhijackthis.exe R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.nylqnyskxhpd.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.gknsnrcvlaiasfenzonp.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx O2 - BHO: Setup.Setup1 - {2E65A557-173C-4DE9-860B-28FC5CACA542} - C:DOCUME~1ALLUSE~1APPLIC~1SetupSetup.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:ProgrammerMSN AppsST1.02.3000.1002en-xustmain.dll O2 - BHO: (no name) - {ADC85A71-9C54-AEE0-E249-A7F0352382B7} - C:DOCUME~1THORAS~1APPLIC~1MEMORE~1Stupid Lies.exe O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:ProgrammerMSN AppsMSN Toolbar1.02.3000.1001damsntb.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:ProgrammerNorton SystemWorksNorton AntiVirusNavShExt.dll O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:ProgrammerMySearchar1.binS4BAR.DLL (file missing) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:ProgrammerMSN AppsMSN Toolbar1.02.3000.1001damsntb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O4 - HKLM..Run: [NAV Agent] C:PROGRA~1NORTON~1NORTON~1 avapw32.exe O4 - HKLM..Run: [MMTray] MMTray.exe O4 - HKLM..Run: [MMTray2K] MMTray2k.exe O4 - HKLM..Run: [MMTrayLSI] MMTrayLSI.exe O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSSystem32qttask.exe" -atboottime O4 - HKLM..Run: [AVG_CC] C:PROGRA~1GrisoftAVG6avgcc32.exe /STARTUP O4 - HKLM..Run: [WinampAgent] C:ProgrammerWinampwinampa.exe O4 - HKLM..Run: [BearShare] "C:ProgrammerBearShareBearShare.exe" /pause O4 - HKLM..Run: [InfoPenMSN] C:ProgrammerInfoKingInfoPenMSNProInfoPenIM.exe O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [MessengerPlus3] "C:ProgrammerMessenger Plus! 3MsgPlus.exe" O4 - HKLM..Run: [4 Dog Hold Ooze] C:Documents and SettingsAll UsersApplication Dataoneweb4dogBits Locks.exe O4 - HKLM..Run: [msnappau] "C:ProgrammerMSN AppsUpdater1.02.3000.1001damsnappau.exe" O4 - HKCU..Run: [Skype] "C:ProgrammerSkypePhoneSkype.exe" /nosplash /minimized O4 - HKCU..Run: [ManagerIdol] C:DOCUME~1THORAS~1APPLIC~1THEBOL~1interlivetrans.exe O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:ProgrammerNorton SystemWorksNorton CleanSweepcsinsmnt.exe O8 - Extra context menu item: &Search - http://bar.mywebsearch.com[...] O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengerMSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengerMSMSGS.EXE O12 - Plugin for .spop: C:ProgrammerInternet ExplorerPluginsNPDocBox.dll O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com[...] O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com[...] O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com[...] O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com[...] O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com[...] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com[...] O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com[...] O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com[...] O23 - Service: AVG6 Service - GRISOFT s.r.o - C:PROGRA~1GrisoftAVG6avgserv.exe O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:ProgrammerNorton SystemWorksNorton AntiVirus avapsvc.exe O23 - Service: Norton Unerase Protection - Symantec Corporation - C:ProgrammerNorton SystemWorksNorton UtilitiesNPROTECT.EXE O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:WINDOWSSystem32 vsvc32.exe O23 - Service: ScriptBlocking Service - Symantec Corporation - C:ProgrammerFælles filerSymantec SharedScript BlockingSBServ.exe O23 - Service: Speed Disk service - Symantec Corporation - C:PROGRA~1NORTON~1SPEEDD~1 opdb.exe
--
#1
??
Ultra Supporter
22-12-2004 14:35

Rapporter til Admin
Logfile of HijackThis v1.99.0 Scan saved at 13:59:26, on 22-12-2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32spoolsv.exe C:PROGRA~1NORTON~1NORTON~1 avapw32.exe C:WINDOWSSystem32MMTray.exe C:WINDOWSSystem32MMTray2k.exe C:WINDOWSSystem32MMTrayLSI.exe C:WINDOWSSystem32qttask.exe C:PROGRA~1GrisoftAVG6avgcc32.exe C:ProgrammerWinampwinampa.exe C:ProgrammerBearShareBearShare.exe C:ProgrammerBearShareBearShare.exe C:ProgrammerMessenger Plus! 3MsgPlus.exe C:ProgrammerMSN AppsUpdater1.02.3000.1001damsnappau.exe C:WINDOWSSystem32 undll32.exe C:ProgrammerSkypePhoneSkype.exe C:ProgrammerNorton SystemWorksNorton CleanSweepcsinsmnt.exe C:ProgrammerInternet Exploreriexplore.exe c:progra~1intern~1iexplore.exe C:PROGRA~1GrisoftAVG6avgserv.exe C:ProgrammerNorton SystemWorksNorton UtilitiesNPROTECT.EXE C:WINDOWSSystem32 vsvc32.exe C:PROGRA~1NORTON~1SPEEDD~1 opdb.exe C:WINDOWSsystem32 tvdm.exe C:ProgrammerInternet Exploreriexplore.exe C:ProgrammerMSN Messengermsnmsgr.exe C:ProgrammerWinampwinamp.exe C:WINDOWSexplorer.exe C:Documents and SettingsThora Samsø FastDokumenterModtagne filerhijackthis.exe R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.nylqnyskxhpd.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.gknsnrcvlaiasfenzonp.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx O2 - BHO: Setup.Setup1 - {2E65A557-173C-4DE9-860B-28FC5CACA542} - C:DOCUME~1ALLUSE~1APPLIC~1SetupSetup.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:ProgrammerMSN AppsST1.02.3000.1002en-xustmain.dll O2 - BHO: (no name) - {ADC85A71-9C54-AEE0-E249-A7F0352382B7} - C:DOCUME~1THORAS~1APPLIC~1MEMORE~1Stupid Lies.exe O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:ProgrammerMSN AppsMSN Toolbar1.02.3000.1001damsntb.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:ProgrammerNorton SystemWorksNorton AntiVirusNavShExt.dll O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:ProgrammerMySearchar1.binS4BAR.DLL (file missing) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:ProgrammerMSN AppsMSN Toolbar1.02.3000.1001damsntb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O4 - HKLM..Run: [NAV Agent] C:PROGRA~1NORTON~1NORTON~1 avapw32.exe O4 - HKLM..Run: [MMTray] MMTray.exe O4 - HKLM..Run: [MMTray2K] MMTray2k.exe O4 - HKLM..Run: [MMTrayLSI] MMTrayLSI.exe O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSSystem32qttask.exe" -atboottime O4 - HKLM..Run: [AVG_CC] C:PROGRA~1GrisoftAVG6avgcc32.exe /STARTUP O4 - HKLM..Run: [WinampAgent] C:ProgrammerWinampwinampa.exe O4 - HKLM..Run: [BearShare] "C:ProgrammerBearShareBearShare.exe" /pause O4 - HKLM..Run: [InfoPenMSN] C:ProgrammerInfoKingInfoPenMSNProInfoPenIM.exe O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [MessengerPlus3] "C:ProgrammerMessenger Plus! 3MsgPlus.exe" O4 - HKLM..Run: [4 Dog Hold Ooze] C:Documents and SettingsAll UsersApplication Dataoneweb4dogBits Locks.exe O4 - HKLM..Run: [msnappau] "C:ProgrammerMSN AppsUpdater1.02.3000.1001damsnappau.exe" O4 - HKCU..Run: [Skype] "C:ProgrammerSkypePhoneSkype.exe" /nosplash /minimized O4 - HKCU..Run: [ManagerIdol] C:DOCUME~1THORAS~1APPLIC~1THEBOL~1interlivetrans.exe O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:ProgrammerNorton SystemWorksNorton CleanSweepcsinsmnt.exe O8 - Extra context menu item: &Search - http://bar.mywebsearch.com[...] O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengerMSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengerMSMSGS.EXE O12 - Plugin for .spop: C:ProgrammerInternet ExplorerPluginsNPDocBox.dll O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com[...] O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com[...] O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com[...] O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com[...] O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com[...] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com[...] O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com[...] O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com[...] O23 - Service: AVG6 Service - GRISOFT s.r.o - C:PROGRA~1GrisoftAVG6avgserv.exe O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:ProgrammerNorton SystemWorksNorton AntiVirus avapsvc.exe O23 - Service: Norton Unerase Protection - Symantec Corporation - C:ProgrammerNorton SystemWorksNorton UtilitiesNPROTECT.EXE O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:WINDOWSSystem32 vsvc32.exe O23 - Service: ScriptBlocking Service - Symantec Corporation - C:ProgrammerFælles filerSymantec SharedScript BlockingSBServ.exe O23 - Service: Speed Disk service - Symantec Corporation - C:PROGRA~1NORTON~1SPEEDD~1 opdb.exe
--
Vejle HTX http://www.chipsguiden.dk[...]
#2
??
Ultra Supporter
22-12-2004 14:37

Rapporter til Admin
krapulsk... uploader den hertil: http://www.mindblade.dk[...]
--
Vejle HTX http://www.chipsguiden.dk[...]
#3
*Cookie
Monsterbruger
23-12-2004 18:57

Rapporter til Admin
Hej igen JK :o)! Der er lige lidt, der skal fixes. Start med at deaktivere systemgendannelse. (Højreklik på "Denne Computer" på skrivebordet, vælg egenskaber og fanebladet "Systemgendannelse" og sæt flueben i "Deaktiver systemgendannelse". Klik OK.) Afinstaller MessengerPlus3 via Kontrolpanel / Tilføj eller fjern Programmer Reboot og kør en ny scanning med HJT og sæt flueben ved disse: R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.nylqnyskxhpd.com[...] R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.gknsnrcvlaiasfenzonp.com[...] R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) O2 - BHO: Setup.Setup1 - {2E65A557-173C-4DE9-860B-28FC5CACA542} - C:DOCUME~1ALLUSE~1APPLIC~1SetupSetup.dll (file missing) O2 - BHO: (no name) - {ADC85A71-9C54-AEE0-E249-A7F0352382B7} - C:DOCUME~1THORAS~1APPLIC~1MEMORE~1Stupid Lies.exe O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:ProgrammerMySearchar1.binS4BAR.DLL (file missing) O4 - HKLM..Run: [MMTray] MMTray.exe O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSSystem32qttask.exe" -atboottime O4 - HKLM..Run: [BearShare] "C:ProgrammerBearShareBearShare.exe" /pause O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [MessengerPlus3] "C:ProgrammerMessenger Plus! 3MsgPlus.exe" O4 - HKLM..Run: [4 Dog Hold Ooze] C:Documents and SettingsAll UsersApplication Dataoneweb4dogBits Locks.exe O4 - HKCU..Run: [ManagerIdol] C:DOCUME~1THORAS~1APPLIC~1THEBOL~1interlivetrans.exe O8 - Extra context menu item: &Search - http://bar.mywebsearch.com[...] O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com[...] Luk alle øvrige programvinduer så kun HJT er åben. Klik på ”Fix checked”. Luk programmet og genstart i fejlsikret tilstand (tryk F8 efter POST skærmen). Søg og slet nedenstående filer/mapper, hvis de stadig er der. Husk at ændre mappeindstillinger så du kan se skjulte filer samt systemfiler. (Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis. Fjern flueben ved "Skjul beskyttede operativsystemfiler". Fjern flueben ved "Skjul filtypenavne for kendte filtyper". Sæt prik i "Vis skjulte filer og mapper".) C:\DOCUME~1\ALLUSE~1\APPLIC~1\Setup\Setup.dll <<<< Slet filen C:\Programmer\MySearch\ <<<< Slet mappen C:\Programmer\BearShare\<<<< Slet mappen C:\Programmer\Messenger Plus! 3\<<<< Slet mappen Jeg kan ikke se hele mappenavnet i loggen på nedenstående filer. Er derfor lidt usikker på, om de er legitime. Hvis der ikke er andre programmer i mappen, kan hun bare slette hele mappen (det med fed skrift), ellers kun filerne: >>>> C:\DOCUME~1\THORAS~1\APPLIC~1\MEMORE~1\Stupid Lies.exe >>>> C:\DOCUME~1\THORAS~1\APPLIC~1\THEBOL~1\interlivetrans.exe Genstart normalt. Kør en ny scanning med HJT og smid loggen herind til kontrol. ----- Hendes system er forresten hullet som en si i øjeblikket, så jeg vil kraftigt anbefale, at hun får installeret en af nedenstående Service Packs samt kritiske opdateringer hurtigst muligt. SP1 DK: ftp://ftp.sdu.dk[...] SP2 DK: ftp://ftp.sdu.dk[...] ----- Vi snakkes :o)! Til da - ha' en RIGTIG GOD JUL & et LYKKEBRINGENDE NYTÅR! //*Cookie
--
Make somebody else's day - commit an act of kindness ... TODAY :o)!

Opret svar til indlægget: Tjek vens HJT-logfil

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning