Administrator
Antal indlæg: 55087
Hej Spywarefri
Jeg har problemer med min PC. Problemet er af samme art som diskuteres i denne tråd. Den synlige del af problemet er startsiden som er “about:blank”. Derudover synes jeg også at min computer er ualmindelig langsom for tiden.Jeg har også oplevet at blive pludselig blive spurgt om jeg vil downloade dialersoftware, efter jeg lukker explore.
Jeg har kørt spybot og ad-aware, men intet hjælper. Jeg fulgt andres eksempel og har netop optaget en en log vha. Hijack this den ser sådan ud:
Logfile of HijackThis v1.97.7
Scan saved at 20:06:22, on 12-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Sophos/Remote Update/cachemgr.exe
C:/Programmer/Cisco Systems/VPN Client/cvpnd.exe
C:/Programmer/Sophos SWEEP for NT/SWNETSUP.EXE
C:/Programmer/Sophos SWEEP for NT/SWEEPSRV.SYS
C:/WINDOWS/Explorer.EXE
F:/winamp/Winamp/winampa.exe
C:/Programmer/D-Tools/daemon.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/Sophos/Remote Update/imonitor.exe
C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
C:/WINDOWS/System32/mesharei.exe
C:/hijackthis/HijackThis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/System32/dfnb.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/System32/dfnb.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/System32/dfnb.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/System32/dfnb.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/System32/dfnb.dll/sp.html (obfuscated)
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/System32/dfnb.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Windows/CurrentVersion/Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,HomeOldSP = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:/WINDOWS/twaintec.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {44C236DE-CFDF-4DEE-AC1C-A22A04A124A0} - C:/WINDOWS/System32/dfnb.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O2 - BHO: (no name) - {FBA94791-7983-4BE5-970F-497450591DCF} - C:/WINDOWS/System32/cindn.dll (file missing)
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O4 - HKLM/../Run: [websx] C:/Programmer/websx/int113777.exe -auto
O4 - HKLM/../Run: [WinampAgent] F:/winamp/Winamp/winampa.exe
O4 - HKLM/../Run: [DAEMON Tools-1033] “C:/Programmer/D-Tools/daemon.exe” -lang 1033
O4 - HKLM/../Run: [alchem] C:/WINDOWS/alchem.exe
O4 - HKLM/../Run: [mesharei] C:/WINDOWS/System32/mesharei.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - Startup: DLHelperEXE.exe
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:/Programmer/Cisco Systems/VPN Client/ipsecdialer.exe
O4 - Global Startup: Remote Update Monitor.lnk = C:/Programmer/Sophos/Remote Update/imonitor.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38063.2840393518
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Er det noget i kan hjælpe mig med??
Hilsen Kresten
Signatur
Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”
Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/
Nierne bomaye - You’ll never walk alone
qui potest, obligatur
Administrator
Antal indlæg: 55087
1. Download og installer følgende programmer:
Reglite - http://www.resplendence.com/reglite
Adaware - http://www.lavasoft.de/support/download/
SpyBot S&D - http://www.safer-networking.org/index.php?lang=en&page=download
2. Download og pak følgende programmer ud til deres egne mapper:
CWShredder - http://www.spywareinfo.com/downloads/tools/CWShredder.exe
TheKillBox - http://download.broadbandmedic.com/VbStuff/KillBox.zip
3. Kør Reglite og skriv
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Windows//AppInit_DLLs
ind i “Adress” feltet, tryk <Enter>.
4. Dobbeltklik på AppInit_DLLs for at åbne “Data Editor”, hvis det nederste felt kaldet “Value” indeholder en .dll fil er det den vi leder efter.
5. Den kan ikke slettes endnu, skriv stien og navnet ned på et stykke papir, det skal bruges senere.
6. I venstre vindue, højreklik på mappen “Windows”(Den er fremhævet med lilla), vælg “Rename” og omdøb den til “Notwindows”.
7. Klik på AppInit_DLLs igen, slet værdien der indeholder .dll’en klik OK, så burde den være væk.
8. Omdøb “Notwindows” tilbage til “Windows”
9. Kør Spybot, Ad-aware og CWShredder, husk at opdatere online inden du kører programmet.
10. Nu er det tid til at slette den .dll fil.
11. Kør TheKillBox (skal være pakket ud til sin egen mappe). I tekstfeltet skriver du stien til den fil du skrev ned tidligere (eksempelvis c:/windows/system23/dllha.dll). Nu skal du vælge Action -> Delete on reboot. Nu dukker der et lille vindue op - vælg File -> Add file. Vælg Action -> Process and reboot
12. Genstart din PC i Fejlsikret tilstand (ved at taste F8 under opstart). Kør Spybot, Ad-aware og CWShredder igen. Genstart i Normal mode og læg en frisk HijackThis log herind.
______________________________________________
Hvis pkt. 11 ikke virker: Gå i Start -> Kør og skriv cmd og klik OK. Du er nu i et DOS-vindue. Skriv attrib -r “stien til filen du skal slette” (eksempelvis attrib -r c:/windows/system23/dllha.dll)
Gentag pkt. 11 - 12.
Signatur
Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”
Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/
Nierne bomaye - You’ll never walk alone
qui potest, obligatur
Jeg har fulgt din opskrift og det ser ud til at virke!!!
Ny log:
Logfile of HijackThis v1.97.7
Scan saved at 21:26:23, on 12-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Sophos/Remote Update/cachemgr.exe
C:/Programmer/Cisco Systems/VPN Client/cvpnd.exe
C:/Programmer/Sophos SWEEP for NT/SWNETSUP.EXE
C:/Programmer/Sophos SWEEP for NT/SWEEPSRV.SYS
C:/WINDOWS/Explorer.EXE
F:/winamp/Winamp/winampa.exe
C:/Programmer/D-Tools/daemon.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/Sophos/Remote Update/imonitor.exe
C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
C:/WINDOWS/System32/ermcapt.exe
C:/hijackthis/HijackThis.exe
R1 - HKCU/Software/Microsoft/Windows/CurrentVersion/Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {39EC805A-FCEE-4B10-8110-67448CD65213} - C:/WINDOWS/System32/dfnb.dll (file missing)
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O2 - BHO: (no name) - {FBA94791-7983-4BE5-970F-497450591DCF} - C:/WINDOWS/System32/cindn.dll (file missing)
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O4 - HKLM/../Run: [websx] C:/Programmer/websx/int113777.exe -auto
O4 - HKLM/../Run: [WinampAgent] F:/winamp/Winamp/winampa.exe
O4 - HKLM/../Run: [DAEMON Tools-1033] “C:/Programmer/D-Tools/daemon.exe” -lang 1033
O4 - HKLM/../Run: [ermcapt] C:/WINDOWS/System32/ermcapt.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - Startup: DLHelperEXE.exe
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:/Programmer/Cisco Systems/VPN Client/ipsecdialer.exe
O4 - Global Startup: Remote Update Monitor.lnk = C:/Programmer/Sophos/Remote Update/imonitor.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38063.2840393518
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Og dog….
Der er stadig pop-up når jeg lukker explore:-<
Administrator
Antal indlæg: 55087
Deaktiver systemgendannelse:
http://www.spywarefri.dk/virusscannere.htm#alle
Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, genstart i fejlsikret(Tryk <F8> under opstart) og slet filerne listet nederst.
Dobbelttjek, så alt kommer med.
R1 - HKCU/Software/Microsoft/Windows/CurrentVersion/Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {39EC805A-FCEE-4B10-8110-67448CD65213} - C:/WINDOWS/System32/dfnb.dll (file missing)
O2 - BHO: (no name) - {FBA94791-7983-4BE5-970F-497450591DCF} - C:/WINDOWS/System32/cindn.dll (file missing)
O4 - HKLM/../Run: [websx] C:/Programmer/websx/int113777.exe -auto
O4 - HKLM/../Run: [ermcapt] C:/WINDOWS/System32/ermcapt.exe
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
———————————————————-
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved “Skjul beskyttede operativsystemfiler”.
Fjern flueben ved “Skjul filtypenavne for kendte filtyper”.
Sæt prik i “Vis skjulte filer og mapper”.
Brug af Start>Søg.
Klik på “Alle filer og Mapper”, klik på “Flere avancerede Indstillinger”, sæt flueben i de tre øverste. ———————————————————-
Slettes i fejlsikret.
C:/Programmer/websx <- Mappen.
C:/WINDOWS/System32/ermcapt.exe <- Filen. ———————————————————-
Du skal også lige hente og installere Servicepack 1, Hotfixes og sasserfix, dem kan du finde her:
http://intern.sdu.dk/it-service/tjenester/ftphotel/ftpindhold/ servicepacks + IE
http://www.microsoft.com/downloads/details.aspx?FamilyId=D531BF00-D7BE-48E3-ABCC-961602BD72C2&displaylang=da - Hotfixes efter SP1 til XP.
http://www.microsoft.com/downloads/details.aspx?displaylang=da&FamilyID=3549EA9E-DA3F-43B9-A4F1-AF243B6168F3 - Sasserfix.
Bagefter opdaterer du online hos microsoft.
Genstart og kom med en ny logfil, så jeg kan se om alt er med.
Signatur
Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”
Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/
Nierne bomaye - You’ll never walk alone
qui potest, obligatur
Hej jeg prøver at følge din vejledning, men kan ikke finde og slette filerne———————————————————-
Slettes i fejlsikret.
C:/Programmer/websx <- Mappen.
C:/WINDOWS/System32/ermcapt.exe <- Filen. ———————————————————-
de er der bare ikke….
tilgengæld har jeg et problem med at installere service pack 1 jeg får besked om at
C:/windows/system32drivers/atapi.sys bliver brugt af et andet program selvom alter lukket ned. her er sidste nye log:
Logfile of HijackThis v1.97.7
Scan saved at 09:09:45, on 13-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Sophos/Remote Update/cachemgr.exe
C:/Programmer/Cisco Systems/VPN Client/cvpnd.exe
C:/Programmer/Sophos SWEEP for NT/SWNETSUP.EXE
C:/Programmer/Sophos SWEEP for NT/SWEEPSRV.SYS
C:/WINDOWS/Explorer.EXE
F:/winamp/Winamp/winampa.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
C:/WINDOWS/System32/cwdiali.exe
C:/hijackthis/HijackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O4 - HKLM/../Run: [WinampAgent] F:/winamp/Winamp/winampa.exe
O4 - HKLM/../Run: [DAEMON Tools-1033] “C:/Programmer/D-Tools/daemon.exe” -lang 1033
O4 - HKLM/../Run: [cwdiali] C:/WINDOWS/System32/cwdiali.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - Startup: DLHelperEXE.exe
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:/Programmer/Cisco Systems/VPN Client/ipsecdialer.exe
O4 - Global Startup: Remote Update Monitor.lnk = C:/Programmer/Sophos/Remote Update/imonitor.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38063.2840393518
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
.....Forsættelse til posten ovenfor
Har netop lørt spybo, ad-aware, cwsschredder. efter at jeg igen ville downloade en eller anden dialer så her er lige en ny log.
ps. jeg har gentaget pkt 1-12 samt afinstalleret mit p2p-program ARES og slettet alt der var i shared folder.
Logfile of HijackThis v1.97.7
Scan saved at 10:12:20, on 13-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Programmer/Sophos/Remote Update/cachemgr.exe
C:/Programmer/Cisco Systems/VPN Client/cvpnd.exe
C:/Programmer/Sophos SWEEP for NT/SWNETSUP.EXE
C:/Programmer/Sophos SWEEP for NT/SWEEPSRV.SYS
C:/WINDOWS/Explorer.EXE
F:/winamp/Winamp/winampa.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
C:/WINDOWS/System32/cwdiali.exe
C:/hijackthis/HijackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O4 - HKLM/../Run: [WinampAgent] F:/winamp/Winamp/winampa.exe
O4 - HKLM/../Run: [DAEMON Tools-1033] “C:/Programmer/D-Tools/daemon.exe” -lang 1033
O4 - HKLM/../Run: [cwdiali] C:/WINDOWS/System32/cwdiali.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - Startup: DLHelperEXE.exe
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:/Programmer/Cisco Systems/VPN Client/ipsecdialer.exe
O4 - Global Startup: Remote Update Monitor.lnk = C:/Programmer/Sophos/Remote Update/imonitor.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:/Programmer/Adobe/Acrobat 6.0/Distillr/acrotray.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:/Programmer/Sophos SWEEP for NT/ICMON.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38063.2840393518
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Redaktør
Antal indlæg: 25535
Hej Kresten
Der er lidt mere. Genstart i fejlsikret tilstand. Du kan taste f8 under opstart og vælge fejlsikret.
Kør en scanning med Hijackthis, så du kan se alle filer.
Det er disse, som skal fixes:
O4 - HKLM/../Run: [cwdiali] C:/WINDOWS/System32/cwdiali.exe
O4 - Startup: DLHelperEXE.exe —————————————————————————————————-
Dem her kan du også med fordel fixe. De forsvinder ikke, kun fra run, og her ligger de bare og sluger dine kræfter:
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE —————————————————————————————————-
For at kunne se alle filer og mapper, så følg denne vejledning:
Åbn en mappe, klik på Funktioner >Mappeindstillinger >Vis.
Fjern flueben ved “Skjul beskyttede operativsystemfiler”.
Fjern flueben ved “Skjul filtypenavne for kendte filtyper”.
Sæt prik i “Vis skjulte filer og mapper”.
Genstart i fejlsikret tilstand søg og slet:
C:/WINDOWS/System32/cwdiali.exe
Jeg vil råde dig kraftigt til at hente og installere Sp1 til Windows og IE samt alle kritiske opdateringer her:
http://v4.windowsupdate.microsoft.com/da/default.asp
Du vil blive ved at få problemer så længe du ikke har opdateret.
Genstart og så en ny log tjek, men først efter opdateringen.
Administrator
Antal indlæg: 55087
Angående Atapi.sys den skal du bare slette, omdøb den evt. til atapi.old.
Der bliver installeret en ny når du installerer Servicepack.
Signatur
Member of “Alliance of Security Analysis Professionals” - Alle angaben wie immer “nur mit pistole”
Græd du også over eventyret om smedens kat, da du var lille?
http://www.spywarefri.dk/medarbejderne/
Nierne bomaye - You’ll never walk alone
qui potest, obligatur
Jeg prøvede at omdøbe ATAPI.sys of slette
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
Derefter genstartede jeg og så gik det galt…..
Computeren insisterede på at der var fejl på partition F: jeg prøvede via dos at omdøbe atapi filen igen men det virkede ikke nu er drevet formateret windows installeret på ny men jeg døjer stadig med popups og uønsket start side….
alle popups drejer sig om spyware removal her er sidste nye log
PS. har kørt spybot,adaware, spykiller, spy sweeper og CWShredder
Logfile of HijackThis v1.97.7
Scan saved at 12:47:55, on 21-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/Programmer/D-Tools/daemon.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/Messenger/msmsgs.exe
C:/Programmer/adobe/Acrobat 6.0/Distillr/acrotray.exe
C:/MATLAB6p5/webserver/bin/win32/matlabserver.exe
C:/Programmer/Fælles filer/Lanovation/PrismXL/PRISMXL.SYS
C:/Programmer/Webroot/Spy Sweeper/SpySweeper.exe
D:/spyware/HijackThis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,HomeOldSP = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {0ABC9079-7B63-44F4-87B9-3AB3B796A729} - C:/WINDOWS/mrhop.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O4 - HKLM/../Run: [DAEMON Tools-1033] “C:/Programmer/D-Tools/daemon.exe” -lang 1033
O4 - HKLM/../Run: [CorelDRAW Graphics Suite 11b] C:/Programmer/Corel/Corel Graphics 12/Languages/EN/Programs/Registration.exe /title=“CorelDRAW Graphics Suite 12” /date=060504 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Programmer/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [ares] “D:/Programmer/Ares/Ares.exe” -h
O4 - HKCU/../Run: [SpyKiller] C:/Programmer/SpyKiller/spykiller.exe /startup
O4 - HKCU/../Run: [SpySweeper] C:/Programmer/Webroot/Spy Sweeper/SpySweeper.exe /0
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:/Programmer/adobe/Acrobat 6.0/Distillr/acrotray.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Redaktør
Antal indlæg: 17644
Hent dette program og installer det:
http://www.diamondcs.com.au/downloads/apm.exe
I det øverste vindue skal du vælge Explorer.exe - i det nederste vindue skal du finde mrhop.dll, højreklikke på den og vælge “Unload DLL” - klik OK.
Kør HijackThis, scan og sæt et flueben ud for følgende linier - luk øvrige programvinduer - klik “Fix checked”:
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/mrhop.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {0ABC9079-7B63-44F4-87B9-3AB3B796A729} - C:/WINDOWS/mrhop.dll
Genstart
Installer, opdater og scan med Adaware (http://www.lavasoft.de/software/adaware ). Indstillinger inden scanning:
http://www.spywarefri.dk/tipsogtricks.htm#adaware
Signatur
Gode råd om sikkerhed….
Ny log
Logfile of HijackThis v1.97.7
Scan saved at 13:37:48, on 21-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/MATLAB6p5/webserver/bin/win32/matlabserver.exe
C:/Programmer/Fælles filer/Lanovation/PrismXL/PRISMXL.SYS
C:/WINDOWS/Explorer.EXE
C:/Programmer/D-Tools/daemon.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/Messenger/msmsgs.exe
D:/Programmer/Ares/Ares.exe
C:/Programmer/Webroot/Spy Sweeper/SpySweeper.exe
C:/Programmer/adobe/Acrobat 6.0/Distillr/acrotray.exe
D:/spyware/HijackThis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/ActiveX/AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:/Programmer/Adobe/Acrobat 6.0/Acrobat/AcroIEFavClient.dll
O4 - HKLM/../Run: [DAEMON Tools-1033] “C:/Programmer/D-Tools/daemon.exe” -lang 1033
O4 - HKLM/../Run: [CorelDRAW Graphics Suite 11b] C:/Programmer/Corel/Corel Graphics 12/Languages/EN/Programs/Registration.exe /title=“CorelDRAW Graphics Suite 12” /date=060504 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Programmer/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [ares] “D:/Programmer/Ares/Ares.exe” -h
O4 - HKCU/../Run: [SpyKiller] C:/Programmer/SpyKiller/spykiller.exe /startup
O4 - HKCU/../Run: [SpySweeper] C:/Programmer/Webroot/Spy Sweeper/SpySweeper.exe /0
O4 - Global Startup: Microsoft Office.lnk = C:/Programmer/Microsoft Office/Office10/OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:/Programmer/adobe/Acrobat 6.0/Distillr/acrotray.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Windows Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Redaktør
Antal indlæg: 17644
Spykiller kan jeg ikke anbefale og jeg vil foreslå, at du afinstallerer den ved Start -> Kontrol Panel -> Tilføj/fjern programmer. Spykiller lægger selv adware/spyware på din computer.
Ares.exe - er det noget du har lagt ind selv?
Signatur
Gode råd om sikkerhed….