Såvidt jeg kan se, ser det rimelig fint ud nu. Jeg har ikke fået en eneste fejlmelding. De forskellige søgestationer er også væk, og efter to forsøg viser en Ad-aware test viser ikke noget.
Prøv at se om du ikke kan poste en Hijackthis log herind nu så det sidste kan blive tjekket. Kør Hijackthis, Scan og vælg Save log. Forhåbentlig åbner Notepad nu som den skal. Kopier alt indholdet af loggen og post det herind.
Logfile of HijackThis v1.98.0
Scan saved at 16:21:02, on 06-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/pctspk.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/SOINTGR.EXE
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/ICQLite/ICQLite.exe
C:/Programmer/MSN Messenger/MsnMsgr.Exe
C:/WINDOWS/System32/RUNDLL32.EXE
C:/Documents and Settings/All Users/Menuen Start/Programmer/Start/BQLF.EXE
C:/Programmer/Fælles filer/Real/Update_OB/rnathchk.exe
D:/Documents and Settings/Bruger/Dokumenter/Hijack/hijackthis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://tdconline.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.tiscali.dk/
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.opasia.dk/msie_search.html
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://tdconline.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [S3TRAY2] S3tray2.exe
O4 - HKLM/../Run: [SO5 Integrator Pass Two] C:/WINDOWS/SOINTGR.EXE
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -minimize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [SuperBar.Component] C:/WINDOWS/system32/inetsrv/services.exe
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [pynwh] C:/WINDOWS/pynwh.exe
O4 - HKCU/../Run: [MsnMsgr] “C:/Programmer/MSN Messenger/MsnMsgr.Exe” /background
O4 - HKCU/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU/../Run: [WNSI] C:/WINDOWS/System32/wnscpcc.exe
O4 - HKCU/../RunOnce: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -trayboot
O4 - Global Startup: BQLF.EXE
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra ‘Tools’ menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.dk/
O15 - Trusted Zone: http://*.mt-download.com
O15 - Trusted Zone: http://*.xxxtoolbar.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/dk/win/QuickTimeInstaller.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
Kør Hijackthis igen, sæt vinge ved dem jeg nævner herunder og luk alle andre vinduer end Hijackthis.
Klik derefter på Fix
Det er disse du skal fixe:
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O4 - HKLM/../Run: [SuperBar.Component] C:/WINDOWS/system32/inetsrv/services.exe
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [pynwh] C:/WINDOWS/pynwh.exe
O4 - HKCU/../Run: [WNSI] C:/WINDOWS/System32/wnscpcc.exe
O4 - Global Startup: BQLF.EXE
O15 - Trusted Zone: http://*.mt-download.com
O15 - Trusted Zone: http://*.xxxtoolbar.com
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
Tryk Ctrl + alt + del for at åbne process manager.
Find programmet BQLF.exe, marker den og klik på Afslut job/process . Kig både under fanen Programmer og processer.
Naviger derefter til denne sti og slet filen BQLF.EXE:
C:/Documents and Settings/All Users/Menuen Start/Programmer/Start/BQLF.EXE
De andre filer ser det ud til du har fået slettet, men brug for en sikkerhedsskyld Stifinder og se om de stadig ligger der:
C:/WINDOWS/system32/inetsrv/services.exe
C:/WINDOWS/system32/drivers/csrss.exe
C:/WINDOWS/System32/wnscpcc.exe
Husk at kigge i de rigtige mapper.
Til sidst en ny log.
Logfile of HijackThis v1.98.0
Scan saved at 12:52:07, on 07-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/SOINTGR.EXE
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/ICQLite/ICQLite.exe
C:/Programmer/MSN Messenger/MsnMsgr.Exe
C:/WINDOWS/System32/RUNDLL32.EXE
C:/Programmer/Fælles filer/Real/Update_OB/rnathchk.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/pctspk.exe
D:/Documents and Settings/Bruger/Dokumenter/Hijack/hijackthis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://tdconline.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.tiscali.dk/
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.opasia.dk/msie_search.html
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://tdconline.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [S3TRAY2] S3tray2.exe
O4 - HKLM/../Run: [SO5 Integrator Pass Two] C:/WINDOWS/SOINTGR.EXE
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -minimize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [SuperBar.Component] C:/WINDOWS/system32/inetsrv/services.exe
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [pynwh] C:/WINDOWS/pynwh.exe
O4 - HKCU/../Run: [MsnMsgr] “C:/Programmer/MSN Messenger/MsnMsgr.Exe” /background
O4 - HKCU/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU/../Run: [WNSI] C:/WINDOWS/System32/wnscpcc.exe
O4 - HKCU/../RunOnce: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -trayboot
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra ‘Tools’ menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.dk/
O15 - Trusted Zone: http://*.mt-download.com
O15 - Trusted Zone: http://*.xxxtoolbar.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/dk/win/QuickTimeInstaller.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
Administrator
Antal indlæg: 55510
Luk alle Internet explorervinduer, når du har kopieret hele indlægget her over i et notesblokdokument.
Åbn Notesblok, kopier det med fed ind, vælg Gem som og gem den som Slet.bat.
Attrib -h -r -s C:/WINDOWS/system32/inetsrv/services.exe
Attrib -h -r -s C:/WINDOWS/system32/drivers/csrss.exe
Attrib -h -r -s C:/WINDOWS/system32/drivers/csrss.exe
Attrib -h -r -s C:/WINDOWS/System32/wnscpcc.exe
del C:/WINDOWS/system32/inetsrv/services.exe /f
del C:/WINDOWS/system32/drivers/csrss.exe /f
del C:/WINDOWS/system32/drivers/csrss.exe /f
del C:/WINDOWS/System32/wnscpcc.exe /f
Dobbeltklik så på Slet.bat, det burde tage livet af dem.
Kør så Hijackthis igen og fix:
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O4 - HKLM/../Run: [SuperBar.Component] C:/WINDOWS/system32/inetsrv/services.exe
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [pynwh] C:/WINDOWS/pynwh.exe
O4 - HKCU/../Run: [WNSI] C:/WINDOWS/System32/wnscpcc.exe
O15 - Trusted Zone: http://*.mt-download.com
O15 - Trusted Zone: http://*.xxxtoolbar.com
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
Åbn så Internet Explorer, klik på Funktioner->Internetindstillinger->Sikkerhed, klik på det grønne skilt med fluebenet, klik på Websteder og fjern alt hvad der ligger derinde.
Hent og installer IE-Spyad herfra:
https://netfiles.uiuc.edu/ehowes/www/res/ie-spyad.exe
Dansk manual finder du her:
http://www.spywarefri.dk/iespyad.manual.htm
Installer programmet efter vejledningen, det burde holde noget af skidtet ude.
Genstart og ny log.
Signatur
qui potest, obligatur
Nierne bomaye - You’ll never walk alone
Kaffen er drukket
Kassen er lukket
Støtten gør mere nytte
Hos de små og forknytte
Børns vilkår
Hospitalsklovne
Logfile of HijackThis v1.98.0
Scan saved at 16:18:56, on 07-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/SOINTGR.EXE
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/ICQLite/ICQLite.exe
C:/Programmer/MSN Messenger/MsnMsgr.Exe
C:/WINDOWS/System32/RUNDLL32.EXE
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/pctspk.exe
D:/Documents and Settings/Bruger/Dokumenter/Hijack/hijackthis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://tdconline.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.tiscali.dk/
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.opasia.dk/msie_search.html
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://tdconline.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [S3TRAY2] S3tray2.exe
O4 - HKLM/../Run: [SO5 Integrator Pass Two] C:/WINDOWS/SOINTGR.EXE
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -minimize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [SuperBar.Component] C:/WINDOWS/system32/inetsrv/services.exe
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [pynwh] C:/WINDOWS/pynwh.exe
O4 - HKCU/../Run: [MsnMsgr] “C:/Programmer/MSN Messenger/MsnMsgr.Exe” /background
O4 - HKCU/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU/../Run: [WNSI] C:/WINDOWS/System32/wnscpcc.exe
O4 - HKCU/../RunOnce: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -trayboot
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra ‘Tools’ menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.dk/
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/dk/win/QuickTimeInstaller.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
Under installationen af IE-spyad kom flere af tingene tilbage. Purity Scan og de ting, jeg havde slettet på sikkerhedsstedet. Jeg har nu kørt Ad-aware, Spybot og slettet de websteder, jeg fik besked på, og nu ser loggen sådan ud:
Logfile of HijackThis v1.98.0
Scan saved at 16:49:27, on 07-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/SOINTGR.EXE
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/ICQLite/ICQLite.exe
C:/WINDOWS/system32/inetsrv/services.exe
C:/Programmer/MSN Messenger/MsnMsgr.Exe
C:/WINDOWS/System32/RUNDLL32.EXE
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/pctspk.exe
D:/Documents and Settings/Bruger/Dokumenter/Hijack/hijackthis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://tdconline.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.tiscali.dk/
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.opasia.dk/msie_search.html
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://tdconline.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [S3TRAY2] S3tray2.exe
O4 - HKLM/../Run: [SO5 Integrator Pass Two] C:/WINDOWS/SOINTGR.EXE
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -minimize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [SuperBar.Component] C:/WINDOWS/system32/inetsrv/services.exe
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [pynwh] C:/WINDOWS/pynwh.exe
O4 - HKLM/../Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:/WINDOWS/system32/wbem/svchost.exe
O4 - HKCU/../Run: [MsnMsgr] “C:/Programmer/MSN Messenger/MsnMsgr.Exe” /background
O4 - HKCU/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU/../Run: [WNSI] C:/WINDOWS/System32/wnscpcc.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra ‘Tools’ menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.dk/
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/dk/win/QuickTimeInstaller.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
Og nu kommer der Spyware-alarmer igen.
Redaktør
Antal indlæg: 25535
Hej fs
Fra fejlsikret tilstand skal du køre en scanning med Hijackthis
Hold CTRL + Alt nede og tast delete. Find denne process og afslut jobbet: C:/WINDOWS/system32/inetsrv/services.exe
Fix disse:
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O4 - HKLM/../Run: [SuperBar.Component] C:/WINDOWS/system32/inetsrv/services.exe
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [pynwh] C:/WINDOWS/pynwh.exe
O4 - HKLM/../Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:/WINDOWS/system32/wbem/svchost.exe
O4 - HKCU/../Run: [WNSI] C:/WINDOWS/System32/wnscpcc.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
For at kunne se alle filer og mapper, så følg denne vejledning:
Åbn en mappe, klik på Funktioner >Mappeindstillinger >Vis.
Fjern flueben ved “Skjul beskyttede operativsystemfiler”.
Fjern flueben ved “Skjul filtypenavne for kendte filtyper”.
Sæt prik i “Vis skjulte filer og mapper”.
Søg og slet de mapper eller filer markeret med fed:
C:/WINDOWS/system32/inetsrv/services.exe
C:/WINDOWS/system32/drivers/csrss.exe
C:/WINDOWS/pynwh.exe
C:/WINDOWS/system32/wbem/svchost.exe
C:/WINDOWS/System32/wnscpcc.exe
Genstart normalt.
Download, installer og køre denne engangscanner: http://www.mwti.net/antivirus/free_utilities.asp
Aktiver det hele i opsætningen derinde, så du får scannet alt igennem
Og når det er gjort, skal vi se en ny log fra dig.
Nogle af System 32-tingene kan jeg ikke finde, og når jeg trykker på fix checked, og har bekræftet, at jeg vil slette det, får jeg en error-meddelelse, og opfordring til at kontakte Spywareinfo.
Men sådan ser loggen ud nu:
Logfile of HijackThis v1.98.0
Scan saved at 20:27:36, on 07-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/SOINTGR.EXE
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/ICQLite/ICQLite.exe
C:/Programmer/MSN Messenger/MsnMsgr.Exe
C:/WINDOWS/System32/RUNDLL32.EXE
C:/Programmer/Fælles filer/Real/Update_OB/rnathchk.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/pctspk.exe
C:/WINDOWS/explorer.exe
D:/Documents and Settings/Bruger/Dokumenter/Hijack/hijackthis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://tdconline.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.tiscali.dk/
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.opasia.dk/msie_search.html
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://tdconline.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [S3TRAY2] S3tray2.exe
O4 - HKLM/../Run: [SO5 Integrator Pass Two] C:/WINDOWS/SOINTGR.EXE
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -minimize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:/WINDOWS/system32/wbem/svchost.exe
O4 - HKCU/../Run: [MsnMsgr] “C:/Programmer/MSN Messenger/MsnMsgr.Exe” /background
O4 - HKCU/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU/../RunOnce: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -trayboot
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra ‘Tools’ menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.dk/
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/dk/win/QuickTimeInstaller.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
Hvad skal jeg gøre med resultatet af virus-scanningen ?
Redaktør
Antal indlæg: 25535
Hej fs
Der er stadig lidt vi skal have væk. Det resultat fra scanningen, kan du bare lukke, den behøver vi ikke at se.
Genstart din maskine i fejlsikret tilstand. (tast f8) under genstart og vælg fejlsikret tilstand.
Kør en scanning med Hijackthis. Luk alle vinduer og fix disse:
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O4 - HKLM/../Run: [AdRotator.Application] C:/WINDOWS/system32/drivers/csrss.exe
O4 - HKLM/../Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:/WINDOWS/system32/wbem/svchost.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
Og så skal du søge og slette det her som er markeret med fed:
C:/WINDOWS/system32/drivers/csrss.exe
C:/WINDOWS/system32/wbem/svchost.exe Pas nu på at det er den som lige præcis ligger i mappen wbem du skal slette, der ligger nemlig en legal i system32 mappen.
Genstart din computer.
Du skal også lige hente og installere programmet Ad-aware hvis du da ikke har det i forvejen. Opdater det straks efter installationen, og inden du kører en scanning med denne. Fjern alt hvad den finder. Programmet samt brugervejledning på dansk finder du her: http://www.spywarefri.dk/vaerktoj.htm#adaware
Følg også vejledningen her til udvidet søgning: http://www.spywarefri.dk/tipsogtricks.htm#adaware
Så kører du atter en tur med engangsskanneren fra Kaspersky - Aktiver det hele i opsætningen derinde, så den kan skanne alt igennem.
Genstart din computer, kør en ny scanning med HijackThis, kopier en ny log herind til tjek.
Jeg kan ikke finde de to system32´er, når jeg søger. I processlinjen er de, men her får man at vide, at det er en kritisk fil, og ikke kan slettes.
Logfile of HijackThis v1.98.0
Scan saved at 22:39:10, on 08-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/SOINTGR.EXE
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/ICQLite/ICQLite.exe
C:/Programmer/MSN Messenger/MsnMsgr.Exe
C:/WINDOWS/System32/RUNDLL32.EXE
C:/Programmer/Fælles filer/Real/Update_OB/rnathchk.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/system32/pctspk.exe
D:/Documents and Settings/Bruger/Dokumenter/Hijack/hijackthis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://tdconline.dk/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.tiscali.dk/
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://www.opasia.dk/msie_search.html
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page_bak = http://tdconline.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Programmer/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/Programmer/Spybot - Search & Destroy/SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [S3TRAY2] S3tray2.exe
O4 - HKLM/../Run: [SO5 Integrator Pass Two] C:/WINDOWS/SOINTGR.EXE
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -minimize
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:/WINDOWS/system32/wbem/svchost.exe
O4 - HKCU/../Run: [MsnMsgr] “C:/Programmer/MSN Messenger/MsnMsgr.Exe” /background
O4 - HKCU/../Run: [NvMediaCenter] RUNDLL32.EXE C:/WINDOWS/System32/NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU/../RunOnce: [ICQ Lite] C:/Programmer/ICQLite/ICQLite.exe -trayboot
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra ‘Tools’ menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:/Programmer/ICQLite/ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:/Programmer/Messenger/MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.dk/
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/dk/win/QuickTimeInstaller.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
Redaktør
Antal indlæg: 25535
Hej fs
Vi skal altså have de sidste med. Genstart i fejlsikret tilstand. Kør en scanning med Hijack og fix disse:
O2 - BHO: (no name) - {38FC6F73-BA42-2EC7-D157-615504A12C1B} - C:/WINDOWS/System32/xml.dll (file missing)
O4 - HKLM/../Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:/WINDOWS/system32/wbem/svchost.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
Søg på denne fil her og slet den:
C:/WINDOWS/system32/wbem/svchost.exe Den som ligger i denne mappe wbem den skal væk, og du burde få lov til at slette den. Den legale svchost.exe ligger direkte i system32 mappen, og den må IKKE slettes.
Disse er overflødige og kan fixes:
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
Genstart normalt
Download, og kør denne engangscanner: http://www.mwti.net/antivirus/free_utilities.asp
Aktiver det hele i opsætningen derinde, så du får scannet alt igennem
Genstart, ny scanning med HJ og ny log herind til tjek.
Redaktør
Antal indlæg: 25535
Hej Wester og velkommen til Spywarefri
Du skal gå ud og oprette din egen tråd her: http://www.spywarefri.dk/forum/forum.asp?FORUM_ID=15
Vi kan ikke have de forskellig tråde blandet sammen. Når du har set denne kommentar, sletter jeg atter din log som ligger og forstyrrer denne tråd her.