Hej Per og kollegaer,
Efter at ha brugt Spybot og Ad-aware er jeg fortsat med Hijackthis og har nu en logliste fra scanningen som det er virkeligt godt hvis I kunne kigge efter for at jeg ikke sletter noget fatalt. Problemet er at min hjemmeside tvinges bort fra den side jeg har valgt og at nogle snuskede links som jeg ikke ved hvor kommer fra hele tiden kommer tilbage i mine favorites selv om jeg sletter dem. Mit Norton program som jeg har hentet i en kort testperiode er heller ikke i stand til at klare problemet, og siger blot “attempt to connect to local computer using the backdoor/Sub Seven Trojan horse detected’. Den siger da at programmet et blevet blokeret, men jeg vil meget gerne helt a med det
Min mistanke er at de her er specielt slemme:
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchURL = http://66.250.130.200/main/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://66.250.130.200/main/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://66.250.130.200/main/sp.php
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://66.250.130.200/main/hp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://66.250.130.200/main/sp.php
Den her siger HijackThis heller ikke er go:
O1 - Hosts: 205.177.124.66 auto.search.msn.com
Men de kommer tilbage selv om jeg “fixer” dem med HijackThis.
Her er hele logen.
Mange tak!
Frank
Logfile of HijackThis v1.97.7
Scan saved at 8:06:05 AM, on 1/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Program Files/Common Files/Symantec Shared/ccSetMgr.exe
C:/Program Files/Common Files/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Program Files/Network Associates/VirusScan/Avsynmgr.exe
C:/Program Files/Common Files/Symantec Shared/ccProxy.exe
C:/Program Files/Norton AntiVirus/navapsvc.exe
C:/Program Files/Norton AntiVirus/SAVScan.exe
C:/Program Files/Common Files/Symantec Shared/SNDSrvc.exe
C:/Program Files/Common Files/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/wanmpsvc.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/System32/00THotkey.exe
C:/Program Files/Apoint2K/Apoint.exe
C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
C:/Program Files/TOSHIBA/TOSHIBA Controls/TFncKy.exe
C:/WINDOWS/System32/TFNF5.exe
C:/WINDOWS/System32/TPWRTRAY.EXE
C:/toshiba/ivp/ism/pinger.exe
C:/Program Files/Apoint2K/Apntex.exe
C:/Program Files/Common Files/Real/Update_OB/realsched.exe
C:/Program Files/Common Files/Real/Update_OB/rnathchk.exe
C:/Program Files/Common Files/Symantec Shared/ccApp.exe
C:/Program Files/Messenger/msmsgs.exe
C:/WINDOWS/UDTQDBBRAUETXO.exe
C:/Program Files/CompuServe 7.0/wcs2000.exe
C:/Program Files/CompuServe 7.0/cstray.exe
C:/Program Files/FinePixViewer/QuickDCF.exe
C:/Program Files/Internet Explorer/iexplore.exe
C:/Documents and Settings/davidson/Desktop/HijackThis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchURL = http://66.250.130.200/main/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://66.250.130.200/main/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://66.250.130.200/main/sp.php
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://66.250.130.200/main/hp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://66.250.130.200/main/sp.php
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.toshiba.com
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchAssistant = http://www.sharempeg.com/find/
R1 - HKCU/Software/Microsoft/Internet Explorer,CustomizeSearch = http://www.sharempeg.com/find/
O1 - Hosts: 205.177.124.66 auto.search.msn.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Program Files/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: Httper - {A5483501-070C-41DD-AF44-9BD8864B3015} - C:/Program Files/Httper/httper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [00THotkey] C:/WINDOWS/System32/00THotkey.exe
O4 - HKLM/../Run: [000StTHK] 000StTHK.exe
O4 - HKLM/../Run: [Apoint] C:/Program Files/Apoint2K/Apoint.exe
O4 - HKLM/../Run: [TouchED] C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
O4 - HKLM/../Run: [TFncKy] TFncKy.exe /Type 20
O4 - HKLM/../Run: [TFNF5] TFNF5.exe
O4 - HKLM/../Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM/../Run: [Pinger] c:/toshiba/ivp/ism/pinger.exe /run
O4 - HKLM/../Run: [Drag’n Drop CD] C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe /StartUp
O4 - HKLM/../Run: [REGSHAVE] C:/Program Files/REGSHAVE/REGSHAVE.EXE /AUTORUN
O4 - HKLM/../Run: [TkBellExe] C:/Program Files/Common Files/Real/Update_OB/realsched.exe -osboot
O4 - HKLM/../Run: [Soundmx] /soundmx.exe
O4 - HKLM/../Run: [ccApp] “C:/Program Files/Common Files/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [URLLSTCK.exe] C:/Program Files/Norton Internet Security/UrlLstCk.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Program Files/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [Internet Washer Pro] C:/Program Files/Internet Washer Pro/iw.exe min
O4 - HKCU/../Run: [System Soap Pro] C:/Program Files/System Soap Pro/soap.exe min
O4 - HKCU/../Run: [loader] c:/WINDOWS/loader.exe
O4 - HKCU/../Run: [SWHNBQULOG] C:/WINDOWS/PTRERNPQY.exe
O4 - Global Startup: CompuServe 7.0 Tray Icon.lnk = C:/Program Files/CompuServe 7.0/cstray.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:/Program Files/Microsoft Office/Office/OSA9.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1074451698987
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.internetwasher.com/iwasher/pptproactauthakamai/internetwasherpro.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38004.3227546296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM/System/CCS/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
O17 - HKLM/System/CS1/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
O19 - User stylesheet: C:/WINDOWS/Web/tips.ini
O19 - User stylesheet: C:/WINDOWS/hh.htt (HKLM)
Redaktør
Antal indlæg: 25535
Hej Frank og velkommen til Spywarefri.
Nu skal vi tjekke din log. Vender tilbage med svar til dig.
Redaktør
Antal indlæg: 25535
Så er jeg her igen
Hent cwsschredder her:
http://www.spywareinfo.com/~merijn/junk/CWShredder.exe
Kør programmet, tjek for updates, luk alle vinduer, undtaget cwsschredder, klik på Next, den scanner nu, når den er færdigt klik på Fix, klik på Exit.
Ny logfil. For der ligger flere ting i den log som skal væk.
Mange tak for tippet om brugen af CWShedder. Her kommer den nye log. Lad mig endelig vide hvis der er mer som jeg burde slette.
Mange tak, Frank.[:D]
Logfile of HijackThis v1.97.7
Scan saved at 10:25:24 PM, on 1/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Program Files/Common Files/Symantec Shared/ccSetMgr.exe
C:/Program Files/Common Files/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Program Files/Network Associates/VirusScan/Avsynmgr.exe
C:/Program Files/Common Files/Symantec Shared/ccProxy.exe
C:/Program Files/Norton AntiVirus/navapsvc.exe
C:/Program Files/Norton AntiVirus/SAVScan.exe
C:/Program Files/Common Files/Symantec Shared/SNDSrvc.exe
C:/Program Files/Common Files/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/wanmpsvc.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/System32/00THotkey.exe
C:/Program Files/Apoint2K/Apoint.exe
C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
C:/Program Files/TOSHIBA/TOSHIBA Controls/TFncKy.exe
C:/Program Files/Apoint2K/Apntex.exe
C:/WINDOWS/System32/TFNF5.exe
C:/WINDOWS/System32/TPWRTRAY.EXE
C:/toshiba/ivp/ism/pinger.exe
C:/WINDOWS/System32/wuauclt.exe
C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe
C:/Program Files/Common Files/Real/Update_OB/realsched.exe
C:/Program Files/Common Files/Symantec Shared/ccApp.exe
C:/Program Files/Common Files/Real/Update_OB/rnathchk.exe
C:/Program Files/Messenger/msmsgs.exe
C:/Program Files/CompuServe 7.0/cstray.exe
C:/Program Files/FinePixViewer/QuickDCF.exe
C:/Program Files/CompuServe 7.0/wcs2000.exe
C:/Documents and Settings/davidson/Desktop/HijackThis.exe
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.toshiba.com
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchAssistant = ,
R1 - HKCU/Software/Microsoft/Internet Explorer,CustomizeSearch = ,
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Program Files/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: Httper - {A5483501-070C-41DD-AF44-9BD8864B3015} - C:/Program Files/Httper/httper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [00THotkey] C:/WINDOWS/System32/00THotkey.exe
O4 - HKLM/../Run: [000StTHK] 000StTHK.exe
O4 - HKLM/../Run: [Apoint] C:/Program Files/Apoint2K/Apoint.exe
O4 - HKLM/../Run: [TouchED] C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
O4 - HKLM/../Run: [TFncKy] TFncKy.exe /Type 20
O4 - HKLM/../Run: [TFNF5] TFNF5.exe
O4 - HKLM/../Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM/../Run: [Pinger] c:/toshiba/ivp/ism/pinger.exe /run
O4 - HKLM/../Run: [Drag’n Drop CD] C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe /StartUp
O4 - HKLM/../Run: [REGSHAVE] C:/Program Files/REGSHAVE/REGSHAVE.EXE /AUTORUN
O4 - HKLM/../Run: [TkBellExe] C:/Program Files/Common Files/Real/Update_OB/realsched.exe -osboot
O4 - HKLM/../Run: [ccApp] “C:/Program Files/Common Files/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [URLLSTCK.exe] C:/Program Files/Norton Internet Security/UrlLstCk.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Program Files/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [Internet Washer Pro] C:/Program Files/Internet Washer Pro/iw.exe min
O4 - HKCU/../Run: [System Soap Pro] C:/Program Files/System Soap Pro/soap.exe min
O4 - HKCU/../Run: [RDCURNVAW] C:/WINDOWS/XDNURQBP.exe
O4 - Global Startup: CompuServe 7.0 Tray Icon.lnk = C:/Program Files/CompuServe 7.0/cstray.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:/Program Files/Microsoft Office/Office/OSA9.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1074451698987
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.internetwasher.com/iwasher/pptproactauthakamai/internetwasherpro.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38004.3227546296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM/System/CCS/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
O17 - HKLM/System/CS1/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
Redaktør
Antal indlæg: 25535
Hej igen
Ja det hjalp jo lidt på det, men som jeg også fortalte så ligger der en del mere som også skal renses ud i.
Jeg vælger at tage det hele fra fejlsikret tilstand, så du skal lige genstarte din computer i fejlsikret tilstand.
Du skal nu til at i gang med at fixe. Først skal du slå systemgendannelse fra. Hvis du ikke ved, hvordan du gør det så kig her: http://spywarefri.dk/virusscannere.htm#alle
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte en vinge ud for alle disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked. Efter fix skal du genstarte din computer.
Det er disse, som skal fixes:
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchAssistant = ,
R1 - HKCU/Software/Microsoft/Internet Explorer,CustomizeSearch = ,
O2 - BHO: Httper - {A5483501-070C-41DD-AF44-9BD8864B3015} - C:/Program Files/Httper/httper.dll
O4 - HKLM/../Run: [TkBellExe] C:/Program Files/Common Files/Real/Update_OB/realsched.exe -osboot
O4 - HKCU/../Run: [Internet Washer Pro] C:/Program Files/Internet Washer Pro/iw.exe min
O4 - HKCU/../Run: [System Soap Pro] C:/Program Files/System Soap Pro/soap.exe min
O4 - HKCU/../Run: [RDCURNVAW] C:/WINDOWS/XDNURQBP.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:/Program Files/Microsoft Office/Office/OSA9.EXE
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.internetwasher.com/iwasher/pptproactauthakamai/internetwasherpro.cab
Dem her :has valid reverse DNS of VTOT.proxy.aol.com – kan du godkende de tellers skal de også fixes
O17 - HKLM/System/CCS/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
O17 - HKLM/System/CS1/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
Så skal du lige se om du kan finde en mappe som vi skal have slettet hvis den er der.
C:/Program Files/Httper <—delete mappen
Tjek også lige at den ikke ligger i tilføj/fjern prg. for så skal den også væk herfra.
Genstart og kopier en ny log herind
Hej igen
Tak for tipsene!
Jeg fik sletter det meste men dog ikke alt tilsyneladende. Der var nogle som I pegede ud som jeg ikke kunne finde i loggen. Det drejer sig om disse her:
O4 - HKCU/../Run: [RDCURNVAW] C:/WINDOWS/XDNURQBP.exe
Det du skrev videre var ikke helt klart for mig. Jeg hunne ikke finde disse her filer:
Dem her :has valid reverse DNS of VTOT.proxy.aol.com – kan du godkende de tellers skal de også fixes
Fandt tilsidst heller ikke de her i loggen:
O17 - HKLM/System/CCS/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
O17 - HKLM/System/CS1/Services/Tcpip/../{396F1FDD-DC71-4D35-ABB3-F3C596B4FEA7}: NameServer = 205.188.146.146
Her kommer den nye log ind til jer:
Logfile of HijackThis v1.97.7
Scan saved at 10:21:57 PM, on 1/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Program Files/Common Files/Symantec Shared/ccSetMgr.exe
C:/Program Files/Common Files/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/Program Files/Network Associates/VirusScan/Avsynmgr.exe
C:/Program Files/Common Files/Symantec Shared/ccProxy.exe
C:/Program Files/Norton AntiVirus/navapsvc.exe
C:/Program Files/Norton AntiVirus/SAVScan.exe
C:/Program Files/Common Files/Symantec Shared/SNDSrvc.exe
C:/Program Files/Common Files/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/wanmpsvc.exe
C:/Program Files/Network Associates/VirusScan/VsStat.exe
C:/WINDOWS/System32/00THotkey.exe
C:/Program Files/Network Associates/VirusScan/Avconsol.exe
C:/Program Files/Apoint2K/Apoint.exe
C:/Program Files/Network Associates/VirusScan/Webscanx.exe
C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
C:/Program Files/TOSHIBA/TOSHIBA Controls/TFncKy.exe
C:/Program Files/Apoint2K/Apntex.exe
C:/WINDOWS/System32/TFNF5.exe
C:/WINDOWS/System32/TPWRTRAY.EXE
C:/toshiba/ivp/ism/pinger.exe
C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe
C:/Program Files/Common Files/Symantec Shared/ccApp.exe
C:/Program Files/Messenger/msmsgs.exe
C:/Program Files/System Soap Pro/soap.exe
C:/Program Files/CompuServe 7.0/cstray.exe
C:/WINDOWS/System32/wuauclt.exe
C:/Documents and Settings/davidson/Desktop/HijackThis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.toshiba.com/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Program Files/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [00THotkey] C:/WINDOWS/System32/00THotkey.exe
O4 - HKLM/../Run: [000StTHK] 000StTHK.exe
O4 - HKLM/../Run: [Apoint] C:/Program Files/Apoint2K/Apoint.exe
O4 - HKLM/../Run: [TouchED] C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
O4 - HKLM/../Run: [TFncKy] TFncKy.exe /Type 20
O4 - HKLM/../Run: [TFNF5] TFNF5.exe
O4 - HKLM/../Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM/../Run: [Pinger] c:/toshiba/ivp/ism/pinger.exe /run
O4 - HKLM/../Run: [Drag’n Drop CD] C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe /StartUp
O4 - HKLM/../Run: [REGSHAVE] C:/Program Files/REGSHAVE/REGSHAVE.EXE /AUTORUN
O4 - HKLM/../Run: [ccApp] “C:/Program Files/Common Files/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [URLLSTCK.exe] C:/Program Files/Norton Internet Security/UrlLstCk.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Program Files/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [System Soap Pro] C:/Program Files/System Soap Pro/soap.exe min
O4 - HKCU/../Run: [OSKNDE] C:/WINDOWS/TURXW.exe
O4 - Global Startup: CompuServe 7.0 Tray Icon.lnk = C:/Program Files/CompuServe 7.0/cstray.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O12 - Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1074451698987
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38004.3227546296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Igen tak
Redaktør
Antal indlæg: 25535
Hej Frank
Det pyntede på det, men der er stadig noget tilbage.
Jeg kan godt forstå du ikke kunne finde den fil der, for den har nemlig lavet sig selv om. Før var der også en som ikke blev vist i din log, men det gør den heldigvis nu, så jeg kan fixe den. Jeg tror at det er derfor den anden fil har lavet sig om. Men nu tager vi forhåbentlig lige de sidste 3 filer i et hug.
Du skal i fejlsikret tilstand.
Gå i start - kør - skriv: msconfig tast enter - fanebladet start. Find og fjern vingen til venstre for disse filer:
C:/Program Files/System Soap Pro/soap.exe min
C:/WINDOWS/TURXW.exe
Kør Hijackthis og fix de to filer:
O4 - HKCU/../Run: [System Soap Pro] C:/Program Files/System Soap Pro/soap.exe min
O4 - HKCU/../Run: [OSKNDE] C:/WINDOWS/TURXW.exe
Find og fjern denne:
C:/Program Files/System Soap Pro/soap.exe = Mappen som skal fjernes
Gå bagefter i tilføj/fjern prg. og se om der ligger noget som helst omkring især soap så skal det væk
Genstart og så kopier en ny log herind igen til forhåbentlig sidste tjek.
Hej igen!
Det ser ud til at du har ret—filerne laver sig om og er ikke til at finde umiddelbart:-(.
1. Kunne ikke finde C:/WINDOWS/TURXW.exe
Mon det nu er den her:
O4 - HKCU/../Run: [UUPNEWLTMAET] C:/WINDOWS/NSRWPPOOBWO.exe
2. Har fixet
O4 - HKCU/../Run: [System Soap Pro] C:/Program Files/System Soap Pro/soap.exe min
men ikke
O4 - HKCU/../Run: [OSKNDE] C:/WINDOWS/TURXW.exe
Skal denne mappe totalt fjernes:
C:/Program Files/System Soap Pro/soap.exe
Jeg anskaffede System Soap Pro for nyligt (men det har problemer med at køre igennem…) mn det skaber altså problemer?
3. Der er igen forsøg paa at hijacke min hjemmeside:
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchURL = http://super-spider.com/greg/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://super-spider.com/greg/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://super-spider.com/greg/sp.php
4. Her kommer ny log.
Logfile of HijackThis v1.97.7
Scan saved at 10:21:45 AM, on 1/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Program Files/Common Files/Symantec Shared/ccSetMgr.exe
C:/Program Files/Common Files/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Program Files/Network Associates/VirusScan/Avsynmgr.exe
C:/Program Files/Common Files/Symantec Shared/ccProxy.exe
C:/Program Files/Norton AntiVirus/navapsvc.exe
C:/Program Files/Norton AntiVirus/SAVScan.exe
C:/Program Files/Common Files/Symantec Shared/SNDSrvc.exe
C:/Program Files/Common Files/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/wanmpsvc.exe
C:/Program Files/Network Associates/VirusScan/VsStat.exe
C:/Program Files/Network Associates/VirusScan/Avconsol.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/System32/00THotkey.exe
C:/Program Files/Apoint2K/Apoint.exe
C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
C:/Program Files/Apoint2K/Apntex.exe
C:/Program Files/TOSHIBA/TOSHIBA Controls/TFncKy.exe
C:/WINDOWS/System32/TFNF5.exe
C:/WINDOWS/System32/TPWRTRAY.EXE
C:/toshiba/ivp/ism/pinger.exe
C:/WINDOWS/System32/wuauclt.exe
C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe
C:/Program Files/Common Files/Symantec Shared/ccApp.exe
C:/Program Files/Messenger/msmsgs.exe
C:/Program Files/System Soap Pro/soap.exe
C:/Program Files/CompuServe 7.0/cstray.exe
C:/WINDOWS/PCHealth/HelpCtr/Binaries/MSConfig.exe
C:/Documents and Settings/davidson/Desktop/HijackThis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchURL = http://super-spider.com/greg/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://super-spider.com/greg/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://super-spider.com/greg/sp.php
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.toshiba.com/
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://super-spider.com/greg/sp.php
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.toshiba.com/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Program Files/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [00THotkey] C:/WINDOWS/System32/00THotkey.exe
O4 - HKLM/../Run: [000StTHK] 000StTHK.exe
O4 - HKLM/../Run: [Apoint] C:/Program Files/Apoint2K/Apoint.exe
O4 - HKLM/../Run: [TouchED] C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
O4 - HKLM/../Run: [TFncKy] TFncKy.exe /Type 20
O4 - HKLM/../Run: [TFNF5] TFNF5.exe
O4 - HKLM/../Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM/../Run: [Pinger] c:/toshiba/ivp/ism/pinger.exe /run
O4 - HKLM/../Run: [Drag’n Drop CD] C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe /StartUp
O4 - HKLM/../Run: [REGSHAVE] C:/Program Files/REGSHAVE/REGSHAVE.EXE /AUTORUN
O4 - HKLM/../Run: [ccApp] “C:/Program Files/Common Files/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [URLLSTCK.exe] C:/Program Files/Norton Internet Security/UrlLstCk.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Program Files/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [UUPNEWLTMAET] C:/WINDOWS/NSRWPPOOBWO.exe
O4 - Global Startup: CompuServe 7.0 Tray Icon.lnk = C:/Program Files/CompuServe 7.0/cstray.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O12 - Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1074451698987
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38004.3227546296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Redaktør
Antal indlæg: 25535
Der findes to Soap og Soap pro. Hvis du har købt og betalt den, så skulle den være ok, hvor den anden er en grim en.
Kan du ikke få den til at køre, så afinstaller den via start programmer. Du kan så altid når du er helt ren geninstallere det prg.
Du skal fixe alt fra fejlsikret tilstand denne gang. Bliv i fejlsikret tilstand og tag en ny log, for ellers laver det sig om igen. Så vidt det er muligt må du slet ikke genstarte din computer før du er sikker på at den fil er væk.
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchURL = http://super-spider.com/greg/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://super-spider.com/greg/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://super-spider.com/greg/sp.php
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = http://super-spider.com/greg/sp.php
Gå i start - kør - skriv: msconfig find denne her og fjern vingen ud for den. Derefter fixer du den. Og så kan den jo godt have lavet sig om en gang til, så jeg vil råde dig til at printe din log ud som den ser ud nu, sammenligne med den her log, som er næsten ren bortset fra dem herover. Ligger der så andre filer end disse i den nye log, så skal du også fixe den eller dem. Tag dem først i msconfig, og fix dem derefter. Alt sammen skal foregå fra fejlsikret tilstand.
O4 - HKCU/../Run: [UUPNEWLTMAET] C:/WINDOWS/NSRWPPOOBWO.exe
Ny log herind til tjek.
Redaktør
Antal indlæg: 25535
Ud fra denne side:http://www.sysinfo.org/startuplist.php?filter=URLLSTCK.exe&count;=&type;=
, ser det ud til at du også roligt kan fixe denne her:
O4 - HKLM/../Run: [URLLSTCK.exe] C:/Program Files/Norton Internet Security/UrlLstCk.exe
Eller i det mindste stoppe den i msconfig.
Redaktør
Antal indlæg: 21397
Hej Frank
Vedr. System Soap Pro så skaber det problemer på næsten enhver computer. Jeg er godt klar over du har købt det, men det er altså ofte et meget problematisk program. Det er et agressivt program og det kører som om det virker, men spørgsmålet er om det gør det. Blot min private mening.
Signatur
“Kræften er mit livs sværeste kamp. Jeg vil håbe, for håbet dør aldrig. Jeg vil kæmpe, for selv en svag kamp er bedre end ingen kamp.”
Hej!
Synes som om det meste er forsvundet. Men ikke alt.
Jeg spekulerer om f.ex ikke den her burde blive slettet
O4 - HKCU/../Run: [SEWGJKRLPL] C:/WINDOWS/WPYVUUPSP.exe
Jeg fixede den men den kommer tilsyneladende tilbage—bare under et andet navn—efter genstart. Jeg har fulgt instruktionen for brug i fejlsikret tilstand, men det ka være at jeg ikke går helt rigtigt frem.
Igen mange tak!
Her kommer logen:
Logfile of HijackThis v1.97.7
Scan saved at 9:28:26 PM, on 1/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/Program Files/Common Files/Symantec Shared/ccSetMgr.exe
C:/Program Files/Common Files/Symantec Shared/ccEvtMgr.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Program Files/Network Associates/VirusScan/Avsynmgr.exe
C:/Program Files/Common Files/Symantec Shared/ccProxy.exe
C:/Program Files/Norton AntiVirus/navapsvc.exe
C:/Program Files/Norton AntiVirus/SAVScan.exe
C:/Program Files/Common Files/Symantec Shared/SNDSrvc.exe
C:/Program Files/Common Files/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/wanmpsvc.exe
C:/Program Files/Network Associates/VirusScan/VsStat.exe
C:/Program Files/Network Associates/VirusScan/Avconsol.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/System32/TPWRTRAY.EXE
C:/WINDOWS/System32/TFNF5.exe
C:/Program Files/TOSHIBA/TOSHIBA Controls/TFncKy.exe
C:/toshiba/ivp/ism/pinger.exe
C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe
C:/Program Files/Common Files/Symantec Shared/ccApp.exe
C:/Program Files/Apoint2K/Apoint.exe
C:/WINDOWS/System32/00THotkey.exe
C:/Program Files/Apoint2K/Apntex.exe
C:/Program Files/Messenger/msmsgs.exe
C:/WINDOWS/System32/wuauclt.exe
C:/Program Files/CompuServe 7.0/cstray.exe
C:/Documents and Settings/davidson/Desktop/HijackThis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.toshiba.com/
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.toshiba.com/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Program Files/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:/Program Files/Common Files/Symantec Shared/AdBlocking/NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM/../Run: [TouchED] C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
O4 - HKLM/../Run: [TFNF5] TFNF5.exe
O4 - HKLM/../Run: [TFncKy] TFncKy.exe /Type 20
O4 - HKLM/../Run: [REGSHAVE] C:/Program Files/REGSHAVE/REGSHAVE.EXE /AUTORUN
O4 - HKLM/../Run: [Pinger] c:/toshiba/ivp/ism/pinger.exe /run
O4 - HKLM/../Run: [Drag’n Drop CD] C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe /StartUp
O4 - HKLM/../Run: [ccApp] “C:/Program Files/Common Files/Symantec Shared/ccApp.exe”
O4 - HKLM/../Run: [Apoint] C:/Program Files/Apoint2K/Apoint.exe
O4 - HKLM/../Run: [00THotkey] C:/WINDOWS/System32/00THotkey.exe
O4 - HKLM/../Run: [000StTHK] 000StTHK.exe
O4 - HKLM/../Run: [URLLSTCK.exe] C:/Program Files/Norton Internet Security/UrlLstCk.exe
O4 - HKCU/../Run: [MSMSGS] “C:/Program Files/Messenger/msmsgs.exe” /background
O4 - HKCU/../Run: [SEWGJKRLPL] C:/WINDOWS/WPYVUUPSP.exe
O4 - Global Startup: CompuServe 7.0 Tray Icon.lnk = C:/Program Files/CompuServe 7.0/cstray.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O12 - Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1074451698987
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38004.3227546296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Redaktør
Antal indlæg: 25535
Hej Frank
Nu har jeg siddet og stirret mig blind på din log de sidste par timer.
Du går i fejlsikret tilstand
Gå i msconfig og fanebladet start og fjern flueben ud for denne fil:
O4 - HKCU/../Run: [SEWGJKRLPL] C:/WINDOWS/WPYVUUPSP.exe
Kør hijackthis og fix den samme fil
O4 - HKCU/../Run: [SEWGJKRLPL] C:/WINDOWS/WPYVUUPSP.exe
Gå i tilføj/fjern prg. for at se om den ligger der, hvis den gør, så afinstaller den.
Søg på filen og fjern alt hvad du måtte finde på den.
Find og fjern denne fil, den hører til Me udgaven, ikke til din Xp udgave
C:/WINDOWS/System32/wuauclt.exe
Lad være med at genstarte. Kør en ny hijackthis
Se om den ligger der endnu, eller om den har lavet sig om igen. Kør samme fremgangsmåde hvis den har gjort det. Du burde nu kunne se hvilken fil det drejer sig om, da du jo kender alle de legale.
Bliver den ved med at lave sig om, så prøver vi at afinstallere dit Norton. Så skal du hente dette prg. som kan fjerne det totalt fra din computer. http://service1.symantec.com/SUPPORT/nav.nsf/8d071816eedd7cac88256c0e005a96e5/33497f6e8a319ece88256ace0076cc02?OpenDocument&sone=nav_2003_tasks.html&stg=3&prod=Norton AntiVirus&ver=2003 for Windows 2000/Me/98/XP&base=http://www.symantec.com/techsupp/nav/&next=nav_2003_contact_tscs_solve.html&src=sg&pcode=nav&svy;=
Gå derefter i regedit og se om der skulle ligge nogle rester.
Gå i start
Kør
Skriv: regedit
Ok
Gå i Rediger
Søg
Skriv: Norton
Delete den nøgle programmet finder (tjek lige der står norton)
Find næste (du kan benytte f3 tasten)
Delete
F3
Delete
F3
Sådan bliver du ved til der ikke er flere nøgler at slette. Programmet fortæller dig når der ikke er flere nøgler.
Ok men Norton hedder også Symantech så det skal vi også have slettet
Gå i Rediger
Søg
Skriv: Symantech
Delete
F3
Altså samme fremgangsmåde som da du skrev Norton
Når der ikke er flere nøgler at slette skal du lukke Regedit. Klik på X
Bliv i fejlsikret tilstand. Jeg vil se en log fra dig, som er taget fra fejlsikert tilstand. Pøj pøj og godnat herfra
Hej,
Jeg kommer tilbage med loggen—for forhåbentligt sidste gang—så snart jeg kan. Igen mange tak, Frank
Hej igen,
Her kommer loggen. Det ser vist godt nok ud nu, eller hva. Ihvertfald er der ingen C:/windows/en-eller-anden-kombination af >8 storebogstaver med .exe til sidst. Men tjek ik’?
Kunne ikke slette Norton Anti Virus 2004. Programmet er helt nyt og der ikke noget sletteprogram.
Ved sletningen af System Soap Pro blev jeg spurgt om jeg vil beholde C:/windows/system32/msinet.ocx og C:/windows/system32/ntsvc.ocx. De er ikke slettet endnu, men skal de slettes, eller bruges de til noget?
Igen, igen tak! Og ha en go weekend
Logfile of HijackThis v1.97.7
Scan saved at 7:52:34 PM, on 1/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/Program Files/Network Associates/VirusScan/Avsynmgr.exe
C:/Program Files/Norton AntiVirus/navapsvc.exe
C:/Program Files/Common Files/Symantec Shared/CCPD-LC/symlcsvc.exe
C:/WINDOWS/wanmpsvc.exe
C:/Program Files/Network Associates/VirusScan/VsStat.exe
C:/Program Files/Network Associates/VirusScan/Avconsol.exe
C:/Program Files/Network Associates/VirusScan/Webscanx.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/System32/TPWRTRAY.EXE
C:/WINDOWS/System32/TFNF5.exe
C:/Program Files/TOSHIBA/TOSHIBA Controls/TFncKy.exe
C:/toshiba/ivp/ism/pinger.exe
C:/Program Files/Apoint2K/Apoint.exe
C:/WINDOWS/System32/00THotkey.exe
C:/Program Files/Common Files/Real/Update_OB/realsched.exe
C:/Program Files/Common Files/Real/Update_OB/rnathchk.exe
C:/Program Files/Apoint2K/Apntex.exe
C:/Program Files/Messenger/msmsgs.exe
C:/Program Files/CompuServe 7.0/cstray.exe
C:/WINDOWS/System32/wuauclt.exe
C:/Program Files/CompuServe 7.0/wcs2000.exe
C:/Program Files/Internet Explorer/iexplore.exe
C:/Documents and Settings/davidson/Desktop/HijackThis.exe
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.toshiba.com/
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.toshiba.com/
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Program Files/Adobe/Acrobat 5.0/Reader/ActiveX/AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:/Program Files/Norton AntiVirus/NavShExt.dll
O4 - HKLM/../Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM/../Run: [TouchED] C:/Program Files/TOSHIBA/TouchED/TouchED.Exe
O4 - HKLM/../Run: [TFNF5] TFNF5.exe
O4 - HKLM/../Run: [TFncKy] TFncKy.exe /Type 20
O4 - HKLM/../Run: [REGSHAVE] C:/Program Files/REGSHAVE/REGSHAVE.EXE /AUTORUN
O4 - HKLM/../Run: [Pinger] c:/toshiba/ivp/ism/pinger.exe /run
O4 - HKLM/../Run: [Drag’n Drop CD] C:/Program Files/Drag’n Drop CD/BinFiles/DragDrop.exe /StartUp
O4 - HKLM/../Run: [Apoint] C:/Program Files/Apoint2K/Apoint.exe
O4 - HKLM/../Run: [00THotkey] C:/WINDOWS/System32/00THotkey.exe
O4 - HKLM/../Run: [000StTHK] 000StTHK.exe
O4 - HKLM/../Run: [TkBellExe] C:/Program Files/Common Files/Real/Update_OB/realsched.exe -osboot
O4 - HKCU/../Run: [MSMSGS] “C:/Program Files/Messenger/msmsgs.exe” /background
O4 - Global Startup: CompuServe 7.0 Tray Icon.lnk = C:/Program Files/CompuServe 7.0/cstray.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O12 - Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1074451698987
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38004.3227546296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Redaktør
Antal indlæg: 25535
Hej Frank
TILLYKKE TILLYKKE endelig lykkedes det. Din log er Clean.
For at sikre din pc fremover ville det være en god idé at bruge nogle af programmerne fra vores lille pakke som du kan se her:
http://www.spywarefri.dk/pakken.htm
Især vil jeg anbefale Spybot, SpywareBlaster og IE-Spyad. De er alle gratis, fylder ikke meget, sløver ikke din pc og konflikter ikke med dine andre programmer
De to filer du spørger om du skal slette, dem lader du bare ligge, de skal ikke slettes.
Pøj pøj for fremtiden.