Kan ikke komme ind i c drev
  wiggum
Antal indlæg: 36

Hej, mit problem er som følger: Efter en tur på nettet begyndte min pc at opføre sig mystisk. En toolbar på min ie lå under min normale toolbar, den hedder “searchsprint” med den fulgte popups hver gang jeg startede ie eller pc op. Disse popups fik jeg bugt med wink Nu kommer så det større problem, jeg kan ikke komme ind i kontrolpanel eller denne computer, eller for den sags skyld de fleste af de programmer jeg normalt kommer ind i på ikonerne på skrivebordet. Jeg har kørt jeres online scan, den fandt og fjernede nogle. En enkelt bliver dog selv om jeg siger remove : C:/Programmer/NavExcel/NavHelper/v2.0.4/NHUpdater.exe
jeg har kørt spybot og virusscan. jeg har zone alarm.
Windows xp
Håber i kan hjælpe….
På forhånd tak…

Logfile of HijackThis v1.97.7
Scan saved at 04:19:00, on 17-02-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/System32/CTHELPER.EXE
C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/PROGRA~1/ZONELA~1/ZONEAL~1/zapro.exe
C:/Programmer/Java/j2re1.4.2_03/bin/jusched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/iTunes/iTunesHelper.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/MSN Messenger/msnmsgr.exe
C:/PROGRA~1/Grisoft/AVG6/avgserv.exe
C:/WINDOWS/System32/gearsec.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/ZoneLabs/vsmon.exe
C:/Programmer/iPod/bin/iPodService.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Programmer/Fælles filer/Real/Update_OB/realevent.exe
C:/Documents and Settings/Jans Dam/Skrivebord/HijackThis.exe

R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.pilots.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = about:blank
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = about:blank
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = about:blank
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchAssistant = http://www.searchv.com/search.html
R1 - HKCU/Software/Microsoft/Internet Explorer,CustomizeSearch = http://www.searchv.com/search.html
O2 - BHO: (no name) - {D55CE9F6-D21C-452C-86B1-6C0CFBB4D42E} - C:/WINDOWS/rQuh2591.dll
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: searchsprint - {AEE46806-2C5A-4A4E-A5DD-B4531F64A187} - C:/WINDOWS/j500GQ.dll
O4 - HKLM/../Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM/../Run: [UpdReg] C:/WINDOWS/UpdReg.EXE
O4 - HKLM/../Run: [Jet Detection] C:/Programmer/Creative/SBLive/PROGRAM/ADGJDet.exe
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [AVG_CC] C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe /STARTUP
O4 - HKLM/../Run: [NeroCheck] C:/WINDOWS/System32//NeroCheck.exe
O4 - HKLM/../Run: [WinampAgent] “C:/Programmer/Winamp/Winampa.exe”
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [Zone Labs Client] C:/PROGRA~1/ZONELA~1/ZONEAL~1/zapro.exe
O4 - HKLM/../Run: [SunJavaUpdateSched] C:/Programmer/Java/j2re1.4.2_03/bin/jusched.exe
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [iTunesHelper] C:/Programmer/iTunes/iTunesHelper.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [msnmsgr] “C:/Programmer/MSN Messenger/msnmsgr.exe” /background
O4 - Startup: Microsoft Hurtig søgning.lnk = C:/Programmer/Microsoft Office/Office/FINDFAST.EXE
O8 - Extra context menu item: &Download; with &DAP; - C:/PROGRA~1/DAP/dapextie.htm
O8 - Extra context menu item: Download &all; with DAP - C:/PROGRA~1/DAP/dapextie2.htm
O9 - Extra ‘Tools’ menuitem: Sun Java Console (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1076976626171
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030523/qtinstall.info.apple.com/drakken/dk/win/QuickTimeInstaller.exe
O16 - DPF: {65B818E1-F4D8-4F96-A1DF-35F3D1C86194} (limmyloding.limmyform) - http://bins.roings.com/crack.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/mail/ymmapi.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

Redaktør
Antal indlæg: 25535

Hej Wiggum og velkommen til Spywarefri

Der er lige et par ting du skal gøre.

Du skal downloade og køre et prg. som hedder CWShredder, det finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=662

Kør programmet,luk alle vinduer, undtaget cwsschredder, klik på Next, den scanner nu, når den er færdigt klik på Fix, klik på Exit.

Genstart din computer

Og så skal du gå i tilføj/fjern prg. og fjerne prg. Dap der kommer meget skidt ind på din computer sammen med det prg.

Genstart din computer

Når du har gjort de to ting, skal du køre en ny scanning med Hijackthis, og kopier en ny log herind, for der ligger mere skidt på din computer.

  wiggum
Antal indlæg: 36

Gjort som du anbefalede. Her er loggen:

Logfile of HijackThis v1.97.7
Scan saved at 10:33:59, on 17-02-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/System32/CTHELPER.EXE
C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/PROGRA~1/ZONELA~1/ZONEAL~1/zapro.exe
C:/Programmer/Java/j2re1.4.2_03/bin/jusched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/iTunes/iTunesHelper.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/MSN Messenger/msnmsgr.exe
C:/PROGRA~1/Grisoft/AVG6/avgserv.exe
C:/WINDOWS/System32/gearsec.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/ZoneLabs/vsmon.exe
C:/Programmer/iPod/bin/iPodService.exe
C:/Documents and Settings/Jans Dam/Skrivebord/HijackThis.exe

R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.pilots.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = about:blank
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = about:blank
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = about:blank
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchAssistant = ,
R1 - HKCU/Software/Microsoft/Internet Explorer,CustomizeSearch = ,
O2 - BHO: (no name) - {D55CE9F6-D21C-452C-86B1-6C0CFBB4D42E} - C:/WINDOWS/rQuh2591.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: searchsprint - {AEE46806-2C5A-4A4E-A5DD-B4531F64A187} - C:/WINDOWS/j500GQ.dll
O4 - HKLM/../Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM/../Run: [UpdReg] C:/WINDOWS/UpdReg.EXE
O4 - HKLM/../Run: [Jet Detection] C:/Programmer/Creative/SBLive/PROGRAM/ADGJDet.exe
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [AVG_CC] C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe /STARTUP
O4 - HKLM/../Run: [NeroCheck] C:/WINDOWS/System32//NeroCheck.exe
O4 - HKLM/../Run: [WinampAgent] “C:/Programmer/Winamp/Winampa.exe”
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [Zone Labs Client] C:/PROGRA~1/ZONELA~1/ZONEAL~1/zapro.exe
O4 - HKLM/../Run: [SunJavaUpdateSched] C:/Programmer/Java/j2re1.4.2_03/bin/jusched.exe
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [iTunesHelper] C:/Programmer/iTunes/iTunesHelper.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [msnmsgr] “C:/Programmer/MSN Messenger/msnmsgr.exe” /background
O4 - Startup: Microsoft Hurtig søgning.lnk = C:/Programmer/Microsoft Office/Office/FINDFAST.EXE
O9 - Extra ‘Tools’ menuitem: Sun Java Console (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1076976626171
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030523/qtinstall.info.apple.com/drakken/dk/win/QuickTimeInstaller.exe
O16 - DPF: {65B818E1-F4D8-4F96-A1DF-35F3D1C86194} (limmyloding.limmyform) - http://bins.roings.com/crack.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/mail/ymmapi.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

Redaktør
Avatar
Antal indlæg: 11785

Følg vejledningen her: http://www.spywarefri.dk/hjtanv.htm (punkt 5 og 6). Fix disse med HijackThis:

R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = about:blank
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = about:blank
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = about:blank
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = about:blank
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = about:blank
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchAssistant = ,
R1 - HKCU/Software/Microsoft/Internet Explorer,CustomizeSearch = ,

O2 - BHO: (no name) - {D55CE9F6-D21C-452C-86B1-6C0CFBB4D42E} - C:/WINDOWS/rQuh2591.dll

O3 - Toolbar: searchsprint - {AEE46806-2C5A-4A4E-A5DD-B4531F64A187} - C:/WINDOWS/j500GQ.dll

O4 - HKLM/../Run: [UpdReg] C:/WINDOWS/UpdReg.EXE
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” –atboottime
O4 - Startup: Microsoft Hurtig søgning.lnk = C:/Programmer/Microsoft Office/Office/FINDFAST.EXE

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030523/qtinstall.info.apple.com/drakken/dk/win/QuickTimeInstaller.exe
O16 - DPF: {65B818E1-F4D8-4F96-A1DF-35F3D1C86194} (limmyloding.limmyform) - http://bins.roings.com/crack.cab

Genstart og ny log - tak

Signatur

Med venlig hilsen
Resist TeamSpywarefri

Member of: Alliance of Security Analysis Professionals

  wiggum
Antal indlæg: 36

Den lavede en masse backup ikoner på skrivebordet. Skal de bare fjernes?
her er den nye log file:

Logfile of HijackThis v1.97.7
Scan saved at 18:24:46, on 17-02-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/System32/CTHELPER.EXE
C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/PROGRA~1/ZONELA~1/ZONEAL~1/zapro.exe
C:/Programmer/Java/j2re1.4.2_03/bin/jusched.exe
C:/Programmer/QuickTime/qttask.exe
C:/Programmer/iTunes/iTunesHelper.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Programmer/MSN Messenger/msnmsgr.exe
C:/PROGRA~1/Grisoft/AVG6/avgserv.exe
C:/WINDOWS/System32/gearsec.exe
C:/WINDOWS/System32/nvsvc32.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/ZoneLabs/vsmon.exe
C:/Programmer/iPod/bin/iPodService.exe
C:/Programmer/Internet Explorer/iexplore.exe
C:/Documents and Settings/Jans Dam/Skrivebord/HijackThis.exe

R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.pilots.dk/
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM/../Run: [Jet Detection] C:/Programmer/Creative/SBLive/PROGRAM/ADGJDet.exe
O4 - HKLM/../Run: [NvCplDaemon] RUNDLL32.EXE C:/WINDOWS/System32/NvCpl.dll,NvStartup
O4 - HKLM/../Run: [nwiz] nwiz.exe /install
O4 - HKLM/../Run: [AVG_CC] C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe /STARTUP
O4 - HKLM/../Run: [NeroCheck] C:/WINDOWS/System32//NeroCheck.exe
O4 - HKLM/../Run: [WinampAgent] “C:/Programmer/Winamp/Winampa.exe”
O4 - HKLM/../Run: [Zone Labs Client] C:/PROGRA~1/ZONELA~1/ZONEAL~1/zapro.exe
O4 - HKLM/../Run: [SunJavaUpdateSched] C:/Programmer/Java/j2re1.4.2_03/bin/jusched.exe
O4 - HKLM/../Run: [iTunesHelper] C:/Programmer/iTunes/iTunesHelper.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [msnmsgr] “C:/Programmer/MSN Messenger/msnmsgr.exe” /background
O4 - Startup: Microsoft Hurtig søgning.lnk = C:/Programmer/Microsoft Office/Office/FINDFAST.EXE
O9 - Extra ‘Tools’ menuitem: Sun Java Console (HKLM)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1076976626171
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/mail/ymmapi.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

Redaktør
Avatar
Antal indlæg: 11785

Fix lige denne:

O4 - Startup: Microsoft Hurtig søgning.lnk = C:/Programmer/Microsoft Office/Office/FINDFAST.EXE

Derefter ser din log fra HijackThis ren ud, og du må slå systemgendannelse til igen.

Har ”kuren” hjulpet?

Backup ikoner på skrivebordet kan fjernes, når der ikke er mere ”snavs”.

Her er et link til en række programmer, som vi kan anbefale. De kan gøre din færden på Nettet mere sikker: http://www.spywarefri.dk/pakken.htm

Signatur

Med venlig hilsen
Resist TeamSpywarefri

Member of: Alliance of Security Analysis Professionals

  wiggum
Antal indlæg: 36

Hep.. Så er det klaret. Tusind tak for hjælpen, i har virkelig reddet min dag. Fedt at i gider hjælpe os andre “dødelige”.
Vil straks dl’de dine anbefalinger.

Endnu en gang mange tak!

Jens

Redaktør
Avatar
Antal indlæg: 11785

Velbekomme wink

Signatur

Med venlig hilsen
Resist TeamSpywarefri

Member of: Alliance of Security Analysis Professionals