Avatar billede mattbaker Nybegynder
13. februar 2006 - 16:23 Der er 9 kommentarer og
1 løsning

Explorer.exe og drwtsn32.exe melder fejl.

Hej nørder ;)

Jeg har nok noget virus halløj på min comp.

Explorer.exe og drwtsn32.exe melder fejl lige efter hinanden.
Når jeg så sender fejlrapport (eller lader være) dukker den anden fejl op og så "låser" computeren.

Hvad er nu det?!?

-MattB
Avatar billede var Nybegynder
13. februar 2006 - 18:01 #1
følg instrukserne:
http://www.arlet.dk/index.html?/ewidohjt
og kom med loggene..
Avatar billede mattbaker Nybegynder
14. februar 2006 - 22:40 #2
Oki...
Her er de så

+ Scanningsresultat:
    HKLM\SOFTWARE\WinHound.com -> Adware.WinHound : Fejl under renselse
    HKLM\SOFTWARE\WinHound.com\WinHound -> Adware.WinHound : Fejl under renselse
    HKLM\SOFTWARE\WinHound.com\WinHound\WinHound -> Adware.WinHound : Fejl under renselse
    HKLM\SOFTWARE\WinHound.com\WinHound\WinHound\License -> Adware.WinHound : Renset med backup
    :mozilla.16:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Doubleclick : Renset med backup
    :mozilla.17:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Adtech : Renset med backup
    :mozilla.18:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Adtech : Renset med backup
    :mozilla.19:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Mediaplex : Renset med backup
    :mozilla.39:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.40:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.41:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.42:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.43:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.44:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.45:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.46:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.47:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yieldmanager : Renset med backup
    :mozilla.48:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Tribalfusion : Renset med backup
    :mozilla.67:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Googleadservices : Renset med backup
    :mozilla.89:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.90:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.91:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Advertising : Renset med backup
    :mozilla.103:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Fastclick : Renset med backup
    :mozilla.104:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Adserver : Renset med backup
    :mozilla.105:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Adserver : Renset med backup
    :mozilla.106:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Fastclick : Renset med backup
    :mozilla.107:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Fastclick : Renset med backup
    :mozilla.108:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Fastclick : Renset med backup
    :mozilla.111:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Zedo : Renset med backup
    :mozilla.114:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Zedo : Renset med backup
    :mozilla.115:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Zedo : Renset med backup
    :mozilla.116:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Zedo : Renset med backup
    :mozilla.118:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Burstnet : Renset med backup
    :mozilla.122:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Tacoda : Renset med backup
    :mozilla.123:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Tacoda : Renset med backup
    :mozilla.125:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Tacoda : Renset med backup
    :mozilla.129:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Burstnet : Renset med backup
    :mozilla.144:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Casalemedia : Renset med backup
    :mozilla.146:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Casalemedia : Renset med backup
    :mozilla.147:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Casalemedia : Renset med backup
    :mozilla.148:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Casalemedia : Renset med backup
    :mozilla.155:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Atdmt : Renset med backup
    :mozilla.196:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Valuead : Renset med backup
    :mozilla.197:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Valuead : Renset med backup
    :mozilla.198:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Valuead : Renset med backup
    :mozilla.199:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Valuead : Renset med backup
    :mozilla.208:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Serving-sys : Renset med backup
    :mozilla.209:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Serving-sys : Renset med backup
    :mozilla.210:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Serving-sys : Renset med backup
    :mozilla.211:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Serving-sys : Renset med backup
    :mozilla.231:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Googleadservices : Renset med backup
    :mozilla.243:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.2o7 : Renset med backup
    :mozilla.290:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Statcounter : Renset med backup
    :mozilla.716:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Clickbank : Renset med backup
    :mozilla.746:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Yadro : Renset med backup
    :mozilla.822:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Goclick : Renset med backup
    :mozilla.823:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Enhance : Renset med backup
    :mozilla.824:C:\Documents and Settings\Matias Bager\Application Data\Mozilla\Firefox\Profiles\f9kdva55.default\cookies.txt -> TrackingCookie.Goclick : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\HKCURun -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\HKCURun\RunOnce -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\HKCURun\RunOnceEx -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\HKLMRun -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\HKLMRun\RunOnce -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\HKLMRun\RunOnceEx -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\StartMenuAllUsers -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\Autorun\StartMenuCurrentUser -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Application Data\WinHound.com\WinHound\BrowserObjects -> Adware.WinHound : Renset med backup
    C:\Documents and Settings\Matias Bager\Cookies\matias bager@1.tnssearch[2].txt -> TrackingCookie.Tnssearch : Renset med backup
    C:\Documents and Settings\Matias Bager\Cookies\matias bager@60.topnssearch[2].txt -> TrackingCookie.Topnssearch : Renset med backup
    C:\Documents and Settings\Matias Bager\Cookies\matias bager@doubleclick[1].txt -> TrackingCookie.Doubleclick : Renset med backup

og her

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Apoint\Apoint.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Matias Bager\Skrivebord\Ny mappe\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AceGain LiveUpdate] C:\Programmer\AceGain\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

Så skulle der være lidt at tage fat på :)

-MattB
Avatar billede var Nybegynder
15. februar 2006 - 11:12 #3
HijackThis loggen viser ikke nogen tegn på snavs men det gør ewido loggen.. kan det passe at du har haft en winhound infektion?

men lad os starte med at fixe.. :)

Gå til tilføj/fjern programmer og fjern:

Winhound

Genstart

Åbn HIjackThis og tjek disse linier:

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE

Luk alle vinduer og browsere undtagen HijackThis og klik Fix checked

Genstart

Hent og dobbeltklik på smitRem.exe

http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

Programmet pakker sig ud til mappen smitRem.

Genstart i fejlsikret ( F8 under opstart ),

Åbn mappen smitRem, og dobbeltklik på RunThis.bat (Følg vejledningen i vinduet.)

Genstart og kom med en frisk Hijackthislog, Find smitfiles.txt via Start/Søg. Kopier også denne log ind. Loggen kopier du ind i dit spørgsmål ;)
Avatar billede mattbaker Nybegynder
15. februar 2006 - 12:29 #4
Tja det kan sikkert godt passe med winhound :)
Jeg ordner det lige og kommer emd en frisk log

-MattB
Avatar billede var Nybegynder
15. februar 2006 - 12:32 #5
iorden.. :D
Avatar billede mattbaker Nybegynder
15. februar 2006 - 13:00 #6
Her


  smitRem © log file
    version 2.8

    by noahdfear


Microsoft Windows XP [version 5.1.2600]

Running from
C:\Documents and Settings\Matias Bager\Skrivebord\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key

WinHound.com key present!



Running WinHound.com fix!



WinHound.com key was successfully removed! :)

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~

logfiles


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 784 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :)



og her



Logfile of HijackThis v1.99.1
Scan saved at 13:00:37, on 15-02-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmer\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Apoint\Apoint.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\Apoint\Apntex.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Matias Bager\Skrivebord\Ny mappe\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Programmer\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Programmer\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmer\Fælles filer\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AceGain LiveUpdate] C:\Programmer\AceGain\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = ?
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE



-MattB
Avatar billede var Nybegynder
15. februar 2006 - 18:18 #7
Din HijackThis log er ren.. oplever du nogle problemer?
Avatar billede mattbaker Nybegynder
15. februar 2006 - 19:11 #8
Ja, desværre...

Efter ca 5 min melder Explorer.exe og drwtsn32.exe fejl som før...

-MattB
Avatar billede var Nybegynder
15. februar 2006 - 19:15 #9
Prøv evt. at reparere systemfiler. Klik Start -> Kør, skriv sfc /scannow. Muligvis anmodes om XP cd'en skal være i drevet
( husk mellemrum mellem sfc og /scannow ) ;)
Avatar billede mattbaker Nybegynder
21. februar 2006 - 20:08 #10
Det virker stadig ikke... Trælst! Men tak for hjælpen! Du får point.
-MattB
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester