Avatar billede langsom Nybegynder
13. juli 2006 - 09:34 Der er 14 kommentarer og
1 løsning

PLz hjælp med denne hijackthis log

Jeg har forskellige problemer, med denne computer. Kan bla. ikke slå windows firewall til, og ikke installerer fra wu. Er der ikke en som vil kigge denne log igemmen?


Logfile of HijackThis v1.99.1
Scan saved at 09:31:59, on 13-07-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\F-Secure\Common\FSM32.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Programmer\Citrix\ICA Client\pnagent.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Programmer\F-Secure\Anti-Virus\FSGK32.EXE
C:\Programmer\F-Secure\Common\FSMA32.EXE
C:\Programmer\F-Secure\Anti-Virus\fssm32.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\F-Secure\Common\FSMB32.EXE
C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Programmer\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Programmer\F-Secure\Common\FCH32.EXE
C:\Programmer\RealVNC\VNC4\WinVNC4.exe
C:\Programmer\F-Secure\Common\FAMEH32.EXE
C:\Programmer\F-Secure\Anti-Virus\fsqh.exe
C:\Programmer\F-Secure\Anti-Virus\fsrw.exe
C:\Programmer\F-Secure\Anti-Virus\fsav32.exe
C:\Programmer\F-Secure\Common\FNRB32.EXE
C:\Programmer\F-Secure\Common\FIH32.EXE
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
C:\Programmer\F-Secure\FSGUI\fsguidll.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Skrivebord\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINDOWS\system32\winbrume.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Programmer\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SysTray] c:\Program Files\ybbga.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programmer\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programmer\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\RunServices: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [07305415.exe] C:\Documents and Settings\Administrator\Lokale indstillinger\Application Data\07305415.exe
O4 - HKCU\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Programmer\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Programmer\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Programmer\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Block this popup - C:\Programmer\F-Secure\Anti-Spyware\blockpopups.htm
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CS1\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CS7\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Programmer\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Programmer\F-Secure\Common\FSMA32.EXE
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programmer\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
Avatar billede nva Praktikant
13. juli 2006 - 10:01 #1
Vil anbefale du følger denne artikel http://www.eksperten.dk/artikler/954 - nok ikke mig der følger op.
Avatar billede langsom Nybegynder
13. juli 2006 - 10:02 #2
Super, gør jeg. mange tak :)
Avatar billede ejvindh Ekspert
13. juli 2006 - 11:41 #3
Ja, det kan nok være en god ide at starte med den vejledning -- for at få lavet en grundrensning (der er mange infektioner i den log). Men der er også Wareout i loggen, og den skal tages med specialværktøj.

Men lad os nu se først, hvad de andre scannere kan klare.
Avatar billede langsom Nybegynder
13. juli 2006 - 12:31 #4
Så blev jeg endelig færdig......
Her er log fra dr. super og hijack:


Fra Dr.
A.0XE;C:\Documents and Settings\Michael Bast\Lokale indstillinger\Temp;Trojan.DownLoader.9447;Deleted.;
C.tmp;C:\Documents and Settings\Michael Bast\Lokale indstillinger\Temp;Trojan.DownLoader.6811;Deleted.;
_IBM00003.0XE;C:\Programmer\Fælles filer\Microsoft Shared\Web Folders;Trojan.PWS.Snap;Deleted.;
A0088197.sys;C:\System Volume Information\_restore{61986120-2846-4E93-9F98-EC0EFBCD00B4}\RP286;BackDoor.Haxdoor.267;Deleted.;
A0088198.sys;C:\System Volume Information\_restore{61986120-2846-4E93-9F98-EC0EFBCD00B4}\RP286;BackDoor.Haxdoor.260;Deleted.;
A0088199.exe;C:\System Volume Information\_restore{61986120-2846-4E93-9F98-EC0EFBCD00B4}\RP286;Trojan.PWS.Snap;Deleted.;
A0088270.dll;C:\System Volume Information\_restore{61986120-2846-4E93-9F98-EC0EFBCD00B4}\RP286;BackDoor.Haxdoor.261;Deleted.;
4092.exe;C:\WINDOWS\system32;Trojan.DownLoader.9898;Incurable.Moved.;
fuxx32.0ll;C:\WINDOWS\system32;BackDoor.Haxdoor.261;Deleted.;
fuxx32.sys;C:\WINDOWS\system32;BackDoor.Haxdoor.267;Deleted.;
fuxx64.sys;C:\WINDOWS\system32;BackDoor.Haxdoor.260;Deleted.;
qy.sys;C:\WINDOWS\system32;BackDoor.Haxdoor.260;Deleted.;
qz.dll;C:\WINDOWS\system32;BackDoor.Haxdoor.261;Deleted.;
qz.sys;C:\WINDOWS\system32;BackDoor.Haxdoor.267;Deleted.;
WXTWDU.0YS;C:\WINDOWS\system32;BackDoor.Haxdoor.267;Deleted.;
WXTWDX.0YS;C:\WINDOWS\system32;BackDoor.Haxdoor.260;Deleted.;
_ZSKDMWIN]EAU`DWOKAPNBFMB.0XE\data001;C:\WINDOWS\system32\_ZSKDMWIN]EAU`DWOKAPNBFMB.0XE;Trojan.Proxy.991;;
_ZSKDMWIN]EAU`DWOKAPNBFMB.0XE\data002;C:\WINDOWS\system32\_ZSKDMWIN]EAU`DWOKAPNBFMB.0XE;Trojan.Proxy.899;;

Fra Super.
SUPERAntiSpyware Scan Log
Generated 07/13/2006 at 12:22 PM

Core Rules Database Version : 2847
Trace Rules Database Version: 1028

Memory threats detected  : 0
Registry threats detected : 3
File threats detected    : 3

Adware.SBSoft
    HKLM\Software\Microsoft\Internet Explorer\Toolbar#{08BEC6AA-49FC-4379-3587-4B21E286C19E}
    HKU\S-1-5-21-1482476501-1580436667-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser#{08BEC6AA-49FC-4379-3587-4B21E286C19E}
    HKU\S-1-5-21-1482476501-1580436667-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{08BEC6AA-49FC-4379-3587-4B21E286C19E}

Adware.Tracking Cookie
    C:\Documents and Settings\Administrator\Cookies\administrator@revsci[1].txt
    C:\Documents and Settings\Administrator\Cookies\administrator@indextools[1].txt

Trojan.Klo5
    C:\WINDOWS\system32\klo5.sys


Fra hijack.
Logfile of HijackThis v1.99.1
Scan saved at 12:27:05, on 13-07-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Programmer\F-Secure\Anti-Virus\FSGK32.EXE
C:\Programmer\F-Secure\Common\FSMA32.EXE
C:\Programmer\F-Secure\Anti-Virus\fssm32.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\F-Secure\Common\FSMB32.EXE
C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Programmer\F-Secure\Common\FCH32.EXE
C:\Programmer\F-Secure\Common\FAMEH32.EXE
C:\Programmer\F-Secure\Anti-Virus\fsqh.exe
C:\Programmer\F-Secure\Anti-Virus\fsrw.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\F-Secure\Common\FSM32.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\RealVNC\VNC4\WinVNC4.exe
C:\Programmer\F-Secure\Anti-Virus\fsav32.exe
C:\Programmer\F-Secure\Common\FNRB32.EXE
C:\Programmer\F-Secure\Common\FIH32.EXE
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
C:\Programmer\F-Secure\FSGUI\fsguidll.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Programmer\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
C:\Programmer\Citrix\ICA Client\pnagent.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Administrator\Skrivebord\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINDOWS\system32\winbrume.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Programmer\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SysTray] c:\Program Files\ybbga.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programmer\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programmer\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\RunServices: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [07305415.exe] C:\Documents and Settings\Administrator\Lokale indstillinger\Application Data\07305415.exe
O4 - HKCU\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Programmer\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Programmer\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Programmer\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Block this popup - C:\Programmer\F-Secure\Anti-Spyware\blockpopups.htm
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CS1\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CS7\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Programmer\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Programmer\F-Secure\Common\FSMA32.EXE
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programmer\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
Avatar billede ejvindh Ekspert
13. juli 2006 - 12:47 #5
Under dette fix vil computeren blive genstartet, og du bør derfor printe vejledningen ud, for at have den ved din side under hele fixet. Fixet skal bruge adgang til internettet, så det skal du sikre dig, at der er.

-- Hent FixWareout fra et af disse links:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

-- Gem filen på dit Skrivebord og dobbeltklik på den. Klik Next -> Install og check, at der er et flueben i "Run fixit" - klik herefter på Finish. Fixet vil nu starte, og du skal blot følge instruktionerne. Du vil blive bedt om at genstarte din computer - gør venligst det. Genstarten vil tage lidt længere tid end normalt...

-- Når dit system genstarter skal du fortsat følge den vejledning, der gives på skærmen. Når fixet er færdigt vil der åbnes en log (report.txt), som du skal gemme og lægge herind i næste post.

-- Kør herefter HijackThis - klik på "Do a systemscan only", og sæt et flueben ud for følgende linier - luk øvrige programvinduer - klik "Fix checked":

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINDOWS\system32\winbrume.dll (file missing)
O4 - HKLM\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKLM\..\RunServices: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [07305415.exe] C:\Documents and Settings\Administrator\Lokale indstillinger\Application Data\07305415.exe
O4 - HKCU\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CS1\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158
O17 - HKLM\System\CS7\Services\Tcpip\..\{06E74D27-21C4-44C1-B901-51157E5DFC6B}: NameServer = 85.255.116.115,85.255.112.158

-- Luk HJT. Genstart din computer, og kopier indholdet af C:\fixwareout\report.txt herind sammen med en frisk HijackThis log.

-- Jeg vil også gerne have en log fra Haxfix. Hent haxfix, og gem den på skrivebordet:
http://users.telenet.be/marcvn/tools/haxfix.exe

Dobbeltklik på haxfix.exe og installér haxfix (standard installations-stien er c:\programmer\haxfix eller c:\program files\haxfix). Når installationen er færdig, skal du sikre dig, at der er flueben i "Launch HaxFix". Klik på "Finish"

Et rødt dos-vindue vil åbne, med følgende muligheder:
1. Make logfile
2. Run auto fix
3. Run manual fix
4. Run Goldun fix
E. Exit Haxfix

Vælg punkt 1, og tryk Enter. Haxfix vil nu scanne compuyteren. Når den er færdig, vil logfilen åbne. Kopiér indholdet af denne fil herind i tråden (c:\haxfix.txt)
Avatar billede langsom Nybegynder
13. juli 2006 - 13:48 #6
Så lang så godt :) håber det blev fint, haxfix log kommer om lidt!!!


Fixwareout ver 1.003
Last edited 07/1/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
...

Random Runs removed from HKLM
...

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is legitimate

»»»»» Search by size and names...

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
Other suspects
Directory of C:\WINDOWS\system32


________________________________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 13:45:58, on 13-07-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Programmer\F-Secure\Anti-Virus\FSGK32.EXE
C:\Programmer\F-Secure\Common\FSMA32.EXE
C:\Programmer\F-Secure\Anti-Virus\fssm32.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\F-Secure\Common\FSMB32.EXE
C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Programmer\F-Secure\Common\FCH32.EXE
C:\Programmer\RealVNC\VNC4\WinVNC4.exe
C:\Programmer\F-Secure\Common\FAMEH32.EXE
C:\Programmer\F-Secure\Anti-Virus\fsqh.exe
C:\Programmer\F-Secure\Anti-Virus\fsrw.exe
C:\Programmer\F-Secure\Common\FNRB32.EXE
C:\Programmer\F-Secure\Anti-Virus\fsav32.exe
C:\Programmer\F-Secure\Common\FIH32.EXE
C:\WINDOWS\Explorer.EXE
C:\Programmer\F-Secure\Common\FSM32.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Messenger\msmsgs.exe
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
C:\Programmer\F-Secure\FSGUI\fsguidll.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Programmer\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
C:\Programmer\Citrix\ICA Client\pnagent.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Documents and Settings\Administrator\Skrivebord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Programmer\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SysTray] c:\Program Files\ybbga.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programmer\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programmer\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\RunServices: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\DOCUME~1\ADMINI~1\LOKALE~1\Temp\SSUPDATE.EXE Software\SUPERAntiSpyware.com\SUPERAntiSpyware
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Programmer\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Programmer\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Programmer\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Block this popup - C:\Programmer\F-Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Programmer\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Programmer\F-Secure\Common\FSMA32.EXE
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programmer\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
Avatar billede langsom Nybegynder
13. juli 2006 - 13:50 #7
Sidste log forhåbenlig

HAXFIX logfile - by Marckie
______________
version 3.06
13-07-2006  13:48:46,47

checking for haxdoor
--------------------
checking for a3d files....
a3d files found
px.a3d

checking for matching notify keys....
no matching notify keys found

checking for matching services....
matching services found
CmBatt
wxtwdx
wxtwdu

checking for matching safeboot services....
matching safeboot services found
wxtwdx.sys
wxtwdu.sys


Checking for goldun
-------------------
checking for notify keys....
no notify keys found

checking for services....
no services found


Finished
Avatar billede ejvindh Ekspert
13. juli 2006 - 14:13 #8
Desværre, så var der bid på Haxfix-loggen, og der er også andre entries, der skal fixes.

-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Luk alle åbne vinduer. Kør fix.bat fra haxfix værktøjet (enten via en genvej på skrivebordet, eller ved at gå ind i den

mappe, hvor du installerede værktøjet). Vælg option 3 ved at taste 3, og trykke Enter. Så vil følgende tekst dukke op:

-------------
Insert the haxdoor notify subkey without the numbers,
and then press enter:
-------------

Her skal du indtaste følgende:
wxtw

Herefter får du mulighed for at indtaste flere nøgler. Her taster du (n).

-- Så vil computeren genstarte. Efter genstarten skal du finde logfilen: c:\haxfix.txt, som du lægger herind.

-- Pak så Avenger-programmet ud og dobbeltklik på avenger.exe

-- Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem de stiplede linier ind:

-----------------------------
Files to delete:
c:\Program Files\ybbga.exe
c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
-----------------------------

-- Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O4 - HKLM\..\Run: [SysTray] c:\Program Files\ybbga.exe
O4 - HKLM\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKLM\..\RunServices: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe

-- Genstart computeren, og lav en ny log med Hijackthis, som du lægger herind sammen med loggen fra Avenger og Haxfix.
Avatar billede langsom Nybegynder
13. juli 2006 - 14:49 #9
Så :)Kan se det russer gøjs stadig er der...

Logfile of HijackThis v1.99.1
Scan saved at 14:47:12, on 13-07-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Programmer\F-Secure\Anti-Virus\FSGK32.EXE
C:\Programmer\F-Secure\Common\FSMA32.EXE
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\F-Secure\Common\FSMB32.EXE
C:\Programmer\F-Secure\Anti-Virus\fssm32.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Programmer\F-Secure\Common\FCH32.EXE
C:\WINDOWS\Explorer.EXE
C:\Programmer\F-Secure\Common\FAMEH32.EXE
C:\Programmer\F-Secure\Anti-Virus\fsqh.exe
C:\Programmer\F-Secure\Anti-Virus\fsrw.exe
C:\Programmer\F-Secure\Common\FSM32.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\RealVNC\VNC4\WinVNC4.exe
C:\Programmer\F-Secure\Anti-Virus\fsav32.exe
C:\Programmer\F-Secure\Common\FNRB32.EXE
C:\Programmer\F-Secure\Common\FIH32.EXE
C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwst.exe
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
C:\Programmer\F-Secure\FSGUI\fsguidll.exe
C:\Documents and Settings\Administrator\Skrivebord\HijackThis.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Programmer\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
C:\Programmer\Citrix\ICA Client\pnagent.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programmer\Linksys\Wireless-G Notebook Adapter\OdHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Programmer\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programmer\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programmer\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\RunServices: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Programmer\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Programmer\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Programmer\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Programmer\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Block this popup - C:\Programmer\F-Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programmer\F-Secure\Anti-Spyware\ieshield.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CS8\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = pol.dk,pollok.lan,rootdom.dk
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programmer\ewido\security suite\ewidoguard.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Programmer\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - C:\Programmer\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Programmer\F-Secure\Common\FSMA32.EXE
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Programmer\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programmer\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

_____________________________________________________

HAXFIX logfile - by Marckie
--------------
version 3.06
13-07-2006  14:29:42,95

Manual Haxdoorfix

Adding haxdoorkeys to delete...
wxtw


haxdoor key: wxtw
searching for services....
services found
deleting services.....
[SWSC] DeleteService SUCCESS
[SWSC] DeleteService SUCCESS


rebooting the computer.....


haxdoor key: wxtw
searching for services....
services not found

checking if files are found.....
wxtwdx.dll

deleting files.....

checking if files are deleted.....


checking for other files.....
xd.bin
px.a3d

deleting other files.....

checking if the files are deleted.....


Finished
________________________________________________________


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\tqqhhwgu

*******************

Script file located at: \??\C:\Documents and Settings\kbanonpj.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File c:\Program Files\ybbga.exe not found!
Deletion of file c:\Program Files\ybbga.exe failed!

Could not process line:
c:\Program Files\ybbga.exe
Status: 0xc0000034



File c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe not found!
Deletion of file c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe failed!

Could not process line:
c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
Status: 0xc0000034


Completed script processing.

*******************

Finished!  Terminate.
Avatar billede ejvindh Ekspert
13. juli 2006 - 16:12 #10
Ja, der sker mærkelige ting på den computer. Før havde du installeret SP2, og nu er der kun SP1 på computeren...

-- Download og gem denne scanner på skrivebordet. Du skal ikke aktivere det endnu.
http://www.spywareinfo.dk/download/mwav.exe

-- Opdater Ewido

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O4 - HKLM\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKLM\..\RunServices: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O4 - HKCU\..\Run: [ÿ_zskbmfbnpakowd`uae]niwmdksz_] c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

-- Du skal nu til at slette. Som indledning hertil skal du have slået "Udvidet filvisning" til:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

-- Slet herefter følgende (hvis du kan finde dem):
c:\windows\system32\_zskdmwin]eau`dwokapnbfmb.exe

-- Kør en fuld scanning med Ewido, og lad den slette det, den finder. Programmet laver en lille log, som du skal kopiere herind i dit næste svar.

-- Klik på mwav.exe som du hentede, programmet pakker sig selv ud og starter.
Sæt flueben i følgende: Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende: All local drives og Scan all files

Klik på scan clean. Det kan godt tage lang tid (nogle timer), men den er også meget effektiv.

-- Genstart til normal tilstand, lav en ny HJT-log, som du sender herind til check.
Avatar billede langsom Nybegynder
13. juli 2006 - 16:26 #11
Super det kigger jeg på. Mht til mwav, skal jeg opdaterer den førest???
Avatar billede ejvindh Ekspert
13. juli 2006 - 20:27 #12
Nej, Mwav er opdateret når du henter den :-)
Avatar billede ejvindh Ekspert
08. august 2006 - 21:41 #13
Fik du løst problemet?
Avatar billede langsom Nybegynder
09. august 2006 - 07:31 #14
Ja, den kom helt i orden....
Undskyld det sene svar,,, Det var ikke med vilje der skulle gå så lang tid...
Rigtig mange tak...
Lægger du ikke et svar?
Det var super fedt du gad og hjælpe!!
Avatar billede ejvindh Ekspert
09. august 2006 - 10:15 #15
Ok, det var så lidt. :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester