Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Software \ Sikkerhed
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

Hijack this log!!

Af Ny på siden flexmester | 07-09-2004 19:11 | 721 visninger | 1 svar, hop til seneste
Hjælp ønskes... Min Computer strejker for vildt... Logfile of HijackThis v1.98.0 Scan saved at 19:07:34, on 07-09-2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:Program FilesCommon FilesSymantec SharedccSetMgr.exe C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe C:WINDOWSsystem32spoolsv.exe C:Program FilesExecutive SoftwareDiskeeperDkService.exe C:Program FilesNorton AntiVirus avapsvc.exe C:WINDOWSExplorer.EXE C:Program FilesNorton AntiVirusAdvToolsNPROTECT.EXE C:WINDOWSSystem32 vsvc32.exe C:Program FilesNorton AntiVirusSAVScan.exe C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe C:Program FilesD-Toolsdaemon.exe C:Program FilesCommon FilesSymantec SharedccApp.exe C:Program FilesQuickTimeqttask.exe C:WINDOWSSystem32 mctrl.exe C:Program FilesMSN Messengermsnmsgr.exe C:WINDOWSSystem32RUNDLL32.EXE C:Program FilesOpenOffice.org1.1.1programsoffice.exe C:WINDOWSSystem32wuauclt.exe C:WINDOWSSystem32wuauclt.exe C:Program FilesInternet Exploreriexplore.exe C:Documents and SettingsAlexDesktopHijackThisHijackThis.exe R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0AcrobatActiveXAcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:Program FilesSpybot - Search & DestroySDHelper.dll O2 - BHO: (no name) - {757523C4-8335-4869-8059-754C6DCD3960} - C:WINDOWSSystem32mgjfhb.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:Program FilesAdobeAcrobat 6.0AcrobatAcroIEFavClient.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton AntiVirusNavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:Program FilesAdobeAcrobat 6.0AcrobatAcroIEFavClient.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton AntiVirusNavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe" -lang 1033 O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe" O4 - HKLM..Run: [Advanced Tools Check] C:PROGRA~1NORTON~1AdvToolsADVCHK.EXE O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k O4 - HKLM..Run: [websx] C:Program Fileswebsxint113777.exe -auto O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime O4 - HKLM..Run: [RemoteControl] C:WINDOWSSystem32 mctrl.exe O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKCU..Run: [msnmsgr] "C:Program FilesMSN Messengermsnmsgr.exe" /background O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NVMCTRAY.DLL,NvTaskbarInit O4 - Startup: OpenOffice.org 1.1.1.lnk = C:Program FilesOpenOffice.org1.1.1programquickstart.exe O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com[...] O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com[...] O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk[...] O18 - Filter: text/html - {EABDAA73-3B27-4153-B1B6-A5B4E573254F} - C:WINDOWSSystem32mgjfhb.dll O18 - Filter: text/plain - {EABDAA73-3B27-4153-B1B6-A5B4E573254F} - C:WINDOWSSystem32mgjfhb.dll På forhånd tak.. Alex
--
#1
Kim In Chul
Semi Supporter
07-09-2004 19:45

Rapporter til Admin
Hej der er lidt som skal fikses... Start med at deaktivere systemgendannelsen, kør en ny hijackthis og sæt flueben ud for: R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSSystem32mgjfhb.dll/sp.html (obfuscated) R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank O2 - BHO: (no name) - {757523C4-8335-4869-8059-754C6DCD3960} - C:WINDOWSSystem32mgjfhb.dll O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k O4 - HKLM..Run: [websx] C:Program Fileswebsxint113777.exe -auto O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime O18 - Filter: text/html - {EABDAA73-3B27-4153-B1B6-A5B4E573254F} - C:WINDOWSSystem32mgjfhb.dll O18 - Filter: text/plain - {EABDAA73-3B27-4153-B1B6-A5B4E573254F} - C:WINDOWSSystem32mgjfhb.dll Luk derefter alle browservinduer og klik på "fix checked" start derefter op i fejlsikret tilstand og slet: C:WINDOWSSystem32mgjfhb.dll C:Program Fileswebsxint113777.exe -auto (webx mappen skal væk) Start derefter op i normal tilstand og smid en ny log herind til kontrol. //Kim In Chul
--

Opret svar til indlægget: Hijack this log!!

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning