efter athave spillet wow, gik jeg ind på internetet. Men opdagede at min startside har ændret fra
http://www.wowi.dk[...] til
http://www.yoursystemupdate.com[...]
her står der:
Attention! Your system is under control of remote computer with IP address 227.4.167.118. The remote computer has access to the following folders on your PC:
- WINDOWSSystem32
- Program FilesInternet Explorer
- My Documents
- Drive C: files
Click here to download official anti-spyware software
Your private info is collected by W32.Sinnaka.A@mm
og så noget "information" om min computer som bla. IP-adresse, Land, operation system og time of investigation... herudover er der nogle antispyware programmer de anbefaler og sådan noget (har ikke downloadet noget!)
syntes det er lidt underligt så jeg smider lige en HJT-log ind, hvis der er nogle der vil være flinke at kigge på den :):
Logfile of HijackThis v1.99.1
Scan saved at 15:56:50, on 09-12-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32
vctrl.exe
C:WINDOWShtpatch.exe
C:PROGRA~1CAETRUST~1ETRUST~1VetTray.exe
C:ProgrammerRazer
azertra.exe
C:ProgrammerNetropaMultimedia KeyboardMMKeybd.exe
C:ProgrammerMicrosoft AntiSpywaregcasServ.exe
C:ProgrammeriTunesiTunesHelper.exe
C:ProgrammerATI TechnologiesATI Control Panelatiptaxx.exe
C:WINDOWSsystem32RunDll32.exe
C:ProgrammerNetropaMultimedia Keyboard
hksrv.exe
C:PROGRA~1eScanTRAYICOS.EXE
C:PROGRA~1eScanTRAYSSER.EXE
C:ProgrammerJavajre1.5.0_04injusched.exe
C:ProgrammerQuickTimeqttask.exe
C:ProgrammerD-Toolsdaemon.exe
C:WINDOWSsystem32ctfmon.exe
C:ValveSteamSteam.exe
C:WINDOWSPMJ151LA.BIN
C:ProgrammerMessengermsmsgs.exe
C:ProgrammerMicrosoft AntiSpywaregcasDtServ.exe
C:WINDOWSsystem32svchost.exe
C:PROGRA~1CAETRUST~1ETRUST~1VetMsg.exe
C:WINDOWSsystem32oneLabsvsmon.exe
C:ProgrammerNetropaMultimedia KeyboardTrayMon.exe
C:ProgrammerNetropaOnscreen DisplayOSD.exe
C:ProgrammeriPodiniPodService.exe
C:PROGRA~1eScaneScanWin.exe
C:PROGRA~1eScankavss.exe
C:ProgrammerTeamspeak2_RC2TeamSpeak.exe
C:WINDOWSsystem32mssearchnet.exe
C:WINDOWSsystem32mmc.exe
C:ProgrammerMicrosoft AntiSpywareGIANTAntiSpywareMain.exe
C:WINDOWSsystem32DfrgNtfs.exe
C:ProgrammerInternet Exploreriexplore.exe
C:ProgrammerMSN Messengermsnmsgr.exe
C:Documents and SettingsSanneSkrivebordCraphijackthisHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://web.krhjrkytkxmjzfikimfbydth.com[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://web1340.nh9.needhost.dk[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
O2 - BHO: HomepageBHO - {724510c3-f3c8-4fb7-879a-d99f29008a2f} - C:WINDOWSsystem32hp9385.tmp
O4 - HKLM..Run: [HTpatch] C:WINDOWShtpatch.exe
O4 - HKLM..Run: [SiSUSBRG] C:WINDOWSSiSUSBrg.exe
O4 - HKLM..Run: [VetTray] C:PROGRA~1CAETRUST~1ETRUST~1VetTray.exe
O4 - HKLM..Run: [Zone Labs Client] C:PROGRA~1CAETRUST~1ETRUST~2ca.exe
O4 - HKLM..Run: [razertra] C:ProgrammerRazer
azertra.exe
O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:ProgrammerNetropaMultimedia KeyboardMMKeybd.exe
O4 - HKLM..Run: [gcasServ] "C:ProgrammerMicrosoft AntiSpywaregcasServ.exe"
O4 - HKLM..Run: [iTunesHelper] "C:ProgrammeriTunesiTunesHelper.exe"
O4 - HKLM..Run: [ATIPTA] C:ProgrammerATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [MailScan Dispatcher] "C:ProgrammereScanLAUNCH.EXE"
O4 - HKLM..Run: [eScan Updater] C:PROGRA~1eScanTRAYICOS.EXE /App
O4 - HKLM..Run: [SunJavaUpdateSched] C:ProgrammerJavajre1.5.0_04injusched.exe
O4 - HKLM..Run: [QuickTime Task] "C:ProgrammerQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [DAEMON Tools-1033] "C:ProgrammerD-Toolsdaemon.exe" -lang 1033
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [Steam] C:ValveSteamSteam.exe -silent
O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background
O4 - HKCU..Run: [MSMSGS] "C:ProgrammerMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Skype] "C:ProgrammerSkypePhoneSkype.exe" /nosplash /minimized
O4 - Startup: Xfire.lnk = C:ProgrammerXfireXfire.exe
O4 - Global Startup: Microsoft Office.lnk = C:ProgrammerMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammerJavajre1.5.0_04in
pjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammerJavajre1.5.0_04in
pjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O12 - Plugin for .spop: C:ProgrammerInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com[...]
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com[...]
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com[...]
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com[...]
O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) -
http://imlive.com[...]
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:PROGRA~1MSNMES~1msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: eScan Server-Updater (eScan-trayicos) - MWTI2 - C:PROGRA~1eScanTRAYSSER.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:ProgrammeriPodiniPodService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:ProgrammerNetropaMultimedia Keyboard
hksrv.exe
O23 - Service: PMJ151 AutoLaunch Service (PMJ151LA) - Matsushita Electric Industrial Co. ,Ltd, - C:WINDOWSPMJ151LA.BIN
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:PROGRA~1CAETRUST~1ETRUST~1VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:WINDOWSsystem32oneLabsvsmon.exe
på forhånd tak!
--
where there's fun, there's pain - its all the same :-)