Najdi forum

Kaj lahko zbrišem? Kako vem kaj mi dela probleme…namesto določene strani se mi odpre “sex” stran..

Logfile of HijackThis v1.99.1
Scan saved at 15:51:25, on 30.6.2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Avant Browser\avant.exe
C:\Documents and Settings\Igor\Local Settings\Temp\Začasen imenik 19 za hijackthis.zip\HijackThis.exe

O3 – Toolbar: &Radio – {8E718888-423F-11D2-876E-00A0C9082467} – C:\WINDOWS\System32\msdxm.ocx
O3 – Toolbar: MSN Toolbar – {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} – C:\Program Files\MSN Toolbar\01.01.2607.0\sl-si\msntb.dll
O4 – HKLM\..\Run: [APVXDWIN] “C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE” /s
O4 – HKLM\..\Run: [lrlplk] c:\windows\system32\vrwevrt.exe
O4 – HKLM\..\Run: [TorontoMail] DCC_send.exe
O4 – HKLM\..\Run: [xsetup] MSTCPDLL.exe
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 – HKCU\..\Run: [MsnMsgr] “C:\Program Files\MSN Messenger\MsnMsgr.Exe” /background
O4 – HKCU\..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 – HKCU\..\Run: [WareOut] “C:\Program Files\WareOut\WareOut.exe”
O4 – HKCU\..\Run: [___] syspanel.exe
O4 – HKCU\..\Run: [AppMasterCenter] ATLIEHELPER.exe
O4 – HKCU\..\Run: [UserSp1] XTermInit.exe
O8 – Extra context menu item: Add to AD Black List – C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 – Extra context menu item: Block All Images from the Same Server – C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 – Extra context menu item: Blokiraj vse slike s tega strežnika – C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 – Extra context menu item: Dodaj na seznam reklam za blokiranje – C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 – Extra context menu item: Highlight – C:\Program Files\Avant Browser\Highlight.htm
O8 – Extra context menu item: I&zvoz v Microsoft Excel – res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 – Extra context menu item: Išči – C:\Program Files\Avant Browser\Search.htm
O8 – Extra context menu item: Open All Links in This Page… – C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 – Extra context menu item: Opri vse povezave na tej strani… – C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 – Extra context menu item: Poudari – C:\Program Files\Avant Browser\Highlight.htm
O8 – Extra context menu item: Search – C:\Program Files\Avant Browser\Search.htm
O9 – Extra button: Raziskovanje – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O16 – DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) – http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 – DPF: {11311111-1551-1661-1771-000000000000} – ms-its:mhtml:file://c:\nosuch.mht!http://www.find-to-you.com/pics/winhelp.chm::/web.exe
O16 – DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} – http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/PopularScreenSaversFWBInitialSetup1.0.0.8-2.cab
O16 – DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) – http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 – DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) – http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 – DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) – http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 – DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) – http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 – DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) – http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 – DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) – http://www5.incredimail.com/contents/setup/downloader/imloader.cab
O16 – DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) – http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{EFEF9559-6A71-4245-ACF8-A4D3E756CD23}: NameServer = 69.50.176.196,195.225.176.110
O23 – Service: LexBce Server (LexBceS) – Lexmark International, Inc. – C:\WINDOWS\system32\LEXBCES.EXE
O23 – Service: Panda anti-virus service (PAVSRV) – Panda Software – C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
O23 – Service: System Startup Service (SvcProc) – Unknown owner – C:\WINDOWS\svcproc.exe (file missing)

Lep pozdrav,

Probaj računalnik spucat še s kakšnim drugim Antivirus-programom,
kajti Panda se mi zdi bolj tko no.Meni ni nič najdu, potem sem zamenjal
za Nortona, mislil kolk sem na varnem, in šele programa Antivir ali pa
Avast sta pa res pomagala.
Probaj v tvojem primeru še kakšn Spybot ali Ad-Aware program.
Drugač pa še malo počakaj, če se bo pravim maherjim dalo iti
skoz tvoj hijack-log, ker fantje res obvladajo, in ti bo sigurno
nekdo namignil kaj je vse za ven, to pa jz sam ne obvladam.

Good Luck & lp

Imaš kar precej šrota na mašini, tako da bi blo najprej verjetno res najbolje, da si dolpotegneš Adware SE, SpyBot S&D, CWShreder, MS AntiSpyware.

Linke do programov dobiš tule
MS AntiSpyware(beta)

Ko boš zadevo popucal s temi, pa še enkrat naredi log s HJT, pa bomo vidli če je še kaj ostalo.

Aja pa DNSja ti je tudi spremenil. Napiši kako dostopaš do neta in kdo je tvoj inet provider.

ok snemam programe, ko bom vse naredil te obvestim…

Do neta dostopam preko kabla (kabelski -Telemach), provider je pa Arnes.

Potem si v DNS (Start –> Control Panel –> Network Connections –> desni klik na tvojo povezavo –> Properties –> poišči Internet Protocol(TCP/IP) –> gumb Properties) vpiši tele cifre :

Prefered DNS : 193.2.1.66
Alternate DNS : 193.2.1.72

Pa sem gor si tudi nekaj pripopal.

Ko kliknem na tvoj post mi AntiVir javi tole:

C:\DOCUMENTS AND SETTINGS\XXX\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\91NCGTFA\READ[8].PHP

Contains signature of the HTML script virus HTML/Exploit.Mhtml

Klemenxxx ???

Lep pozdrav

Ja, meni tudi!

Norton Virus Alert

C:\Documents and Settings\….\read[1].php
BLOODHOUND.EXPLOIT.6

Lp, Lady L

A v prvem (osnovnem) postu od medota al v kterem postu je to??

Yes, (samo) v prvem postu od medota…

Lep pozdrav

Hehehehe – se vidi, da ženske bolje poskrbimo za zaščito…

:))))

Lep pozdrav

Haha. Dekleta čudne AV programa imata. Mar po novem virus fašeš kar med prebiranjem postov na forumu?

Tale vročina že pušča posledice… Kako prav je prišel današnji dežek, prav osvežujoče, kajne?

Ne ne, se vid, da ženske pretiravate pri zaščiti, oz. ne uporabljate prave :))

Problem je v enem tekstu, ki je del medotovega loga. Antivirus zazna, da je tekst tak, kot ga vsebuje podpis za ta virus in pač zajambra. Boljši antivirusniki pa zaznajo, da to ni nevarnost, slabši pa ga itak ne prepoznajo 🙂
Pa da ne bo kdo zdaj rekel, da je antivir slab antivirus, to so pač malenkosti.

Pa da boste vidli, da je to res to, tukajle bom še enkrat skopiral ta sporni tekst, za katerega antivirusnik misli, da je Bloodhound.Exploit.6. Tko da vam bo tudi v tem postu jambralo 🙂

O16 – DPF: {11311111-1551-1661-1771-000000000000} – ms-its:mhtml:file://c:\nosuch.mht!http://www.find-to-you.com/pics/winhelp.chm::/web.exe

Če pa imate Q837009, ste pa itak imuni na to pošast 🙂

Saj ne rečem, da je AntiVir slab, čisto luškan je za osnovno pucanje prehlajenih mlinčkov v varnem zagonu. Potem se pravo delo šele začne.

‘Če pa imate Q837009, ste pa itak imuni na to pošast :)’

Pa kolkrat moram povedat, da ne maram XP-jev :))

Kar nej jambra, zaradi tega mene ne bo kap…

Pa sej nuna da tud olagumo na svečo… :))

Lep pozdrav

Ni to le problem xpjev, ampak vseh polkenc od 98 naprej ki imajo OE od 5.5 naprej.

@ Tajfun

Virus pa zlahka fašeš tudi med prebiranjem forumov, sicer tule na MONu so že fejst pobje in dekline, tko da od njih res ne bi bilo za pričakovat, nikol pa nisi 100% kdo..od kje…podtakne kako zlonamerno kodo.

Samo v prvem, ja!

Saj nič ne naredi, samo zajamra. Kakšno zaščito pa naj potem uporabim?
Mogoče tole?

Jah, hmm, ne vem sicer po katerih forumih rulaš, ampak doslej se mi res še ni primerilo, da bi se okužil kar z branjem posta. Kako le?? Tega ti zaenkrat ne verjamem. Argumentiraj prosim!

Meni se je to zgodilo, ko sem pregledoval in licitiral na Bolhi! Dobil licitacijo, dobil mail in glej ga zlomka bolhe ni več, no se prikaže za trenutek, potem pa preskoči na sex stran. drugače pa vse normalno dela.

Se jutri tipkamo, ko bom vse programe snel…

Glede na tole grozljivko bi dejal, da gre ali za Longhorn ali za MACX.

To ne morejo biti XP, izgleda preveč grozljivo.

Kaj dosti ni za argumentirat…

To da se okužiš z branjem(gledanjem) spletne strani ti je verjetno čisto jasno in logično.
Kaj pa je forum drugega kot ena spletna stran??

zivjo,
a bi lahko se men hmm in ostali pogledali tale log od hjacka in povedali kaj gre lahko stran. ne vem, ce je pomembno, cekiran je bil laptop.

hvala in lep pozdrav

evo log;
Logfile of HijackThis v1.99.1
Scan saved at 05:15:05 PM, on 2005/07/06
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Documents and Settings\luka leskosek\Desktop\HijackThis.exe

R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gaydar.co.za/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
O2 – BHO: AcroIEHlprObj Class – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 – BHO: DriveLetterAccess – {5CA3D70E-1895-11CF-8E15-001234567890} – C:\WINDOWS\system32\dla\tfswshx.dll
O2 – BHO: NAV Helper – {BDF3E430-B101-42AD-A544-FADC6B084872} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 – Toolbar: &Radio – {8E718888-423F-11D2-876E-00A0C9082467} – C:\WINDOWS\System32\msdxm.ocx
O4 – HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 – HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 – HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 – HKLM\..\Run: [UpdateManager] “C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe” /r
O4 – HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 – HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 – HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 – HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 – HKLM\..\Run: [HP Software Update] “c:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe”
O4 – HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 – HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 – HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 – HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 – HKLM\..\Run: [ccApp] “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”
O4 – HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 – HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1
O4 – HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 – HKCU\..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 – Global Startup: Image Transfer.lnk = ?
O4 – Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O14 – IERESET.INF: START_PAGE_URL=http://www.hp.com
O20 – Winlogon Notify: igfxcui – C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 – Service: HP WMI Interface (hpqwmi) – Hewlett Packard Company – C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 – Service: Norton AntiVirus Auto Protect Service (navapsvc) – Symantec Corporation – C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 – Service: SAVScan – Symantec Corporation – C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 – Service: ScriptBlocking Service (SBService) – Symantec Corporation – C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 – Service: Symantec Network Drivers Service (SNDSrvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 – Service: Symantec Core LC – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 – Service: SymWMI Service (SymWSC) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Nič ni narobe, videti je vse ok..

lp

(\__/) Copy and paste bunny (='.'=) to help him gain (")_(") world domination

ok, hvala:}

Forum je zaprt za komentiranje.

New Report

Close