HijackThis
Kaj lahko zbrišem? Kako vem kaj mi dela probleme…namesto določene strani se mi odpre “sex” stran..
Logfile of HijackThis v1.99.1
Scan saved at 15:51:25, on 30.6.2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Avant Browser\avant.exe
C:\Documents and Settings\Igor\Local Settings\Temp\Začasen imenik 19 za hijackthis.zip\HijackThis.exe
O3 – Toolbar: &Radio – {8E718888-423F-11D2-876E-00A0C9082467} – C:\WINDOWS\System32\msdxm.ocx
O3 – Toolbar: MSN Toolbar – {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} – C:\Program Files\MSN Toolbar\01.01.2607.0\sl-si\msntb.dll
O4 – HKLM\..\Run: [APVXDWIN] “C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE” /s
O4 – HKLM\..\Run: [lrlplk] c:\windows\system32\vrwevrt.exe
O4 – HKLM\..\Run: [TorontoMail] DCC_send.exe
O4 – HKLM\..\Run: [xsetup] MSTCPDLL.exe
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 – HKCU\..\Run: [MsnMsgr] “C:\Program Files\MSN Messenger\MsnMsgr.Exe” /background
O4 – HKCU\..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 – HKCU\..\Run: [WareOut] “C:\Program Files\WareOut\WareOut.exe”
O4 – HKCU\..\Run: [___] syspanel.exe
O4 – HKCU\..\Run: [AppMasterCenter] ATLIEHELPER.exe
O4 – HKCU\..\Run: [UserSp1] XTermInit.exe
O8 – Extra context menu item: Add to AD Black List – C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 – Extra context menu item: Block All Images from the Same Server – C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 – Extra context menu item: Blokiraj vse slike s tega strežnika – C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 – Extra context menu item: Dodaj na seznam reklam za blokiranje – C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 – Extra context menu item: Highlight – C:\Program Files\Avant Browser\Highlight.htm
O8 – Extra context menu item: I&zvoz v Microsoft Excel – res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 – Extra context menu item: Išči – C:\Program Files\Avant Browser\Search.htm
O8 – Extra context menu item: Open All Links in This Page… – C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 – Extra context menu item: Opri vse povezave na tej strani… – C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 – Extra context menu item: Poudari – C:\Program Files\Avant Browser\Highlight.htm
O8 – Extra context menu item: Search – C:\Program Files\Avant Browser\Search.htm
O9 – Extra button: Raziskovanje – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O16 – DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) – http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 – DPF: {11311111-1551-1661-1771-000000000000} – ms-its:mhtml:file://c:\nosuch.mht!http://www.find-to-you.com/pics/winhelp.chm::/web.exe
O16 – DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} – http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/PopularScreenSaversFWBInitialSetup1.0.0.8-2.cab
O16 – DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) – http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 – DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) – http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 – DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) – http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 – DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) – http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 – DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) – http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 – DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) – http://www5.incredimail.com/contents/setup/downloader/imloader.cab
O16 – DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) – http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{EFEF9559-6A71-4245-ACF8-A4D3E756CD23}: NameServer = 69.50.176.196,195.225.176.110
O23 – Service: LexBce Server (LexBceS) – Lexmark International, Inc. – C:\WINDOWS\system32\LEXBCES.EXE
O23 – Service: Panda anti-virus service (PAVSRV) – Panda Software – C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
O23 – Service: System Startup Service (SvcProc) – Unknown owner – C:\WINDOWS\svcproc.exe (file missing)
Lep pozdrav,
Probaj računalnik spucat še s kakšnim drugim Antivirus-programom,
kajti Panda se mi zdi bolj tko no.Meni ni nič najdu, potem sem zamenjal
za Nortona, mislil kolk sem na varnem, in šele programa Antivir ali pa
Avast sta pa res pomagala.
Probaj v tvojem primeru še kakšn Spybot ali Ad-Aware program.
Drugač pa še malo počakaj, če se bo pravim maherjim dalo iti
skoz tvoj hijack-log, ker fantje res obvladajo, in ti bo sigurno
nekdo namignil kaj je vse za ven, to pa jz sam ne obvladam.
Good Luck & lp
Imaš kar precej šrota na mašini, tako da bi blo najprej verjetno res najbolje, da si dolpotegneš Adware SE, SpyBot S&D, CWShreder, MS AntiSpyware.
Linke do programov dobiš tule
MS AntiSpyware(beta)
Ko boš zadevo popucal s temi, pa še enkrat naredi log s HJT, pa bomo vidli če je še kaj ostalo.
Aja pa DNSja ti je tudi spremenil. Napiši kako dostopaš do neta in kdo je tvoj inet provider.
Ne ne, se vid, da ženske pretiravate pri zaščiti, oz. ne uporabljate prave :))
Problem je v enem tekstu, ki je del medotovega loga. Antivirus zazna, da je tekst tak, kot ga vsebuje podpis za ta virus in pač zajambra. Boljši antivirusniki pa zaznajo, da to ni nevarnost, slabši pa ga itak ne prepoznajo 🙂
Pa da ne bo kdo zdaj rekel, da je antivir slab antivirus, to so pač malenkosti.
Pa da boste vidli, da je to res to, tukajle bom še enkrat skopiral ta sporni tekst, za katerega antivirusnik misli, da je Bloodhound.Exploit.6. Tko da vam bo tudi v tem postu jambralo 🙂
O16 – DPF: {11311111-1551-1661-1771-000000000000} – ms-its:mhtml:file://c:\nosuch.mht!http://www.find-to-you.com/pics/winhelp.chm::/web.exe
Če pa imate Q837009, ste pa itak imuni na to pošast 🙂
evo log;
Logfile of HijackThis v1.99.1
Scan saved at 05:15:05 PM, on 2005/07/06
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Documents and Settings\luka leskosek\Desktop\HijackThis.exe
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gaydar.co.za/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
O2 – BHO: AcroIEHlprObj Class – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 – BHO: DriveLetterAccess – {5CA3D70E-1895-11CF-8E15-001234567890} – C:\WINDOWS\system32\dla\tfswshx.dll
O2 – BHO: NAV Helper – {BDF3E430-B101-42AD-A544-FADC6B084872} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 – Toolbar: &Radio – {8E718888-423F-11D2-876E-00A0C9082467} – C:\WINDOWS\System32\msdxm.ocx
O4 – HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 – HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 – HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 – HKLM\..\Run: [UpdateManager] “C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe” /r
O4 – HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 – HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 – HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 – HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 – HKLM\..\Run: [HP Software Update] “c:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe”
O4 – HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 – HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 – HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 – HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 – HKLM\..\Run: [ccApp] “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”
O4 – HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 – HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1
O4 – HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 – HKCU\..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 – Global Startup: Image Transfer.lnk = ?
O4 – Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O14 – IERESET.INF: START_PAGE_URL=http://www.hp.com
O20 – Winlogon Notify: igfxcui – C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 – Service: HP WMI Interface (hpqwmi) – Hewlett Packard Company – C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 – Service: Norton AntiVirus Auto Protect Service (navapsvc) – Symantec Corporation – C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 – Service: SAVScan – Symantec Corporation – C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 – Service: ScriptBlocking Service (SBService) – Symantec Corporation – C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 – Service: Symantec Network Drivers Service (SNDSrvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 – Service: Symantec Core LC – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 – Service: SymWMI Service (SymWSC) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Forum je zaprt za komentiranje.