Gå til innhold

Hvordan fjerne en Trojansk Hest?


Anbefalte innlegg

Videoannonse
Annonse

Logfile of Browser Hijack Recover(BHR) v2.3
http://www.browser-hijack.com/
Log created on 28.11.2006 16:05:18
Microsoft Windows XP Professional Service Pack 2 (Build 2600)
Internet Explorer v6.0.2900.2180  Update Versions:;SP2;

[Process Manager] - [Process]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
d:\Programfiler\Avast4\aswUpdSv.exe
d:\Programfiler\Avast4\ashServ.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\Avast4\ashDisp.exe
C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe
C:\Programfiler\DAEMON Tools\daemon.exe
C:\Programfiler\QuickTime\qttask.exe
I:\iTunesHelper.exe
C:\Programfiler\Mozilla Firefox\winstall.exe
C:\Programfiler\iPod\bin\iPodService.exe
d:\Programfiler\Avast4\ashMaiSv.exe
d:\Programfiler\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Programfiler\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
C:\Programfiler\MSN Messenger\msnmsgr.exe
C:\Programfiler\MSN Messenger\msrr.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Mozilla Firefox\firefox.exe
C:\Programfiler\Fellesfiler\{AC3C697C-06C5-1044-1115-02111520002f}\Update.exe
C:\Programfiler\Browser Hijack Recover\bhr.exe

[IE Options] - [Normal]
R0 - HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R0 - HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
R0 - HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main,Window Title = 
R1 - HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

[IE Options] - [IE Menu]

[IE Options] - [Internet Options]

[IE Options] - [IE Search Hooks]
R3 - URLSearchHook: Microsoft-binding for URL-søk - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\shdocvw.dll

[IE Add-Ons] - [Toolbars]
O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\FELLES~1\{3C3C6~1\888Bar.dll

[IE Add-Ons] - [Explorer Bars]
O9 - Extra "View" Explorer Bars: Shell Search Band - {21569614-B795-46B1-85F4-E737A8DC09AD} - C:\WINDOWS\system32\browseui.dll
O9 - Extra "View" Explorer Bars: (No Name) - {32683183-48a0-441b-a342-7c2a440a9478} - (No File)
O9 - Extra "View" Explorer Bars: Favorites Band - {EFA24E61-B078-11D0-89E4-00C04FC9E26E} - C:\WINDOWS\System32\shdocvw.dll

[IE Add-Ons] - [Context Menu]

[IE Add-Ons] - [BHOs]
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\FELLES~1\{3C3C6~1\888Bar.dll

[IE Add-Ons] - [Tools Menu]
O9 - Extra "Tool" Menu Item: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

[IE Add-Ons] - [Tools Button]
O9 - Extra "Tool" Menu Item: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

[System Options]

[StartUp]
04 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run MsnMsgr = C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Cmaudio = RunDll32 cmicnfg.cpl,CMICtrlWnd
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run SoundMan = SOUNDMAN.EXE
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run avast! = d:\PROGRA~1\Avast4\ashDisp.exe
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run SunJavaUpdateSched = C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run DAEMON Tools = C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run QuickTime Task = C:\Programfiler\QuickTime\qttask.exe" -atboottime
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run iTunesHelper = I:\iTunesHelper.exe
04 - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run explorer = C:\Programfiler\Mozilla Firefox\winstall.exe
04 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run {AC3C697C-06C5-1044-1115-02111520002f} = C:\Programfiler\Fellesfiler\{AC3C697C-06C5-1044-1115-02111520002f}\Update.exe" mc-110-12-0001411
O4 - C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\Adobe Gamma Loader.lnk = C:\PROGRA~1\FELLES~1\Adobe\CALIBR~1\ADOBEG~1.EXE
O4 - C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\Adobe Reader Speed Launch.lnk = D:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE

 

Håper jeg har gjordt rett, skal nå kjøre den SAS-greien :)

Lenke til kommentar
Logfile of HijackThis v1.99.1
Scan saved at 17:00:22, on 28.11.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
d:\Programfiler\Avast4\aswUpdSv.exe
d:\Programfiler\Avast4\ashServ.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\Avast4\ashDisp.exe
C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe
C:\Programfiler\DAEMON Tools\daemon.exe
C:\Programfiler\QuickTime\qttask.exe
I:\iTunesHelper.exe
C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programfiler\iPod\bin\iPodService.exe
d:\Programfiler\Avast4\ashMaiSv.exe
d:\Programfiler\Avast4\ashWebSv.exe
C:\Programfiler\Mozilla Firefox\firefox.exe
C:\Programfiler\MSN Messenger\msnmsgr.exe
C:\Programfiler\MSN Messenger\msrr.exe
C:\Programfiler\Fellesfiler\{AC3C697C-06C5-1044-1115-02111520002f}\Update.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\WinRAR\WinRAR.exe
C:\DOCUME~1\LARSGA~1\LOKALE~1\Temp\Rar$EX00.219\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\FELLES~1\{3C3C6~1\888Bar.dll
O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\FELLES~1\{3C3C6~1\888Bar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] d:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "I:\iTunesHelper.exe"
O4 - HKLM\..\Run: [explorer] C:\Programfiler\Mozilla Firefox\winstall.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - d:\Programfiler\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - d:\Programfiler\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - d:\Programfiler\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - d:\Programfiler\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

Lenke til kommentar

Heisann, fortvil ikke. La oss prøve dette:

 

Avinstaller følgende fra legg til/fjern programmer:

888bar

 

Kjør HJT og merk for sletting:

O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\FELLES~1\{3C3C6~1\888Bar.dll

O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\FELLES~1\{3C3C6~1\888Bar.dll

O4 - HKLM\..\Run: [explorer] C:\Programfiler\Mozilla Firefox\winstall.exe

 

Sørg for at du kan se skjulte filer og mapper (kontrollpanel->mappealternativer->vis->"vis skjulte filer og mapper"

 

Restart i sikker modus (tapp f8 under oppstart)

 

Bruk utforsker til å finne og slette filen (i bold)

C:\Programfiler\Mozilla Firefox\winstall.exe

 

Restart i normal modus

 

Last ned combofix, kjør programmet

 

Legg ut en ny HJT-logg

Lenke til kommentar

Jepp! Har trykket F8 engang før, og da komm det opp et fullskjerms oppdateringer, Med den Windows XP bakgrunnen. Skal jeg restarte på nytt og prøve?

Kan jo også være at sist gang jeg trykte F( (Og det funket) så kom det opp at jeg måtte restarte maskinen! Ikke nå som jeg tykkte Restart knappen, kansje det er problemet?

Endret av Skorpey
Lenke til kommentar
Logfile of HijackThis v1.99.1
Scan saved at 22:40:55, on 28.11.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\Avast4\ashDisp.exe
C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe
C:\Programfiler\DAEMON Tools\daemon.exe
C:\Programfiler\QuickTime\qttask.exe
I:\iTunesHelper.exe
C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe
d:\Programfiler\Avast4\aswUpdSv.exe
d:\Programfiler\Avast4\ashServ.exe
C:\Programfiler\iPod\bin\iPodService.exe
d:\Programfiler\Avast4\ashMaiSv.exe
d:\Programfiler\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programfiler\Mozilla Firefox\firefox.exe
C:\Programfiler\WinRAR\WinRAR.exe
C:\DOCUME~1\LARSGA~1\LOKALE~1\Temp\Rar$EX00.562\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] d:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programfiler\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "I:\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - d:\Programfiler\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - d:\Programfiler\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - d:\Programfiler\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - d:\Programfiler\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

Lenke til kommentar

PC'en kjører som normalt. Men når jeg var på skolen har min lillebror vært på PC'en og sa det kom opp en feilmelding :hmm: Men skal se om jeg ikke får fikset det selv!

kan legge til at når jeg skulle slette: C:\Programfiler\Mozilla Firefox\winstall.exe så kommer det bare opp "Kan ikke lese fra kildefilen eller kildedisken".

 

EDIT: Avast! sier at det fortsatt er virus på PC'en, og samme meldingen som i screenshotet kommer opp!

Endret av Skorpey
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...