praegune kellaaeg 20.06.2025 00:35:38
|
Hinnavaatlus
:: Foorum
:: Uudised
:: Ärifoorumid
:: HV F1 ennustusvõistlus
:: Pangalink
:: Telekavad
:: HV toote otsing
|
|
autor |
|
Uueke
HV vaatleja
liitunud: 14.12.2004
|
14.12.2004 23:24:22
Explorer.dll |
|
|
Kasutasin ka otsingut aga ammendavat vastust ei leidnud, seega siis uus teema.
Mure siis selles, et NAV leidis explorer.dll failist Hacktool.SCKeylogger aga ära ta seda ei kustuta.
Olen proovinud Ad-aware, Spybot ja HijackThis aga lahti ei ole sellest saanud. Olen üritanud ka julmalt
ära kustutada aga ei lase seda teha. Kõike seda olen proovinud ka Safe Mode's. OS XP SP2 ja ka kõik
eelpool mainitud proged on uuendatud. Viirust turvab Norton Internet Security 2005.
|
|
Kommentaarid: 15 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
15 |
|
tagasi üles |
|
 |
.phonkyp.
Kreisi kasutaja

liitunud: 17.09.2004
|
14.12.2004 23:35:22
|
|
|
Ei hakka ümber tõlkima:
tsitaat: |
Read this and follow the directions:
link
It's hiding in your system-restore files which cannot be vaulted or cleansed except by dumping them. Do not re-enable system restore until you are 100% sure you are clean. You should also dump %TEMP% files>
double click My Computer, put %TEMP% in address bar, enter, highlight and delete all. To dump TIF click tools > options > delete files, check the box for delete off line content > click ok > click delete cookies. > click ok. Dump recycle bin. Do it all from Safe Mode if you can.
Shut down for two full minutes.
This will help a lot, and if you do not have a firewall in place, get Sygate, it's free, no hassles, and keeps me clean.
This will also help, read:
Downloading hint:
One other thing I do is on downloading, after you get the download (M$ does not structure its downloads so you can do this for some reason), after download BEFORE INSTALL, #1. log off the net, #2. disable AV (right click tray icon), #3. then ctrl-alt-delete to close AV in close-program, THEN (and only then) #4. click on the install procedure. Otherwise your AV might read the install as an invader and mess with it. Then manually shut down for two full minutes.
Spybot:
Download and Read the SpyBot tutorial here:
http://s89223352.onlinehome.us/mirror/spybot/index1.php
Download it, Unzip the program, and immediately check for updates, install the updates and then do the scan.
Let it fix everything marked in red. Reboot but not with restart, shut it down for two full minutes. You�ve got two measely minutes and it�s worth it, and let Spybot run if it indicates.
To add an item to your �Ignore List� click on the little �+� sign next to the item and left click it to highlight it, then right click it and a menu appears, select the function you want.
When you are done reboot again same way. Two full minutes shut sown is best.
Tea Time discussed by designer here:
http://forums.net-integration.net/index.php?showtopic=13433
Also, go to the update page. Notice 3 icons across the top. Between "Search For Updates" and "Download Updates" there is an icon for the download mirror location. After you click on �search for updates,� the one in the middle will change. If it doesn't say "Spybot.US by Rootboxen.net USA" click on the dropbox arrows and click on Rootboxen, and use only that one. If you got a "checksum error" trying to download --that's why.
Ad-Aware:
Download AdAware from http://www.lavasoft.de/
check for updates at "webupdate".
I use these settings (green check)
From main window click "Start" then make sure " Activate in-depth scan" has a green check next to it.
Put a black dot nest to "Use custom scanning options� and click Customize" next to it, then green check these options:
"Scan within archives" ,"Scan active processes", "Scan registry",
"Deep scan registry" ,"Scan my IE Favorites for banned URL"
"Scan my host-files"
At the top of the �STATUS� page notice the Tweak (gear) icon. Click on it.
The first setting is �Scanning Engine.� Click on the little plus sign next to it, and in the drop-down green check "Unload recognized processes during scanning", and �include basic Ad-Aware settings in log file�. Next click on the �+� next to "Cleaning Engine" and in the drop-down green check "Let windows remove files in use at next reboot" and Delete quarantine objects after restoring�
Click "proceed", that will save those settings.
Click "Scan"
When the scan finishes, mark everything for removal and delete it. Right-click the window and choose "select all" from the drop down menu, press �next� and then �yes� to the prompt: �remove all these entries�.
However, if you have certain programs running that will give a false indicator of a browser hijack attempt, such as Script Sentry, which places a monitoring function in the registry and looks like a browser hijacker but is not, then you may want to add that to the ignore list because you want to keep it there to do it�s job. To add an item to the ignore list, put the a cursor on the file it reveals and left click it to highlight it, then right click it and a menu appears. Click on �ignore list.�
Shut down, two minute shut down is best, and let Adaware run on reboot if it indicates.
That should keep you off the streets for a a half hour or so....
Thresher |
_________________ Ärge uskuge, mida teised teile räägivad. |
|
Kommentaarid: 11 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
1 :: |
9 |
|
tagasi üles |
|
 |
TzigaLind
HV veteran
liitunud: 12.01.2002
|
15.12.2004 00:25:42
|
|
|
Noh kui Norton selle leidis siis ka
Nortoni Petsi käest saab teada
selle kustutamise meetodi.
_________________ Piix! |
|
Kommentaarid: 16 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
2 :: |
14 |
|
tagasi üles |
|
 |
Uueke
HV vaatleja
liitunud: 14.12.2004
|
15.12.2004 00:40:11
|
|
|
Ta pakub välja registrist HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, kuid
RunServices kataloogi minul millegipärast ei eksisteeri.
|
|
Kommentaarid: 15 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
15 |
|
tagasi üles |
|
 |
TzigaLind
HV veteran
liitunud: 12.01.2002
|
15.12.2004 00:54:50
|
|
|
Vaata ikka korralikult järgi, peab olema.
_________________ Piix! |
|
Kommentaarid: 16 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
2 :: |
14 |
|
tagasi üles |
|
 |
HacaX
HV Guru

liitunud: 22.01.2004
|
15.12.2004 02:12:36
|
|
|
Sa HijackThisi "Delete file on boot" võimalust ei kasutanud?
_________________ IMO & GPLed |
|
Kommentaarid: 24 loe/lisa |
Kasutajad arvavad: |
   |
:: |
1 :: |
0 :: |
22 |
|
tagasi üles |
|
 |
Uueke
HV vaatleja
liitunud: 14.12.2004
|
15.12.2004 08:47:09
|
|
|
To TzigaLind: No ei ole seda, äkki tal mingi Hidden peal?
To HacaX: Hijack'i jama selles, et ta ei näita seda progressi ja faili. Igax juhux uhan siia ka logi, ehk on abi.
Logfile of HijackThis v1.98.2
Scan saved at 7:45:13, on 15.12.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Keyboard\Ikeymain.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Download\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neti.ee/
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{64AEEFE6-458A-48C7-95E2-A6C72FA489BB}: NameServer = 192.168.3.1
A võibolla aitab lihtsalt selle faili asendamine?
|
|
Kommentaarid: 15 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
15 |
|
tagasi üles |
|
 |
HacaX
HV Guru

liitunud: 22.01.2004
|
15.12.2004 15:31:55
|
|
|
Logis paistavad ainukesed imelikud olevat too policy piirang ning et nimeserver on paika pandud...
Kas ma sellest sain ikka õieti aru, et faili EXPLORER.DLL leidsid üles, aga kustutada ei saa? Ja HijackThisis Config=>Misc Tools=>"Delete file on reboot..." üleüldse seda faili valida ei võimalda?
RegEditis võid ju ka lihtsalt otsingut kasutada et ExPLORER.DLL sissekanne üles leida kui seda tõesti ...\SERVICES alt ei leia.
_________________ IMO & GPLed |
|
Kommentaarid: 24 loe/lisa |
Kasutajad arvavad: |
   |
:: |
1 :: |
0 :: |
22 |
|
tagasi üles |
|
 |
Uueke
HV vaatleja
liitunud: 14.12.2004
|
15.12.2004 23:45:35
|
|
|
Nii, probleem lahendatud ja masin ka kõige pisemast saastast vabastatud(hetkel vähemalt). Probleemi
aitas lahendada regedit kus sai kasutatud otsingut(mille peale mina muidugi ei tulnud, loll pää - palju vaeva)
leidmaks faili explorer.dll, mis oli hoopis teises kohas, kui Symantec'i lehekülg oli väitnud. Leides selle sissekande
ja peale õnnestunud kustutamist(oh seda imet), ei leidnud NAV enam midagi. Seega arvan, probleem on lahendatud.
Aitähh kõigile, kes abiks olid.
See teema nüüd lõpetatud.
|
|
Kommentaarid: 15 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
0 :: |
15 |
|
tagasi üles |
|
 |
|
lisa lemmikuks |
|
|
sa ei või postitada uusi teemasid siia foorumisse sa ei või vastata selle foorumi teemadele sa ei või muuta oma postitusi selles foorumis sa ei või kustutada oma postitusi selles foorumis sa ei või vastata küsitlustele selles foorumis sa ei saa lisada manuseid selles foorumis sa võid manuseid alla laadida selles foorumis
|
|
Hinnavaatlus ei vastuta foorumis tehtud postituste eest.
|