Ewido lakkasi toimimasta

Discussion in 'Virukset ja haittaohjelmat' started by onkelma, Mar 3, 2006.

  1. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    Ewido lakkasi toimimasta kun scannasin konetta läpi...

    55.791 saastunutta tiedostoa ja kun ewido oli korjaamassa/poistamassa tiedostoja niin 20.000 kohdalla ewido lakkasi vastaamasta...

    Mikä eteen ?

    Tein tämän siis vikasietotilassa.

    Ruutuun hyppii popuppeja minkä ehtii ja kone yrittää asentaa jotain ihmeen spyware ohjelmaa itsestään...

    Neuvokaa hyvät osaajat.
     
  2. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
  3. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    Tässä tämä:

    Logfile of HijackThis v1.99.1
    Scan saved at 20:15:22, on 3.3.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\LXSUPMON.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\MultiRes\MultiRes.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Documents and Settings\pasi koivu\Työpöytä\hijackthis_199\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.p2p-load.de/share/?l=e
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.p2p-load.de/share/?l=e
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: googl.de
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: www.googl.de
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: google.se
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: www.googl.ch
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: googl.ch
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: www.googl.nl
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Shellapi32] svcnet.exe
    O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [MultiRes] C:\Program Files\MultiRes\MultiRes.exe
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Shellapi32] svcnet.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: SMS-viesti - {18BC259E-7404-4A2D-800F-395EC2EDC35F} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Tuki - {4A6B751C-129B-49B7-9883-555136288A6F} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {68532556-E710-4C82-ADB5-7F0EEDDAC1E5} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {D6E2C70F-C694-4FDB-9283-459FC77FEFE0} (Softers.efOrderX) - https://www.efoto.fi/efOrderX.CAB
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

     
  4. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Missä on virustentorjuntaohjelma? Eipä näy. Olisiko siinä syy tuohon 55.791:ään+ ;)

    Fixaa nämä (do a system scan only, merkkaa ja paina fix checked):

    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: googl.de
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: www.googl.de
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: google.se
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: www.googl.ch
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: googl.ch
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O1 - Hosts: <H1>Not Found</H1>
    O1 - Hosts: The requested URL /ip.txt was not found on this server.<P>
    O1 - Hosts: </BODY></HTML>
    O1 - Hosts: www.googl.nl
    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    O1 - Hosts: <HTML><HEAD>
    O1 - Hosts: <TITLE>404 Not Found</TITLE>
    O1 - Hosts: </HEAD><BODY>
    O4 - HKLM\..\Run: [Shellapi32] svcnet.exe
    O4 - HKCU\..\Run: [Shellapi32] svcnet.exe


    Etsi Etsi-toiminnolla (kaikki tiedostot ja kansiot -> lisävaihtoehdot ja merkkaa kolme ylimmäistä) -> svcnet.exe

    Poista se, jos löytyy.

    Käynnistä uudelleen ja lähetä uusi HjT-loki.
     
  5. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    Tehty neuvomasi toimenpiteet...

    Tuo perkeleen spy ohjelma vaan asentautuu aina uudestaan itsestään vaikka laittaa sen estoon palomuurista..?

    Ja pitäisi näkyä tuo zonealarm security suite siellä kyllä...
    --->C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    ja O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    Logfile of HijackThis v1.99.1
    Scan saved at 21:04:16, on 3.3.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\LXSUPMON.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\MultiRes\MultiRes.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\pasi koivu\Työpöytä\hijackthis_199\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.p2p-load.de/share/?l=e
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.p2p-load.de/share/?l=e
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O1 - Hosts: googl.nl
    O1 - Hosts: www.googl.se
    O1 - Hosts: googl.se
    O1 - Hosts: auto.search.msn.de
    O1 - Hosts: ww.googl.nl
    O1 - Hosts: ww.googl.se
    O1 - Hosts: ww.google.de
    O1 - Hosts: ww.google.ch
    O1 - Hosts: ww.google.nl
    O1 - Hosts: ww.google.de
    O1 - Hosts: www.gooogle.de
    O1 - Hosts: www.gooogle.nl
    O1 - Hosts: www.gooogle.se
    O1 - Hosts: www.gooogle.ch
    O1 - Hosts: gooogle.de
    O1 - Hosts: gooogle.nl
    O1 - Hosts: gooogle.se
    O1 - Hosts: gooogle.ch
    O1 - Hosts: wwwgoogle.de
    O1 - Hosts: wwwgoogle.nl
    O1 - Hosts: wwwgoogle.ch
    O1 - Hosts: www.gogle.de
    O1 - Hosts: www.gogle.nl
    O1 - Hosts: www.gogle.se
    O1 - Hosts: www.gogle.ch
    O1 - Hosts: gogle.de
    O1 - Hosts: gogle.nl
    O1 - Hosts: gogle.se
    O1 - Hosts: gogle.ch
    O1 - Hosts: wwwgoogle.com
    O1 - Hosts: www.gooogle.com
    O1 - Hosts: www.googl.com
    O1 - Hosts: gooogl.com
    O1 - Hosts: gogl.com
    O1 - Hosts: www.gogl.com
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [MultiRes] C:\Program Files\MultiRes\MultiRes.exe
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: SMS-viesti - {18BC259E-7404-4A2D-800F-395EC2EDC35F} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Tuki - {4A6B751C-129B-49B7-9883-555136288A6F} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {68532556-E710-4C82-ADB5-7F0EEDDAC1E5} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {D6E2C70F-C694-4FDB-9283-459FC77FEFE0} (Softers.efOrderX) - https://www.efoto.fi/efOrderX.CAB
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

     
    Last edited: Mar 3, 2006
  6. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    Uppista...

    Auttakaa nyt joku.
     
  7. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Kokeillaas näin:

    Hae hoster ->
    http://www.funkytoad.com/download/hoster.zip

    Pura zippi ja tuplaklikkaa hoster.exe

    Paina "Restore original hosts" ja ok.

    Käynnistä kone uudelleen ja lähetä uusi HjT-loki.

    Mikä sen spyohjelman nimi on?
     
  8. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    Spy falcon 2.0 on se ohjelma mikä yrittää asentaa itteään kokoajan.

    Tässä tämä uusi loki:

    Logfile of HijackThis v1.99.1
    Scan saved at 23:45:14, on 4.3.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\LXSUPMON.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\MultiRes\MultiRes.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\pasi koivu\Työpöytä\hijackthis_199\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.p2p-load.de/share/?l=e
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.p2p-load.de/share/?l=e
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpEF2.tmp
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [MultiRes] C:\Program Files\MultiRes\MultiRes.exe
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: SMS-viesti - {18BC259E-7404-4A2D-800F-395EC2EDC35F} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Tuki - {4A6B751C-129B-49B7-9883-555136288A6F} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {68532556-E710-4C82-ADB5-7F0EEDDAC1E5} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {D6E2C70F-C694-4FDB-9283-459FC77FEFE0} (Softers.efOrderX) - https://www.efoto.fi/efOrderX.CAB
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


     
    Last edited: Mar 4, 2006
  9. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Tämä selvä, tässä ohjeet poistoon:

    * Lataa smitrem työpöydälle
    http://noahdfear.geekstogo.com/click counter/click.php?id=1
    Tuplaklikkaa sitä ja Start, niin saat smitrem-kansion työpöydälle.

    * Ota FixSF.reg työpöydälle
    http://www.bleepingcomputer.com/files/reg/FixSF.reg

    Tuplaklikkaa sitä ja vastaa myöntävästi.
    * Käynnistä sitten kone vikasietotilassa(F8 käynnistyksen yhteydessä)

    * Fixaa tämä HjT:llä
    (do a system scan only, merkkaa ja paina fix checked:

    O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpEF2.tmp

    * Poista ohjauspaneelista (lisää/poista sovellus)
    - SpyFalcon
    ja jos se käskee\vaatii käynnistään koneen uudestaan, älä käynnistä.

    Sitten poista
    C:\Program\SpyFalcon\ < kansio voi olla, että ei löydy enää
    C:\Windows\System32\dxmpp.dll
    C:\WINDOWS\system32\ginuerep.dll

    * Sen jälkeen avaa smitrem-kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.

    *Käynnistä sitten normaalisti ja lähetä uus Hijack logi ja C:\smitfiles.txt-tiedoston sisältö
     
  10. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    nämä kohdat ei onnistuneet:
    C:\Windows\System32\dxmpp.dll <--- ei löytynyt.
    C:\WINDOWS\system32\ginuerep.dll <---- löytyi mutta ei anna poistaa, väittää että käytössä.



    uusi logi:

    Logfile of HijackThis v1.99.1
    Scan saved at 13:41:33, on 5.3.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\LXSUPMON.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\MultiRes\MultiRes.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Documents and Settings\pasi koivu\Työpöytä\hijackthis_199\HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [MultiRes] C:\Program Files\MultiRes\MultiRes.exe
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: SMS-viesti - {18BC259E-7404-4A2D-800F-395EC2EDC35F} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Tuki - {4A6B751C-129B-49B7-9883-555136288A6F} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {68532556-E710-4C82-ADB5-7F0EEDDAC1E5} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {D6E2C70F-C694-4FDB-9283-459FC77FEFE0} (Softers.efOrderX) - https://www.efoto.fi/efOrderX.CAB
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


    Smitrem:

    smitRem © log file
    version 2.8

    by noahdfear


    Microsoft Windows XP [versio 5.1.2600]

    Running from
    C:\Documents and Settings\pasi koivu\Ty”p”yt„\smitRem

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Pre-run SharedTask Export

    (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
    Copyright(C) 2006 BleepingComputer.com

    Registry Pseudo-Format Mode (Not a valid reg file):

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    checking for ShudderLTD key

    ShudderLTD key not present!

    checking for PSGuard.com key


    PSGuard.com key not present!


    checking for WinHound.com key


    WinHound.com key not present!

    spyaxe uninstaller NOT present
    Winhound uninstaller NOT present
    SpywareStrike uninstaller NOT present

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Existing Pre-run Files


    ~~~ Program Files ~~~



    ~~~ Shortcuts ~~~



    ~~~ Favorites ~~~



    ~~~ system32 folder ~~~

    1024 dir
    msvol.tlb
    ld****.tmp
    mssearchnet.exe
    ncompat.tlb
    nvctrl.exe
    hp***.tmp


    ~~~ Icons in System32 ~~~

    ts.ico
    ot.ico


    ~~~ Windows directory ~~~



    ~~~ Drive root ~~~


    ~~~ Miscellaneous Files/folders ~~~




    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 796 'explorer.exe'

    Starting registry repairs

    Registry repairs complete

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    SharedTask Export after registry fix

    (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
    Copyright(C) 2006 BleepingComputer.com

    Registry Pseudo-Format Mode (Not a valid reg file):

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Deleting files

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Remaining Post-run Files


    ~~~ Program Files ~~~



    ~~~ Shortcuts ~~~



    ~~~ Favorites ~~~



    ~~~ system32 folder ~~~



    ~~~ Icons in System32 ~~~



    ~~~ Windows directory ~~~



    ~~~ Drive root ~~~


    ~~~ Miscellaneous Files/folders ~~~


    ~~~ Wininet.dll ~~~

    CLEAN! :)
     
  11. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Selvä, kyllä se ginuerep.dll:kin saadaan pois :)

    Hae KillBox

    http://www.bleepingcomputer.com/files/spyware/KillBox.zip

    Pura,avaa ja täppi kohtaan Delete on Reboot
    Sitten kopioi rivi tosta alapuolelta

    C:\WINDOWS\system32\ginuerep.dll

    Sitten KillBoxissa ylhäältä File > Paste from Clipboard
    Valitse "All Files".Sen jälkeen paina Delete (punainen, jossa on valkonen X)
    Vastaa myöntävästi kysymyksiin ja jos kone ei itestään käynnisty uudestaan,niin käynnistä se.

    Lähetä sen jälkeen uus Hijack-logi ja kerro, onko vielä ongelmia.
     
  12. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    tässä uusi logi.

    Tehty toimenpiteet mitä neuvoit.

    Nyt ongelma näyttää kadonneen eli kone ei varoita enään kokoajan "your computer is infected"


    Logfile of HijackThis v1.99.1
    Scan saved at 14:30:00, on 5.3.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\LXSUPMON.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\MultiRes\MultiRes.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Documents and Settings\pasi koivu\Työpöytä\hijackthis_199\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [MultiRes] C:\Program Files\MultiRes\MultiRes.exe
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: SMS-viesti - {18BC259E-7404-4A2D-800F-395EC2EDC35F} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Tuki - {4A6B751C-129B-49B7-9883-555136288A6F} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {68532556-E710-4C82-ADB5-7F0EEDDAC1E5} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {D6E2C70F-C694-4FDB-9283-459FC77FEFE0} (Softers.efOrderX) - https://www.efoto.fi/efOrderX.CAB
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

     
  13. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Juu, se dll oli sen "your computer is infected"-viestin takana :) Kaikki taitaa olla kunnossa?
     
  14. onkelma

    onkelma Member

    Joined:
    Apr 7, 2005
    Messages:
    70
    Likes Received:
    0
    Trophy Points:
    16
    Juu näyttäis kone tottelevan nyt normaalisti...

    SUUR kiitos sinulle kemisti!.
     
  15. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Olepa hyvä :)
     

Share This Page