ei asenna f-secure. Logfile of HijackThis v1.99.1 Scan saved at 15:51:53, on 22.1.2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\serbw.exe C:\Program Files\Athan\Athan.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Shareaza\Shareaza.exe C:\Program Files\VoipCheap\VoipCheap.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O1 - Hosts: 64.233.167.104 www.symantec.com O1 - Hosts: 64.233.167.104 www.sophos.com O1 - Hosts: 64.233.167.104 www.mcafee.com O1 - Hosts: 64.233.167.104 www.viruslist.com O1 - Hosts: 64.233.167.104 www.f-secure.com O1 - Hosts: 64.233.167.104 www.avp.com O1 - Hosts: 64.233.167.104 www.kaspersky.com O1 - Hosts: 64.233.167.104 www.networkassociates.com O1 - Hosts: 64.233.167.104 www.ca.com O1 - Hosts: 64.233.167.104 www.my-etrust.com O1 - Hosts: 64.233.167.104 www.nai.com O1 - Hosts: 64.233.167.104 www.trendmicro.com O1 - Hosts: 64.233.167.104 www.grisoft.com O1 - Hosts: 64.233.167.104 securityresponse.symantec.com O1 - Hosts: 64.233.167.104 symantec.com O1 - Hosts: 64.233.167.104 sophos.com O1 - Hosts: 64.233.167.104 mcafee.com O1 - Hosts: 64.233.167.104 liveupdate.symantecliveupdate.com O1 - Hosts: 64.233.167.104 viruslist.com O1 - Hosts: 64.233.167.104 f-secure.com O1 - Hosts: 64.233.167.104 kaspersky.com O1 - Hosts: 64.233.167.104 kaspersky-labs.com O1 - Hosts: 64.233.167.104 avp.com O1 - Hosts: 64.233.167.104 networkassociates.com O1 - Hosts: 64.233.167.104 ca.com O1 - Hosts: 64.233.167.104 mast.mcafee.com O1 - Hosts: 64.233.167.104 my-etrust.com O1 - Hosts: 64.233.167.104 download.mcafee.com O1 - Hosts: 64.233.167.104 dispatch.mcafee.com O1 - Hosts: 64.233.167.104 secure.nai.com O1 - Hosts: 64.233.167.104 nai.com O1 - Hosts: 64.233.167.104 update.symantec.com O1 - Hosts: 64.233.167.104 updates.symantec.com O1 - Hosts: 64.233.167.104 us.mcafee.com O1 - Hosts: 64.233.167.104 liveupdate.symantec.com O1 - Hosts: 64.233.167.104 customer.symantec.com O1 - Hosts: 64.233.167.104 rads.mcafee.com O1 - Hosts: 64.233.167.104 trendmicro.com O1 - Hosts: 64.233.167.104 grisoft.com O1 - Hosts: 64.233.167.104 sandbox.norman.no O1 - Hosts: 64.233.167.104 www.pandasoftware.com O1 - Hosts: 64.233.167.104 uk.trendmicro-europe.com O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [serpe] C:\WINDOWS\System32\serbw.exe O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ltwob] C:\WINDOWS\System32\formatsys.exe O4 - HKLM\..\Run: [avnort] C:\WINDOWS\msmbw.exe O4 - HKLM\..\RunServices: [serpe] C:\WINDOWS\System32\serbw.exe O4 - HKLM\..\RunServices: [ltwob] C:\WINDOWS\System32\formatsys.exe O4 - HKLM\..\RunServices: [avnort] C:\WINDOWS\msmbw.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray O4 - HKCU\..\Run: [VoipCheap] "C:\Program Files\VoipCheap\VoipCheap.exe" -nosplash -minimized O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{2E9C5F71-7CB2-4E90-B6DE-23896FD523EF}: NameServer = 212.83.96.242 212.83.96.250 O17 - HKLM\System\CS1\Services\Tcpip\..\{2E9C5F71-7CB2-4E90-B6DE-23896FD523EF}: NameServer = 212.83.96.242 212.83.96.250 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Voisin jo tähän alkuun sanoa että kannattais päivittää SP-2seen ja voisit käyttää parempaa selainta esim firefox. Serbw.exe tiedosto näyttää virukselta. Voisit tarkistaa sen. O4 - HKLM\..\Run: [serpe] C:\WINDOWS\System32\serbw.exe Tommosen kohan voisit fixsata. Lisä tietoo tosta virukseta täältä http://securityresponse.symantec.com/avcenter/venc/data/w32.serflog.a.html Ja vielä tämn kohan voisit fixsata O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll Ja nämä: O1 - Hosts: 64.233.167.104 www.symantec.com O1 - Hosts: 64.233.167.104 www.sophos.com O1 - Hosts: 64.233.167.104 www.mcafee.com O1 - Hosts: 64.233.167.104 www.viruslist.com O1 - Hosts: 64.233.167.104 www.f-secure.com O1 - Hosts: 64.233.167.104 www.avp.com O1 - Hosts: 64.233.167.104 www.kaspersky.com O1 - Hosts: 64.233.167.104 www.networkassociates.com O1 - Hosts: 64.233.167.104 www.ca.com O1 - Hosts: 64.233.167.104 www.my-etrust.com O1 - Hosts: 64.233.167.104 www.nai.com O1 - Hosts: 64.233.167.104 www.trendmicro.com O1 - Hosts: 64.233.167.104 www.grisoft.com O1 - Hosts: 64.233.167.104 securityresponse.symantec.com O1 - Hosts: 64.233.167.104 symantec.com O1 - Hosts: 64.233.167.104 sophos.com O1 - Hosts: 64.233.167.104 mcafee.com O1 - Hosts: 64.233.167.104 liveupdate.symantecliveupdate.com O1 - Hosts: 64.233.167.104 viruslist.com O1 - Hosts: 64.233.167.104 f-secure.com O1 - Hosts: 64.233.167.104 kaspersky.com O1 - Hosts: 64.233.167.104 kaspersky-labs.com O1 - Hosts: 64.233.167.104 avp.com O1 - Hosts: 64.233.167.104 networkassociates.com O1 - Hosts: 64.233.167.104 ca.com O1 - Hosts: 64.233.167.104 mast.mcafee.com O1 - Hosts: 64.233.167.104 my-etrust.com O1 - Hosts: 64.233.167.104 download.mcafee.com O1 - Hosts: 64.233.167.104 dispatch.mcafee.com O1 - Hosts: 64.233.167.104 secure.nai.com O1 - Hosts: 64.233.167.104 nai.com O1 - Hosts: 64.233.167.104 update.symantec.com O1 - Hosts: 64.233.167.104 updates.symantec.com O1 - Hosts: 64.233.167.104 us.mcafee.com O1 - Hosts: 64.233.167.104 liveupdate.symantec.com O1 - Hosts: 64.233.167.104 customer.symantec.com O1 - Hosts: 64.233.167.104 rads.mcafee.com O1 - Hosts: 64.233.167.104 trendmicro.com O1 - Hosts: 64.233.167.104 grisoft.com O1 - Hosts: 64.233.167.104 sandbox.norman.no O1 - Hosts: 64.233.167.104 www.pandasoftware.com O1 - Hosts: 64.233.167.104 uk.trendmicro-europe.com Tuo virus näytää aiheuttavan ton ongelman http://securityresponse.symantec.com/avcenter/venc/data/w32.serflog.removal.tool.html tolla ohjelmalla voit postaa sen viruksen
Kun oot tehny nuo q-hub-opin mainitsemat seikat, suosittelen vielä Ewidon (ohjeet ->http://keskustelu.afterdawn.com/thread_view.cfm/269186) ajamista vikasietotilassa (pääsee painamalla F8:ia koneen käynnistyksen yhteydessä). Postaa tämän jälkeen Ewidon loki ja uusi HjT loki tänne.
Sinulla ei siis löydy palomuuria ja antivirus softaa mutta örkin nappasit ja sellaisen vielä joka estää sinua saamasta palomuuria ja antivirus softa, loistavaa. Kerrohan minulle kuinka tuossa onnistuit? Olisko näin: Formatoit koneesi ja annoit sen olla nettiin yhteydessä kun windows asennettiin uudelleen. Pidit nettiä vaan päällä ja hait kaikkia muita ohjelmia paitsi palomuuri ja antivirus unohtui asentaa? Sait örkin ja huomasit että et saakkaan enään tietoturva ohjelmia? Meniö jotenkin näin? Tässä tälläinen yksinkertainen ohje puhdistamiseen. Fixaa: Avaa Hijackthis -> Do a system scan only -> Merkkaa -> Paina fix cheked. O1 - Hosts: 64.233.167.104 www.symantec.com O1 - Hosts: 64.233.167.104 www.sophos.com O1 - Hosts: 64.233.167.104 www.mcafee.com O1 - Hosts: 64.233.167.104 www.viruslist.com O1 - Hosts: 64.233.167.104 www.f-secure.com O1 - Hosts: 64.233.167.104 www.avp.com O1 - Hosts: 64.233.167.104 www.kaspersky.com O1 - Hosts: 64.233.167.104 www.networkassociates.com O1 - Hosts: 64.233.167.104 www.ca.com O1 - Hosts: 64.233.167.104 www.my-etrust.com O1 - Hosts: 64.233.167.104 www.nai.com O1 - Hosts: 64.233.167.104 www.trendmicro.com O1 - Hosts: 64.233.167.104 www.grisoft.com O1 - Hosts: 64.233.167.104 securityresponse.symantec.com O1 - Hosts: 64.233.167.104 symantec.com O1 - Hosts: 64.233.167.104 sophos.com O1 - Hosts: 64.233.167.104 mcafee.com O1 - Hosts: 64.233.167.104 liveupdate.symantecliveupdate.com O1 - Hosts: 64.233.167.104 viruslist.com O1 - Hosts: 64.233.167.104 f-secure.com O1 - Hosts: 64.233.167.104 kaspersky.com O1 - Hosts: 64.233.167.104 kaspersky-labs.com O1 - Hosts: 64.233.167.104 avp.com O1 - Hosts: 64.233.167.104 networkassociates.com O1 - Hosts: 64.233.167.104 ca.com O1 - Hosts: 64.233.167.104 mast.mcafee.com O1 - Hosts: 64.233.167.104 my-etrust.com O1 - Hosts: 64.233.167.104 download.mcafee.com O1 - Hosts: 64.233.167.104 dispatch.mcafee.com O1 - Hosts: 64.233.167.104 secure.nai.com O1 - Hosts: 64.233.167.104 nai.com O1 - Hosts: 64.233.167.104 update.symantec.com O1 - Hosts: 64.233.167.104 updates.symantec.com O1 - Hosts: 64.233.167.104 us.mcafee.com O1 - Hosts: 64.233.167.104 liveupdate.symantec.com O1 - Hosts: 64.233.167.104 customer.symantec.com O1 - Hosts: 64.233.167.104 rads.mcafee.com O1 - Hosts: 64.233.167.104 trendmicro.com O1 - Hosts: 64.233.167.104 grisoft.com O1 - Hosts: 64.233.167.104 sandbox.norman.no O1 - Hosts: 64.233.167.104 www.pandasoftware.com O1 - Hosts: 64.233.167.104 uk.trendmicro-europe.com O4 - HKLM\..\Run: [serpe] C:\WINDOWS\System32\serbw.exe O4 - HKLM\..\Run: [ltwob] C:\WINDOWS\System32\formatsys.exe O4 - HKLM\..\Run: [avnort] C:\WINDOWS\msmbw.exe O4 - HKLM\..\RunServices: [serpe] C:\WINDOWS\System32\serbw.exe O4 - HKLM\..\RunServices: [ltwob] C:\WINDOWS\System32\formatsys.exe O4 - HKLM\..\RunServices: [avnort] C:\WINDOWS\msmbw.exe O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll -----------> Laita piilotiedostot näkyviin: http://keskustelu.afterdawn.com/thread_view.cfm/248944 <<<<<<<<<<<<<<<<<<Vikasietotila>>>>>>>>>>>>>>>>> Naputtele F8 koneen käynnistyksen yhteydessä ja valitse vikasietotila Poista käsin: C:\WINDOWS\System32\-->serbw.exe<-- C:\WINDOWS\System32\-->formatsys.exe<-- C:\WINDOWS\-->msmbw.exe<-- Palaa normaalitilaan: Hae eScan -> http://koti.mbnet.fi/pattaya1/escanmwav.htm Päivitä ohjeiden mukaan ja lähetä sen alalaatikon tulokset tänne uuden hjt lokin kera! Onko seuraavat sinun asentamia ohjelmia? VoipCheap VoipStunt