Here we go again! Mopo tuhannen sekasin, apua tarvitaan! (hijackthis-loki)

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by ScanPC, Jun 11, 2008.

  1. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    Pokerstrategy, troijalainen, msn-virus. Nähtävästi löytyy myös emännän työkoneesta, kiitoksia etukäteen avustanne!

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:05:07, on 12.6.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\OneStepSearch\onestep.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\Program Files\OneStepSearch\onestep.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\winudpmr.exe
    C:\WINDOWS\winudmr.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\svho.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O3 - Toolbar: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - (no file)
    O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [Windows svchost] ups.exe
    O4 - HKLM\..\Run: [Windows Control Center] winudpmr.exe
    O4 - HKLM\..\Run: [Windows Controls Center] winudmr.exe
    O4 - HKLM\..\Run: [System Service Manager Device] svho.exe
    O4 - HKLM\..\Run: [BM235979bc] Rundll32.exe "C:\WINDOWS\system32\gcasigly.dll",s
    O4 - HKLM\..\Run: [206a4a20] rundll32.exe "C:\WINDOWS\system32\idcewcgh.dll",b
    O4 - HKLM\..\RunServices: [Microsoft] wplayer.exe
    O4 - HKLM\..\RunServices: [System Service Manager Device] svho.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-21-1275210071-688789844-839522115-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-21-1275210071-688789844-839522115-1007\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent (User '?')
    O4 - HKUS\S-1-5-21-1275210071-688789844-839522115-1007\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: BetOnBet Poker - {2B936D2B-EDD7-405f-9057-3685BE897E62} - C:\Program Files\betonbetMPP\MPPoker.exe
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL
    O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O22 - SharedTaskScheduler: Reload Browse - {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} - (no file)
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automaattinen LiveUpdate-ajastustoiminto - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: OneStep Search Service - OneStepSearch.net, Inc. - C:\Program Files\OneStepSearch\onestep.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

    --
    End of file - 9069 bytes

    COMBOFIXUN LOGI

    ComboFix 08-06-10.3 - OJ 2008-06-12 2:24:44.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.184 [GMT 3:00]
    Running from: C:\Documents and Settings\OJ\Työpöytä\VIRUSTOOLS\ComboFix.exe
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\Ofb1
    C:\Program Files\Ofb1\Ofb1.dll
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\service.exe
    C:\WINDOWS\system32\aglsxayn.dll
    C:\WINDOWS\system32\awtrQJAt.dll
    C:\WINDOWS\system32\awtttuUn.dll
    C:\WINDOWS\system32\badqiufy.dll
    C:\WINDOWS\system32\bmigpduy.dll
    C:\WINDOWS\system32\byXOeDSK.dll
    C:\WINDOWS\system32\ddcYqrPG.dll
    C:\WINDOWS\system32\efcCrSlJ.dll
    C:\WINDOWS\system32\eoihvmnr.ini
    C:\WINDOWS\system32\eolvsoxp.dll
    C:\WINDOWS\system32\eqscbeao.ini
    C:\WINDOWS\system32\famivtct.ini
    C:\WINDOWS\system32\fccbAQki.dll
    C:\WINDOWS\system32\fchwykog.ini
    C:\WINDOWS\system32\fphufthv.dll
    C:\WINDOWS\system32\fxyrfood.dll
    C:\WINDOWS\system32\gcasigly.dll
    C:\WINDOWS\system32\gshelscn.dll
    C:\WINDOWS\system32\hgcwecdi.ini
    C:\WINDOWS\system32\hgGvuTMD.dll
    C:\WINDOWS\system32\htmojwic.ini
    C:\WINDOWS\system32\idcewcgh.dll
    C:\WINDOWS\system32\jempbgvg.dll
    C:\WINDOWS\system32\jkkIXqoo.dll
    C:\WINDOWS\system32\jxbnxuld.ini
    C:\WINDOWS\system32\khfDuSkL.dll
    C:\WINDOWS\system32\kvtklofi.ini
    C:\WINDOWS\system32\ljJCsrSi.dll
    C:\WINDOWS\system32\ljJCtsqp.dll
    C:\WINDOWS\system32\ljJDSLCs.dll
    C:\WINDOWS\system32\ljJYOghF.dll
    C:\WINDOWS\system32\ltkkbgli.dll
    C:\WINDOWS\system32\mbiiaqkd.dll
    C:\WINDOWS\system32\mbwaxhon.ini
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\mipnyjiy.ini
    C:\WINDOWS\system32\mlJApMgH.dll
    C:\WINDOWS\system32\MSINET.oca
    C:\WINDOWS\system32\ombcweln.dll
    C:\WINDOWS\system32\opedxksd.dll
    C:\WINDOWS\system32\pelruenh.ini
    C:\WINDOWS\system32\pmnmjIBT.dll
    C:\WINDOWS\system32\pqstCJjl.ini
    C:\WINDOWS\system32\pqstCJjl.ini2
    C:\WINDOWS\system32\qiibndgg.dll
    C:\WINDOWS\system32\qpykbgpb.dll
    C:\WINDOWS\system32\sskkceoa.dll
    C:\WINDOWS\system32\tuvTjKCs.dll
    C:\WINDOWS\system32\ukhoutgs.ini
    C:\WINDOWS\system32\urqOIbAr.dll
    C:\WINDOWS\system32\urqPgeBS.dll
    C:\WINDOWS\system32\vcppgsal.dll
    C:\WINDOWS\system32\vdkplrmb.ini
    C:\WINDOWS\system32\vfhgcrjp.dll
    C:\WINDOWS\system32\wshsymnf.ini
    C:\WINDOWS\system32\wvUnOIBs.dll
    C:\WINDOWS\system32\xdcuwjim.ini
    C:\WINDOWS\system32\yaywuuUL.dll
    C:\WINDOWS\system32\yayxwXpo.dll
    C:\WINDOWS\system32\ydnepfqi.ini
    C:\WINDOWS\system32\ygcpnpdi.dll
    C:\WINDOWS\system32\yoybkxji.dll
    C:\WINDOWS\ups.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_XPROTECTOR
    -------\Service_XPROTECTOR


    ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-11 to 2008-06-11 )))))))))))))))))
    .

    2008-06-12 02:04 . 2008-06-12 02:04 <KANSIO> d-------- C:\Program Files\Trend Micro
    2008-06-11 13:44 . 2008-06-11 13:44 2,231 --a------ C:\is155815.exe
    2008-06-08 23:10 . 2008-06-09 17:31 29,342 --a------ C:\Documents and Settings\OJ\ps.exe
    2008-06-08 23:08 . 2008-06-08 23:08 29,342 -r-hs---- C:\WINDOWS\winudmr.exe
    2008-06-08 23:04 . 2008-06-08 23:04 29,339 -r-hs---- C:\WINDOWS\winudpmr.exe
    2008-06-08 22:21 . 2008-06-08 22:21 18,587 --a------ C:\Documents and Settings\OJ\packed.exe
    2008-06-06 15:03 . 2008-06-06 20:39 49,156 --a------ C:\Documents and Settings\OJ\sz.exe
    2008-06-06 14:48 . 2008-06-06 14:48 2,231 --a------ C:\Documents and Settings\OJ\sex2.exe
    2008-06-06 00:38 . 2008-06-06 01:14 49,156 --a------ C:\Documents and Settings\OJ\fs.exe
    2008-06-06 00:15 . 2008-06-06 00:16 49,156 --a------ C:\Documents and Settings\OJ\f.exe
    2008-06-05 01:32 . 2008-06-05 01:32 <KANSIO> d-------- C:\VundoFix Backups
    2008-06-05 00:15 . 2008-06-05 00:15 290,110 --a------ C:\WINDOWS\ftp.exe
    2008-06-04 22:00 . 2008-06-04 22:00 86,528 --a------ C:\Documents and Settings\OJ\stp.exe
    2008-06-03 18:36 . 2008-06-03 23:24 86,548 --a------ C:\Documents and Settings\OJ\setupa.exe
    2008-06-03 01:01 . 2008-06-03 01:01 104,078 --a------ C:\WINDOWS\sb.exe
    2008-06-02 22:29 . 2008-06-02 22:29 97,116 --a------ C:\WINDOWS\DC5177176.zip
    2008-06-02 21:35 . 2008-06-04 16:03 3,424 --a------ C:\Documents and Settings\OJ\setup.exe
    2008-06-02 11:52 . 2008-06-03 19:54 4,217 --a------ C:\WINDOWS\is154890.exe
    2008-05-30 23:49 . 2008-03-06 21:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
    2008-05-30 23:49 . 2008-03-06 21:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
    2008-05-30 23:49 . 2008-03-06 21:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
    2008-05-30 12:24 . 2008-06-09 23:38 117 --a------ C:\WINDOWS\BM235979bc.xml
    2008-05-29 23:03 . 2008-05-29 23:03 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\pixelStorm
    2008-05-29 20:31 . 2008-05-29 20:31 249,496 --a------ C:\Documents and Settings\OJ\sexy.exe
    2008-05-29 20:16 . 2008-05-29 20:25 249,496 --a------ C:\Documents and Settings\OJ\exy.exe
    2008-05-24 12:33 . 2008-05-24 12:33 <KANSIO> d-------- C:\Program Files\Common Files\xing shared
    2008-05-22 16:46 . 2008-05-22 16:46 <KANSIO> d-------- C:\Program Files\Ubisoft

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-06-11 10:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-06-09 17:27 --------- d-----w C:\Program Files\mIRC
    2008-06-09 09:19 --------- d-----w C:\Documents and Settings\OJ\Application Data\LimeWire
    2008-06-01 23:00 --------- d-----w C:\Program Files\Opera
    2008-05-31 14:39 --------- d-----w C:\Documents and Settings\OJ\Application Data\uTorrent
    2008-05-30 20:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-05-30 20:42 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
    2008-05-30 20:42 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
    2008-05-30 20:42 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
    2008-05-30 20:42 --------- d-----w C:\Program Files\Symantec
    2008-05-29 19:21 --------- d-----w C:\Program Files\OneStepSearch
    2008-05-28 13:52 --------- d-----w C:\Documents and Settings\OJ\Application Data\OpenOffice.org2
    2008-05-24 09:33 --------- d-----w C:\Program Files\Common Files\Real
    2008-05-22 13:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-05-10 17:09 --------- d-----w C:\Program Files\ESBC Moniveto
    2008-04-24 13:45 --------- d-----w C:\Program Files\The Creative Assembly
    2008-04-12 10:28 --------- d-----w C:\Program Files\EA SPORTS
    2006-11-30 21:12 6,144 -csha-w C:\Program Files\Thumbs.db
    2007-06-13 13:22 115,215 --sh--r C:\WINDOWS\system32\svho.exe
    2007-06-13 13:22 290,110 --sh--r C:\WINDOWS\system32\wplayer.exe
    .

    (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
    "Windows svchost"="ups.exe" [2004-09-14 16:12 18432 C:\WINDOWS\system32\ups.exe]
    "Windows Control Center"="winudpmr.exe" [2008-06-08 23:04 29339 C:\WINDOWS\winudpmr.exe]
    "Windows Controls Center"="winudmr.exe" [2008-06-08 23:08 29342 C:\WINDOWS\winudmr.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
    "ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-13 16:00 100032]
    "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "AllowLegacyWebView"= 1 (0x1)
    "AllowUnhashedWebView"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.3iv2"= 3ivxVfWCodec.dll
    "VIDC.HFYU"= huffyuv.dll
    "VIDC.VP31"= vp31vfw.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
    "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
    "C:\\Program Files\\Soulseek\\slsk.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\a1e183f05652bdbca0e57d93311bbf60\\day of defeat source\\hl2.exe"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "D:\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\Java\\jre1.5.0_10\\bin\\javaw.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\Program Files\\mIRC\\mirc.exe"=
    "C:\\Program Files\\Parbet.com Poker\\UA.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
    "C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
    "C:\\Program Files\\DNA\\btdna.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
    "C:\\Program Files\\Empire Interactive\\FlatOut2\\FlatOut2.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "21618:TCP"= 21618:TCP:BitComet 21618 TCP
    "21618:UDP"= 21618:UDP:BitComet 21618 UDP

    R2 OneStep Search Service;OneStep Search Service;"C:\Program Files\OneStepSearch\onestep.exe" "C:\Program Files\OneStepSearch\onestep.dll" Service []
    R3 SMC55T;SMC EZ Card 10/100 (SMC1255TX-PF);C:\WINDOWS\system32\DRIVERS\SMC55T51.sys [2002-07-05 16:31]
    S2 Automaattinen LiveUpdate-ajastustoiminto;Automaattinen LiveUpdate-ajastustoiminto;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-09-13 16:00]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b217703-933f-11db-93a5-0004e2432a1b}]
    \shell\play\Command - "C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9b1e83c2-7d3f-11db-937b-0004e2432a1b}]
    \Shell\AutoRun\command - G:\LaunchU3.exe -a

    .
    'Ajoitetut teht„v„t'-kansion sis„lt”
    "2008-06-06 17:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Suorita täyd. järj.tarkistus - OJ.job"
     
    Last edited: Jun 11, 2008
  2. Hujo

    Hujo Guest

    Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:

    Tallenna se nimellä CFScript.txt

    Sitten raahaa CFScript ComboFix.exeen kuten alla.
    [​IMG]

    Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.

    =============

    scannaa hjt:llä merkkaa paina Fix checked

    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O3 - Toolbar: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - (no file)
    O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O4 - HKLM\..\Run: [Windows svchost] ups.exe
    O4 - HKLM\..\Run: [Windows Control Center] winudpmr.exe
    O4 - HKLM\..\Run: [Windows Controls Center] winudmr.exe
    O4 - HKLM\..\Run: [System Service Manager Device] svho.exe
    O4 - HKLM\..\Run: [BM235979bc] Rundll32.exe "C:\WINDOWS\system32\gcasigly.dll",s
    O4 - HKLM\..\Run: [206a4a20] rundll32.exe "C:\WINDOWS\system32\idcewcgh.dll",b
    O4 - HKLM\..\RunServices: [Microsoft] wplayer.exe
    O4 - HKLM\..\RunServices: [System Service Manager Device] svho.exe
    O22 - SharedTaskScheduler: Reload Browse - {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} - (no file
    )

    ====================

    Lataa Malwarebytes' Anti-Malware työpöydällesi.

    1. Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman.
    2. Lopuksi varmistu, että seuraavat on valittu: Update Malwarebytes', Anti-Malwareja
    Launch Malwarebytes' Anti-Malware ja sen jälkeen klikkaaFinish.
    3. Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version.
    4. Kun ohjelma on latautunut, valitse Perform full scan ja klikkaa Scan.
    5. Kun skanni on valmis, klikkaa OK ja sitten Show Results nähdäksesi tulokset.
    6. Varmistu, että kaikki on merkitty ja klikkaa Remove Selected.
    7. Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki
    löytyy myös täältä: C:\Documents and Settings\Käyttäjänimi\Application
    Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt
    8. Lähetä lokin sisältö seuraavassa viestissäsi.


     
  3. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    Joo ajoin ton hijackthis:n scannin, ja seuraavat puuttu fixattavien listalta:

    O4 - HKLM\..\Run: [System Service Manager Device] svho.exe
    O4 - HKLM\..\Run: [BM235979bc] Rundll32.exe "C:\WINDOWS\system32\gcasigly.dll",s
    O4 - HKLM\..\Run: [206a4a20] rundll32.exe "C:\WINDOWS\system32\idcewcgh.dll",b
    O4 - HKLM\..\RunServices: [Microsoft] wplayer.exe
    O4 - HKLM\..\RunServices: [System Service Manager Device] svho.exe

    tässä loki:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:45:08, on 12.6.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\OneStepSearch\onestep.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\OneStepSearch\onestep.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
    O3 - Toolbar: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - (no file)
    O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [Windows svchost] ups.exe
    O4 - HKLM\..\Run: [Windows Control Center] winudpmr.exe
    O4 - HKLM\..\Run: [Windows Controls Center] winudmr.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: BetOnBet Poker - {2B936D2B-EDD7-405f-9057-3685BE897E62} - C:\Program Files\betonbetMPP\MPPoker.exe
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL
    O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O22 - SharedTaskScheduler: Reload Browse - {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} - (no file)
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automaattinen LiveUpdate-ajastustoiminto - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: OneStep Search Service - OneStepSearch.net, Inc. - C:\Program Files\OneStepSearch\onestep.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

    --
    End of file - 8916 bytes

    Fixataanko ne jotka löyty ja jatketaan Malwareen, vai mitä teemme?
     
  4. Hujo

    Hujo Guest

    scannaa combofix uudelleen
     
  5. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    tuon CFScriptin kera?
     
  6. Hujo

    Hujo Guest

    ihan vaan pelkästään uusi combofix ajo
     
  7. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    Loki uuden ajon jälkeen

    ComboFix 08-06-10.3 - OJ 2008-06-12 14:13:30.3 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.195 [GMT 3:00]
    Running from: C:\Documents and Settings\OJ\Työpöytä\VIRUSTOOLS\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-12 to 2008-06-12 )))))))))))))))))
    .

    2008-06-12 13:03 . 2008-06-12 13:03 <KANSIO> d-------- C:\Documents and Settings\OJ\Application Data\Malwarebytes
    2008-06-12 13:02 . 2008-06-12 13:02 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-06-12 13:02 . 2008-06-12 13:02 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-06-12 13:02 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
    2008-06-12 13:02 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-06-12 02:04 . 2008-06-12 02:04 <KANSIO> d-------- C:\Program Files\Trend Micro
    2008-06-08 22:21 . 2008-06-08 22:21 18,587 --a------ C:\Documents and Settings\OJ\packed.exe
    2008-06-05 00:15 . 2008-06-05 00:15 290,110 --a------ C:\WINDOWS\ftp.exe
    2008-05-30 23:49 . 2008-03-06 21:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
    2008-05-30 23:49 . 2008-03-06 21:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
    2008-05-30 23:49 . 2008-03-06 21:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
    2008-05-30 12:24 . 2008-06-09 23:38 117 --a------ C:\WINDOWS\BM235979bc.xml
    2008-05-29 23:03 . 2008-05-29 23:03 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\pixelStorm
    2008-05-24 12:33 . 2008-05-24 12:33 <KANSIO> d-------- C:\Program Files\Common Files\xing shared
    2008-05-22 16:46 . 2008-05-22 16:46 <KANSIO> d-------- C:\Program Files\Ubisoft

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-06-11 10:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-06-09 17:27 --------- d-----w C:\Program Files\mIRC
    2008-06-09 09:19 --------- d-----w C:\Documents and Settings\OJ\Application Data\LimeWire
    2008-06-01 23:00 --------- d-----w C:\Program Files\Opera
    2008-05-31 14:39 --------- d-----w C:\Documents and Settings\OJ\Application Data\uTorrent
    2008-05-30 20:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-05-30 20:42 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
    2008-05-30 20:42 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
    2008-05-30 20:42 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
    2008-05-30 20:42 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
    2008-05-30 20:42 --------- d-----w C:\Program Files\Symantec
    2008-05-29 19:21 --------- d-----w C:\Program Files\OneStepSearch
    2008-05-28 13:52 --------- d-----w C:\Documents and Settings\OJ\Application Data\OpenOffice.org2
    2008-05-24 09:33 --------- d-----w C:\Program Files\Common Files\Real
    2008-05-22 13:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-05-10 17:09 --------- d-----w C:\Program Files\ESBC Moniveto
    2008-04-24 13:45 --------- d-----w C:\Program Files\The Creative Assembly
    2008-04-12 10:28 --------- d-----w C:\Program Files\EA SPORTS
    2008-03-26 20:24 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
    2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-03-19 17:48 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
    2008-03-18 16:06 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
    2006-11-30 21:12 6,144 -csha-w C:\Program Files\Thumbs.db
    .

    ((((((((((((((((((((((((((((( snapshot@2008-06-12_ 2.53.11.37 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-06-11 23:37:48 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-06-12 10:41:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    .
    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
    "Windows svchost"="ups.exe" [2004-09-14 16:12 18432 C:\WINDOWS\system32\ups.exe]
    "Windows Control Center"="winudpmr.exe" []
    "Windows Controls Center"="winudmr.exe" []

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
    "ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-13 16:00 100032]
    "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "AllowLegacyWebView"= 1 (0x1)
    "AllowUnhashedWebView"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.3iv2"= 3ivxVfWCodec.dll
    "VIDC.HFYU"= huffyuv.dll
    "VIDC.VP31"= vp31vfw.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
    "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
    "C:\\Program Files\\Soulseek\\slsk.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\a1e183f05652bdbca0e57d93311bbf60\\day of defeat source\\hl2.exe"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "D:\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\Java\\jre1.5.0_10\\bin\\javaw.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\Program Files\\mIRC\\mirc.exe"=
    "C:\\Program Files\\Parbet.com Poker\\UA.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
    "C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
    "C:\\Program Files\\DNA\\btdna.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
    "C:\\Program Files\\Empire Interactive\\FlatOut2\\FlatOut2.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "21618:TCP"= 21618:TCP:BitComet 21618 TCP
    "21618:UDP"= 21618:UDP:BitComet 21618 UDP

    R2 Automaattinen LiveUpdate-ajastustoiminto;Automaattinen LiveUpdate-ajastustoiminto;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-09-13 16:00]
    R2 OneStep Search Service;OneStep Search Service;"C:\Program Files\OneStepSearch\onestep.exe" "C:\Program Files\OneStepSearch\onestep.dll" Service []
    R3 SMC55T;SMC EZ Card 10/100 (SMC1255TX-PF);C:\WINDOWS\system32\DRIVERS\SMC55T51.sys [2002-07-05 16:31]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b217703-933f-11db-93a5-0004e2432a1b}]
    \shell\play\Command - "C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9b1e83c2-7d3f-11db-937b-0004e2432a1b}]
    \Shell\AutoRun\command - G:\LaunchU3.exe -a

    .
    'Ajoitetut tehtävät'-kansion sisältö
    "2008-06-06 17:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Suorita täyd. järj.tarkistus - OJ.job"
    - C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-12 14:18:02
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-06-12 14:21:19
    ComboFix-quarantined-files.txt 2008-06-12 11:20:29
    ComboFix2.txt 2008-06-12 09:13:58

    Pre-Run: 2,783,539,200 tavua vapaana
    Post-Run: 2,771,689,472 tavua vapaana

    138 --- E O F --- 2008-05-16 15:02:54

    Jatketaanko tuolla Hijackthis:n Fixcheckedillä?
     
  8. Hujo

    Hujo Guest

    scannaa hjt:llä merkkaa paina Fix checked

    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O3 - Toolbar: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - (no file)
    O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O4 - HKLM\..\Run: [Windows svchost] ups.exe
    O4 - HKLM\..\Run: [Windows Control Center] winudpmr.exe
    O4 - HKLM\..\Run: [Windows Controls Center] winudmr.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O22 - SharedTaskScheduler: Reload Browse - {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} - (no file)


    =================

    Lataa SmitfraudFix (c) S!Ri
    Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:

    Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
    Postita ponnahtava rapport – muistion sisältö viestiketjuusi.
    Löytyy myös C:\rapport.txt

    Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat
    (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja.
    A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä,
    silloin ne saattavat varoittaa käyttäjää.

     
  9. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    SmitFraudFix v2.323

    Scan done at 14:46:02,28, to 12.06.2008
    Run from C:\Documents and Settings\OJ\Ty”p”yt„\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\OneStepSearch\onestep.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\OneStepSearch\onestep.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\cmd.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\ot.ico FOUND !
    C:\WINDOWS\system32\1024\ FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\OJ


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\OJ\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\O~1\Suosikit


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Nykyinen kotisivu"


    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, following keys are not inevitably infected!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, following keys are not inevitably infected!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, following keys are not inevitably infected!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Rustock



    »»»»»»»»»»»»»»»»»»»»»»»» DNS



    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End
     
  10. Hujo

    Hujo Guest

    Printtaa ohjeet ulos

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi.

    Vikasietotilaan:

    sammuta ja käynnistä
    käynnistyksen yhteydessä hakkaa F8 nappia
    valitse nuolinäppäimellä vikasietotila
    paina enter ja enter
    valitse käyttäjätilisi
    paina kyllä

    Jossakin koneissa hakataan F8:sin sijasta F5:tä

    Kun vikasietotilassa, avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.

    Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.

    Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".

    Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
    Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
    Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt.

    Varoitus : Ajamalla optio 2:n EI-tarttuneessa tietokoneessa, poistaa sinun työpöytäsi taustakuvan.

    ===================

    aja Malwarebytes' Anti-Malware
     
  11. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    SmitFraudFix v2.323

    Scan done at 15:08:18,57, to 12.06.2008
    Run from C:\Documents and Settings\OJ\Ty”p”yt„\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

    S!Ri's WS2Fix: LSP not Found.


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\WINDOWS\system32\ot.ico Deleted
    C:\WINDOWS\system32\1024\ Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» DNS



    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

    malware

    Malwarebytes' Anti-Malware 1.17
    Tietokantaversio: 846

    16:42:56 12.6.2008
    mbam-log-6-12-2008 (16-42-56).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
    Tarkistetut kohteet: 193571
    Kulunut aika: 1 hour(s), 10 minute(s), 26 second(s)

    Saastuneita muistiprosesseja: 2
    Saastuneita muistimoduuleja: 1
    Saastuneita rekisteriavaimia: 11
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 8
    Saastuneita tiedostoja: 303

    Saastuneita muistiprosesseja:
    C:\Program Files\OneStepSearch\onestep.exe (Adware.OneStepSearch) -> Unloaded process successfully.
    C:\Program Files\OneStepSearch\onestep.exe (Adware.OneStepSearch) -> Unloaded process successfully.

    Saastuneita muistimoduuleja:
    C:\Program Files\OneStepSearch\onestep.dll (Adware.OneStepSearch) -> Unloaded module successfully.

    Saastuneita rekisteriavaimia:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5b4c3b43-49b6-42a7-a602-f7acdca0d409} (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5b4c3b43-49b6-42a7-a602-f7acdca0d409} (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\onestepsearch (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\OneStepSearch (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OneStep Search Service (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneStepSearch (Adware.OneStepSearch) -> Quarantined and deleted successfully.

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    C:\Casino (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\logs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\promo (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\sfx (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Program Files\OneStepSearch (Adware.OneStepSearch) -> Delete on reboot.

    Saastuneita tiedostoja:
    C:\QooBox\Quarantine\C\Documents and Settings\Oskari Jaakonaho\exy.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Documents and Settings\Oskari Jaakonaho\sexy.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\efcCrSlJ.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\fccbAQki.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\gshelscn.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\idcewcgh.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\jkkIXqoo.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\ltkkbgli.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\urqPgeBS.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\wvUnOIBs.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\yaywuuUL.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\yayxwXpo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe (Backdoor.Bot) -> Delete on reboot.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1080\A0212385.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1080\A0212397.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1081\A0215514.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1082\A0216537.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1082\A0216538.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1083\A0217556.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1087\A0217703.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1087\A0217704.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1087\A0217705.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1087\A0217706.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1087\A0217707.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1087\A0217708.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1087\A0217709.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1090\A0218567.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1090\A0218569.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1090\A0218570.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1091\A0219551.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1091\A0219552.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1091\A0219553.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1092\A0219581.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1092\A0219582.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1092\A0219583.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1093\A0219608.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1093\A0219609.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1093\A0219610.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1094\A0219697.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1094\A0219728.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1094\A0219730.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1094\A0219731.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1095\A0219750.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1095\A0219765.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1095\A0219778.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1098\A0221750.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222537.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222539.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222543.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222545.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222547.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222553.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222564.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222567.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222568.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222569.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1101\A0222605.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1102\A0222643.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1102\A0222650.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1102\A0222669.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{C9F85A73-4EAC-41BF-B177-A8A9B17AA3AF}\RP1102\A0222720.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\blackjack.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\browser.exe (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\cacerts.crt (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\cam.cas (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\cardlib.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\common.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\db.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\devlib.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\devlibcomm.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\filemap.lst (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\fivecard.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\games.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\gsid.txt (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\id.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\INSTALL.LOG (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\languages.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\libeay32.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\licens.txt (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\mfc80.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\microsoft.vc80.crt.manifest (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\microsoft.vc80.mfc.manifest (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\modstatus.lst (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\mp3dec.asi (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\mss32.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\msvcp80.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\msvcr80.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\navigator.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\omaha.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\options.cfg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\poker.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\poker.exe (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\sc.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\srvmap.lst (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\ssleay32.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\texas.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\UNWISE.EXE (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\update.exe (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\webdollar.exe (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xml.dll (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\0.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\1.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\10.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\11.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\12.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\13.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\14.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\15.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\16.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\17.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\18.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\19.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\2.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\20.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\21.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\22.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\23.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\24.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\25.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\26.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\27.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\28.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\29.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\3.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\30.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\31.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\32.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\33.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\34.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\35.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\36.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\37.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\38.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\39.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\4.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\40.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\41.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\42.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\43.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\44.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\45.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\46.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\47.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\48.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\49.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\5.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\50.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\51.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\6.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\7.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\8.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\9.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\allin_popup.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\archive.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\archive_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\avatar.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\b.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\base.css (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\bj_bkg.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\bkg.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\browserdetect.js (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_blackjack.png (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_close.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_filters_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_filters_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_game.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_general.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_join.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_main.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_medium.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_minmax.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_sublevels_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\but_sublevels_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\caret.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\chatbubble.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\chips.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\decktype_settings.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\edit.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\gamelimits1.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\gamelimits2.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\gamelimits3.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\game_bjframe.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\game_blackjack.png (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\game_summary.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\gre_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\hand.html (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\hand.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\hand_cursor.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\hand_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\harrow.cur (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\headers_bkg.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\headers_text.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\history.html (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\history.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\history_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\input_additional.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\input_boxes.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\input_lists.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\language.xml (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\language.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\languages.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\language_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\main.js (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\main_bkg.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\main_listhi.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\navigator_bg.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\navigator_buttons.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\navigator_moneytext.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\navigator_timer.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_bottom.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_game_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_game_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_game_top.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_left.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_medium.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_moretables.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_texts.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\panel_top.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\pointer.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_cardback.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_cards.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_cards_4c.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_cards_large.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_cards_large_4c.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_deckside.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_font_11p_bold.xbf (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_makechoice.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\poker_pucks.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\pol_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\popups.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\position_actions.png (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\position_active.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\position_inactive.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\position_mute.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\position_note.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\position_numbers.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\progress_ani.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\promo-test1.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\rus_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\sc_bkg8.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\tabs_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\tabs_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\tab_casino.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\text.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\timeslider.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\tur_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\tx_bkg10.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\tx_bkg5.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\user.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\user_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\white_line.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\win_graphics.bmp (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\xml.gif (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\data\xml_decoder.js (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\promo\PHHelsinki.jpg (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\sfx\c_button.wav (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\sfx\c_chip.wav (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\sfx\c_deal.mp3 (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\sfx\p_alert.wav (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\sfx\p_checkknock.wav (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\blackjack_game_panel.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\blackjack_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\common.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\ext_clientspecific.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\ext_game.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\ext_general.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\ext_mc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\ext_navigator.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\fcs_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\fc_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\fc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\filemap.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\filerefs.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\gameclient.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\game_common.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\game_common_message.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\game_panel.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\gizmo.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\mc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\message.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\mtt_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\mtt_lobby.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\navigator.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\omaha_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\omaha_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\optdef.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\poker_limits.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\sc_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\sc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\soko_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\tel_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\texas_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\texas_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Casino\Poker Heaven\xrs\tournament_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
    C:\Program Files\OneStepSearch\home.js (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    C:\Program Files\OneStepSearch\onestep.dll (Adware.OneStepSearch) -> Delete on reboot.
    C:\Program Files\OneStepSearch\onestep.exe (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    C:\Program Files\OneStepSearch\osopt.exe (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    C:\Program Files\OneStepSearch\readme.html (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    C:\Program Files\OneStepSearch\uninstall.exe (Adware.OneStepSearch) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

     
  12. Hujo

    Hujo Guest

    1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
    2. Valitse ominaisuudet
    3. Valitse järjestelmän palauttaminen välilehti
    4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
    5. Paina Käytä
    6. Paina ok
    7. Sammuta ja käynnistä
    8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
    9. Käytä ja OK
     
  13. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    Okei. Mitäs sen jälkeen?
     
  14. Hujo

    Hujo Guest

    scannaa uusi combofix loki
    scannaa uusi Malwarebytes' Anti-Malware loki
    viimisenä uusi hjt:n loki
     
  15. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    ComboFix 08-06-10.3 - OJ 2008-06-12 17:27:53.4 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.169 [GMT 3:00]
    Running from: C:\Documents and Settings\OJ\Työpöytä\VIRUSTOOLS\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-12 to 2008-06-12 )))))))))))))))))
    .

    2008-06-12 14:46 . 2008-06-12 15:08 1,282 --a------ C:\WINDOWS\system32\tmp.reg
    2008-06-12 13:03 . 2008-06-12 13:03 <KANSIO> d-------- C:\Documents and Settings\OJ\Application Data\Malwarebytes
    2008-06-12 13:02 . 2008-06-12 13:02 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-06-12 13:02 . 2008-06-12 13:02 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-06-12 13:02 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
    2008-06-12 13:02 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-06-12 02:04 . 2008-06-12 02:04 <KANSIO> d-------- C:\Program Files\Trend Micro
    2008-06-08 22:21 . 2008-06-08 22:21 18,587 --a------ C:\Documents and Settings\OJ\packed.exe
    2008-06-05 00:15 . 2008-06-05 00:15 290,110 --a------ C:\WINDOWS\ftp.exe
    2008-05-30 23:49 . 2008-03-06 21:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
    2008-05-30 23:49 . 2008-03-06 21:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
    2008-05-30 23:49 . 2008-03-06 21:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
    2008-05-30 12:24 . 2008-06-09 23:38 117 --a------ C:\WINDOWS\BM235979bc.xml
    2008-05-29 23:03 . 2008-05-29 23:03 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\pixelStorm
    2008-05-24 12:33 . 2008-05-24 12:33 <KANSIO> d-------- C:\Program Files\Common Files\xing shared
    2008-05-22 16:46 . 2008-05-22 16:46 <KANSIO> d-------- C:\Program Files\Ubisoft

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-06-11 10:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-06-09 17:27 --------- d-----w C:\Program Files\mIRC
    2008-06-09 09:19 --------- d-----w C:\Documents and Settings\OJ\Application Data\LimeWire
    2008-06-01 23:00 --------- d-----w C:\Program Files\Opera
    2008-05-31 14:39 --------- d-----w C:\Documents and Settings\OJ\Application Data\uTorrent
    2008-05-30 20:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-05-30 20:42 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
    2008-05-30 20:42 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
    2008-05-30 20:42 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
    2008-05-30 20:42 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
    2008-05-30 20:42 --------- d-----w C:\Program Files\Symantec
    2008-05-28 13:52 --------- d-----w C:\Documents and Settings\OJ\Application Data\OpenOffice.org2
    2008-05-24 09:33 --------- d-----w C:\Program Files\Common Files\Real
    2008-05-22 13:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-05-10 17:09 --------- d-----w C:\Program Files\ESBC Moniveto
    2008-04-24 13:45 --------- d-----w C:\Program Files\The Creative Assembly
    2008-04-12 10:28 --------- d-----w C:\Program Files\EA SPORTS
    2008-03-26 20:24 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
    2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-03-19 17:48 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
    2008-03-18 16:06 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
    2006-11-30 21:12 6,144 -csha-w C:\Program Files\Thumbs.db
    .

    ((((((((((((((((((((((((((((( snapshot@2008-06-12_ 2.53.11.37 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-06-11 23:37:48 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-06-12 14:20:47 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    .
    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
    "ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-13 16:00 100032]
    "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "AllowLegacyWebView"= 1 (0x1)
    "AllowUnhashedWebView"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.3iv2"= 3ivxVfWCodec.dll
    "VIDC.HFYU"= huffyuv.dll
    "VIDC.VP31"= vp31vfw.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
    "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
    "C:\\Program Files\\Soulseek\\slsk.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\a1e183f05652bdbca0e57d93311bbf60\\day of defeat source\\hl2.exe"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "D:\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\Java\\jre1.5.0_10\\bin\\javaw.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\Program Files\\mIRC\\mirc.exe"=
    "C:\\Program Files\\Parbet.com Poker\\UA.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
    "C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
    "C:\\Program Files\\DNA\\btdna.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
    "C:\\Program Files\\Empire Interactive\\FlatOut2\\FlatOut2.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "21618:TCP"= 21618:TCP:BitComet 21618 TCP
    "21618:UDP"= 21618:UDP:BitComet 21618 UDP

    R2 Automaattinen LiveUpdate-ajastustoiminto;Automaattinen LiveUpdate-ajastustoiminto;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-09-13 16:00]
    R3 SMC55T;SMC EZ Card 10/100 (SMC1255TX-PF);C:\WINDOWS\system32\DRIVERS\SMC55T51.sys [2002-07-05 16:31]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b217703-933f-11db-93a5-0004e2432a1b}]
    \shell\play\Command - "C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9b1e83c2-7d3f-11db-937b-0004e2432a1b}]
    \Shell\AutoRun\command - G:\LaunchU3.exe -a

    .
    'Ajoitetut tehtävät'-kansion sisältö
    "2008-06-06 17:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Suorita täyd. järj.tarkistus - OJ.job"
    - C:\PROGRA~1\NORTON~1\Navw32.exe
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-12 17:33:40
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-06-12 17:42:11
    ComboFix-quarantined-files.txt 2008-06-12 14:41:25
    ComboFix2.txt 2008-06-12 11:21:21
    ComboFix3.txt 2008-06-12 09:13:58

    Pre-Run: 4,431,503,360 tavua vapaana
    Post-Run: 4,419,317,760 tavua vapaana

    135 --- E O F --- 2008-05-16 15:02:54




    Malwarebytes' Anti-Malware 1.17

    Tietokantaversio: 846

    22:49:49 12.6.2008
    mbam-log-6-12-2008 (22-49-49).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
    Tarkistetut kohteet: 188374
    Kulunut aika: 1 hour(s), 5 minute(s), 50 second(s)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 0
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 0
    Saastuneita tiedostoja: 0

    Saastuneita muistiprosesseja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita tiedostoja:
    (Haitallisia kohteita ei löydetty)



    hijack this

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:50:28, on 12.6.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
    O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-21-1275210071-688789844-839522115-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-21-1275210071-688789844-839522115-1007\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent (User '?')
    O4 - HKUS\S-1-5-21-1275210071-688789844-839522115-1007\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: BetOnBet Poker - {2B936D2B-EDD7-405f-9057-3685BE897E62} - C:\Program Files\betonbetMPP\MPPoker.exe
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL
    O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automaattinen LiveUpdate-ajastustoiminto - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

    --
    End of file - 8352 bytes
     
  16. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    Onko puhdasta?
     
  17. ScanPC

    ScanPC Member

    Joined:
    Jun 11, 2008
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    16
    Asialla on kiire, joten pyydän mahdollisimman nopeaa vastausta!
     
  18. Hujo

    Hujo Guest

    Näyttää puhtaalta mites kone toimii nyt

    ===========

    Javan päivitys ja välimuistin tyhjennys:

    1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
    2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
    Niissä pitäisi olla seuraava kuva vieressä: [​IMG]

    3. Valitse kaikki entiset Java versiosi ja valitse Poista.
    4. Asenna uusin Java päivitys seuraavasta linkistä..
    5. Käynnistä kone uudelleen asennuksen jälkeen:

    http://java.sun.com/javase/downloads/index.jsp

    Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u6

    Paina Download

    Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se.

    6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).

    7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia.

    (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa.
    Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle).

    8. Varmista että kaikki kaksi valintaa ovat rastitettuja:

    *Applications and Applets

    *Trace and Log Files

    Ja paina OK -nappia

    9. Klikkaa OK "Temporary Files Settings" -ikkunassasi.

    10. Klikkaa OK jättääksesi Java asetusikkunasi.
     
    Last edited by a moderator: Jun 12, 2008

Share This Page