Hijacked domains (HjT-logi)

Discussion in 'Virukset ja haittaohjelmat' started by Boheemia, Sep 17, 2005.

  1. Boheemia

    Boheemia Regular member

    Joined:
    Jun 10, 2005
    Messages:
    109
    Likes Received:
    0
    Trophy Points:
    26
    Ajoin pitkästä aikaa HjT:n, ja skannauksen yhteydessä se ilmoitti seuraavaa:

    "You have a particularly large amount of hijacked domains. It's probably better to delete the file itself then to fix each item (and create a backup). If you see the same IP number on all the reported 01 items, consider deleting your Hosts file, which is located at C:\Windows\System32\Drivers\etc\hosts."

    Liittyneekö asia yliopiston systeemeihin, kun tykkäävät rajoittaa monia asioita? Jottä yhteydet toimisivat niin täytyy erikseen määrittää http proxy ja portti, joita halutaan käyttää.


    Logfile of HijackThis v1.99.1
    Scan saved at 17:26:24, on 17.9.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\acs.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Atheros\ACU.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Samurize\Client.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\hjt\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O1 - Hosts: 62.75.224.159 www.bns1.net
    O1 - Hosts: 62.75.224.159 www.bns2.net
    O1 - Hosts: 62.75.224.159 www.bns3.net
    O1 - Hosts: 62.75.224.159 www.bns4.net
    O1 - Hosts: 62.75.224.159 www.bns5.net
    O1 - Hosts: 62.75.224.159 www.bns6.net
    O1 - Hosts: 62.75.224.159 www.bns7.net
    O1 - Hosts: 62.75.224.159 www.bns8.net
    O1 - Hosts: 62.75.224.159 www.cms1.net
    O1 - Hosts: 62.75.224.159 www.cms2.net
    O1 - Hosts: 62.75.224.159 www.cms3.net
    O1 - Hosts: 62.75.224.159 www.cms4.net
    O1 - Hosts: 62.75.224.159 www.cms5.net
    O1 - Hosts: 62.75.224.159 www.cms6.net
    O1 - Hosts: 62.75.224.159 www.cms7.net
    O1 - Hosts: 62.75.224.159 www.cms8.net
    O1 - Hosts: 62.75.224.159 www.rg1.com
    O1 - Hosts: 62.75.224.159 www.rg2.com
    O1 - Hosts: 62.75.224.159 www.rg3.com
    O1 - Hosts: 62.75.224.159 www.rg4.com
    O1 - Hosts: 62.75.224.159 www.rg5.com
    O1 - Hosts: 62.75.224.159 www.rg6.com
    O1 - Hosts: 62.75.224.159 www.rg7.com
    O1 - Hosts: 62.75.224.159 www.rg8.com
    O1 - Hosts: 62.75.224.159 www.cjt1.net
    O1 - Hosts: 62.75.224.159 www.rgs1.net
    O1 - Hosts: 62.75.224.159 www.rgs2.net
    O1 - Hosts: 62.75.224.159 www.bns1.net
    O1 - Hosts: 62.75.224.159 www.bns2.net
    O1 - Hosts: 62.75.224.159 www.cms1.net
    O1 - Hosts: 62.75.224.159 www.cms2.net
    O1 - Hosts: 62.75.224.159 bns1.net
    O1 - Hosts: 62.75.224.159 bns2.net
    O1 - Hosts: 62.75.224.159 bns3.net
    O1 - Hosts: 62.75.224.159 bns4.net
    O1 - Hosts: 62.75.224.159 bns5.net
    O1 - Hosts: 62.75.224.159 bns6.net
    O1 - Hosts: 62.75.224.159 bns7.net
    O1 - Hosts: 62.75.224.159 bns8.net
    O1 - Hosts: 62.75.224.159 cms1.net
    O1 - Hosts: 62.75.224.159 cms2.net
    O1 - Hosts: 62.75.224.159 cms3.net
    O1 - Hosts: 62.75.224.159 cms4.net
    O1 - Hosts: 62.75.224.159 cms5.net
    O1 - Hosts: 62.75.224.159 cms6.net
    O1 - Hosts: 62.75.224.159 cms7.net
    O1 - Hosts: 62.75.224.159 cms8.net
    O1 - Hosts: 62.75.224.159 rg1.com
    O1 - Hosts: 62.75.224.159 rg2.com
    O1 - Hosts: 62.75.224.159 rg3.com
    O1 - Hosts: 62.75.224.159 rg4.com
    O1 - Hosts: 62.75.224.159 rg5.com
    O1 - Hosts: 62.75.224.159 rg6.com
    O1 - Hosts: 62.75.224.159 rg7.com
    O1 - Hosts: 62.75.224.159 rg8.com
    O1 - Hosts: 62.75.224.159 cjt1.net
    O1 - Hosts: 62.75.224.159 rgs1.net
    O1 - Hosts: 62.75.224.159 rgs2.net
    O1 - Hosts: 62.75.224.159 bns1.net
    O1 - Hosts: 62.75.224.159 bns2.net
    O1 - Hosts: 62.75.224.159 cms1.net
    O1 - Hosts: 62.75.224.159 cms2.net
    O1 - Hosts: 62.75.224.159 j800banners.cjt1.net
    O1 - Hosts: 62.75.224.159 jadlogix.cjt1.net
    O1 - Hosts: 62.75.224.159 jadtegrity.cjt1.net
    O1 - Hosts: 62.75.224.159 jaimmedia.cjt1.net
    O1 - Hosts: 62.75.224.159 javatar.cjt1.net
    O1 - Hosts: 62.75.224.159 jbeet.cjt1.net
    O1 - Hosts: 62.75.224.159 jbigpops.cjt1.net
    O1 - Hosts: 62.75.224.159 jbouncetek.cjt1.net
    O1 - Hosts: 62.75.224.159 jbravenet.cjt1.net
    O1 - Hosts: 62.75.224.159 jcdcover.cjt1.net
    O1 - Hosts: 62.75.224.159 jclickspring.cjt1.net
    O1 - Hosts: 62.75.224.159 jcollegehumor.cjt1.net
    O1 - Hosts: 62.75.224.159 jdownloadacc.cjt1.net
    O1 - Hosts: 62.75.224.159 jedonkey.cjt1.net
    O1 - Hosts: 62.75.224.159 jeuniverse.cjt1.net
    O1 - Hosts: 62.75.224.159 jhot.cjt1.net
    O1 - Hosts: 62.75.224.159 jicmedia.cjt1.net
    O1 - Hosts: 62.75.224.159 jicq.cjt1.net
    O1 - Hosts: 62.75.224.159 jieplugin.cjt1.net
    O1 - Hosts: 62.75.224.159 jinternetoptimizer.cjt1.net
    O1 - Hosts: 62.75.224.159 jmediabuy1.cjt1.net
    O1 - Hosts: 62.75.224.159 jmediabuyad.cjt1.net
    O1 - Hosts: 62.75.224.159 jmindset.cjt1.net
    O1 - Hosts: 62.75.224.159 jmindsettest.cjt1.net
    O1 - Hosts: 62.75.224.159 jnictech.cjt1.net
    O1 - Hosts: 62.75.224.159 jnova.cjt1.net
    O1 - Hosts: 62.75.224.159 jpiolet.cjt1.net
    O1 - Hosts: 62.75.224.159 jsanboxer.cjt1.net
    O1 - Hosts: 62.75.224.159 jsercee.cjt1.net
    O1 - Hosts: 62.75.224.159 jthedelfin.cjt1.net
    O1 - Hosts: 62.75.224.159 jwarezp2p.cjt1.net
    O1 - Hosts: 62.75.224.159 jwildmedia.cjt1.net
    O1 - Hosts: 62.75.224.159 mediabuy-nic.cjt1.net
    O1 - Hosts: 62.75.224.159 www.m7z.net
    O1 - Hosts: 62.75.224.159 m7z.net
    O1 - Hosts: 62.75.224.159 jcms.cydoor.com
    O1 - Hosts: 62.75.224.159 cydoor.com
    O1 - Hosts: 62.75.224.159 www.cydoor.com
    O1 - Hosts: 62.75.224.159 jnova.cjt1.net
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Client Default.lnk = C:\Program Files\Samurize\Client.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
    O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
     
  2. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Ei liity, vaan sun hosts-tiedostoa on päästy tavalla tai toisella sormeilemaan. On siis kaksi vaihtoehtoa: joko poistat nuo kaikki 01-rivit hijackthisillä tai sitten poista tuo hosts-tiedosto(löytyy hakemistosta C:\Windows\System32\Drivers\etc\ nimellä hosts (ei siis tiedostopäätettä)).
     
  3. Boheemia

    Boheemia Regular member

    Joined:
    Jun 10, 2005
    Messages:
    109
    Likes Received:
    0
    Trophy Points:
    26
    Kiitos nopeasta toiminnasta! Poistin hosts-tiedoston ja niinhän ne ylimääräiset rivit hävisivätkin. Tässä nyt vielä varmuuden vuoksi uusi logi.


    Logfile of HijackThis v1.99.1
    Scan saved at 18:08:34, on 17.9.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\acs.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Atheros\ACU.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Samurize\Client.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\LVComsX.exe
    C:\Program Files\eDATA Unerase\eDATAUnerase.exe
    C:\Program Files\eDATA Unerase\eDATAUnerase.exe
    C:\hjt\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Client Default.lnk = C:\Program Files\Samurize\Client.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
    O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
     
  4. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Ole hyvä vaan :) Loki on kunnossa.
     

Share This Page