Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:29:45, on 4.2.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Avast4\aswUpdSv.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Program Files\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\a-squared Anti-Malware\a2service.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sandboxie\SbieSvc.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Avast4\ashMaiSv.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Avast4\ashWebSv.exe C:\Program Files\Opera\Opera.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Avast4\ashChest.exe C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\rs32net.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\E.tmp C:\WINDOWS\Explorer.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\services.exe C:\Program Files\Easy SpyRemover\EasySpyRemover.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe C:\WINDOWS\system32\cmd.exe C:\PROGRA~1\Avast4\ashDisp.exe C:\WINDOWS\System32\rs32net.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files\Microsoft Office\Office\OSA.EXE C:\WINDOWS\services.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\services.exe C:\WINDOWS\Explorer.exe C:\Program Files\a-squared Anti-Malware\a2start.exe C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2wizard.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Avast4\ashSimpl.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fi.wikipedia.org/wiki/Wikipedia:Etusivu R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" O4 - HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-21-1004336348-413027322-725345543-1003\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" (User '?') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - S-1-5-21-1004336348-413027322-725345543-1003 Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE (User '?') O4 - Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: AutorunsDisabled O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: HP-leikekirja - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: HP Smart -valitse - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe -- End of file - 7671 bytes ----- a-squared Anti-Malware - Version 4.0 Last update: 4.2.2009 11:55:04 Scan settings: Objects: Memory, Traces, Cookies, C:\, E:\ Scan archives: On Heuristics: On ADS Scan: On Scan start: 4.2.2009 11:56:07 [580] C:\WINDOWS\system32\crypts.dll detected: Trojan-Spy.Finanz.J!IK [1048] C:\WINDOWS\system32\wdfmgr.exe detected: Virus.Win32.Virut.q!IK [20360] C:\WINDOWS\Explorer.exe detected: Trojan.Win32.Patched!IK [20932] C:\WINDOWS\system32\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK [22348] C:\WINDOWS\system32\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK [23536] C:\WINDOWS\Explorer.exe detected: Trojan.Win32.Patched!IK [14572] C:\WINDOWS\system32\NOTEPAD.EXE detected: Virus.Win32.Hupigon.MAP!IK Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run --> Services detected: Trace.Registry.SKL 1.0!A2 c:\windows\services.exe detected: Trace.File.Backdoor.Prorat.RC!A2 C:\Documents and Settings\MaijuR\Cookies\system@atdmt[2].txt detected: Trace.TrackingCookie.atdmt!A2 C:\Documents and Settings\MaijuR\Cookies\system@doubleclick[2].txt detected: Trace.TrackingCookie.doubleclick!A2 C:\Documents and Settings\MaijuR\Local Settings\Temp\44568.exe detected: Constructor.Win32.Agent.bm!IK C:\Documents and Settings\MaijuR\Local Settings\Temp\ICD1.tmp\jinstall.exe detected: Virus.Win32.Bancos.AWF!IK C:\Documents and Settings\MaijuR\Local Settings\Temp\rbSolnUpdateFIN.3.1.0.exe detected: Constructor.Win32.Agent.bm!IK C:\Documents and Settings\MaijuR\Local Settings\Temporary Internet Files\Content.IE5\OVZ3IGPD\aad[1].txt detected: Trojan-Dropper.Win32.Agent.afvt!A2 C:\kill\WDM_A402\WDM\SoundMan.exe detected: Trojan-PWS.Win32.Sysrater!IK C:\Program Files\DAEMON Tools Lite\daemon.exe detected: Virus.Win32.Agent.aj!IK C:\Program Files\EMCO Malware Destroyer\Quarantine\MAIJU\NMC.LOGPOLE.C\Files\WINDOWS\system32.exe detected: Trojan-Spy.Finanz.J!IK C:\Program Files\Google\Google Earth\googleearth.exe detected: Virus.Constructor.Win32.Joiner.bf!IK C:\Program Files\InstallShield Installation Information\{9A200E68-D5F4-4E70-910F-2871753A0E2B}\Setup.exe detected: Virus.Win32.Tufik.A!IK C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe detected: Virus.Win32.Virut.n!IK C:\Program Files\Internet Explorer\iexplore.exe detected: Trojan-Banker.Win32.Banbra!IK C:\Program Files\Jasc Software Inc\Paint Shop Pro 9\Paint Shop Pro 9.exe detected: Backdoor.Win32.Bifrose!IK C:\Program Files\Java\jre1.6.0_02\bin\java.exe detected: Virus.Win32.Bancos.AWF!IK C:\Program Files\Java\jre1.6.0_02\bin\javacpl.exe detected: Virus.Win32.Bancos.AWF!IK C:\Program Files\Java\jre1.6.0_02\bin\javaw.exe detected: Virus.Win32.Bancos.AWF!IK C:\Program Files\Java\jre1.6.0_02\bin\javaws.exe detected: Virus.Win32.Bancos.AWF!IK C:\Program Files\Movie Maker\moviemk.exe detected: Trojan-Downloader.Win32.Banload!IK C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe detected: Virus.Win32.Virut.q!IK C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe detected: Virus.Win32.Virut.q!IK C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe detected: Virus.Win32.Virut.q!IK C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe detected: Virus.Win32.Virut.q!IK C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe detected: Virus.Win32.Virut.q!IK C:\Program Files\NetMeeting\cb32.exe detected: Virus.Win32.Virut.n!IK C:\Program Files\Outlook Express\msimn.exe detected: Email-Worm.Win32.Tanatos.B!IK C:\Program Files\Outlook Express\wab.exe detected: Trojan-Dropper.Agent!IK C:\Program Files\Outlook Express\wabmig.exe detected: Virus.Win32.Virut.q!IK C:\Program Files\Windows Media Player\setup_wm.exe detected: Trojan-Downloader.Win32.Banload!IK C:\Program Files\Windows Media Player\wmplayer.exe detected: Trojan-Downloader.Win32.Banload!IK C:\Program Files\Windows Media Player\wmsetsdk.exe detected: Trojan-Downloader.Win32.Banload!IK C:\Program Files\Windows NT\hypertrm.exe detected: Virus.Win32.Virut.q!IK C:\Program Files\Windows NT\Pinball\pinball.exe detected: Virus.Win32.Virut.n!IK C:\Program Files\WinRAR\Uninstall.exe detected: Backdoor.Win32.PoeBot.A!IK C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentsvr.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe detected: Trojan.Win32.Patched!IK C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msiexec.exe detected: Virus.Win32.Virtob!IK C:\WINDOWS\$NtServicePackUninstall$\admin.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\$NtServicePackUninstall$\agentsvr.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\$NtServicePackUninstall$\ahui.exe detected: Trojan.Win32.VB!IK C:\WINDOWS\$NtServicePackUninstall$\alg.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\$NtServicePackUninstall$\asr_pfu.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\author.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\$NtServicePackUninstall$\blastcln.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\cfgwiz.exe detected: Virus.Win32.Virut!IK C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK C:\WINDOWS\$NtServicePackUninstall$\comrereg.exe detected: Win32.Virut.R!IK C:\WINDOWS\$NtServicePackUninstall$\dcomcnfg.exe detected: Win32.Virut.R!IK C:\WINDOWS\$NtServicePackUninstall$\diantz.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\dllhost.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\dmadmin.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\explorer.exe detected: Trojan.Win32.Patched!IK C:\WINDOWS\$NtServicePackUninstall$\fontview.exe detected: Virus.Win32.Zezal.a!IK C:\WINDOWS\$NtServicePackUninstall$\fp98swin.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\helpctr.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\ie4uinit.exe detected: Virus.Win32.Virut!IK C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe detected: Trojan-Banker.Win32.Banbra!IK C:\WINDOWS\$NtServicePackUninstall$\imapi.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\ipconfig.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\locator.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\logon.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\logonui.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\magnify.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\$NtServicePackUninstall$\makecab.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\mmc.exe detected: Trojan-PWS.Win32.VB.ER!IK C:\WINDOWS\$NtServicePackUninstall$\mnmsrvc.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\$NtServicePackUninstall$\mobsync.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\moviemk.exe detected: Trojan-Downloader.Win32.Banload!IK C:\WINDOWS\$NtServicePackUninstall$\mplay32.exe detected: Virus.Win32.DeadCode.b!IK C:\WINDOWS\$NtServicePackUninstall$\mplayer2.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\$NtServicePackUninstall$\msiexec.exe detected: Virus.Win32.Virtob!IK C:\WINDOWS\$NtServicePackUninstall$\msimn.exe detected: Email-Worm.Win32.Tanatos.B!IK C:\WINDOWS\$NtServicePackUninstall$\mspaint.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\mtstocom.exe detected: Win32.Virut.R!IK C:\WINDOWS\$NtServicePackUninstall$\net.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\$NtServicePackUninstall$\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK C:\WINDOWS\$NtServicePackUninstall$\osk.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\pinball.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\$NtServicePackUninstall$\powercfg.exe detected: Virus.Win32.Socks.BA!IK C:\WINDOWS\$NtServicePackUninstall$\progman.exe detected: Trojan-Spy.Win32.Banker.ciy!IK C:\WINDOWS\$NtServicePackUninstall$\rcimlby.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\rdshost.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe detected: Win32.Virtob.2!IK C:\WINDOWS\$NtServicePackUninstall$\sessmgr.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\setup.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\shmgrate.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\shtml.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\skeys.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\smbinst.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\smi2smir.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\sndrec32.exe detected: Virus.Win32.DeadCode.b!IK C:\WINDOWS\$NtServicePackUninstall$\spnpinst.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\ssmarque.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\ssmyst.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\svchost.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\tcptest.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\$NtServicePackUninstall$\upnpcont.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\ups.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\$NtServicePackUninstall$\vssvc.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\wab.exe detected: Trojan-Dropper.Agent!IK C:\WINDOWS\$NtServicePackUninstall$\wabmig.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\wextract.exe detected: Constructor.Win32.Agent.bm!IK C:\WINDOWS\$NtServicePackUninstall$\wiaacmgr.exe detected: Trojan-Spy.Win32.Banker.bkj!IK C:\WINDOWS\$NtServicePackUninstall$\wmiadap.exe detected: Win32.Virtob.P!IK C:\WINDOWS\$NtServicePackUninstall$\wmiapsrv.exe detected: Win32.Virtob.P!IK C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtServicePackUninstall$\wscntfy.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtUninstallKB920213$\agentsvr.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\$NtUninstallKB922582$\fltmc.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\$NtUninstallKB938828$\explorer.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\dbupjauj.exe detected: Trojan-Downloader.Win32.Small!IK C:\WINDOWS\explorer.exe detected: Trojan.Win32.Patched!IK C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe detected: Virus.Constructor.Win32.Joiner.bf!IK C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut2_407B9B5CDAC54F44A756B57CAB4E6A8B.exe detected: Virus.Constructor.Win32.Joiner.bf!IK C:\WINDOWS\msagent\agentsvr.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}\setup_wm.exe detected: Trojan-Downloader.Win32.Banload!IK C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfmgr.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}\wmplayer.exe detected: Trojan-Downloader.Win32.Banload!IK C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe detected: Virus.Win32.VB.dl!IK C:\WINDOWS\ServicePackFiles\i386\admin.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\ServicePackFiles\i386\agentsvr.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\ServicePackFiles\i386\ahui.exe detected: Trojan.Win32.VB!IK C:\WINDOWS\ServicePackFiles\i386\alg.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\ServicePackFiles\i386\author.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\ServicePackFiles\i386\cfgwiz.exe detected: Virus.Win32.Virut!IK C:\WINDOWS\ServicePackFiles\i386\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK C:\WINDOWS\ServicePackFiles\i386\dmadmin.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\explorer.exe detected: Trojan.Win32.Patched!IK C:\WINDOWS\ServicePackFiles\i386\fontview.exe detected: Virus.Win32.Zezal.a!IK C:\WINDOWS\ServicePackFiles\i386\fp98swin.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\fpsrvadm.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\ServicePackFiles\i386\ie4uinit.exe detected: Virus.Win32.Virut!IK C:\WINDOWS\ServicePackFiles\i386\iexplore.exe detected: Trojan-Banker.Win32.Banbra!IK C:\WINDOWS\ServicePackFiles\i386\ilasm.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\ServicePackFiles\i386\imapi.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\ipconfig.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\lang\imjpdct.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\ServicePackFiles\i386\lang\imjputy.exe detected: Virus.Win32.SillyW.1459!IK C:\WINDOWS\ServicePackFiles\i386\locator.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\logon.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\logonui.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\magnify.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\ServicePackFiles\i386\migwiza.exe detected: Win32.Virtob.2!IK C:\WINDOWS\ServicePackFiles\i386\mmc.exe detected: Trojan-PWS.Win32.VB.ER!IK C:\WINDOWS\ServicePackFiles\i386\mnmsrvc.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\ServicePackFiles\i386\mobsync.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\moviemk.exe detected: Trojan-Downloader.Win32.Banload!IK C:\WINDOWS\ServicePackFiles\i386\mplay32.exe detected: Virus.Win32.DeadCode.b!IK C:\WINDOWS\ServicePackFiles\i386\msiexec.exe detected: Virus.Win32.Virtob!IK C:\WINDOWS\ServicePackFiles\i386\msimn.exe detected: Email-Worm.Win32.Tanatos.B!IK C:\WINDOWS\ServicePackFiles\i386\mspaint.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\net.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\ServicePackFiles\i386\ngen.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\ServicePackFiles\i386\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK C:\WINDOWS\ServicePackFiles\i386\osk.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\pinball.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\ServicePackFiles\i386\powercfg.exe detected: Virus.Win32.Socks.BA!IK C:\WINDOWS\ServicePackFiles\i386\progman.exe detected: Trojan-Spy.Win32.Banker.ciy!IK C:\WINDOWS\ServicePackFiles\i386\rcimlby.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\rundll32.exe detected: Win32.Virtob.2!IK C:\WINDOWS\ServicePackFiles\i386\sessmgr.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\shmgrate.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\shtml.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\sndrec32.exe detected: Virus.Win32.DeadCode.b!IK C:\WINDOWS\ServicePackFiles\i386\ss3dfo.scr detected: Virus.Win32.Zezal.a!IK C:\WINDOWS\ServicePackFiles\i386\ssmarque.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\ssmyst.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\tcptest.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\ServicePackFiles\i386\ups.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\ServicePackFiles\i386\vssvc.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\wab.exe detected: Trojan-Dropper.Agent!IK C:\WINDOWS\ServicePackFiles\i386\wabmig.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\ServicePackFiles\i386\wextract.exe detected: Constructor.Win32.Agent.bm!IK C:\WINDOWS\ServicePackFiles\i386\wiaacmgr.exe detected: Trojan-Spy.Win32.Banker.bkj!IK C:\WINDOWS\ServicePackFiles\i386\wmiadap.exe detected: Win32.Virtob.P!IK C:\WINDOWS\ServicePackFiles\i386\wmiapsrv.exe detected: Win32.Virtob.P!IK C:\WINDOWS\SOUNDMAN.EXE detected: Trojan-PWS.Win32.Sysrater!IK C:\WINDOWS\system32\ahui.exe detected: Trojan.Win32.VB!IK C:\WINDOWS\system32\alg.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\system32\chkntfs.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\cidaemon.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK C:\WINDOWS\system32\convert.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\crypts.dll detected: Trojan-Spy.Finanz.J!IK C:\WINDOWS\system32\dllcache\bckgzm.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\cb32.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\system32\dllcache\chkntfs.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\chkrzm.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\cidaemon.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\convert.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\hrtzzm.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\imjpdct.exe detected: Win32.Cadoiac.A!IK C:\WINDOWS\system32\dllcache\imjputy.exe detected: Virus.Win32.SillyW.1459!IK C:\WINDOWS\system32\dllcache\isignup.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\system32\dllcache\mplay32.exe detected: Virus.Win32.DeadCode.b!IK C:\WINDOWS\system32\dllcache\rsmui.exe detected: Virus.Win32.Virut!IK C:\WINDOWS\system32\dllcache\rsvp.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\rvsezm.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\setup_wm.exe detected: Trojan-Downloader.Win32.Banload!IK C:\WINDOWS\system32\dllcache\shvlzm.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\dllcache\sol.exe detected: Trojan.Win32.Agent!IK C:\WINDOWS\system32\dllcache\twunk_32.exe detected: Trojan-Clicker.Win32.NetBuie.H!IK C:\WINDOWS\system32\dllcache\wmplayer.exe detected: Trojan-Downloader.Win32.Banload!IK C:\WINDOWS\system32\dmadmin.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\drivers\ndisio.sys detected: Trojan-Dropper.Win32.Tofsee!IK C:\WINDOWS\system32\fontview.exe detected: Virus.Win32.Zezal.a!IK C:\WINDOWS\system32\ie4uinit.exe detected: Virus.Win32.Virut!IK C:\WINDOWS\system32\imapi.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\ipconfig.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\java.exe detected: Virus.Win32.Bancos.AWF!IK C:\WINDOWS\system32\javaw.exe detected: Virus.Win32.Bancos.AWF!IK C:\WINDOWS\system32\javaws.exe detected: Virus.Win32.Bancos.AWF!IK C:\WINDOWS\system32\locator.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\logon.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\logonui.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\magnify.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\system32\mmc.exe detected: Trojan-PWS.Win32.VB.ER!IK C:\WINDOWS\system32\mnmsrvc.exe detected: Virus.Win32.Virut.n!IK C:\WINDOWS\system32\mobsync.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\mplay32.exe detected: Virus.Win32.DeadCode.b!IK C:\WINDOWS\system32\msiexec.exe detected: Virus.Win32.Virtob!IK C:\WINDOWS\system32\mspaint.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\NeroCheck.exe detected: Trojan.Win32.Patched!IK C:\WINDOWS\system32\net.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\system32\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK C:\WINDOWS\system32\osk.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\powercfg.exe detected: Virus.Win32.Socks.BA!IK C:\WINDOWS\system32\progman.exe detected: Trojan-Spy.Win32.Banker.ciy!IK C:\WINDOWS\system32\rcimlby.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\rsmui.exe detected: Virus.Win32.Virut!IK C:\WINDOWS\system32\rsvp.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\rundll32.exe detected: Win32.Virtob.2!IK C:\WINDOWS\system32\sessmgr.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\shmgrate.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\sndrec32.exe detected: Virus.Win32.DeadCode.b!IK C:\WINDOWS\system32\sol.exe detected: Trojan.Win32.Agent!IK C:\WINDOWS\system32\ss3dfo.scr detected: Virus.Win32.Zezal.a!IK C:\WINDOWS\system32\ssmarque.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\ssmyst.scr detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\ups.exe detected: Virus.Win32.Virut.ak!IK C:\WINDOWS\system32\usmt\migwiza.exe detected: Win32.Virtob.2!IK C:\WINDOWS\system32\vssvc.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\wbem\wmiadap.exe detected: Win32.Virtob.P!IK C:\WINDOWS\system32\wbem\wmiapsrv.exe detected: Win32.Virtob.P!IK C:\WINDOWS\system32\wdfmgr.exe detected: Virus.Win32.Virut.q!IK C:\WINDOWS\system32\wextract.exe detected: Constructor.Win32.Agent.bm!IK C:\WINDOWS\system32\wiaacmgr.exe detected: Trojan-Spy.Win32.Banker.bkj!IK C:\WINDOWS\Temp\28FE.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\3590.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\542A.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\5606.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\920B.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\A13E.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\A32E.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\B042.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\D431.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\E9E4.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\FA11.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\FBBE.tmp detected: Backdoor.Win32.KeyStart!IK C:\WINDOWS\Temp\VRT4D.tmp detected: Trojan-Downloader.Win32.Injecter!IK C:\WINDOWS\twunk_32.exe detected: Trojan-Clicker.Win32.NetBuie.H!IK Scanned Files: 276487 Traces: 711950 Cookies: 124 Processes: 55 Found Files: 265 Traces: 2 Cookies: 2 Processes: 7 Registry keys: 0 Scan end: 4.2.2009 14:10:01 Scan time: 2:13:54 ----- En tehnyt tuolla A2:sellakaan vielä mitään kun sen verran kriittisen näköisiä tiedostoja sieltä löytyi, enkä niistä mitään ymmärrä.
Ainiin ja Avast siirsi undname.exe ja windres.exe -tiedostot system32-kansiosta "virus chestiin", eikä niitä saa palautettua sieltä.
joo niin näyttää olevan että exe tiedostot saastuneet. Kai sulla on Käyttöjärjestelmä cd ja tarvittavat muutkin cd tallessa jos kone viskasee voltin takaperin kerien kierteellä. Eikä meinaan inahdakkaan mihkään suuntaan. En vielä ainakaan kokonaan nielase tuon a2 löytöjä Kumpaa virustorjuntaa käytät avastia vai avg8 Poista toinen =============== Lataa Atribunen ATF Cleaner Ohjeet; Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman.Main:n alla valitse: Select All Klikkaa Empty Selected valintaa. Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Jos käytät Operaa selaimenasiKlikkaa Opera yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa taas. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Klikkaa Exit päävalikosta sulkeaksesi ohjelman. Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi) =============== Lataa Tästä Ccleaner CCleaner v 2.14.750.- Standard Build, ÄLÄ aseenna Yahoo toolbaria! Asennuksessa poista merkki/rasti kohdasta "asenna Yahoo! toolbar/työkalupalkki". Asennuksen jälkeen aukaise CCleaneri. Valitse vasemmalta pystyrivistä Options. Valitse viereisestä pystyrivistä Settings. Language kohtaan valitse Suomi. Puhdistaja Valitse vasemmalta pystyrivistä Puhdistaja. Paina alhaalta Tutki. Nyt CCleaneri tutkii, mitä voidaan poistaa (tempit, cookiessit jne.). Kun tutkiminen on valmis, paina Aja CCleaner. Nyt CCleaneri poistaa löydetyt tempit, cookiessit jne. Rekisterin virheiden korjaus Valitse vasemmalta pystyrivistä Rekisteri. Paina alhaalta Etsi rekisterin virheitä. Kun etsintä on valmis ja olet varma, että haluat korjata ne rivit jotka ovat merkattuja, niin paina Korjaa valitut rekisterin virheet. Sinulta kysytään "haluatko varmuuskopioida muutokset rekisteriin", paina Kyllä. Tallenna varmuuskopio vaikka "Omat tiedostot" -kansioon. Klikkaa uudesta aukeavasta ikkunasta Korjaa kaikki valitut virheet. Saat vielä varmistus kysymyksen, paina Ok. Kun virheet on korjattu, paina Sulje. Nyt voit sulkea CCleanerin painamalla oikealta ylhäältä punaista rastia. ================ sammuta ja käynnistä ================