HjT-loki tarkastettavaksi

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by anttih_, May 19, 2007.

  1. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 15:45:28, on 19.5.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ghmhyzup.exe
    C:\WINDOWS\system32\pchtls32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    C:\lotus\wordpro\ltsstart.exe
    C:\lotus\register\remind32.exe
    C:\lotus\smartctr\suitest.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\alg.exe
    C:\Documents and Settings\DTK Computer\Työpöytä\HiJackThis_v2.0.0.0.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netsor.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: (no name) - _{0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file)
    R3 - URLSearchHook: (no name) - _{0FA33B6C-71BC-69D3-DB7A-472A4D6F3452} - (no file)
    R3 - URLSearchHook: (no name) - {E5A2678F-DA83-4D2E-BA85-6236E90098FA} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
    O4 - HKLM\..\Run: [LOUDPOLL] C:\PROGRA~1\info bend\funk mess sixth.exe
    O4 - HKLM\..\Run: [ofwl] C:\WINDOWS\ofwl.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
    O4 - HKLM\..\Run: [ghmhyzup.exe] C:\WINDOWS\system32\ghmhyzup.exe
    O4 - HKLM\..\Run: [PCHelp tools] C:\WINDOWS\system32\pchtls32.exe
    O4 - HKCU\..\Run: [Etma] C:\Documents and Settings\DTK Computer\Application Data\tuhh.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Contact Manager Alerts] C:\Program Files\Contact Manager 2007\Alerts.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Lotus Opetusohjelma.lnk = C:\lotus\wordpro\ltsstart.exe
    O4 - Startup: Lotus SmartSuite 97 rekisteröiminen.lnk = C:\lotus\register\remind32.exe
    O4 - Startup: Lotus SuiteStart 97.lnk = C:\lotus\smartctr\suitest.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Free WebSite Tools.lnk = ?
    O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0C06EFC2-12E3-4F14-B644-4C49F131CCB0}: NameServer = 85.255.115.59,85.255.112.77
    O17 - HKLM\System\CCS\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer = 85.255.115.59,85.255.112.77
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8F5A9453-FF2E-4988-9C93-45EA53108459}: NameServer = 85.255.115.59,85.255.112.77
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.77
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0C06EFC2-12E3-4F14-B644-4C49F131CCB0}: NameServer = 85.255.115.59,85.255.112.77
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.77
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O19 - User stylesheet: (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Reload Browse - {E802FFFF-8E58-4d2c-A435-8BEEFB10AB77} - C:\WINDOWS\system32\svchosts.dll (file missing)
    O22 - SharedTaskScheduler: Security Update - {A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} - (no file)
    O22 - SharedTaskScheduler: boob - {01b55afa-f451-474b-9e91-c35b24d02641} - (no file)
    O22 - SharedTaskScheduler: admissibility - {da3b49f6-8c54-4429-a275-21a86dcca413} - C:\WINDOWS\system32\xuoce.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
    O23 - Service: iPod-palvelu (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
    O23 - Service: Windows Media Playerin verkkojakamispalvelu (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
    O24 - Desktop Component 0: Warning homepage - C:\WINDOWS\warnhp.html
     
  2. Hujo

    Hujo Guest

    Lataa fixwareout.exe täältä > http://downloads.subratam.org/Fixwareout.exe
    tai täältä >
    http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
    ja tallenna se työpöydälle. Tuplaklikkaa sitä ja seuraa ohjeita. Klikkaa Next, sitten Install ja varmistu, että "Run fixit" on valittu. Sinun pitää käynnistää kone uudelleen, kun niin käsketään.


    Lähetä uusi HjT-loki ja c:\fixwareout\report.txt sisältö

    ===================

    scannaa hjt:llä merkkaa paina Fix checked

    R3 - URLSearchHook: (no name) - _{0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file)
    R3 - URLSearchHook: (no name) - _{0FA33B6C-71BC-69D3-DB7A-472A4D6F3452} - (no file)
    R3 - URLSearchHook: (no name) - {E5A2678F-DA83-4D2E-BA85-6236E90098FA} - (no file)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0C06EFC2-12E3-4F14-B644-4C49F131CCB0}: NameServer = 85.255.115.59,85.255.112.77
    O17 - HKLM\System\CCS\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer = 85.255.115.59,85.255.112.77
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8F5A9453-FF2E-4988-9C93-45EA53108459}: NameServer = 85.255.115.59,85.255.112.77
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.77
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0C06EFC2-12E3-4F14-B644-4C49F131CCB0}: NameServer = 85.255.115.59,85.255.112.77

    =======================

    Lataa SmitfraudFix (c) S!Ri http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:

    Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
    Postita tämän tekstitiedoston sisältö viestiketjuusi.

    Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja. A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä, silloin ne saattavat varoittaa käyttäjää.
     
    Last edited by a moderator: May 19, 2007
  3. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    Tässä tämä HjT-loki:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 18:29:10, on 19.5.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\SYSTEM32\notepad.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ghmhyzup.exe
    C:\WINDOWS\system32\pchtls32.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Contact Manager 2007\Alerts.exe
    C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    C:\lotus\wordpro\ltsstart.exe
    C:\lotus\register\remind32.exe
    C:\lotus\smartctr\suitest.exe
    C:\Documents and Settings\DTK Computer\Työpöytä\HiJackThis_v2.0.0.0.exe
    C:\Program Files\Mozilla Firefox\firefox.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netsor.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
    O4 - HKLM\..\Run: [LOUDPOLL] C:\PROGRA~1\info bend\funk mess sixth.exe
    O4 - HKLM\..\Run: [ofwl] C:\WINDOWS\ofwl.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
    O4 - HKLM\..\Run: [ghmhyzup.exe] C:\WINDOWS\system32\ghmhyzup.exe
    O4 - HKLM\..\Run: [PCHelp tools] C:\WINDOWS\system32\pchtls32.exe
    O4 - HKCU\..\Run: [Etma] C:\Documents and Settings\DTK Computer\Application Data\tuhh.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Contact Manager Alerts] C:\Program Files\Contact Manager 2007\Alerts.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Lotus Opetusohjelma.lnk = C:\lotus\wordpro\ltsstart.exe
    O4 - Startup: Lotus SmartSuite 97 rekisteröiminen.lnk = C:\lotus\register\remind32.exe
    O4 - Startup: Lotus SuiteStart 97.lnk = C:\lotus\smartctr\suitest.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Free WebSite Tools.lnk = ?
    O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O19 - User stylesheet: (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Reload Browse - {E802FFFF-8E58-4d2c-A435-8BEEFB10AB77} - C:\WINDOWS\system32\svchosts.dll (file missing)
    O22 - SharedTaskScheduler: Security Update - {A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} - (no file)
    O22 - SharedTaskScheduler: boob - {01b55afa-f451-474b-9e91-c35b24d02641} - (no file)
    O22 - SharedTaskScheduler: admissibility - {da3b49f6-8c54-4429-a275-21a86dcca413} - C:\WINDOWS\system32\xuoce.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
    O23 - Service: iPod-palvelu (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
    O23 - Service: Windows Media Playerin verkkojakamispalvelu (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
    O24 - Desktop Component 0: Warning homepage - C:\WINDOWS\warnhp.html

    ------------------

    Tässä puolestaan fixwareout -ohjelman raportti:


    Fixwareout Last edited 5/15/2007
    Post this report in the forums please
    ...
    »»»»»Prerun check
    HKLM\SOFTWARE\~\Winlogon\ "System"="kdnga.exe"

    »»»»»

    »»»»» Postrun check
    HKLM\SOFTWARE\~\Winlogon\ "system"=""
    ....
    ....
    »»»»» Misc files.
    C:\Documents and Settings\DTK Computer\Application Data\Install.dat Deleted
    ....
    »»»»» Checking for older varients.
    ....

    Search five digit cs, dm, kd, jb, other, files.
    The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.


    Click browse, find the file then click submit.
    http://www.virustotal.com/flash/index_en.html
    Or http://virusscan.jotti.org/

    »»»»» Other
    C:\WINDOWS\Temp\kdnga.ren 63822 15.09.2004

    »»»»» Current runs
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan"="SOUNDMAN.EXE"
    "Upgrade Service"="C:\\WINDOWS\\sxchost.exe"
    "LOUDPOLL"="C:\\PROGRA~1\\info bend\\funk mess sixth.exe"
    "ofwl"="C:\\WINDOWS\\ofwl.exe"
    "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
    "iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "Easy-PrintToolBox"="C:\\Program Files\\Canon\\Easy-PrintToolBox\\BJPSMAIN.EXE /logon"
    "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
    "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
    "ppmate"="C:\\Program Files\\PPMate\\PPMate\\ppmate.exe -autoplay"
    "ghmhyzup.exe"="C:\\WINDOWS\\system32\\ghmhyzup.exe"
    "PCHelp tools"="C:\\WINDOWS\\system32\\pchtls32.exe"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Etma"="C:\\Documents and Settings\\DTK Computer\\Application Data\\tuhh.exe"
    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "Contact Manager Alerts"="C:\\Program Files\\Contact Manager 2007\\Alerts.exe"
    ....
    Hosts file was reset, If you use a custom hosts file please replace it
    »»»»» End report »»»»»

    ------------------------

    Ja tässä tuo SmitfraudFix -ohjelman raportti:

    SmitFraudFix v2.183

    Scan done at 18:37:46,82, la 19.05.2007
    Run from C:\Documents and Settings\DTK Computer\Ty”p”yt„\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ghmhyzup.exe
    C:\WINDOWS\system32\pchtls32.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Contact Manager 2007\Alerts.exe
    C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    C:\lotus\wordpro\ltsstart.exe
    C:\lotus\register\remind32.exe
    C:\lotus\smartctr\suitest.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\cmd.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    C:\WINDOWS\warnhp.html FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\ot.ico FOUND !
    C:\WINDOWS\system32\st3.dll FOUND !
    C:\WINDOWS\system32\ts.ico FOUND !
    C:\WINDOWS\system32\xuoce.dll FOUND !
    C:\WINDOWS\system32\1024\ FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\DTK Computer


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\DTK Computer\Application Data

    C:\Documents and Settings\DTK Computer\Application Data\Skinux FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

    C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Online Security Guide.url FOUND !
    C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Security Troubleshooting.url FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\DTKCOM~1\Suosikit

    C:\DOCUME~1\DTKCOM~1\Suosikit\Antivirus Test Online.url FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    C:\Program Files\Video AX Object\ FOUND !
    C:\Program Files\VirusBurster\ FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

    HKLM\SOFTWARE\PSGuard.com FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="C:\\WINDOWS\\warnhp.html"
    "SubscribedURL"=""
    "FriendlyName"="Warning homepage"

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Nykyinen kotisivu"

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}"="Reload Browse"

    [HKEY_CLASSES_ROOT\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}\InProcServer32]
    @="C:\WINDOWS\system32\svchosts.dll"

    [HKEY_CURRENT_USER\Software\Classes\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}\InProcServer32]
    @="C:\WINDOWS\system32\svchosts.dll"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"="Security Update"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{01b55afa-f451-474b-9e91-c35b24d02641}"="boob"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{da3b49f6-8c54-4429-a275-21a86dcca413}"="admissibility"

    [HKEY_CLASSES_ROOT\CLSID\{da3b49f6-8c54-4429-a275-21a86dcca413}\InProcServer32]
    @="C:\WINDOWS\system32\xuoce.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{da3b49f6-8c54-4429-a275-21a86dcca413}\InProcServer32]
    @="C:\WINDOWS\system32\xuoce.dll"



    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "system"=""


    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32



    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: VIA Compatable Fast Ethernet Adapter
    DNS Server Search Order: 193.210.18.18
    DNS Server Search Order: 212.213.216.195

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer=193.210.18.18,212.213.216.195
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer=193.210.18.18,212.213.216.195


    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End
     
  4. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    Tuli tuplat.
     
    Last edited: May 19, 2007
  5. Hujo

    Hujo Guest

    Poista toi lisää poista sovelutuksesta

    ewido anti-malware


    =========================

    sitten latailaan uusi

    Ohje AVG:n Anti-Spyware 7.5:n käyttöön
    Huom! Tässä ohjeessa sammutetaan tuo reaaliaikasuojaus (Shield). Näin vältetään tilanteet joissa suojaus estäisi esim HijackThis:n työkalun toimintaa.

    Tallenna nämä ohjeet tekstitiedostoon tai tulosta nämä, muuten et pääse niihin käsiksi vikasietotilasta

    Lataa AVG:n Anti-Spyware 7.5:n
    ja tallenna ohjelma työpöydällesi.
    o Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa.
    o Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää.
    o Käynnistä AVG:n Anti-Spyware.
    o Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.

    o Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.

    o Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    o Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".

    o Sitten "Reports" valikon alta:
    o Laita täppi kohtaan "Automatically generate report after every scan"
    o Ota täppi pois kohdasta"Only if threats were found"

    o Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
    o "Resident shield is", muuta tila active:sta inactive:ksi
    o Sulje ohjelma, ÄLÄ skannaa vielä.

    Käynnistä koneesi vikasietotilaan,
    sammuta ja käynnistä
    käynnistyksen yhteydessä naputtele F8
    valitse nuoli näppäimellä vikasietotila
    paina enter ja enter

    HUOM! Älä käytä muita ohjelmia AVG:n skannauksen aikana, tämä saattaa häiritä skannausta.
    o Kun vikasietotilassa, käynnistä AVG:n Anti-Spyware.
    o Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
    o Ewido aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.

    Kun skannaus on valmis:
    TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
    o Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
    o Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"
    [​IMG]
    o Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
    o Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.
    o Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestikejuusi.

    ========================

    Printtaa ohjeet ulos.

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi.

    Kun vikasietotilassa, avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.

    Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.

    Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".

    Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
    Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
    Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt.

    Varoitus : Ajamalla optio 2:n EI-tarttuneessa tietokoneessa, poistaa sinun työpöytäsi taustakuvan.

    ===============
     
    Last edited by a moderator: May 19, 2007
  6. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 21:59:48 19.5.2007

    + Scan result:



    C:\Program Files\Video AX Object -> Adware.Generic : Cleaned with backup (quarantined).
    C:\Program Files\Video AX Object\uninst.exe -> Adware.Generic : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{B212D577-05B7-4963-911E-4A8588160DFA} -> Adware.Generic : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{da3b49f6-8c54-4429-a275-21a86dcca413} -> Adware.Generic : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\desktrf-cat_b2s.exe -> Adware.HotSearchBar : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\PSGuard.com -> Adware.PSGuard : Error during cleaning.
    HKLM\SOFTWARE\PSGuard.com\PSGuard -> Adware.PSGuard : Error during cleaning.
    HKLM\SOFTWARE\PSGuard.com\PSGuard\P.S.Guard -> Adware.PSGuard : Error during cleaning.
    HKLM\SOFTWARE\PSGuard.com\PSGuard\P.S.Guard\License -> Adware.PSGuard : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{7288C0BD-7F2F-4229-A0C4-3C90A6E2A881} -> Adware.SpyAxe : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} -> Adware.SpyAxe : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\tptbtcfs\tptbtcfs1.exe -> Adware.UltimateDefender : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\tptbtcfs\tptbtcfs3.exe -> Adware.UltimateDefender : Cleaned with backup (quarantined).
    C:\Program Files\VirusBurster -> Adware.VirusBurster : Cleaned with backup (quarantined).
    C:\Program Files\VirusBurster\ignored.lst -> Adware.VirusBurster : Cleaned with backup (quarantined).
    C:\Program Files\VirusBurster\virusburster.ini -> Adware.VirusBurster : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\xuoce.dll -> Downloader.Agent.bkd : Cleaned with backup (quarantined).
    [764] C:\WINDOWS\system32\xuoce.dll -> Downloader.Agent.bkd : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{7507739F-BC2E-4DC3-B233-816783C25DC9} -> Downloader.Delf : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{826B2228-BC09-49F2-B5F8-42CE26B1B712} -> Downloader.Delf : Cleaned with backup (quarantined).
    :mozilla.189:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.190:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.616:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Adition : Cleaned.
    :mozilla.617:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Adition : Cleaned.
    :mozilla.29:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\xo0o5y2f.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.30:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\xo0o5y2f.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.58:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.59:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.157:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.158:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.159:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.160:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.27:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\xo0o5y2f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.110:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.449:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.281:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
    :mozilla.20:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.278:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.649:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Fortunecity : Cleaned.
    :mozilla.603:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
    :mozilla.604:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
    :mozilla.803:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Information : Cleaned.
    :mozilla.497:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
    :mozilla.106:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.266:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Planetactive : Cleaned.
    :mozilla.102:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.103:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.656:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.263:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.264:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.265:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.602:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
    :mozilla.528:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.529:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.530:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    C:\Documents and Settings\DTK Computer\Cookies\dtk_computer@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned.
    :mozilla.644:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.645:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.505:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Trafic : Cleaned.
    :mozilla.279:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.430:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Weborama : Cleaned.
    :mozilla.431:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Weborama : Cleaned.
    :mozilla.432:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Weborama : Cleaned.
    :mozilla.502:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.757:C:\Documents and Settings\DTK Computer\Application Data\Mozilla\Firefox\Profiles\d50cehkq.Oletuskäyttäjä\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    C:\System Volume Information\_restore{0403B3BA-2F2A-48AB-B4D9-D9783FCFA8E1}\RP616\A0313130.exe -> Trojan.DNSChanger.in : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\kdnga.ren -> Trojan.DNSChanger.in : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0403B3BA-2F2A-48AB-B4D9-D9783FCFA8E1}\RP583\A0307176.exe -> Trojan.DNSChanger.ir : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0403B3BA-2F2A-48AB-B4D9-D9783FCFA8E1}\RP583\A0307177.exe -> Trojan.DNSChanger.ir : Cleaned with backup (quarantined).
    C:\Documents and Settings\DTK Computer\Local Settings\Temp\laf2C.tmp -> Trojan.Renos.naz : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld114A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld1945.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld1A77.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld2450.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld276E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld29EC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld2A4B.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld2C22.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld2E84.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld3057.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld31D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld328F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld3D3F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld3DDA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld3E0.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld402E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4168.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld425E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld42AD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4419.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld44FF.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld457D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld45F9.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4651.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4715.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld472F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4BAF.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4CC1.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4D8E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld4FFA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld5266.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld526F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld52A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld52D6.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld53DB.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld5567.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld5672.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld5739.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld5D29.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld60A3.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld6CF3.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld6D07.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld6DD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld6EAF.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld7086.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld72C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld7340.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld766E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld7686.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld7712.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld7822.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld8466.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld8754.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld87C6.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld886F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld88FF.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld8A8.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld8A82.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld8D52.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld8E20.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld8F24.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld92FE.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9330.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9426.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld94AC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9639.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld981F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld98C9.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9ADC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9BF7.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9C24.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9CF1.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9DEB.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9E70.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9EB8.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ld9F80.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldA148.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldA656.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldA732.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldAB86.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldABC2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldAC11.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldAD1C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldAE83.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldAF8D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB028.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB143.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB17B.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB20A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB22E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB355.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB366.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB538.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB5B9.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB6D2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB7CC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldB92.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldBB2F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldBC1F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldBCDB.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldBCFB.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldBF9B.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC009.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC13F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC142.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC20.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC2D5.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC6DA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC7FA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC836.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC84E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldC9FA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCA05.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCAE3.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCAE4.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCB92.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCBE.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCBFD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCC09.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCC19.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCCB5.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCD95.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCEAD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCF2A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCF47.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldCF87.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD004.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD14C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD179.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD335.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD36C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD3EC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD45A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD4D1.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD54D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD648.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldD783.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDA07.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDA1F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDA74.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDAA1.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDB1A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDB8F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDC49.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDD53.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDE2F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldDE3D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE09E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE12C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE17C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE1D7.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE33F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE342.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE3DD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE496.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldE551.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldEB4D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldEB71.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldEC58.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF3B2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF431.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF495.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF4B6.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF4F7.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF540.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF6C2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF8AD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF932.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldF940.tmp -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024\ldFF7.tmp -> Trojan.Small : Cleaned with backup (quarantined).


    ::Report end

     
  7. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    SmitFraudFix v2.183

    Scan done at 22:10:50,48, la 19.05.2007
    Run from C:\Documents and Settings\DTK Computer\Ty”p”yt„\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}"="Reload Browse"

    [HKEY_CLASSES_ROOT\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}\InProcServer32]
    @="C:\WINDOWS\system32\svchosts.dll"

    [HKEY_CURRENT_USER\Software\Classes\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}\InProcServer32]
    @="C:\WINDOWS\system32\svchosts.dll"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"="Security Update"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{01b55afa-f451-474b-9e91-c35b24d02641}"="boob"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{da3b49f6-8c54-4429-a275-21a86dcca413}"="admissibility"


    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\WINDOWS\warnhp.html Deleted
    C:\WINDOWS\system32\ot.ico Deleted
    C:\WINDOWS\system32\st3.dll Deleted
    C:\WINDOWS\system32\ts.ico Deleted
    C:\Documents and Settings\DTK Computer\Application Data\Skinux\ Deleted
    C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Security Troubleshooting.url Deleted
    C:\DOCUME~1\DTKCOM~1\Suosikit\Antivirus Test Online.url Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer=193.210.18.18,212.213.216.195
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer=193.210.18.18,212.213.216.195
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer=193.210.18.18,212.213.216.195


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "system"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    HKLM\SOFTWARE\PSGuard.com Deleted

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

     
  8. Hujo

    Hujo Guest

    Lataa Dr.Web CureIt työpöydälle:

    Tuplaklikkaa drweb-cureit.exe ja anna sen tehdä express scan
    Se skannaa käynnissä olevat ohjelmat ja jos jotain löytyy, klikkaa yes kun se kysyy haluatko poistaa sen. Tämä on vain lyhyt scan.
    Kun scan on valmis, merkkaa asemat, jotka haluat scannata.
    Valitse kaikki asemat. Punainen piste osoittaa, mitkä asemat on valittu.
    Klikaa vihreää nuolta oikealla ja scan alkaa.
    Klikkaa 'Yes to all', jos kysytään haluatko poistaa/siirtää tiedoston.
    Kun scan on valmis, katso voitko klikata next-kuvaketta löytyneiden tiedostojen vieressä: [​IMG]
    Jos asia on niin, klikkaa sitä ja sitten klikkaa next-kuvaketta oikealla alhaalla ja valitse Move incurable kuten alla olevalla kuvassa:
    [​IMG]
    Tämä siirtää sen %userprofile%\DoctorWeb\quarantine-hakemistoon.
    Tämän jälkeen klikkaa Dr.Web CureIt-valikossa file ja valitse save report list
    Tallenna raportti työpöydälle. Raportin nimi on DrWeb.csv
    Sulje Dr.Web Cureit.
    Käynnistä kone uudelleen !! Tämä siksi, että käytössä olevat tiedostot poistetaan/siirretään käynnistyksen yhteydessä.
    Käynnistyksen jälkeen liitä Dr.Web-lokin, jonka tallensit aiemmin, sisältö seuraavaan vastaukseesi.
     
  9. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    Dr. Web-loki:

    Process.exe;C:\Documents and Settings\DTK Computer\Työpöytä\SmitfraudFix;Tool.Prockill;Incurable.Moved.;
    restart.exe;C:\Documents and Settings\DTK Computer\Työpöytä\SmitfraudFix;Tool.ShutDown.11;Incurable.Moved.;
    A0310418.exe;C:\System Volume Information\_restore{0403B3BA-2F2A-48AB-B4D9-D9783FCFA8E1}\RP609;Trojan.DownLoader.based;Deleted.;
    A0313257.exe;C:\System Volume Information\_restore{0403B3BA-2F2A-48AB-B4D9-D9783FCFA8E1}\RP616;Trojan.DownLoader.based;Deleted.;
     
  10. Hujo

    Hujo Guest

    Poista tuo Trend Micro HijackThis:n v2.0.0 (BETA) versio
    lisää poista sovelutuksesta.

    lataa tuosta HijackThis:n 1.99.1 versio

    Lataa hjt:n tuosta http://koti.mbnet.fi/pattaya1/lataus/hijackthis_self.exe

    asenna naputtele numero järjestyksessä

    1.Unzip
    2.OK
    3.Close

    scannaa paina tuosta > Do a system scan and save a logfile

    Kopioi ponnahtava muistio hjt loki ja laita tänne.
     
    Last edited by a moderator: May 20, 2007
  11. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    Tässäpä tämä..

    ---

    Logfile of HijackThis v1.99.1
    Scan saved at 13:31:43, on 20.5.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\pchtls32.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Contact Manager 2007\Alerts.exe
    C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    C:\lotus\wordpro\ltsstart.exe
    C:\lotus\register\remind32.exe
    C:\lotus\smartctr\suitest.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
    O4 - HKLM\..\Run: [LOUDPOLL] C:\PROGRA~1\info bend\funk mess sixth.exe
    O4 - HKLM\..\Run: [ofwl] C:\WINDOWS\ofwl.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
    O4 - HKLM\..\Run: [PCHelp tools] C:\WINDOWS\system32\pchtls32.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [Etma] C:\Documents and Settings\DTK Computer\Application Data\tuhh.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Contact Manager Alerts] C:\Program Files\Contact Manager 2007\Alerts.exe
    O4 - Startup: Lotus Opetusohjelma.lnk = C:\lotus\wordpro\ltsstart.exe
    O4 - Startup: Lotus SmartSuite 97 rekisteröiminen.lnk = C:\lotus\register\remind32.exe
    O4 - Startup: Lotus SuiteStart 97.lnk = C:\lotus\smartctr\suitest.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Free WebSite Tools.lnk = ?
    O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer = 193.210.18.18,212.213.216.195
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O19 - User stylesheet: (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod-palvelu (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

     
  12. Hujo

    Hujo Guest

    scannaa hjt:llä merkkaa paina Fix checked

    O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
    O4 - HKLM\..\Run: [ofwl] C:\WINDOWS\ofwl.exe
    O4 - HKLM\..\Run: [ghmhyzup.exe] C:\WINDOWS\system32\ghmhyzup.exe
    O4 - HKCU\..\Run: [Etma] C:\Documents and Settings\DTK Computer\Application Data\tuhh.exe

    ========

    Lataa NoLop työpöydällesi yhdestä seuraavista linkeistä...
    Linkki1
    Linkki2
    Linkki3

    1.Sulje kaikki ohjelmat, koska tämä vaihe vaatii uudelleenkäynnistyksen
    2.Tuplaklikkaa NoLop.exe ajaaksesi sen
    3.Klikkaa nappulaa "Search and Destroy"
    <<Tietokoneesi skannataan saastuneiden tiedostojen osalta>>
    4, Kun skannaus on valmis, sinua pyydetään käynnistämään kone uudestaan, jos infektio löytyy. Klikkaa OK
    5. Klikkaa "REBOOT"-painiketta.
    6. NoLopin pitäisi antaa viesti. Jos ei, tuplaklikkaa ohjelmaa ja se valmistuu. Lähetä C:\NoLop.log-tiedoston sisältö uuden HijackThis-lokin kera.
    -- Jos saat seuraavan virheen, "mscomctl.ocx or one of its dependencies are not correctly registered," lataa mscomctl.ocx ja tallenna se system32-hakemistoosi (yleensä c:\Windows\system32). Tämän jälkeen aja ohjelma uudestaan.
     
  13. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    NoLop! Log by Skate_Punk_21

    Please Note: any existing old logs will have now been renamed to NoLop!OLD.log

    Fix running from: C:\Documents and Settings\DTK Computer\Työpöytä
    [20.5.2007]
    [14:02:30]

    ---Infection Files Found/Removed---
    NO INFECTION FILES FOUND - Cleaning Aborted.

    ---Listing AppData sub directories---

    C:\Documents and Settings\All Users\Application Data\Adobe
    C:\Documents and Settings\All Users\Application Data\Apple Computer
    C:\Documents and Settings\All Users\Application Data\Google
    C:\Documents and Settings\All Users\Application Data\Microsoft
    C:\Documents and Settings\All Users\Application Data\Msn6
    C:\Documents and Settings\All Users\Application Data\Quicktime
    C:\Documents and Settings\All Users\Application Data\Skype
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    C:\Documents and Settings\All Users\Application Data\Symantec
    C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    C:\Documents and Settings\All Users\Application Data\Winsoftware
    C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    C:\Documents and Settings\Default User\Application Data\Identities
    C:\Documents and Settings\Default User\Application Data\Microsoft
    C:\Documents and Settings\Dtk Computer\Application Data\Acd Systems
    C:\Documents and Settings\Dtk Computer\Application Data\Adobe
    C:\Documents and Settings\Dtk Computer\Application Data\Adobeum -- EMPTY Directory
    C:\Documents and Settings\Dtk Computer\Application Data\Album Shaper
    C:\Documents and Settings\Dtk Computer\Application Data\Apple Computer
    C:\Documents and Settings\Dtk Computer\Application Data\Crystal Art Software
    C:\Documents and Settings\Dtk Computer\Application Data\Cyberlink
    C:\Documents and Settings\Dtk Computer\Application Data\Ebss -- EMPTY Directory
    C:\Documents and Settings\Dtk Computer\Application Data\F-secure
    C:\Documents and Settings\Dtk Computer\Application Data\Fifa2003cc
    C:\Documents and Settings\Dtk Computer\Application Data\Filemaker
    C:\Documents and Settings\Dtk Computer\Application Data\Flightgear.org
    C:\Documents and Settings\Dtk Computer\Application Data\Fltk.org -- EMPTY Directory
    C:\Documents and Settings\Dtk Computer\Application Data\Google
    C:\Documents and Settings\Dtk Computer\Application Data\Help -- EMPTY Directory
    C:\Documents and Settings\Dtk Computer\Application Data\Identities
    C:\Documents and Settings\Dtk Computer\Application Data\Intertrust
    C:\Documents and Settings\Dtk Computer\Application Data\Lavasoft
    C:\Documents and Settings\Dtk Computer\Application Data\Macromedia
    C:\Documents and Settings\Dtk Computer\Application Data\Microsoft
    C:\Documents and Settings\Dtk Computer\Application Data\Mozilla
    C:\Documents and Settings\Dtk Computer\Application Data\Msn6
    C:\Documents and Settings\Dtk Computer\Application Data\Nvu
    C:\Documents and Settings\Dtk Computer\Application Data\Openoffice.org2
    C:\Documents and Settings\Dtk Computer\Application Data\Opera
    C:\Documents and Settings\Dtk Computer\Application Data\Otvreg
    C:\Documents and Settings\Dtk Computer\Application Data\Ppmate
    C:\Documents and Settings\Dtk Computer\Application Data\Real
    C:\Documents and Settings\Dtk Computer\Application Data\Skype
    C:\Documents and Settings\Dtk Computer\Application Data\Symantec
    C:\Documents and Settings\Dtk Computer\Application Data\Talkback
    C:\Documents and Settings\Dtk Computer\Application Data\Template
    C:\Documents and Settings\Dtk Computer\Application Data\Vlc
    C:\Documents and Settings\Dtk Computer\Application Data\Webroot
    C:\Documents and Settings\Dtk Computer\Application Data\Winsoftware
    C:\Documents and Settings\Dtk Computer\Application Data\X-chat 2
    C:\Documents and Settings\Dtk Computer\Application Data\Xnview -- EMPTY Directory
    C:\Documents and Settings\Dtk Computer\Application Data\Ytcd2004
    C:\Documents and Settings\Dtk Computer\Application Data\Ytcd2005
    C:\Documents and Settings\Dtk Computer\Application Data\Ytcd2006
    C:\Documents and Settings\Localservice\Application Data\Microsoft
    C:\Documents and Settings\Localservice\Application Data\Webroot
    C:\Documents and Settings\Networkservice\Application Data\Microsoft
    C:\Documents and Settings\Networkservice\Application Data\Mozilla

    Seuraavassa sitten tuo uusi HjT-logi:

    Logfile of HijackThis v1.99.1
    Scan saved at 14:09:04, on 20.5.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\pchtls32.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Contact Manager 2007\Alerts.exe
    C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    C:\lotus\wordpro\ltsstart.exe
    C:\lotus\register\remind32.exe
    C:\lotus\smartctr\suitest.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\HJT\HijackThis.exe
    C:\Program Files\Mozilla Firefox\firefox.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LOUDPOLL] C:\PROGRA~1\info bend\funk mess sixth.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
    O4 - HKLM\..\Run: [PCHelp tools] C:\WINDOWS\system32\pchtls32.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Contact Manager Alerts] C:\Program Files\Contact Manager 2007\Alerts.exe
    O4 - Startup: Lotus Opetusohjelma.lnk = C:\lotus\wordpro\ltsstart.exe
    O4 - Startup: Lotus SmartSuite 97 rekisteröiminen.lnk = C:\lotus\register\remind32.exe
    O4 - Startup: Lotus SuiteStart 97.lnk = C:\lotus\smartctr\suitest.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Free WebSite Tools.lnk = ?
    O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{18BB8178-C223-4E64-8E91-AF45A6FB9098}: NameServer = 193.210.18.18,212.213.216.195
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O19 - User stylesheet: (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod-palvelu (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
    Last edited: May 20, 2007
  14. Hujo

    Hujo Guest

    Lataa Atribunen ATF Cleaner

    Ohjeet;

    Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman.Main:n alla valitse: Select All
    Klikkaa Empty Selected valintaa.
    Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All
    Klikkaa Empty Selected valintaa.
    HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
    Jos käytät Operaa selaimenasiKlikkaa Opera yläpuolelta ja valitse: Select All
    Klikkaa Empty Selected valintaa taas.
    HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
    Klikkaa Exit päävalikosta sulkeaksesi ohjelman.
    Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi)


    Jokos ongelmat loppu?
     
  15. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    Eiköhän tämä pikku hiljaa ala olemaan jo puhdas kone. Vielä yksi asia täytyy mainita. Tuonne ruudun oikeaan alareunaan ilmestyy aina välillä keltainen kolmio (jossa on huutomerkki päällä), sen myötä ilmestyy pieneen laatikkoon teksti "Integrity threats found", tms. Saakohan tuon vielä jollain tapaa pois, vai miten on?
     
  16. Hujo

    Hujo Guest

    Scannaa hjt:llä merkkaa paina Fix checked

    O4 - HKLM\..\Run: [PCHelp tools] C:\WINDOWS\system32\pchtls32.exe


    mene vikasietotilaan

    Poista jos löytyy

    C:\WINDOWS\system32\pchtls32.exe
    C:\WINDOWS\ofwl.exe
    C:\WINDOWS\sxchost.exe
    C:\WINDOWS\system32\ghmhyzup.exe
    C:\Documents and Settings\DTK Computer\Application Data\tuhh.exe
    C:\Program Files\Video AX Object
    C:\Program Files\VirusBurster

    =====================
    Takasin normaaliin tilaan

    1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
    2. Valitse ominaisuudet
    3. Valitse järjestelmän palauttaminen välilehti
    4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
    5. Paina Käytä
    6. Paina ok
    7. Sammuta ja käynnistä
    8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
    9. Käytä ja OK

    ================

    scannaa vielä escanilla

    Ohjeet tuolla sivulla.
    http://koti.mbnet.fi/pattaya1/escanmwav.htm
    lataa tuosta
    http://www.spywareinfo.dk/download/mwav.exe
    päivitä tuosta
    http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat
    laita täpit merkkauksien mukaan
    http://koti.mbnet.fi/pattaya1/eScan6.jpg

    scannaa

    jos ala luukkuun tulee jotain niin kopioi se näin:
    Käytä komentoa Ctrl+A.
    Kopioi rivit komennolla Ctrl+C.
    Liitä rivit komennolla Ctrl+V.

    Laita virus log tänne.
     
    Last edited by a moderator: May 20, 2007
  17. pczippas

    pczippas Guest

    Kysyisin sellasta hommaa näistä skannauksista että tehdäänkö ne nettiboxin ollessa päällä vai pois?Toinen ei niin asiaan liittyvä juttu olisi miten saan liitettyä kuvakaappauksella tehdyn kuvan viestiini?
    Tiedoista etukäteen kiitollinen.
     
  18. koW4Rlock

    koW4Rlock Regular member

    Joined:
    Apr 5, 2007
    Messages:
    353
    Likes Received:
    0
    Trophy Points:
    26
    painat print screen, meet painttiin ja painat ctrl+V ja tallennat jpg:nä ja pistät vaikka imageshckiin/afterdawnin omaan tai jonnekki muuhu kuvien esittely paikkaa :)

     
  19. anttih_

    anttih_ Member

    Joined:
    Jan 2, 2007
    Messages:
    62
    Likes Received:
    0
    Trophy Points:
    16
    Tässä sitten nämä alaluukkuun ilmestyneet tekstit eScanista:

    File C:\WINDOWS\secure.0tml infected by "Trojan.Win32.Harnig.a" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\secureb.0tml infected by "Trojan.Win32.Harnig.a" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS.zip infected by "Password-protected-EXE" Virus. Action Taken: File Renamed.
    File C:\Documents and Settings\DTK Computer\Omat tiedostot\päättötyö.wps infected by "BkCln.Unknown" Virus. Action Taken: File Renamed.
    File C:\sderqe32.exe infected by "Trojan.Win32.Obfuscated.ev" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{0403B3BA-2F2A-48AB-B4D9-D9783FCFA8E1}\RP1\A0000009.exe infected by "Trojan.Win32.Obfuscated.ev" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\system32\tptbtcfs\tptbtcfs1.exe tagged as not-a-virus:FraudTool.Win32.UltimateDefender.c. No Action Taken.
    File C:\WINDOWS\system32\tptbtcfs\tptbtcfs3.exe tagged as not-a-virus:FraudTool.Win32.UltimateDefender.c. No Action Taken.
     
    Last edited: May 20, 2007
  20. pczippas

    pczippas Guest

    Jep,kuva olisi jo .jpg:nä mutta en osaa liittää sitä viestiin,kyse on
    Advanced WindowsCare V2 Personal ohjelman löydöstä,en saa kyseisellä ohjelmalla logia jonka voisin lähettää tänne HjT login seuraksi.
    Asia liittyy rekisteri virheisiin jotka ei vain yksinkertaisesti korjaannu kyseisellä ohjelmalla.kone on skannattu AVG Spy-Ware;lla,
    eScan:illa,Smirf:illä,Compofix:illä...AVG Anti-Virus ohjelmilla normaalitilassa ja vikasietotilassa.
    mitään ei ole kyseiset ohjelmat löytäneet.
    Kyseiset rekisterin sekä laitteisto asetusten virheet liittyvät
    \CurrentVersion\Policies\Explorer\ rekisteriin.
    Niin,voisiko joku ystävällisesti neuvoa .jpg kuvan liittämisen viestiin.
     

Share This Page