HJT-lokiin proapua kiitos

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by mickeyboy, Jul 28, 2007.

  1. mickeyboy

    mickeyboy Member

    Joined:
    May 13, 2005
    Messages:
    71
    Likes Received:
    0
    Trophy Points:
    16
    Logfile of HijackThis v1.99.1
    Scan saved at 14:06:03, on 28.7.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\F-Secure\FSGUI\fsguidll.exe
    C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    c:\windows\system\hpsysdrv.exe
    C:\PROGRA~1\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FI_FI&c=63&bd=PRESARIO&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FI_FI&c=63&bd=PRESARIO&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://redirect.hp.com/svs/rdr?TYPE=4&tp=dticon&s=Yahoo&pf=desktop&locale=fi_fi&bd=all&c=63
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Yhteysohje - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Yhteysohje - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
     
  2. Hujo

    Hujo Guest

    Ookos ajelut AVG Anti-Spyware 7.5 konetta lävitse vikasietotilassa?
    Päivitä ennen ajoa.
     
  3. mickeyboy

    mickeyboy Member

    Joined:
    May 13, 2005
    Messages:
    71
    Likes Received:
    0
    Trophy Points:
    16
    No enhän mä nyt onnistunut ottamaan raporttia. :( Sieltä löytyi vain worm.VB.dw. Mutta tämänkin pitäisi olla vain "No cd-crack" peliin.
    Pystytkö etenemään ilman tätä raporttia?
     
  4. Hujo

    Hujo Guest

    eipä tuossa lokissa näy erikoista, mutta kaikkihan ei näy lokissa joten kaivetaas tuolla escanilla.

    Ohjeet tuolla sivulla.
    http://koti.mbnet.fi/pattaya1/escanmwav.htm
    lataa tuosta
    http://www.spywareinfo.dk/download/mwav.exe
    päivitä tuosta
    http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat
    laita täpit merkkauksien mukaan
    http://koti.mbnet.fi/pattaya1/eScan6.jpg

    scannaa

    jos ala luukkuun tulee jotain niin kopioi se näin:
    Käytä komentoa Ctrl+A.
    Kopioi rivit komennolla Ctrl+C.
    Liitä rivit komennolla Ctrl+V.


    Laita virus log tänne.
     
    Last edited by a moderator: Jul 29, 2007
  5. mickeyboy

    mickeyboy Member

    Joined:
    May 13, 2005
    Messages:
    71
    Likes Received:
    0
    Trophy Points:
    16
    Mon Jul 30 18:53:12 2007 => **********************************************************
    Mon Jul 30 18:53:12 2007 => eScan AntiVirus Toolkit Utility.
    Mon Jul 30 18:53:12 2007 => Copyright © 2003-2004, MicroWorld Technologies Inc.
    Mon Jul 30 18:53:12 2007 => **********************************************************
    Mon Jul 30 18:53:12 2007 => Version 4.4.7
    Mon Jul 30 18:53:12 2007 => Log File: C:\KASPER~1\mwav.log
    Mon Jul 30 18:53:12 2007 => Latest Date of files inside MWAV: 13 May 2007 14:04:31.
    Mon Jul 30 18:53:14 2007 => AV Library Loaded...
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavss.exe
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\Getvlist.exe
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavss.dll
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavssdi.dll
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavssi.dll
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavvlg.dll
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\msvlclnt.dll
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\ipc.dll
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\main.avi
    Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\virus.avi
    Mon Jul 30 18:53:14 2007 => Virus Database Date: 2007/05/13
    Mon Jul 30 18:53:14 2007 => Virus Database Count: 318294
    Mon Jul 30 19:16:39 2007 => **********************************************************
    Mon Jul 30 19:16:39 2007 => eScan AntiVirus Toolkit Utility.
    Mon Jul 30 19:16:39 2007 => Copyright © 2003-2004, MicroWorld Technologies Inc.
    Mon Jul 30 19:16:39 2007 => **********************************************************
    Mon Jul 30 19:16:39 2007 => Version 4.4.7
    Mon Jul 30 19:16:39 2007 => Log File: C:\KASPER~1\mwav.log
    Mon Jul 30 19:16:40 2007 => Latest Date of files inside MWAV: 30 Jul 2007 18:18:19.
    Mon Jul 30 19:16:41 2007 => AV Library Loaded...
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavss.exe
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\Getvlist.exe
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavss.dll
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavssdi.dll
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavssi.dll
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavvlg.dll
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\msvlclnt.dll
    Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\ipc.dll
    Mon Jul 30 19:16:42 2007 => Scanning File C:\KASPER~1\main.avi
    Mon Jul 30 19:16:42 2007 => Scanning File C:\KASPER~1\virus.avi
    Mon Jul 30 19:16:42 2007 => Virus Database Date: 2007/07/30
    Mon Jul 30 19:16:42 2007 => Virus Database Count: 369716

    Mon Jul 30 19:17:12 2007 => **********************************************************
    Mon Jul 30 19:17:12 2007 => eScan AntiVirus Toolkit Utility.
    Mon Jul 30 19:17:12 2007 => Copyright © 2003-2004, MicroWorld Technologies Inc.
    Mon Jul 30 19:17:12 2007 =>
    Mon Jul 30 19:17:12 2007 => Support: support@mwti.net
    Mon Jul 30 19:17:12 2007 => Web: http://www.mwti.net
    Mon Jul 30 19:17:12 2007 => **********************************************************
    Mon Jul 30 19:17:12 2007 => Version 4.4.7
    Mon Jul 30 19:17:12 2007 => Log File: C:\KASPER~1\mwav.log
    Mon Jul 30 19:17:12 2007 => Latest Date of files inside MWAV: 30 Jul 2007 18:18:19.

    Mon Jul 30 19:17:12 2007 => Options Selected by User:
    Mon Jul 30 19:17:12 2007 => Memory Check: Enabled
    Mon Jul 30 19:17:12 2007 => Registry Check: Enabled
    Mon Jul 30 19:17:12 2007 => StartUp Folder Check: Enabled
    Mon Jul 30 19:17:12 2007 => System Folder Check: Enabled
    Mon Jul 30 19:17:12 2007 => System Area Check: Disabled
    Mon Jul 30 19:17:12 2007 => Services Check: Enabled
    Mon Jul 30 19:17:12 2007 => Drive Check: Disabled
    Mon Jul 30 19:17:12 2007 => All Drive Check :Enabled
    Mon Jul 30 19:17:12 2007 => Scanning Type: Scan And Clean
    Mon Jul 30 19:17:12 2007 => Folder Check: Disabled
     
  6. mickeyboy

    mickeyboy Member

    Joined:
    May 13, 2005
    Messages:
    71
    Likes Received:
    0
    Trophy Points:
    16
    Tästä tulikin nyt säätö. Ei jaksa jauhaa koko lokitiedostoa. Antaa liittää,mutta ei jaksa lähettää - junkaa vain. Yhteenveto nyt kuitenkin alla. Kerrohan jos tarvitset lisäinfoa lokista.


    Mon Jul 30 20:56:30 2007 => ***** Checking for specific ITW Viruses *****
    Mon Jul 30 20:56:31 2007 => Checking for Welchia Virus...
    Mon Jul 30 20:56:31 2007 => Checking for LovGate Virus...
    Mon Jul 30 20:56:31 2007 => Checking for CodeRed Virus...
    Mon Jul 30 20:56:31 2007 => Checking for OpaServ Virus...
    Mon Jul 30 20:56:31 2007 => Checking for Sobig.e Virus...
    Mon Jul 30 20:56:31 2007 => Checking for Winupie Virus...
    Mon Jul 30 20:56:31 2007 => Checking for Swen Virus...
    Mon Jul 30 20:56:31 2007 => Checking for JS.Fortnight Virus...
    Mon Jul 30 20:56:31 2007 => Checking for Novarg Virus...
    Mon Jul 30 20:56:31 2007 => Checking for Pagabot Virus...
    Mon Jul 30 20:56:31 2007 => Checking for Parite.b Virus...
    Mon Jul 30 20:56:31 2007 => Checking for Parite.a Virus...

    Mon Jul 30 20:56:31 2007 => ***** Scanning complete. *****

    Mon Jul 30 20:56:31 2007 => Total Number of Files Scanned: 70276
    Mon Jul 30 20:56:31 2007 => Total Number of Virus(es) Found: 1
    Mon Jul 30 20:56:31 2007 => Total Number of Disinfected Files: 0
    Mon Jul 30 20:56:31 2007 => Total Number of Files Renamed: 0
    Mon Jul 30 20:56:31 2007 => Total Number of Deleted Files: 1
    Mon Jul 30 20:56:31 2007 => Total Number of Errors: 104
    Mon Jul 30 20:56:31 2007 => Time Elapsed: 01:39:18
    Mon Jul 30 20:56:31 2007 => Virus Database Date: 2007/07/30
    Mon Jul 30 20:56:31 2007 => Virus Database Count: 369716

    Mon Jul 30 20:56:31 2007 => Scan Completed

     
  7. Hujo

    Hujo Guest

    siellä oli virus joka on deletoitu nyt
     
  8. mickeyboy

    mickeyboy Member

    Joined:
    May 13, 2005
    Messages:
    71
    Likes Received:
    0
    Trophy Points:
    16
    mä en tiedä tarkkaan mikä se on, kun herjaa no cd crackistä GTA:ssa.
    Onko tuolla jotain muuta roskaa( hjt:ssä), jotka korjata?

    Kiitti
     
  9. Hujo

    Hujo Guest

    Javan päivitys ja välimuistin tyhjennys:

    1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
    2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
    Niissä pitäisi olla seuraava kuva vieressä: [​IMG]

    3. Valitse kaikki entiset Java versiosi ja valitse Poista.
    4. Asenna uusin Java päivitys seuraavasta linkistä..
    5. Käynnistä kone uudelleen asennuksen jälkeen:

    http://java.sun.com/javase/downloads/index.jsp

    Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u2

    Paina Download

    Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se.

    6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).

    7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia.

    (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa.
    Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle).

    8. Varmista että kaikki kaksi valintaa ovat rastitettuja:

    *Applications and Applets

    *Trace and Log Files

    Ja paina OK -nappia

    9. Klikkaa OK "Temporary Files Settings" -ikkunassasi.

    10. Klikkaa OK jättääksesi Java asetusikkunasi.

    =======================0

    Lataa tuolta http://www.ccleaner.com/download/builds.aspx
    CCleaner v1.41.544 - Basic, ÄLÄ aseenna Yahoo toolbaria!

    laita asetukset näin:
    Valinnat --> Lisäasetukset --> Ota ruksi pois kohdasta Poista vain yli 48 tuntia vanhat tilapäistiedostot.

    aja Puhdistaja > tutki nappi > aja ccleaner nappi oikea alakulma
    aja Virheet > etsi rekisteri virheitä nappi > Korjaa rekisteri virheet. nappi
     
  10. mickeyboy

    mickeyboy Member

    Joined:
    May 13, 2005
    Messages:
    71
    Likes Received:
    0
    Trophy Points:
    16
    Kiitos paljon vinkeistä..
     

Share This Page