Logfile of HijackThis v1.99.1 Scan saved at 14:06:03, on 28.7.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\F-Secure\Common\FSMB32.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure\Common\FCH32.EXE C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsqh.exe C:\Program Files\F-Secure\FSAUA\program\fsaua.exe C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\HP\HP Software Update\HPwuSchd2.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\F-Secure\Common\FSM32.EXE C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\F-Secure\FSGUI\fsguidll.exe C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Microsoft Office\Office\FINDFAST.EXE C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Microsoft Office\Office\OSA.EXE C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\svchost.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\ALCXMNTR.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe c:\windows\system\hpsysdrv.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FI_FI&c=63&bd=PRESARIO&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FI_FI&c=63&bd=PRESARIO&pf=desktop R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://redirect.hp.com/svs/rdr?TYPE=4&tp=dticon&s=Yahoo&pf=desktop&locale=fi_fi&bd=all&c=63 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Yhteysohje - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Yhteysohje - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll O11 - Options group: [INTERNATIONAL] International* O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\AVG Anti-Spyware 7.5 Oikea\AVG Anti-Spyware 7.5\guard.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
No enhän mä nyt onnistunut ottamaan raporttia. Sieltä löytyi vain worm.VB.dw. Mutta tämänkin pitäisi olla vain "No cd-crack" peliin. Pystytkö etenemään ilman tätä raporttia?
eipä tuossa lokissa näy erikoista, mutta kaikkihan ei näy lokissa joten kaivetaas tuolla escanilla. Ohjeet tuolla sivulla. http://koti.mbnet.fi/pattaya1/escanmwav.htm lataa tuosta http://www.spywareinfo.dk/download/mwav.exe päivitä tuosta http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat laita täpit merkkauksien mukaan http://koti.mbnet.fi/pattaya1/eScan6.jpg scannaa jos ala luukkuun tulee jotain niin kopioi se näin: Käytä komentoa Ctrl+A. Kopioi rivit komennolla Ctrl+C. Liitä rivit komennolla Ctrl+V. Laita virus log tänne.
Mon Jul 30 18:53:12 2007 => ********************************************************** Mon Jul 30 18:53:12 2007 => eScan AntiVirus Toolkit Utility. Mon Jul 30 18:53:12 2007 => Copyright © 2003-2004, MicroWorld Technologies Inc. Mon Jul 30 18:53:12 2007 => ********************************************************** Mon Jul 30 18:53:12 2007 => Version 4.4.7 Mon Jul 30 18:53:12 2007 => Log File: C:\KASPER~1\mwav.log Mon Jul 30 18:53:12 2007 => Latest Date of files inside MWAV: 13 May 2007 14:04:31. Mon Jul 30 18:53:14 2007 => AV Library Loaded... Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavss.exe Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\Getvlist.exe Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavss.dll Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavssdi.dll Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavssi.dll Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\kavvlg.dll Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\msvlclnt.dll Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\ipc.dll Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\main.avi Mon Jul 30 18:53:14 2007 => Scanning File C:\KASPER~1\virus.avi Mon Jul 30 18:53:14 2007 => Virus Database Date: 2007/05/13 Mon Jul 30 18:53:14 2007 => Virus Database Count: 318294 Mon Jul 30 19:16:39 2007 => ********************************************************** Mon Jul 30 19:16:39 2007 => eScan AntiVirus Toolkit Utility. Mon Jul 30 19:16:39 2007 => Copyright © 2003-2004, MicroWorld Technologies Inc. Mon Jul 30 19:16:39 2007 => ********************************************************** Mon Jul 30 19:16:39 2007 => Version 4.4.7 Mon Jul 30 19:16:39 2007 => Log File: C:\KASPER~1\mwav.log Mon Jul 30 19:16:40 2007 => Latest Date of files inside MWAV: 30 Jul 2007 18:18:19. Mon Jul 30 19:16:41 2007 => AV Library Loaded... Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavss.exe Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\Getvlist.exe Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavss.dll Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavssdi.dll Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavssi.dll Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\kavvlg.dll Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\msvlclnt.dll Mon Jul 30 19:16:41 2007 => Scanning File C:\KASPER~1\ipc.dll Mon Jul 30 19:16:42 2007 => Scanning File C:\KASPER~1\main.avi Mon Jul 30 19:16:42 2007 => Scanning File C:\KASPER~1\virus.avi Mon Jul 30 19:16:42 2007 => Virus Database Date: 2007/07/30 Mon Jul 30 19:16:42 2007 => Virus Database Count: 369716 Mon Jul 30 19:17:12 2007 => ********************************************************** Mon Jul 30 19:17:12 2007 => eScan AntiVirus Toolkit Utility. Mon Jul 30 19:17:12 2007 => Copyright © 2003-2004, MicroWorld Technologies Inc. Mon Jul 30 19:17:12 2007 => Mon Jul 30 19:17:12 2007 => Support: support@mwti.net Mon Jul 30 19:17:12 2007 => Web: http://www.mwti.net Mon Jul 30 19:17:12 2007 => ********************************************************** Mon Jul 30 19:17:12 2007 => Version 4.4.7 Mon Jul 30 19:17:12 2007 => Log File: C:\KASPER~1\mwav.log Mon Jul 30 19:17:12 2007 => Latest Date of files inside MWAV: 30 Jul 2007 18:18:19. Mon Jul 30 19:17:12 2007 => Options Selected by User: Mon Jul 30 19:17:12 2007 => Memory Check: Enabled Mon Jul 30 19:17:12 2007 => Registry Check: Enabled Mon Jul 30 19:17:12 2007 => StartUp Folder Check: Enabled Mon Jul 30 19:17:12 2007 => System Folder Check: Enabled Mon Jul 30 19:17:12 2007 => System Area Check: Disabled Mon Jul 30 19:17:12 2007 => Services Check: Enabled Mon Jul 30 19:17:12 2007 => Drive Check: Disabled Mon Jul 30 19:17:12 2007 => All Drive Check :Enabled Mon Jul 30 19:17:12 2007 => Scanning Type: Scan And Clean Mon Jul 30 19:17:12 2007 => Folder Check: Disabled
Tästä tulikin nyt säätö. Ei jaksa jauhaa koko lokitiedostoa. Antaa liittää,mutta ei jaksa lähettää - junkaa vain. Yhteenveto nyt kuitenkin alla. Kerrohan jos tarvitset lisäinfoa lokista. Mon Jul 30 20:56:30 2007 => ***** Checking for specific ITW Viruses ***** Mon Jul 30 20:56:31 2007 => Checking for Welchia Virus... Mon Jul 30 20:56:31 2007 => Checking for LovGate Virus... Mon Jul 30 20:56:31 2007 => Checking for CodeRed Virus... Mon Jul 30 20:56:31 2007 => Checking for OpaServ Virus... Mon Jul 30 20:56:31 2007 => Checking for Sobig.e Virus... Mon Jul 30 20:56:31 2007 => Checking for Winupie Virus... Mon Jul 30 20:56:31 2007 => Checking for Swen Virus... Mon Jul 30 20:56:31 2007 => Checking for JS.Fortnight Virus... Mon Jul 30 20:56:31 2007 => Checking for Novarg Virus... Mon Jul 30 20:56:31 2007 => Checking for Pagabot Virus... Mon Jul 30 20:56:31 2007 => Checking for Parite.b Virus... Mon Jul 30 20:56:31 2007 => Checking for Parite.a Virus... Mon Jul 30 20:56:31 2007 => ***** Scanning complete. ***** Mon Jul 30 20:56:31 2007 => Total Number of Files Scanned: 70276 Mon Jul 30 20:56:31 2007 => Total Number of Virus(es) Found: 1 Mon Jul 30 20:56:31 2007 => Total Number of Disinfected Files: 0 Mon Jul 30 20:56:31 2007 => Total Number of Files Renamed: 0 Mon Jul 30 20:56:31 2007 => Total Number of Deleted Files: 1 Mon Jul 30 20:56:31 2007 => Total Number of Errors: 104 Mon Jul 30 20:56:31 2007 => Time Elapsed: 01:39:18 Mon Jul 30 20:56:31 2007 => Virus Database Date: 2007/07/30 Mon Jul 30 20:56:31 2007 => Virus Database Count: 369716 Mon Jul 30 20:56:31 2007 => Scan Completed
mä en tiedä tarkkaan mikä se on, kun herjaa no cd crackistä GTA:ssa. Onko tuolla jotain muuta roskaa( hjt:ssä), jotka korjata? Kiitti
Javan päivitys ja välimuistin tyhjennys: 1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa. 2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... ) Niissä pitäisi olla seuraava kuva vieressä: 3. Valitse kaikki entiset Java versiosi ja valitse Poista. 4. Asenna uusin Java päivitys seuraavasta linkistä.. 5. Käynnistä kone uudelleen asennuksen jälkeen: http://java.sun.com/javase/downloads/index.jsp Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u2 Paina Download Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se. 6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi). 7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia. (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa. Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle). 8. Varmista että kaikki kaksi valintaa ovat rastitettuja: *Applications and Applets *Trace and Log Files Ja paina OK -nappia 9. Klikkaa OK "Temporary Files Settings" -ikkunassasi. 10. Klikkaa OK jättääksesi Java asetusikkunasi. =======================0 Lataa tuolta http://www.ccleaner.com/download/builds.aspx CCleaner v1.41.544 - Basic, ÄLÄ aseenna Yahoo toolbaria! laita asetukset näin: Valinnat --> Lisäasetukset --> Ota ruksi pois kohdasta Poista vain yli 48 tuntia vanhat tilapäistiedostot. aja Puhdistaja > tutki nappi > aja ccleaner nappi oikea alakulma aja Virheet > etsi rekisteri virheitä nappi > Korjaa rekisteri virheet. nappi