koneeseeni pesi jokin "koijari". Kun explorerin avaa, kotisivua ei voi muuttaa vaan se on jokin "safetyupdate.net"joka kertoo että koneessani on mato tms. ja kehoittaa klikkaamaan kuvaketta jonka kautta voi ostaa siihen poistoohjelman.Mikään haittapoisto-ohjelma ei ole kyennyt matoa poistamaan koneestani ja keinoni alkaa loppumaan. Voisiko joku kertoa mitä pitäisi tehdä? Säännöllisesti koneen oikeaan alalaitaan ilmestyi keltainen kolmio ja teksi että kone on saastunut. Lisäksi välillä tuli pop-uppeja vaikka selain ei ollut auki.Sain ne pois kun tyhjensin regeditillä explorerin history-rekisterit tyhjäksi. Joku haittapoisto ohjelma läysi jonkin smitfraud-systeemin ja ei kuitenkaan sitä poistanut. Mikä lie ollut? Mutta millä tuon exploreri-ongelman saisi pois?
Logfile of HijackThis v1.99.1 Scan saved at 16:21:11, on 18.6.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\atmclk.exe C:\WINDOWS\system32\dcomcfg.exe C:\ATI-CPanel\atiptaxx.exe C:\Norman\bin\ZLH.EXE C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\Logitech\Profiler\lwemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\WinTV\Ir.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Norman\Bin\Zanda.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wdfmgr.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Norman\Nvc\bin\nvcoas.exe C:\Norman\bin\NJEEVES.EXE C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\BIN\nipsvc.exe C:\WINDOWS\System32\alg.exe C:\Norman\Nvc\bin\cclaw.exe C:\WINDOWS\System32\msiexec.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Vilma\Omat tiedostot\Ylläpito\Haittaohjelmien poisto\Hijack\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fi R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [ToniArts EasyCleaner] "C:\Program Files\ToniArts\EasyCleaner\EasyClea.exe" -s -startup O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132952094024 O18 - Protocol: bw+0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw+0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw-0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw-0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw00 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw00s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw10 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw10s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw20 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw20s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw30 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw30s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw40 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw40s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw50 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw50s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw60 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw60s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw70 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw70s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw80 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw80s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw90 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw90s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwa0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwa0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwb0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwb0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwc0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwc0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwd0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwd0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwe0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwe0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwf0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwf0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file) O18 - Protocol: bwg0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwg0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwh0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwh0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwi0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwi0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwj0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwj0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwk0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwk0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwl0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwl0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwm0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwm0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwn0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwn0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwo0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwo0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwp0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwp0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwq0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwq0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwr0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwr0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bws0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bws0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwt0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwt0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwu0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwu0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwv0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwv0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bww0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bww0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwx0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwx0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwy0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwy0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwz0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwz0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: offline-8876480 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe ################33 tässä tämä minun logitiedosto. Vastauksia odotellen.....
Lataa SmitfraudFix © S!Ri http://siri.urz.free.fr/Fix/SmitfraudFix.zip Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi: Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa). Postita tämän tekstitiedoston sisältö viestiketjuusi.
SmitFraudFix v2.61 Scan done at 17:46:50,04, su 18.06.2006 Run from C:\Documents and Settings\Vilma\Omat tiedostot\Yll„pito\Haittaohjelmien poisto\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\atmclk.exe FOUND ! C:\WINDOWS\system32\dcomcfg.exe FOUND ! C:\WINDOWS\system32\hp???.tmp FOUND ! C:\WINDOWS\system32\hp????.tmp FOUND ! C:\WINDOWS\system32\ld????.tmp FOUND ! C:\WINDOWS\system32\simpole.tlb FOUND ! C:\WINDOWS\system32\stdole3.tlb FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vilma\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Vilma\Suosikit C:\DOCUME~1\Vilma\Suosikit\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Nykyinen kotisivu" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{8dc1f789-e073-4363-b40d-07376bc5ecc5}"="articulation" [HKEY_CLASSES_ROOT\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32] »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End siinähän se....
Avaa HijackThis, paina do a system scan only ja merkkaa nämä: O18 - Protocol: bw+0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw+0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw-0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw-0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw00 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw00s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw10 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw10s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw20 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw20s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw30 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw30s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw40 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw40s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw50 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw50s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw60 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw60s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw70 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw70s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw80 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw80s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw90 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bw90s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwa0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwa0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwb0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwb0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwc0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwc0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwd0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwd0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwe0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwe0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwf0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwf0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file) O18 - Protocol: bwg0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwg0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwh0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwh0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwi0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwi0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwj0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwj0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwk0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwk0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwl0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwl0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwm0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwm0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwn0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwn0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwo0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwo0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwp0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwp0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwq0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwq0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwr0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwr0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bws0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bws0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwt0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwt0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwu0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwu0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwv0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwv0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bww0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bww0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwx0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwx0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwy0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwy0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwz0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: bwz0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) O18 - Protocol: offline-8876480 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file) sulje kaikki ikkunat ja paina fix cheked Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi http://www.pchell.com/support/safemode.shtml Kun vikasietotilassa, avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot. Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet. Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter". Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin. Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi. Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt. Lähetä lisäksi uusi HijackThis loki.
SmitFraudFix v2.61 Scan done at 18:35:38,84, su 18.06.2006 Run from C:\Documents and Settings\Vilma\Omat tiedostot\Yll„pito\Haittaohjelmien poisto\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{8dc1f789-e073-4363-b40d-07376bc5ecc5}"="articulation" [HKEY_CLASSES_ROOT\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32] »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\atmclk.exe Deleted C:\WINDOWS\system32\dcomcfg.exe Deleted C:\WINDOWS\system32\hp???.tmp Deleted C:\WINDOWS\system32\ld????.tmp Deleted C:\WINDOWS\system32\simpole.tlb Deleted C:\WINDOWS\system32\stdole3.tlb Deleted C:\DOCUME~1\Vilma\Suosikit\Antivirus Test Online.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End ja lisäksi uusi hijackThis logi Logfile of HijackThis v1.99.1 Scan saved at 18:41:10, on 18.6.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\ATI-CPanel\atiptaxx.exe C:\Norman\bin\ZLH.EXE C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\Logitech\Profiler\lwemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\WinTV\Ir.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Norman\Bin\Zanda.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wdfmgr.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\WINDOWS\System32\wbem\wmiprvse.exe C:\Norman\Nvc\bin\nvcoas.exe C:\Norman\bin\NJEEVES.EXE C:\Norman\Nvc\BIN\nipsvc.exe C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\WINDOWS\System32\alg.exe C:\Norman\Nvc\bin\cclaw.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\wbem\wmiprvse.exe C:\Documents and Settings\Vilma\Omat tiedostot\Ylläpito\Haittaohjelmien poisto\Hijack\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [ToniArts EasyCleaner] "C:\Program Files\ToniArts\EasyCleaner\EasyClea.exe" -s -startup O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132952094024 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe siinäpä ne.....mitäs sitten seuraavaksi? Mutta nytpä tuo tuntuu toimivan, ei herjaa eikä tule pop-uppeja.