Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 18:37:40, on 24.6.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Norman\Npm\bin\ELOGSVC.EXE C:\Norman\Npm\Bin\Zanda.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Norman\Npm\bin\ZLH.EXE C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\CursorXP\CursorXP.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Program Files\Norman\NPF\NPFMSG.EXE C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Norman\NPF\NPFSVICE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Norman\Npm\bin\NJEEVES.EXE C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\bin\nvcoas.exe C:\WINDOWS\System32\alg.exe C:\Norman\Nvc\bin\cclaw.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\MSN Messenger\livecall.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\HJT\HiJackThis_v2.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\Npm\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420" O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Logitech SetPoint.lnk = ? O4 - Global Startup: NPF Messenger.lnk = ? O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Norman\Npm\bin\ELOGSVC.EXE O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\Npm\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Program Files\Norman\NPF\NPFSVICE.EXE O23 - Service: Norman ZANDA - Norman ASA - C:\Norman\Npm\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe O23 - Service: Windows Media Playerin verkkojakamispalvelu (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe -- End of file - 5937 bytes
Uudelleennimeä HijackThis.exe -> scanner.exe:ksi näin: 1. Klikkaa hiiren oikealla painikkeella HijackThis ikonia. 2. Valitse Uudelleennineä/ Rename. 3. Kirjoita scanner.exe Vaihtamalla HJT:n nimeä saamme varmuuden, onko koneellasi Vundo-infektiota. 4. Laita uusi Hijackthis-logi
Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 21:33:20, on 24.6.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Norman\Npm\bin\ELOGSVC.EXE C:\Norman\Npm\Bin\Zanda.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Norman\Npm\bin\ZLH.EXE C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\CursorXP\CursorXP.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Norman\NPF\NPFMSG.EXE C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Norman\NPF\NPFSVICE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Norman\Npm\bin\NJEEVES.EXE C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\bin\nvcoas.exe C:\WINDOWS\System32\alg.exe C:\Norman\Nvc\bin\cclaw.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\MSN Messenger\livecall.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\HJT\scanner.exe.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\Npm\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420" O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Logitech SetPoint.lnk = ? O4 - Global Startup: NPF Messenger.lnk = ? O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Norman\Npm\bin\ELOGSVC.EXE O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\Npm\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Program Files\Norman\NPF\NPFSVICE.EXE O23 - Service: Norman ZANDA - Norman ASA - C:\Norman\Npm\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe O23 - Service: Windows Media Playerin verkkojakamispalvelu (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe -- End of file - 5837 bytes
Tallena nämä ohjeet teksitiedostoon sillä et voi lukea niitä muuten vikasietotilassa. ========== 2. [*]Käynnistä AVG Anti-Spyware. [*]Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta. [*]Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa. [*]Paina hetken kuluttua uudestaan "Start Update" , jos päivitykset eivät heti onnistu [*]Jos automaattipäivitys ei jostain syystä toimi, niin tunnisteet voi ladata manuaalisesti http://www.ewido.net/en/download/updates/ -linkin takaa. [*]Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti. [*]Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine". [*]Sitten "Reports" valikon alta:a [*]Laita täppi kohtaan "Automatically generate report after every scan" [*]Ota täppi pois kohdasta"Only if threats were found" [*]Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa [*]"Resident shield is", muuta tila active:sta inactive:ksi [*]Sulje ohjelma, ÄLÄ skannaa vielä. Käynnistä tietokoneesi vikasietotilaan HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta. [*]Kun vikasietotilassa, käynnistä AVG Anti-Spyware. [*]Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan". [*]AVG aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa. Kun skannaus on valmis: TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions" [*]Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta. [*]Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions" [*]Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta. [*]Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle. [*]Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestiketjuusi. ========== Tämä jos tunnet tietokoneesi olevan hitaan puoleinen, etkä ole eheyttänyt pitkään aikaan: Avaa Oma tietokone -> Tee seuraava toimenpide kaikille Paikallisille levyille ========== Lataa CCleaner ja asenna se: Avaa "Options", sieltä "Language" ja valitse "Suomi (Finnish)" Avaa "Virheet" kohta, paina "Etsi rekisterin virheitä", paina "Korjaa valitut rekisterin virheet..". Paina "Kyllä", kun ohjelma kysyy "Haluatko varmuuskopioida muutokset rekisteriin", tallenna tiedosto esim. työpöydälle. Avaa "Puhdistaja", paina "Tutki" ja tämän jälkeen "Aja Ccleaner". Puhdista väliaikaistiedostot ja -kansiot ohjelmalla säännöllisesti. ========== Uusi Hijackthis logi ja AVG as:n raportti, onko ongelmia?
Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 12:54:16, on 25.6.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Norman\Npm\bin\ELOGSVC.EXE C:\Norman\Npm\Bin\Zanda.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Norman\Npm\bin\ZLH.EXE C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Norman\Nvc\BIN\NIP.EXE C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\CursorXP\CursorXP.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Norman\NPF\NPFMSG.EXE C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Norman\NPF\NPFSVICE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Norman\Npm\bin\NJEEVES.EXE C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\bin\nvcoas.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\alg.exe C:\Norman\Nvc\bin\cclaw.exe C:\WINDOWS\system32\wuauclt.exe C:\HJT\scanner.exe.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\Npm\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420" O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Logitech SetPoint.lnk = ? O4 - Global Startup: NPF Messenger.lnk = ? O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1182711590671 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\MaKe\Työpöytä\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Norman\Npm\bin\ELOGSVC.EXE O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\Npm\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Program Files\Norman\NPF\NPFSVICE.EXE O23 - Service: Norman ZANDA - Norman ASA - C:\Norman\Npm\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe O23 - Service: Windows Media Playerin verkkojakamispalvelu (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe -- End of file - 6084 bytes --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 12:50:14 25.6.2007 + Scan result: :mozilla.164:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.56:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.57:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.58:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.171:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.174:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.123:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.124:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.13:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.16:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.17:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.18:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.19:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.92:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.94:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.95:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.96:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.157:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.170:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Bfast : Cleaned. :mozilla.172:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.173:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.21:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.23:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.39:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.91:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.93:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@CATMJ9DJ.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.103:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.104:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.48:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.49:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.50:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.11:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.12:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.41:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.42:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@search.live[2].txt -> TrackingCookie.Live : Cleaned. :mozilla.22:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Navrcholu : Cleaned. :mozilla.23:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Navrcholu : Cleaned. :mozilla.68:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.69:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.70:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.71:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.72:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.73:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.12:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned. :mozilla.13:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned. :mozilla.6:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned. :mozilla.33:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Toplist : Cleaned. :mozilla.11:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.14:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.15:C:\Documents and Settings\Erkki\Application Data\Mozilla\Firefox\Profiles\1n96nwqk.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.31:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.32:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.97:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.98:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.99:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@CA941PLI.txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.163:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.112:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.113:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.114:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.26:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.27:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.28:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.29:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.30:C:\Documents and Settings\Tero\Application Data\Mozilla\Firefox\Profiles\k9deaesq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.107:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.108:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.109:C:\Documents and Settings\MaKe\Application Data\Mozilla\Firefox\Profiles\tnc7ebzo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\MaKe\Cookies\make@zedo[1].txt -> TrackingCookie.Zedo : Cleaned. ::Report end
eli lokit kunnossa ongelmat muualla kuin haittaohjelmissa Pysy puhtaana -> Tyhjennä järjestelmänpalautus Ohjeet Tyhjennä järjestelmänpalautuskansio ja luo uusi palautuspiste. Tämä puhdistaa palautuskansion mahdollisista haittaohjelmajäännöksistä. -> Käytä CCleaneria -> CCleaner Lataa ja asenna CCleaner. Puhdista väliaikaistiedostot ja -kansiot ohjelmalla säännöllisesti. -> Asenna SpywareBlaster -> SpywareBlaster SpywareBlaster estää haittaohjelmia asentumasta koneellesi. Ei kuluta muistia! Opas saatavilla suomeksi! Nimimerkki Ad-Awaren opas -> Asenna MVPS Hosts tiedosto -> MVPS Hosts Estää koneesi yhteyden haitallisiin sivustoihin. Opas saatavilla suomeksi! Nimimerkki Axelin opas -> Vaihda selaimesi Firefoxiin -> Firefox Firefox on nopeampi, turvallisempi ja parempi selain kuin Internet Explorer. -> Pidä järjestelmäsi ajantasalla. -> Windows Update Vieraile Windows Updatessa säännöllisesti. -> Pidä palomuuri ja virustorjunta ajantasalla Päivitä ja skannaa koneesi säännöllisesti virustorjuntaohjelmallasi. ja hyvä myös escan http://koti.mbnet.fi/pattaya1/escanmwav.htm ->Pidä ohjelmistosi ajantasalla. -> Secunia Software Inspector Secunia Software Inspector tutkii sinun järjestälmäsi ja ohjelmistosi puuttuvien turvallisuuspäivityksien osalta. Tavallinen tutkinta kestää normaalisti 5-40 sekuntia, kun läpikotainen (thorough system inspection) voi kestää useita minuutteja. ->Seuraa säännöllisesti viestintäviraston tietoja uusista haavoittuvuuksista -> CERT-FI -> Rekistöröidy. -> Virustorjunta.net Virustorjunta.net on suomalainen haittaohjelmien poistoon keskittyvä sivusto joka kykenee auttamaan sinua mitä erilaisimmissa ongelmissa. Lisäksi siellä on suomen ainut HJT-koulu. Koulussa syvennytään HJT-ohjelman tuottaman informaation analysoimiseen sekä analysoinnin jälkeiseen tietokoneen puhdistamiseen. Jos tulevaisuudessa tulee haittaohjelmien kanssa ongelmia, älä epäröi laittaa Hijackthis-logia tarkistettavaksi!