Logfile of HijackThis v1.99.1 Scan saved at 19:49:43, on 27.5.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\MSSQL7\binn\sqlservr.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\MSSQL7\binn\sqlagent.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Mixer.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Messenger Plus! 3\MsgPlus.exe C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Program Files\AVPersonal\AVSCHED32.EXE C:\Documents and Settings\Joni\Työpöytä\Ohjelmat yms\Digital Imaging\Unload\hpqcmon.exe C:\Documents and Settings\Joni\Työpöytä\Ohjelmat yms\HP Share-to-Web\hpgs2wnd.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Documents and Settings\Joni\Työpöytä\Ohjelmat yms\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE C:\Program Files\AVERTV2K\QuickTV.exe C:\MSSQL7\Binn\sqlmangr.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Tarja\Työpöytä\HijackThis_v1.99.1.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.fi.soneraplaza.net/cgi/sonera-ie5 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soneraplaza.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=...Dp/tS1xYqCf02yQ7dU4Tx3w/199Ke08UoSumKu9RAqQ== R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.inet.fi:800 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O1 - Hosts: 129.107.56.93 onlineaccounts2.abbeynational.co.uk O1 - Hosts: 129.107.56.93 www3.aibgbonline.co.uk O1 - Hosts: 129.107.56.93 www.bank.alliance-leicester.co.uk O1 - Hosts: 129.107.56.93 login.iblogin.com O1 - Hosts: 129.107.56.93 ww2.bankofscotlandhalifax-online.co.uk O1 - Hosts: 129.107.56.93 inet.barclays.co.uk O1 - Hosts: 129.107.56.93 iibank.barclays.co.uk O1 - Hosts: 129.107.56.93 iibank.cahoot.com O1 - Hosts: 129.107.56.93 www3.coventrybuildingsociety.co.uk O1 - Hosts: 129.107.56.93 ww.hsbc.co.uk O1 - Hosts: 129.107.56.93 login.ebank.offshore.hsbc.co.je O1 - Hosts: 129.107.56.93 ww3.online-offshore.lloydstsb.com O1 - Hosts: 129.107.56.93 ww3.online-business.lloydstsb.co.uk O1 - Hosts: 129.107.56.93 ww3.online.lloydstsb.co.uk O1 - Hosts: 129.107.56.93 ww3.online.lloydstsb.co.uk O1 - Hosts: 129.107.56.93 ww3.online-business.lloydstsb.co.uk O1 - Hosts: 129.107.56.93 ob2.nationet.com O1 - Hosts: 129.107.56.93 ww3.onlinebanking.natwestoffshore.com O1 - Hosts: 129.107.56.93 ww1.nwolb.com O1 - Hosts: 129.107.56.93 ww1.onlinebanking.iombank.com O1 - Hosts: 129.107.56.93 ww1.www.rbsdigital.com O1 - Hosts: 129.107.56.93 welcome.smile.co.uk O1 - Hosts: 129.107.56.93 login.365online.com O1 - Hosts: 129.107.56.93 wvw.citizensbankonline.com O1 - Hosts: 129.107.56.93 esecure.regionsnet.com O1 - Hosts: 129.107.56.93 rollb.associatedbank.com O1 - Hosts: 129.107.56.93 upb.unionplanters.com O1 - Hosts: 129.107.56.93 www.onlinebanking.huntington.com O1 - Hosts: 129.107.56.93 inet.southtrustonlinebanking.com O1 - Hosts: 129.107.56.93 logon.personal.wamu.com O1 - Hosts: 129.107.56.93 login.compassweb.com O1 - Hosts: 129.107.56.93 logon.firstmeritib.com O1 - Hosts: 129.107.56.93 login.ccfcuonline.org O1 - Hosts: 129.107.56.93 ww3.etimebanker.bankofthewest.com O1 - Hosts: 129.107.56.93 ww2.onlinebanking.lasallebank.com O1 - Hosts: 129.107.56.93 wvw.totallyfreebanking.com O1 - Hosts: 129.107.56.93 www.online.wellsfargo.com O1 - Hosts: 129.107.56.93 www.onlinebanking.bankofoklahoma.com O1 - Hosts: 129.107.56.93 accounts4.keybank.com O1 - Hosts: 129.107.56.93 logon.bankone.com O1 - Hosts: 129.107.56.93 www.secure.tdbanknorth.com O1 - Hosts: 129.107.56.93 www.secure.mvnt4.com O1 - Hosts: 129.107.56.93 ww.mynfbonline.com O1 - Hosts: 129.107.56.93 login.forumcuonline.com O1 - Hosts: 129.107.56.93 www.eds.usersonlnet.com O1 - Hosts: 129.107.56.93 www.onlineid.bankofamerica.com O1 - Hosts: 129.107.56.93 wvw.e-gold.com O1 - Hosts: 129.107.56.93 pcbs.peoples.com O1 - Hosts: 129.107.56.93 www.global1.onlinebank.com O1 - Hosts: 129.107.56.93 ww2.mybranch.lafcu.com O1 - Hosts: 129.107.56.93 login.webbanking.comerica.com O1 - Hosts: 129.107.56.93 web.banking.firsttennessee.com O1 - Hosts: 129.107.56.93 logon.members1st.org O1 - Hosts: 129.107.56.93 www.cib.ibanking-services.com O1 - Hosts: 129.107.56.93 www.miwebbusbank.ebanking-services.com O1 - Hosts: 129.107.56.93 wvw.paypal.com O1 - Hosts: 129.107.56.93 www.signin.ebay.com O1 - Hosts: 129.107.56.93 wvw.etrade.com O1 - Hosts: 129.107.56.93 ww4.fleethomelink.fleet.com O1 - Hosts: 129.107.56.93 ww3.connect.skyfi.com O1 - Hosts: 129.107.56.93 www6.usbank.com O1 - Hosts: 129.107.56.93 www.bvi.bancodevalencia.es O1 - Hosts: 129.107.56.93 extrant.banesto.es O1 - Hosts: 129.107.56.93 banesnt.banesto.es O1 - Hosts: 129.107.56.93 activia.caixagalicia.es O1 - Hosts: 129.107.56.93 www.bancae.caixapenedes.com O1 - Hosts: 129.107.56.93 login.caixasabadell.net O1 - Hosts: 129.107.56.93 oii.cajamadrid.es O1 - Hosts: 129.107.56.93 login.cajamar.es O1 - Hosts: 129.107.56.93 login.ccm.es O1 - Hosts: 129.107.56.93 ww.unicaja.es O1 - Hosts: 129.107.56.93 www5.bancopopular.es O1 - Hosts: 129.107.56.93 ww3.bbvanet.com O1 - Hosts: 129.107.56.93 ww.bayernlb.de O1 - Hosts: 129.107.56.93 ww2.berliner-volksbank.de O1 - Hosts: 129.107.56.93 ww7.homebanking-berlin.de O1 - Hosts: 129.107.56.93 portal09.commerzbanking.de O1 - Hosts: 129.107.56.93 www.meine.deutsche-bank.de O1 - Hosts: 129.107.56.93 ww2.dresdner-privat.de O1 - Hosts: 129.107.56.93 ww.e-banking.helaba.de O1 - Hosts: 129.107.56.93 ww.hsh-nordbank.de O1 - Hosts: 129.107.56.93 www.my.hypovereinsbank.de O1 - Hosts: 129.107.56.93 ww3.homebanking-berlin.de O1 - Hosts: 129.107.56.93 ww3.homebanking-berlin.de O1 - Hosts: 129.107.56.93 www.banking.lbbw.de O1 - Hosts: 129.107.56.93 lrp.sparkasse-banking.de O1 - Hosts: 129.107.56.93 ww3.homebanking-niedersachsen.de O1 - Hosts: 129.107.56.93 www.onlinebanking.norisbank.de O1 - Hosts: 129.107.56.93 www.banking.postbank.de O1 - Hosts: 129.107.56.93 wvw.internetbanking.gad.de O1 - Hosts: 129.107.56.93 ww1.portal.izb.de O1 - Hosts: 129.107.56.93 wvw.kunden-service.lbs.de O1 - Hosts: 129.107.56.93 ibanking.seb.de O1 - Hosts: 129.107.56.93 bw7.sparkasse-banking.de O1 - Hosts: 129.107.56.93 ww2.homebanking-sparkasse.de O1 - Hosts: 129.107.56.93 ww2.vr-networld-ebanking.de O1 - Hosts: 129.107.56.93 ww.bics.fr O1 - Hosts: 129.107.56.93 www.co.caixabank.fr O1 - Hosts: 129.107.56.93 ww.creditmutuel.fr O1 - Hosts: 129.107.56.93 internetbank.intesabci.it O1 - Hosts: 129.107.56.93 ww.extensive.bancalombarda.it O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) O2 - BHO: (no name) - {AFA624E3-C8DC-DBDB-BB18-4A6250AFB721} - C:\DOCUME~1\Ville\APPLIC~1\THIRDB~1\new eq.exe (file missing) O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [OWS Setup CmdLine] "C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\40\bin\cfgwiz.exe" /pkg "Office 2000 Server Extensions" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe O4 - HKLM\..\Run: [NetPumper] "C:\Documents and Settings\Joni\Työpöytä\Ohjelmat yms\NetPumper\NetPumperIEProxy.exe" O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min O4 - HKLM\..\Run: [CamMonitor] C:\Documents and Settings\Joni\Työpöytä\Ohjelmat yms\Digital Imaging\\Unload\hpqcmon.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Documents and Settings\Joni\Työpöytä\Ohjelmat yms\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [This log cast hope] C:\Documents and Settings\All Users\Application Data\Mapi Eq This Log\About Tray.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Error Safe] "C:\Program Files\Error Safe Free\ers.exe" /scan O4 - Global Startup: EPSON Status Monitor 3 Ympäristötarkistus 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Picture Package Menu.lnk = ? O4 - Global Startup: Picture Package VCD Maker.lnk = ? O4 - Global Startup: QuickTV.lnk = C:\Program Files\AVERTV2K\QuickTV.exe O4 - Global Startup: Service Manager.lnk = C:\MSSQL7\Binn\sqlmangr.exe O4 - Global Startup: TeleSA.lnk = C:\Program Files\AVer Teletext\AVerSA.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://www.flyordie.com/pub/dl/msjavx86.exe O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/134d4cffda37752d3a16/netzip/RdxIE601.cab O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://www.advnt01.com/dialer/internazionale_ver3.CAB O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/en/SysWebTelecom.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: nvidGUIv (nvidGUIv2) - Unknown owner - C:\WINDOWS\nvidGUIv.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Office Server Extensions Notification Service (OWSTimer) - Unknown owner - C:\Program Files\Microsoft Office\Office\OWSTIMER.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Sulla on aika paha infektio ja putsauksessa kestää jonkin aikaa, eli aloitetaan tällä: Lataa WinPFind työpöydällesi http://www.bleepingcomputer.com/files/oldtimer/WinPFind.zip Pura tiedoston WinPFind.zip sisältö (kansio WinPFind) C-aseman juureen. Mene sitten kansioon C:\WinPFind ja tuplaklikkaa tiedostoa WinPFind.exe, ohjelma käynnistyy. Paina Start Scan- painiketta ja odota kunnes skannaus on valmis. Ohjelma skannaa todella suuren määrään tiedostoja etsien vastaavuutta haittaohjelmille tyypillisiin tiedostoihin, joten ole kärsivällinen ja anna ohjelman skannata. Skannaus saattaa kestää jopa yli 30 minuuttia. Kun skannaus on valmis, ohjelma näyttää skannaustuloksen. Paina Copy to Clipboard-painiketta, tulos kopioituu leikepöydälle. Avaa sitten Muistio ja liitä tulos siihen, tallenna dokumentti työpöydälle nimellä WinPFind-loki. Liitä sitten tämän dokumentin sisältö viestiketjuusi. Huom! Kaikki listatut kohteet eivät välttämättä ole haittaohjelmia.