mese virus ongelma

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by maikmaik, Jul 29, 2007.

  1. maikmaik

    maikmaik Member

    Joined:
    Jul 29, 2007
    Messages:
    18
    Likes Received:
    0
    Trophy Points:
    11
    moi! mä menin kans tyhmänä aukaseen tän "näytönsäästäjä" meiningin. näyttää olevan monella muullakin samaongelma täällä.
    Logfile of HijackThis v1.99.1
    Scan saved at 6:46:13, on 30.7.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\B2BPOKER\Club4Aces.com\Client.exe
    C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe
    C:\scanner.exe.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
    O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\pokerit\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\pokerit\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_43.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F3D1460F-7A8B-42D0-9428-95C2C1C1740A}: NameServer = 213.139.190.3 212.50.131.153
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O21 - SSODL: printers - {8D08E290-7FF5-489D-9482-4F12ABAED88F} - libcintles3.dll (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Documents and Settings\Mikko\Työpöytä\AVG Anti-Spyware 7.5\guard.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe

    eli tämmöstä tekstiä mulla. mitä pitäisi tehdä?
     
  2. maikmaik

    maikmaik Member

    Joined:
    Jul 29, 2007
    Messages:
    18
    Likes Received:
    0
    Trophy Points:
    11
    eli oon aika keltanokka vielä näiden koneiden kans uskon että saan avun täältä. kiitos jo etukäteen:)
     
  3. maikmaik

    maikmaik Member

    Joined:
    Jul 29, 2007
    Messages:
    18
    Likes Received:
    0
    Trophy Points:
    11
    ja tämä mun spyware blokkailee jatkuvasti tämmösiä sovelluksia ijxyqw,mqgxeh,srilys,vogera jne... ne ilmestyy tonne C:\Documents and Settings\Mikko
     
  4. Porshe

    Porshe Regular member

    Joined:
    Dec 1, 2006
    Messages:
    1,111
    Likes Received:
    0
    Trophy Points:
    46
    Mää kans latasin yhen tommosen ja AVG anti-spywarella ja AVG anti-viruksella scannasin koneen + sitten vainoharhanen kun olen niin scannasin bitdefender ja kaspersky online scannereilla viel ja koneeni ja kyllä tuntu löytyvän kaiken näkösiä mutta lähtipä toi mesemato.

    http://downloads.ewido.net/ewido_micro.exe <---- Tuolla kannattaa scannata kone kerran kuukaudessa. Ja myös tuolla bitdefenderillä.
    http://www.kaspersky.com/virusscanner
    http://www.bitdefender.com/scan8/ie.html

    Tuolla jotain tietoa: http://netsecurity.about.com/cs/generalsecurity/a/aa033104_2.htm

    -----
    Tässä yksi ratkaisu poistoon. Muistathan tehdä järjestelmän palautuspisteen ennenkuin muokkaat rekisteriä.

    How to remove this worm:
    Step 1.
    "Start"->"Run", type "REGEDIT", open the reistry editor.
    Step 2.
    Go to
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

    delete "printers"="{CLSID}" in right panel
    ( please copy the {CLSID} before deleting it )
    Step 3.
    Go to
    HKEY_CLASSES_ROOT\CLSID

    delete the {CLSID} in Step 2.
    Step 4.
    Restart your computer
    Step 5.
    Delete the following files:
    %System%\notiffy.dll
    %System%\printers.exe
    %userprofile%\new.txt
    %Windows%\{string1}{random number}.zip (file size:119KB)


    {string1} is one of the following:
    images0
    photos0
    album
    photo
    pictures0
    picture


    For example:
    images047.zip (images047.scr)
    photo92.zip (photo92.scr)
     
  5. maikmaik

    maikmaik Member

    Joined:
    Jul 29, 2007
    Messages:
    18
    Likes Received:
    0
    Trophy Points:
    11
    sain viruksen jo pois omin kätösin:) mutta kiitoksia silti avusta:) tiedän kyllä tästä lähtien mistä pyytää apua seuraavan kerran mutta toivotaan että sitä kertaa ei tule.
    ystävällisin terveisin mikko
     
  6. maikmaik

    maikmaik Member

    Joined:
    Jul 29, 2007
    Messages:
    18
    Likes Received:
    0
    Trophy Points:
    11
    ja toi evido anti spyware oli aivan tosi hyvä
     

Share This Page