Koneeseen on tarttunut mese virus. Tässä HJT loki. Kiitokset kaikesta avusta jo etukäteen. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:01:57, on 18.6.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Acer\eManager\anbmServ.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\sistray.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\avserv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\rundll32.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [Windows svchost] avserv.exe O4 - HKLM\..\Run: [Windows UDP Control Center] winudpmgrs.exe O4 - HKLM\..\Run: [BM0a6725ef] Rundll32.exe "C:\WINDOWS\system32\hkfjucfb.dll",s O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe -- End of file - 5560 bytes
1. Lataa Combofix.exe työpöydällesi jommastakummasta linkistä: Combofix.exe Combofix.exe Avaa Combofix.exe ja seuraa näyttöön tulevia ohjeita Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen. Käynnistä kone uudelleen, jos niin pyydetään ja lähetä combofix.txt-tiedoston sisältö tänne. Tyhjennä roskakori ja käynnistä koneesi uudelleen. Postita tänne seuraavat lokit: * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta) * (C:\ComboFix.txt) raportti *
Moi tässä lokit. ComboFix 08-06-20.4 - Ville 2008-06-24 13:32:33.1 - FAT32x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.114 [GMT 3:00] Running from: C:\Documents and Settings\Ville\Työpöytä\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . (((((((((((((((((((((((((((((((((((((( Muut poistot )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\bot.exe C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat C:\WINDOWS\BM0a6725ef.xml C:\WINDOWS\pskt.ini C:\WINDOWS\service.exe C:\WINDOWS\system32\efcATNHw.dll C:\WINDOWS\system32\iajrunll.ini C:\WINDOWS\system32\mlJYpOeC.dll C:\WINDOWS\system32\pmnKdAqp.dll C:\WINDOWS\system32\PVDdeMoq.ini C:\WINDOWS\system32\PVDdeMoq.ini2 C:\WINDOWS\system32\rqRJAQJA.dll C:\WINDOWS\system32\rqRJAqQI.dll C:\WINDOWS\system32\wlpulbbl.dll C:\WINDOWS\system32\vtUlJccC.dll C:\WINDOWS\system32\vtUlLCst.dll C:\WINDOWS\system32\yayaArrS.dll C:\WINDOWS\ups.exe ----- BITS: Possible infected sites ----- hxxp://sync.avustaja.sonera.fi . ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-24 to 2008-06-24 ))))))))))))))))) . 2008-06-24 13:45 . 2008-06-24 13:46 120,606 --a------ C:\WINDOWS\BM0a6725ef.xml 2008-06-24 13:45 . 2008-06-24 13:45 22 --a------ C:\WINDOWS\pskt.ini 2008-06-24 13:12 . 2008-06-24 13:12 105,472 --a------ C:\WINDOWS\system32\rnwjpgvu.dll 2008-06-24 13:12 . 2008-06-24 13:12 91,136 --a------ C:\WINDOWS\system32\ppwwcxdv.dll 2008-06-18 21:55 . 2008-06-18 21:55 29,359 --a------ C:\usbg22.exe 2008-06-18 20:02 . 2008-06-18 20:02 29,359 --a------ C:\usb22.exe 2008-06-18 19:55 . 2008-06-18 19:55 29,359 --a------ C:\Documents and Settings\Ville\usb2.exe 2008-06-18 19:51 . 2008-06-18 19:55 29,359 --a------ C:\usb2.exe 2008-06-18 19:48 . 2008-06-18 19:48 29,346 --a------ C:\usb.exe 2008-06-18 19:01 . 2008-06-18 19:01 <KANSIO> d-------- C:\Program Files\Trend Micro 2008-06-18 19:01 . 80,896 C:\WINDOWS\system32\LLNURJAI.DLL 2008-06-18 18:57 . 89,600 C:\WINDOWS\system32\hkfjucfb.dll 2008-06-18 18:55 . 2008-06-18 18:55 322,560 --a------ C:\WINDOWS\system32\qoMedDVP.dll 2008-06-18 18:50 . 39,075 C:\WINDOWS\avserv.exe 2008-06-18 18:50 . 25,600 C:\WINDOWS\system32\urqOHYRK.dll 2008-06-06 23:29 . 2008-06-06 23:29 <KANSIO> d-------- C:\Program Files\ProPilkki2 2008-06-06 21:38 . 2008-06-06 21:36 691,545 --a------ C:\WINDOWS\unins000.exe 2008-06-06 21:38 . 2008-06-06 21:38 2,551 --a------ C:\WINDOWS\unins000.dat 2008-06-06 21:14 . 2008-06-06 21:14 49,156 --a------ C:\sz.exe 2008-06-06 21:14 . 2008-06-06 21:14 49,156 --a------ C:\hszs.exe 2008-06-06 21:12 . 2008-06-06 21:12 <KANSIO> d--hs---- C:\FOUND.007 2008-06-01 16:46 . 2008-06-01 16:46 86,512 --a------ C:\irc.com 2008-05-28 09:39 . 2008-05-28 09:39 <KANSIO> d-------- C:\Program Files\Sun 2008-05-28 09:38 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-05-28 09:27 . 2008-05-28 09:27 <KANSIO> d-------- C:\Program Files\Windows Defender 2008-05-27 23:36 . 2008-05-27 23:36 40,960 --a------ C:\dcis.exe 2008-05-27 23:26 . 2008-05-28 11:30 56,832 --a------ C:\sexy.com 2008-05-27 23:25 . 2008-05-28 09:01 40,960 --a------ C:\dciz.exe 2008-05-27 23:21 . 2008-05-27 23:20 56,832 -r-hs---- C:\WINDOWS\winudspm.exe 2008-05-27 23:21 . 2008-05-27 23:21 40,960 --a------ C:\dci.exe . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-12 16:13 --------- d-----w C:\Program Files\MSECache 2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll 2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll . Code: <pre> ----a-w 131,097,968 2006-06-25 16:35:34 C:\Documents and Settings\Ville\Omat tiedostot\lataukset\Nero.Premium.v7.2.3.2b.Incl.Keygen-DeathW\Nero-7.2.3.2b-ENG .exe </pre> (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„ [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1cdef220-fbba-412e-8943-d989de013b25}] 2008-06-24 13:12 105472 --a------ C:\WINDOWS\system32\rnwjpgvu.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8BA35092-9698-4EC6-858C-A41609B07270}] 2008-06-18 18:55 322560 --a------ C:\WINDOWS\system32\qoMedDVP.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE7E4CE1-8CBA-44A6-956F-462A667D3286}] C:\WINDOWS\system32\urqOHYRK.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 20:00 15360] "msnmsgr"="~C:\Program Files\MSN Messenger\msnmsgr.exe" [ ] "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" [] "SiSPower"="SiSPower.dll" [2005-02-25 19:35 49152 C:\WINDOWS\system32\SiSPower.dll] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-09-15 20:00 208952] "LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:30 315392] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-23 21:35 180269] "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512] "Sonera"="C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" [2007-08-19 11:47 197880] "Windows svchost"="avserv.exe" [] "BM0a6725ef"="C:\WINDOWS\system32\ppwwcxdv.dll" [2008-06-24 13:12 91136] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-15 20:00 15360] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264] "Picasa Media Detector"="C:\Documents and Settings\Ville\Omat tiedostot\Omat kuvatiedostot\Picasa2\PicasaMediaDetector.exe" [2008-02-26 04:23 443968] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{BE7E4CE1-8CBA-44A6-956F-462A667D3286}"= C:\WINDOWS\system32\urqOHYRK.dll [ ] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJYqOHY] mlJYqOHY.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqOHYRK] urqOHYRK.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=rnwjpgvu.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4500:UDP"= 4500:UDPilkki R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16] R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-03-04 16:37] R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57] R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 01:43] S3 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 14:46] S3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2005-01-31 11:13] . 'Ajoitetut teht„v„t'-kansion sis„lt” "2008-06-24 10:44:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-24 13:44:06 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\urqOHYRK.dll PROCESS: C:\WINDOWS\explorer.exe -> C:\WINDOWS\system32\ppwwcxdv.dll . ------------------------ Other Running Processes ------------------------ . C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE C:\ACER\EMANAGER\ANBMSERV.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\system32\sistray.exe . ************************************************************************** . Completion time: 2008-06-24 13:51:28 - machine was rebooted ComboFix-quarantined-files.txt 2008-06-24 10:51:04 Pre-Run: 13,264,355,328 tavua vapaana Post-Run: 13,879,246,848 tavua vapaana 168 --- E O F --- 2008-06-24 10:48:33 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:43:52, on 24.6.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Acer\eManager\anbmServ.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O2 - BHO: {52b310ed-989d-3498-e214-abbf022fedc1} - {1cdef220-fbba-412e-8943-d989de013b25} - C:\WINDOWS\system32\rnwjpgvu.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {8BA35092-9698-4EC6-858C-A41609B07270} - C:\WINDOWS\system32\qoMedDVP.dll (file missing) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {BE7E4CE1-8CBA-44A6-956F-462A667D3286} - C:\WINDOWS\system32\urqOHYRK.dll (file missing) O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera O4 - HKLM\..\Run: [Windows svchost] avserv.exe O4 - HKLM\..\Run: [BM0a6725ef] Rundll32.exe "C:\WINDOWS\system32\ppwwcxdv.dll",s O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: rnwjpgvu.dll O20 - Winlogon Notify: mlJYqOHY - mlJYqOHY.dll (file missing) O20 - Winlogon Notify: urqOHYRK - urqOHYRK.dll (file missing) O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe -- End of file - 6238 bytes
1. Lataa Combofix.exe työpöydällesi jommastakummasta linkistä: Combofix.exe Combofix.exe Avaa Muistio ja kopioi/liitä Lainaus: laatikon sisältö sinne: Tallenna nimellä CFScript (itse asiassa combofix tunnistaa tuon vaikka tiedostopääte ei olisi edes .txt). Sitten raahaa ja pudota CFScript ComboFix.exeen kuten alla.(Älä klikkaa) Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen. Käynnistä kone uudelleen, jos niin pyydetään ja lähetä combofix.txt-tiedoston sisältö tänne. Sammuta selain ja muut ohjelmat Fixin ajaksi. (ei virustorjuntaa) Käynnistä HijackThis:ja Scan ja ruksaa seuraavat punaisella listatut tiedostot sekä poista ne.(fix Chekked) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O2 - BHO: {52b310ed-989d-3498-e214-abbf022fedc1} - {1cdef220-fbba-412e-8943-d989de013b25} - C:\WINDOWS\system32\rnwjpgvu.dll O2 - BHO: (no name) - {8BA35092-9698-4EC6-858C-A41609B07270} - C:\WINDOWS\system32\qoMedDVP.dll (file missing) O2 - BHO: (no name) - {BE7E4CE1-8CBA-44A6-956F-462A667D3286} - C:\WINDOWS\system32\urqOHYRK.dll (file missing) O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [Windows svchost] avserv.exe O4 - HKLM\..\Run: [BM0a6725ef] Rundll32.exe "C:\WINDOWS\system32\ppwwcxdv.dll",s O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O20 - AppInit_DLLs: rnwjpgvu.dll O20 - Winlogon Notify: mlJYqOHY - mlJYqOHY.dll (file missing) O20 - Winlogon Notify: urqOHYRK - urqOHYRK.dll (file missing) Tyhjennä roskakori ja käynnistä koneesi uudelleen. Postita tänne seuraavat lokit: * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta) * (C:\ComboFix.txt) raportti *
Moi tässä HJT ja combofix. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:47:18, on 24.6.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Acer\eManager\anbmServ.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\sistray.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe -- End of file - 4978 bytes ComboFix 08-06-20.4 - Ville 2008-06-24 16:28:21.2 - FAT32x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.110 [GMT 3:00] Running from: C:\Documents and Settings\Ville\Työpöytä\ComboFix.exe Command switches used :: C:\Documents and Settings\Ville\Työpöytä\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: C:\dci.exe C:\dcis.exe C:\dciz.exe C:\Documents and Settings\Ville\usb2.exe C:\hszs.exe C:\irc.com C:\sexy.com C:\sz.exe C:\usb.exe C:\usb2.exe C:\usb22.exe C:\usbg22.exe C:\WIND C:\WINDOWS\avserv.exe C:\WINDOWS\BM0a6725ef.xml C:\WINDOWS\system32\hkfjucfb.dll C:\WINDOWS\system32\LLNURJAI.DLL C:\WINDOWS\system32\ppwwcxdv.dll C:\WINDOWS\system32\rnwjpgvu.dll C:\WINDOWS\system32\urqOHYRK.dll C:\WINDOWS\winudspm.exe . (((((((((((((((((((((((((((((((((((((( Muut poistot )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\dci.exe C:\dcis.exe C:\dciz.exe C:\Documents and Settings\Ville\usb2.exe C:\hszs.exe C:\irc.com C:\sexy.com C:\sz.exe C:\usb.exe C:\usb2.exe C:\usb22.exe C:\usbg22.exe C:\WINDOWS\avserv.exe C:\WINDOWS\BM0a6725ef.xml C:\WINDOWS\pskt.ini C:\WINDOWS\system32\hkfjucfb.dll C:\WINDOWS\system32\LLNURJAI.DLL C:\WINDOWS\system32\ppwwcxdv.dll C:\WINDOWS\system32\rnwjpgvu.dll C:\WINDOWS\system32\urqOHYRK.dll C:\WINDOWS\winudspm.exe . ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-24 to 2008-06-24 ))))))))))))))))) . 2008-06-24 14:03 . 2008-06-14 20:59 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-24 14:03 . 2008-06-14 20:59 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-18 19:01 . 2008-06-18 19:01 <KANSIO> d-------- C:\Program Files\Trend Micro 2008-06-18 18:55 . 2008-06-18 18:55 322,560 --a------ C:\WINDOWS\system32\qoMedDVP.dll 2008-06-06 23:29 . 2008-06-06 23:29 <KANSIO> d-------- C:\Program Files\ProPilkki2 2008-06-06 21:38 . 2008-06-06 21:36 691,545 --a------ C:\WINDOWS\unins000.exe 2008-06-06 21:38 . 2008-06-06 21:38 2,551 --a------ C:\WINDOWS\unins000.dat 2008-06-06 21:12 . 2008-06-06 21:12 <KANSIO> d--hs---- C:\FOUND.007 2008-05-28 09:39 . 2008-05-28 09:39 <KANSIO> d-------- C:\Program Files\Sun 2008-05-28 09:38 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-05-28 09:27 . 2008-05-28 09:27 <KANSIO> d-------- C:\Program Files\Windows Defender . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-12 16:13 --------- d-----w C:\Program Files\MSECache 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-17 10:52 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe 2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll 2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll . Code: <pre> ----a-w 131,097,968 2006-06-25 16:35:34 C:\Documents and Settings\Ville\Omat tiedostot\lataukset\Nero.Premium.v7.2.3.2b.Incl.Keygen-DeathW\Nero-7.2.3.2b-ENG .exe </pre> ((((((((((((((((((((((((((((( snapshot@2008-06-24_13.49.58.78 ))))))))))))))))))))))))))))))))))))))))) . - 2008-06-24 10:41:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-06-24 13:34:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-02-16 09:02:36 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll + 2008-04-21 07:02:46 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll - 2008-02-16 09:02:36 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll + 2008-04-21 07:02:46 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll - 2008-02-16 09:02:38 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll + 2008-04-21 07:02:48 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll - 2008-02-16 09:02:36 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll + 2008-04-21 07:02:46 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll - 2008-02-16 09:02:36 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll + 2008-04-21 07:02:46 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll - 2008-02-16 09:02:38 1,055,232 ----a-w C:\WINDOWS\system32\dllcache\danim.dll + 2008-04-21 07:02:48 1,055,232 ----a-w C:\WINDOWS\system32\dllcache\danim.dll - 2008-02-16 09:02:38 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll + 2008-04-21 07:02:48 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll - 2008-02-16 09:02:38 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll + 2008-04-21 07:02:48 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll - 2008-02-16 09:02:38 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll + 2008-04-21 07:02:48 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll - 2008-02-16 09:02:38 250,880 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll + 2008-04-21 07:02:48 250,880 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll - 2008-02-16 09:02:38 96,256 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll + 2008-04-21 07:02:48 96,256 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll - 2008-02-16 09:02:38 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll + 2008-04-21 07:02:48 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll - 2008-02-16 22:32:40 3,080,704 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll + 2008-04-21 07:02:50 3,080,704 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll - 2008-02-16 09:02:40 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll + 2008-04-21 07:02:50 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll - 2008-02-16 09:02:40 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll + 2008-04-21 07:02:50 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll - 2008-02-16 09:02:40 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll + 2008-04-21 07:02:50 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll - 2008-02-16 09:02:40 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll + 2008-04-21 07:02:50 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll - 2008-02-16 09:02:42 1,494,016 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll + 2008-04-21 07:02:52 1,494,016 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll - 2008-02-16 09:02:42 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll + 2008-04-21 07:02:52 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll - 2008-02-16 09:02:42 616,448 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll + 2008-04-21 07:02:52 616,448 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll - 2008-02-16 09:02:42 659,456 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll + 2008-04-21 07:02:52 659,456 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll - 2008-02-16 09:02:38 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll + 2008-04-21 07:02:48 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll - 2008-02-16 09:02:38 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll + 2008-04-21 07:02:48 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll - 2008-02-16 09:02:38 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll + 2008-04-21 07:02:48 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll - 2008-02-16 09:02:38 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll + 2008-04-21 07:02:48 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll - 2008-02-16 09:02:38 96,256 ----a-w C:\WINDOWS\system32\inseng.dll + 2008-04-21 07:02:48 96,256 ----a-w C:\WINDOWS\system32\inseng.dll - 2008-02-16 09:02:38 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll + 2008-04-21 07:02:48 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll - 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe + 2008-05-29 23:35:12 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe - 2008-02-16 22:32:40 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll + 2008-04-21 07:02:50 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll - 2008-02-16 09:02:40 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll + 2008-04-21 07:02:50 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll - 2008-02-16 09:02:40 146,432 ----a-w C:\WINDOWS\system32\msrating.dll + 2008-04-21 07:02:50 146,432 ----a-w C:\WINDOWS\system32\msrating.dll - 2008-02-16 09:02:40 532,480 ----a-w C:\WINDOWS\system32\mstime.dll + 2008-04-21 07:02:50 532,480 ----a-w C:\WINDOWS\system32\mstime.dll - 2008-02-16 09:02:40 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll + 2008-04-21 07:02:50 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll - 2008-02-16 09:02:42 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll + 2008-04-21 07:02:52 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll - 2008-02-16 09:02:42 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll + 2008-04-21 07:02:52 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll - 2008-03-20 11:41:20 14,640 ------w C:\WINDOWS\system32\spmsg.dll + 2007-11-30 11:19:02 17,272 ------w C:\WINDOWS\system32\spmsg.dll - 2008-02-16 09:02:42 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll + 2008-04-21 07:02:52 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll - 2008-02-16 09:02:42 659,456 ----a-w C:\WINDOWS\system32\wininet.dll + 2008-04-21 07:02:52 659,456 ----a-w C:\WINDOWS\system32\wininet.dll - 2008-02-15 23:03:12 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll + 2008-04-17 11:03:44 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll + 2008-06-24 13:34:52 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_5c4.dat . -- Snapshot reset to current date -- . (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„ [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8BA35092-9698-4EC6-858C-A41609B07270}] 2008-06-18 18:55 322560 --a------ C:\WINDOWS\system32\qoMedDVP.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 20:00 15360] "msnmsgr"="~C:\Program Files\MSN Messenger\msnmsgr.exe" [ ] "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" [] "SiSPower"="SiSPower.dll" [2005-02-25 19:35 49152 C:\WINDOWS\system32\SiSPower.dll] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-09-15 20:00 208952] "LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:30 315392] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-23 21:35 180269] "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512] "Sonera"="C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" [2007-08-19 11:47 197880] "Windows svchost"="avserv.exe" [] "BM0a6725ef"="C:\WINDOWS\system32\ppwwcxdv.dll" [ ] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-15 20:00 15360] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264] "Picasa Media Detector"="C:\Documents and Settings\Ville\Omat tiedostot\Omat kuvatiedostot\Picasa2\PicasaMediaDetector.exe" [2008-02-26 04:23 443968] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJYqOHY] mlJYqOHY.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqOHYRK] urqOHYRK.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=rnwjpgvu.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4500:UDP"= 4500:UDPilkki R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16] R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-03-04 16:37] R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57] R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 01:43] S3 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 14:46] S3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2005-01-31 11:13] . 'Ajoitetut teht„v„t'-kansion sis„lt” "2008-06-24 13:38:04 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-24 16:35:17 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE C:\ACER\EMANAGER\ANBMSERV.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\system32\sistray.exe . ************************************************************************** . Completion time: 2008-06-24 16:39:05 - machine was rebooted ComboFix-quarantined-files.txt 2008-06-24 13:38:56 ComboFix2.txt 2008-06-24 10:51:32 Pre-Run: 16,892,657,664 tavua vapaana Post-Run: 16,977,985,536 tavua vapaana 251 --- E O F --- 2008-06-24 12:22:18
No niin alkaako tuntua kone vähän paremmalta? ****************************************** Kirjoita windowsin käynnistävalikon suorita-kenttään ComboFix.exe /u paina OK *************************************************************************** Lataa Malwarebytes' Anti-Malware työpöydällesi. * Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman. * Lopuksi varmistu, että seuraavat on valittu: Päivitä Malwarebytes' Anti-Malware ja Käynnistä Malwarebytes' Anti-Malware ja sen jälkeen klikkaa Lopeta. * Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version. * Kun ohjelma on latautunut, valitse Suorita täysi tarkistus ja klikkaa Tarkista. * Kun skanni on valmis, klikkaa OK ja sitten Näytä tulokset nähdäksesi tulokset. * Varmistu, että kaikki on merkitty ja klikkaa Poista valitut. * Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt * Lähetä lokin sisältö seuraavassa viestissäsi + uusi hjt-loki.
Hihi! Kivaa! Pitkästä aikaa saa oikein INTTERNETTIN avattua Tässä olis tämä anti-malware: Malwarebytes' Anti-Malware 1.18 Tietokantaversio: 885 18:06:40 24.6.2008 mbam-log-6-24-2008 (18-06-40).txt Tarkistustyyppi: Täysi tarkistus (C:\|D:\|) Tarkistetut kohteet: 87925 Kulunut aika: 40 minute(s), 7 second(s) Saastuneita muistiprosesseja: 0 Saastuneita muistimoduuleja: 0 Saastuneita rekisteriavaimia: 1 Saastuneita rekisteriarvoja: 0 Saastuneita rekisterikohteita: 0 Saastuneita hakemistoja: 0 Saastuneita tiedostoja: 67 Saastuneita muistiprosesseja: (Haitallisia kohteita ei löydetty) Saastuneita muistimoduuleja: (Haitallisia kohteita ei löydetty) Saastuneita rekisteriavaimia: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. Saastuneita rekisteriarvoja: (Haitallisia kohteita ei löydetty) Saastuneita rekisterikohteita: (Haitallisia kohteita ei löydetty) Saastuneita hakemistoja: (Haitallisia kohteita ei löydetty) Saastuneita tiedostoja: C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1339\A0096653.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1339\A0096657.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1340\A0096672.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1340\A0096675.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1341\A0096720.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1342\A0096723.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1344\A0096724.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1345\A0096729.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1347\A0096775.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1347\A0096791.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1348\A0096806.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1349\A0098812.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1349\A0098813.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0099000.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0099017.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0099021.EXE (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0100058.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100074.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100078.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100079.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100080.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100081.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100082.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100084.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100085.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100086.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100118.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100119.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100120.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100121.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100135.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100136.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100308.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100309.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100310.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100311.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100313.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100314.com (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100316.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100317.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100318.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100319.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100322.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100337.EXE (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\dci.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\dcis.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\dciz.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\irc.com.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\sexy.com.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\usb.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\usb2.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\usb22.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\usbg22.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\service.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\winudspm.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\avserv.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\efcATNHw.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\mlJYpOeC.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\pmnKdAqp.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\rqRJAQJA.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\rqRJAqQI.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\vtUlJccC.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\vtUlLCst.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\yayaArrS.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\Documents and Settings\Ville\usb2.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINDOWS\system32\qoMedDVP.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully. Ja tässä uusin HJT: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:09:31, on 24.6.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Acer\eManager\anbmServ.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\sistray.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\LVComsX.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe -- End of file - 5101 bytes
Hyvä sitten ****************************************** Kirjoita windowsin käynnistävalikon suorita-kenttään ComboFix.exe /u paina OK *************************************************************************** Järjestelmän palauttamisen poistaminen käytöstä Voit poistaa järjestelmän palauttamisen käytöstä seuraavasti: 1.Napsauta Käynnistä-painiketta, napsauta Oma tietokone -kuvaketta hiiren kakkospainikkeella ja valitse sitten Ominaisuudet. 2.Valitse Järjestelmän palauttaminen -välilehti. 3.Valitse Poista järjestelmän palauttaminen käytöstä -valintaruutu (tai Poista järjestelmän palauttaminen käytöstä kaikissa asemissa -valintaruutu) ja valitse sitten OK. 4.Valitse Kyllä, kun näyttöön tulee kehote järjestelmän palauttamisen poistamisesta käytöstä. Lataa CCleaner tästä - Asennuksessa poista merkki/rasti kohdasta "asenna Yahoo! toolbar/työkalupalkki". - Asennuksen jälkeen aukaise CCleaner. - Valitse vasemmalta pystyrivistä Options. - Valitse viereisestä pystyrivistä Settings. - Language kohtaan valitse Suomi. - Käynnistä CCleaner. - Valitse Valinnat. - Paina Lisäasetukset. - Ota ruksi pois kohdasta "Poista vain yli 48 tuntia vanhat tiedostot Windowsin tilapäiskansioista". Puhdistaja - Valitse vasemmalta pystyrivistä Puhdistaja. - Paina alhaalta Tutki. Nyt CCleaner tutkii, mitä voidaan poistaa (tempit, cookiessit jne.). - Kun tutkiminen on valmis, paina Aja CCleaner. Nyt CCleaner poistaa löydetyt tempit, cookiessit jne. Rekisterin virheiden korjaus - Valitse vasemmalta pystyrivistä Rekisteri. - Paina alhaalta Etsi rekisterin virheitä. - Kun etsintä on valmis ja olet varma, että haluat korjata ne rivit jotka ovat merkattuja, niin paina Korjaa valitut rekisterin virheet. - Sinulta kysytään "haluatko varmuuskopioida muutokset rekisteriin", paina Kyllä. Tallenna varmuuskopio vaikka "Omat tiedostot" -kansioon. - Klikkaa uudesta aukeavasta ikkunasta Korjaa kaikki valitut virheet. - Saat vielä varmistus kysymyksen, paina Ok. - Kun virheet on korjattu, paina Sulje. Nyt voit suljea CCleanerin painamalla oikealta ylhäältä punaista rastia. Javan päivitys ja välimuistin tyhjennys: 1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa. 2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... ) Niissä pitäisi olla seuraava kuva vieressä: 3. Valitse kaikki entiset Java versiosi ja valitse Poista. 4. Asenna uusin Java päivitys seuraavasta linkistä.. 5. Käynnistä kone uudelleen asennuksen jälkeen: http://java.sun.com/javase/downloads/index.jsp Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u6 Paina Download Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se. 6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi). 7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia. (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa. Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle). 8. Varmista että kaikki kaksi valintaa ovat rastitettuja: *Applications and Applets *Trace and Log Files Ja paina OK -nappia 9. Klikkaa OK "Temporary Files Settings" -ikkunassasi. 10. Klikkaa OK jättääksesi Java asetusikkunasi. No niin ja lopuksi skannaa viellä tuolla Malwarebytesillä niin katsotaan ettei ole tullt takaisin noit mörkkejä.
Nyt on kaikki tehty mitä käsketty, eikä anti-malwarella löytynyt enää mitään. Olisko se nyt niinku putsattu? Vai pitääkö vielä jotain tehdä? Kiitoksia älyttömän paljon. En olisi itse saanut koskaan konettani käyttökuntoon. Nyt se Javan (disc space) liukusäädin on siinä keskikohdassa. Onks se siinä hyvä, vai pitääkö sitä vielä siirrellä? Tässä tämä anti-malware: Malwarebytes' Anti-Malware 1.18 Tietokantaversio: 885 20:22:32 24.6.2008 mbam-log-6-24-2008 (20-22-32).txt Tarkistustyyppi: Täysi tarkistus (C:\|D:\|) Tarkistetut kohteet: 81639 Kulunut aika: 21 minute(s), 44 second(s) Saastuneita muistiprosesseja: 0 Saastuneita muistimoduuleja: 0 Saastuneita rekisteriavaimia: 0 Saastuneita rekisteriarvoja: 0 Saastuneita rekisterikohteita: 0 Saastuneita hakemistoja: 0 Saastuneita tiedostoja: 0 Saastuneita muistiprosesseja: (Haitallisia kohteita ei löydetty) Saastuneita muistimoduuleja: (Haitallisia kohteita ei löydetty) Saastuneita rekisteriavaimia: (Haitallisia kohteita ei löydetty) Saastuneita rekisteriarvoja: (Haitallisia kohteita ei löydetty) Saastuneita rekisterikohteita: (Haitallisia kohteita ei löydetty) Saastuneita hakemistoja: (Haitallisia kohteita ei löydetty) Saastuneita tiedostoja: (Haitallisia kohteita ei löydetty)