Mese-virus

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by luettelo, Jun 18, 2008.

  1. luettelo

    luettelo Member

    Joined:
    Jun 18, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Koneeseen on tarttunut mese virus. Tässä HJT loki. Kiitokset kaikesta avusta jo etukäteen.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:01:57, on 18.6.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\sistray.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\avserv.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\rundll32.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [Windows svchost] avserv.exe
    O4 - HKLM\..\Run: [Windows UDP Control Center] winudpmgrs.exe
    O4 - HKLM\..\Run: [BM0a6725ef] Rundll32.exe "C:\WINDOWS\system32\hkfjucfb.dll",s
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    --
    End of file - 5560 bytes
     
  2. yaht

    yaht Regular member

    Joined:
    Dec 6, 2005
    Messages:
    2,261
    Likes Received:
    0
    Trophy Points:
    46
    1. Lataa Combofix.exe työpöydällesi jommastakummasta linkistä:
    Combofix.exe
    Combofix.exe

    Avaa Combofix.exe ja seuraa näyttöön tulevia ohjeita

    Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
    Käynnistä kone uudelleen, jos niin pyydetään ja lähetä combofix.txt-tiedoston sisältö tänne.


    Tyhjennä roskakori ja käynnistä koneesi uudelleen.

    Postita tänne seuraavat lokit:
    * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta)
    * (C:\ComboFix.txt) raportti
    *
     
  3. luettelo

    luettelo Member

    Joined:
    Jun 18, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Moi tässä lokit.

    ComboFix 08-06-20.4 - Ville 2008-06-24 13:32:33.1 - FAT32x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.114 [GMT 3:00]
    Running from: C:\Documents and Settings\Ville\Työpöytä\ComboFix.exe
    * Created a new restore point
    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    C:\bot.exe
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    C:\WINDOWS\BM0a6725ef.xml
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\service.exe
    C:\WINDOWS\system32\efcATNHw.dll
    C:\WINDOWS\system32\iajrunll.ini
    C:\WINDOWS\system32\mlJYpOeC.dll
    C:\WINDOWS\system32\pmnKdAqp.dll
    C:\WINDOWS\system32\PVDdeMoq.ini
    C:\WINDOWS\system32\PVDdeMoq.ini2
    C:\WINDOWS\system32\rqRJAQJA.dll
    C:\WINDOWS\system32\rqRJAqQI.dll
    C:\WINDOWS\system32\wlpulbbl.dll
    C:\WINDOWS\system32\vtUlJccC.dll
    C:\WINDOWS\system32\vtUlLCst.dll
    C:\WINDOWS\system32\yayaArrS.dll
    C:\WINDOWS\ups.exe
    ----- BITS: Possible infected sites -----
    hxxp://sync.avustaja.sonera.fi
    .
    ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-24 to 2008-06-24 )))))))))))))))))
    .
    2008-06-24 13:45 . 2008-06-24 13:46 120,606 --a------ C:\WINDOWS\BM0a6725ef.xml
    2008-06-24 13:45 . 2008-06-24 13:45 22 --a------ C:\WINDOWS\pskt.ini
    2008-06-24 13:12 . 2008-06-24 13:12 105,472 --a------ C:\WINDOWS\system32\rnwjpgvu.dll
    2008-06-24 13:12 . 2008-06-24 13:12 91,136 --a------ C:\WINDOWS\system32\ppwwcxdv.dll
    2008-06-18 21:55 . 2008-06-18 21:55 29,359 --a------ C:\usbg22.exe
    2008-06-18 20:02 . 2008-06-18 20:02 29,359 --a------ C:\usb22.exe
    2008-06-18 19:55 . 2008-06-18 19:55 29,359 --a------ C:\Documents and Settings\Ville\usb2.exe
    2008-06-18 19:51 . 2008-06-18 19:55 29,359 --a------ C:\usb2.exe
    2008-06-18 19:48 . 2008-06-18 19:48 29,346 --a------ C:\usb.exe
    2008-06-18 19:01 . 2008-06-18 19:01 <KANSIO> d-------- C:\Program Files\Trend Micro
    2008-06-18 19:01 . 80,896 C:\WINDOWS\system32\LLNURJAI.DLL
    2008-06-18 18:57 . 89,600 C:\WINDOWS\system32\hkfjucfb.dll
    2008-06-18 18:55 . 2008-06-18 18:55 322,560 --a------ C:\WINDOWS\system32\qoMedDVP.dll
    2008-06-18 18:50 . 39,075 C:\WINDOWS\avserv.exe
    2008-06-18 18:50 . 25,600 C:\WINDOWS\system32\urqOHYRK.dll
    2008-06-06 23:29 . 2008-06-06 23:29 <KANSIO> d-------- C:\Program Files\ProPilkki2
    2008-06-06 21:38 . 2008-06-06 21:36 691,545 --a------ C:\WINDOWS\unins000.exe
    2008-06-06 21:38 . 2008-06-06 21:38 2,551 --a------ C:\WINDOWS\unins000.dat
    2008-06-06 21:14 . 2008-06-06 21:14 49,156 --a------ C:\sz.exe
    2008-06-06 21:14 . 2008-06-06 21:14 49,156 --a------ C:\hszs.exe
    2008-06-06 21:12 . 2008-06-06 21:12 <KANSIO> d--hs---- C:\FOUND.007
    2008-06-01 16:46 . 2008-06-01 16:46 86,512 --a------ C:\irc.com
    2008-05-28 09:39 . 2008-05-28 09:39 <KANSIO> d-------- C:\Program Files\Sun
    2008-05-28 09:38 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
    2008-05-28 09:27 . 2008-05-28 09:27 <KANSIO> d-------- C:\Program Files\Windows Defender
    2008-05-27 23:36 . 2008-05-27 23:36 40,960 --a------ C:\dcis.exe
    2008-05-27 23:26 . 2008-05-28 11:30 56,832 --a------ C:\sexy.com
    2008-05-27 23:25 . 2008-05-28 09:01 40,960 --a------ C:\dciz.exe
    2008-05-27 23:21 . 2008-05-27 23:20 56,832 -r-hs---- C:\WINDOWS\winudspm.exe
    2008-05-27 23:21 . 2008-05-27 23:21 40,960 --a------ C:\dci.exe
    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-05-12 16:13 --------- d-----w C:\Program Files\MSECache
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
    2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
    2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
    .
    Code:
    <pre>
    ----a-w       131,097,968 2006-06-25 16:35:34  C:\Documents and Settings\Ville\Omat tiedostot\lataukset\Nero.Premium.v7.2.3.2b.Incl.Keygen-DeathW\Nero-7.2.3.2b-ENG .exe
    </pre>
    (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1cdef220-fbba-412e-8943-d989de013b25}]
    2008-06-24 13:12 105472 --a------ C:\WINDOWS\system32\rnwjpgvu.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8BA35092-9698-4EC6-858C-A41609B07270}]
    2008-06-18 18:55 322560 --a------ C:\WINDOWS\system32\qoMedDVP.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE7E4CE1-8CBA-44A6-956F-462A667D3286}]
    C:\WINDOWS\system32\urqOHYRK.dll
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 20:00 15360]
    "msnmsgr"="~C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
    "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" []
    "SiSPower"="SiSPower.dll" [2005-02-25 19:35 49152 C:\WINDOWS\system32\SiSPower.dll]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-09-15 20:00 208952]
    "LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:30 315392]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-23 21:35 180269]
    "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512]
    "Sonera"="C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" [2007-08-19 11:47 197880]
    "Windows svchost"="avserv.exe" []
    "BM0a6725ef"="C:\WINDOWS\system32\ppwwcxdv.dll" [2008-06-24 13:12 91136]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-15 20:00 15360]
    "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
    "Picasa Media Detector"="C:\Documents and Settings\Ville\Omat tiedostot\Omat kuvatiedostot\Picasa2\PicasaMediaDetector.exe" [2008-02-26 04:23 443968]
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{BE7E4CE1-8CBA-44A6-956F-462A667D3286}"= C:\WINDOWS\system32\urqOHYRK.dll [ ]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJYqOHY]
    mlJYqOHY.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqOHYRK]
    urqOHYRK.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=rnwjpgvu.dll
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "4500:UDP"= 4500:UDP:pilkki
    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
    R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-03-04 16:37]
    R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
    R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 01:43]
    S3 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 14:46]
    S3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2005-01-31 11:13]
    .
    'Ajoitetut teht„v„t'-kansion sis„lt”
    "2008-06-24 10:44:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
    - C:\Program Files\Windows Defender\MpCmdRun.exe
    .
    **************************************************************************
    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-24 13:44:06
    Windows 5.1.2600 Service Pack 2 FAT NTAPI
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\WINDOWS\system32\urqOHYRK.dll
    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\WINDOWS\system32\ppwwcxdv.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
    C:\ACER\EMANAGER\ANBMSERV.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
    C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
    C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
    C:\WINDOWS\system32\sistray.exe
    .
    **************************************************************************
    .
    Completion time: 2008-06-24 13:51:28 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-06-24 10:51:04
    Pre-Run: 13,264,355,328 tavua vapaana
    Post-Run: 13,879,246,848 tavua vapaana
    168 --- E O F --- 2008-06-24 10:48:33




    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:43:52, on 24.6.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O2 - BHO: {52b310ed-989d-3498-e214-abbf022fedc1} - {1cdef220-fbba-412e-8943-d989de013b25} - C:\WINDOWS\system32\rnwjpgvu.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {8BA35092-9698-4EC6-858C-A41609B07270} - C:\WINDOWS\system32\qoMedDVP.dll (file missing)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {BE7E4CE1-8CBA-44A6-956F-462A667D3286} - C:\WINDOWS\system32\urqOHYRK.dll (file missing)
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera
    O4 - HKLM\..\Run: [Windows svchost] avserv.exe
    O4 - HKLM\..\Run: [BM0a6725ef] Rundll32.exe "C:\WINDOWS\system32\ppwwcxdv.dll",s
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: rnwjpgvu.dll
    O20 - Winlogon Notify: mlJYqOHY - mlJYqOHY.dll (file missing)
    O20 - Winlogon Notify: urqOHYRK - urqOHYRK.dll (file missing)
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    --
    End of file - 6238 bytes
     
  4. yaht

    yaht Regular member

    Joined:
    Dec 6, 2005
    Messages:
    2,261
    Likes Received:
    0
    Trophy Points:
    46
    1. Lataa Combofix.exe työpöydällesi jommastakummasta linkistä:
    Combofix.exe
    Combofix.exe

    Avaa Muistio ja kopioi/liitä Lainaus: laatikon sisältö sinne:



    Tallenna nimellä CFScript (itse asiassa combofix tunnistaa tuon vaikka tiedostopääte ei olisi
    edes .txt).

    Sitten raahaa ja pudota CFScript ComboFix.exeen kuten alla.(Älä klikkaa)

    [​IMG]


    Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
    Käynnistä kone uudelleen, jos niin pyydetään ja lähetä combofix.txt-tiedoston sisältö tänne.

    Sammuta selain ja muut ohjelmat Fixin ajaksi. (ei virustorjuntaa)
    Käynnistä HijackThis:ja Scan ja ruksaa seuraavat punaisella listatut tiedostot sekä poista ne.(fix Chekked)


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O2 - BHO: {52b310ed-989d-3498-e214-abbf022fedc1} - {1cdef220-fbba-412e-8943-d989de013b25} - C:\WINDOWS\system32\rnwjpgvu.dll
    O2 - BHO: (no name) - {8BA35092-9698-4EC6-858C-A41609B07270} - C:\WINDOWS\system32\qoMedDVP.dll (file missing)
    O2 - BHO: (no name) - {BE7E4CE1-8CBA-44A6-956F-462A667D3286} - C:\WINDOWS\system32\urqOHYRK.dll (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [Windows svchost] avserv.exe
    O4 - HKLM\..\Run: [BM0a6725ef] Rundll32.exe "C:\WINDOWS\system32\ppwwcxdv.dll",s
    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O20 - AppInit_DLLs: rnwjpgvu.dll
    O20 - Winlogon Notify: mlJYqOHY - mlJYqOHY.dll (file missing)
    O20 - Winlogon Notify: urqOHYRK - urqOHYRK.dll (file missing)


    Tyhjennä roskakori ja käynnistä koneesi uudelleen.

    Postita tänne seuraavat lokit:
    * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta)
    * (C:\ComboFix.txt) raportti
    *
     
  5. luettelo

    luettelo Member

    Joined:
    Jun 18, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Moi tässä HJT ja combofix.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:47:18, on 24.6.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\sistray.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    --
    End of file - 4978 bytes


    ComboFix 08-06-20.4 - Ville 2008-06-24 16:28:21.2 - FAT32x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.110 [GMT 3:00]
    Running from: C:\Documents and Settings\Ville\Työpöytä\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Ville\Työpöytä\CFScript.txt
    * Created a new restore point
    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    FILE ::
    C:\dci.exe
    C:\dcis.exe
    C:\dciz.exe
    C:\Documents and Settings\Ville\usb2.exe
    C:\hszs.exe
    C:\irc.com
    C:\sexy.com
    C:\sz.exe
    C:\usb.exe
    C:\usb2.exe
    C:\usb22.exe
    C:\usbg22.exe
    C:\WIND
    C:\WINDOWS\avserv.exe
    C:\WINDOWS\BM0a6725ef.xml
    C:\WINDOWS\system32\hkfjucfb.dll
    C:\WINDOWS\system32\LLNURJAI.DLL
    C:\WINDOWS\system32\ppwwcxdv.dll
    C:\WINDOWS\system32\rnwjpgvu.dll
    C:\WINDOWS\system32\urqOHYRK.dll
    C:\WINDOWS\winudspm.exe
    .
    (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    C:\dci.exe
    C:\dcis.exe
    C:\dciz.exe
    C:\Documents and Settings\Ville\usb2.exe
    C:\hszs.exe
    C:\irc.com
    C:\sexy.com
    C:\sz.exe
    C:\usb.exe
    C:\usb2.exe
    C:\usb22.exe
    C:\usbg22.exe
    C:\WINDOWS\avserv.exe
    C:\WINDOWS\BM0a6725ef.xml
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\system32\hkfjucfb.dll
    C:\WINDOWS\system32\LLNURJAI.DLL
    C:\WINDOWS\system32\ppwwcxdv.dll
    C:\WINDOWS\system32\rnwjpgvu.dll
    C:\WINDOWS\system32\urqOHYRK.dll
    C:\WINDOWS\winudspm.exe
    .
    ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-24 to 2008-06-24 )))))))))))))))))
    .
    2008-06-24 14:03 . 2008-06-14 20:59 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-24 14:03 . 2008-06-14 20:59 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-06-18 19:01 . 2008-06-18 19:01 <KANSIO> d-------- C:\Program Files\Trend Micro
    2008-06-18 18:55 . 2008-06-18 18:55 322,560 --a------ C:\WINDOWS\system32\qoMedDVP.dll
    2008-06-06 23:29 . 2008-06-06 23:29 <KANSIO> d-------- C:\Program Files\ProPilkki2
    2008-06-06 21:38 . 2008-06-06 21:36 691,545 --a------ C:\WINDOWS\unins000.exe
    2008-06-06 21:38 . 2008-06-06 21:38 2,551 --a------ C:\WINDOWS\unins000.dat
    2008-06-06 21:12 . 2008-06-06 21:12 <KANSIO> d--hs---- C:\FOUND.007
    2008-05-28 09:39 . 2008-05-28 09:39 <KANSIO> d-------- C:\Program Files\Sun
    2008-05-28 09:38 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
    2008-05-28 09:27 . 2008-05-28 09:27 <KANSIO> d-------- C:\Program Files\Windows Defender
    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-05-12 16:13 --------- d-----w C:\Program Files\MSECache
    2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
    2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
    2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
    2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
    2008-04-17 10:52 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
    2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
    2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
    .
    Code:
    <pre>
    ----a-w       131,097,968 2006-06-25 16:35:34  C:\Documents and Settings\Ville\Omat tiedostot\lataukset\Nero.Premium.v7.2.3.2b.Incl.Keygen-DeathW\Nero-7.2.3.2b-ENG .exe
    </pre>
    ((((((((((((((((((((((((((((( snapshot@2008-06-24_13.49.58.78 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-06-24 10:41:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-06-24 13:34:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    - 2008-02-16 09:02:36 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
    + 2008-04-21 07:02:46 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
    - 2008-02-16 09:02:36 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
    + 2008-04-21 07:02:46 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
    - 2008-02-16 09:02:38 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll
    + 2008-04-21 07:02:48 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll
    - 2008-02-16 09:02:36 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
    + 2008-04-21 07:02:46 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
    - 2008-02-16 09:02:36 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
    + 2008-04-21 07:02:46 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
    - 2008-02-16 09:02:38 1,055,232 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
    + 2008-04-21 07:02:48 1,055,232 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
    - 2008-02-16 09:02:38 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    + 2008-04-21 07:02:48 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    - 2008-02-16 09:02:38 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    + 2008-04-21 07:02:48 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    - 2008-02-16 09:02:38 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    + 2008-04-21 07:02:48 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    - 2008-02-16 09:02:38 250,880 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
    + 2008-04-21 07:02:48 250,880 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
    - 2008-02-16 09:02:38 96,256 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
    + 2008-04-21 07:02:48 96,256 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
    - 2008-02-16 09:02:38 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    + 2008-04-21 07:02:48 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    - 2008-02-16 22:32:40 3,080,704 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    + 2008-04-21 07:02:50 3,080,704 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    - 2008-02-16 09:02:40 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    + 2008-04-21 07:02:50 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    - 2008-02-16 09:02:40 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
    + 2008-04-21 07:02:50 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
    - 2008-02-16 09:02:40 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
    + 2008-04-21 07:02:50 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
    - 2008-02-16 09:02:40 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    + 2008-04-21 07:02:50 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    - 2008-02-16 09:02:42 1,494,016 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
    + 2008-04-21 07:02:52 1,494,016 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
    - 2008-02-16 09:02:42 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
    + 2008-04-21 07:02:52 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
    - 2008-02-16 09:02:42 616,448 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    + 2008-04-21 07:02:52 616,448 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    - 2008-02-16 09:02:42 659,456 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
    + 2008-04-21 07:02:52 659,456 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
    - 2008-02-16 09:02:38 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    + 2008-04-21 07:02:48 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    - 2008-02-16 09:02:38 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
    + 2008-04-21 07:02:48 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
    - 2008-02-16 09:02:38 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    + 2008-04-21 07:02:48 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    - 2008-02-16 09:02:38 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll
    + 2008-04-21 07:02:48 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll
    - 2008-02-16 09:02:38 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
    + 2008-04-21 07:02:48 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
    - 2008-02-16 09:02:38 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
    + 2008-04-21 07:02:48 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
    - 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2008-05-29 23:35:12 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe
    - 2008-02-16 22:32:40 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
    + 2008-04-21 07:02:50 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
    - 2008-02-16 09:02:40 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
    + 2008-04-21 07:02:50 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
    - 2008-02-16 09:02:40 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    + 2008-04-21 07:02:50 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    - 2008-02-16 09:02:40 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
    + 2008-04-21 07:02:50 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
    - 2008-02-16 09:02:40 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    + 2008-04-21 07:02:50 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    - 2008-02-16 09:02:42 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll
    + 2008-04-21 07:02:52 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll
    - 2008-02-16 09:02:42 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
    + 2008-04-21 07:02:52 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
    - 2008-03-20 11:41:20 14,640 ------w C:\WINDOWS\system32\spmsg.dll
    + 2007-11-30 11:19:02 17,272 ------w C:\WINDOWS\system32\spmsg.dll
    - 2008-02-16 09:02:42 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll
    + 2008-04-21 07:02:52 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll
    - 2008-02-16 09:02:42 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
    + 2008-04-21 07:02:52 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
    - 2008-02-15 23:03:12 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    + 2008-04-17 11:03:44 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    + 2008-06-24 13:34:52 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_5c4.dat
    .
    -- Snapshot reset to current date --
    .
    (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8BA35092-9698-4EC6-858C-A41609B07270}]
    2008-06-18 18:55 322560 --a------ C:\WINDOWS\system32\qoMedDVP.dll
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 20:00 15360]
    "msnmsgr"="~C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
    "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" []
    "SiSPower"="SiSPower.dll" [2005-02-25 19:35 49152 C:\WINDOWS\system32\SiSPower.dll]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-09-15 20:00 208952]
    "LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:30 315392]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-23 21:35 180269]
    "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-07-25 16:35 102512]
    "Sonera"="C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" [2007-08-19 11:47 197880]
    "Windows svchost"="avserv.exe" []
    "BM0a6725ef"="C:\WINDOWS\system32\ppwwcxdv.dll" [ ]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-15 20:00 15360]
    "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
    "Picasa Media Detector"="C:\Documents and Settings\Ville\Omat tiedostot\Omat kuvatiedostot\Picasa2\PicasaMediaDetector.exe" [2008-02-26 04:23 443968]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJYqOHY]
    mlJYqOHY.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqOHYRK]
    urqOHYRK.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=rnwjpgvu.dll
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "4500:UDP"= 4500:UDP:pilkki
    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
    R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-03-04 16:37]
    R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
    R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 01:43]
    S3 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 14:46]
    S3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2005-01-31 11:13]
    .
    'Ajoitetut teht„v„t'-kansion sis„lt”
    "2008-06-24 13:38:04 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
    - C:\Program Files\Windows Defender\MpCmdRun.exe
    .
    **************************************************************************
    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-24 16:35:17
    Windows 5.1.2600 Service Pack 2 FAT NTAPI
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
    C:\ACER\EMANAGER\ANBMSERV.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
    C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
    C:\WINDOWS\system32\sistray.exe
    .
    **************************************************************************
    .
    Completion time: 2008-06-24 16:39:05 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-06-24 13:38:56
    ComboFix2.txt 2008-06-24 10:51:32
    Pre-Run: 16,892,657,664 tavua vapaana
    Post-Run: 16,977,985,536 tavua vapaana
    251 --- E O F --- 2008-06-24 12:22:18
     
  6. yaht

    yaht Regular member

    Joined:
    Dec 6, 2005
    Messages:
    2,261
    Likes Received:
    0
    Trophy Points:
    46
    No niin alkaako tuntua kone vähän paremmalta?

    ******************************************
    Kirjoita windowsin käynnistävalikon suorita-kenttään ComboFix.exe /u paina OK
    ***************************************************************************


    Lataa Malwarebytes' Anti-Malware työpöydällesi.

    * Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman.
    * Lopuksi varmistu, että seuraavat on valittu: Päivitä Malwarebytes' Anti-Malware ja Käynnistä Malwarebytes' Anti-Malware ja sen jälkeen klikkaa Lopeta.
    * Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version.
    * Kun ohjelma on latautunut, valitse Suorita täysi tarkistus ja klikkaa Tarkista.
    * Kun skanni on valmis, klikkaa OK ja sitten Näytä tulokset nähdäksesi tulokset.
    * Varmistu, että kaikki on merkitty ja klikkaa Poista valitut.
    * Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös
    täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt
    * Lähetä lokin sisältö seuraavassa viestissäsi + uusi hjt-loki.
     
  7. luettelo

    luettelo Member

    Joined:
    Jun 18, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Hihi! Kivaa! Pitkästä aikaa saa oikein INTTERNETTIN avattua:)

    Tässä olis tämä anti-malware:

    Malwarebytes' Anti-Malware 1.18
    Tietokantaversio: 885

    18:06:40 24.6.2008
    mbam-log-6-24-2008 (18-06-40).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|)
    Tarkistetut kohteet: 87925
    Kulunut aika: 40 minute(s), 7 second(s)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 1
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 0
    Saastuneita tiedostoja: 67

    Saastuneita muistiprosesseja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita tiedostoja:
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1339\A0096653.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1339\A0096657.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1340\A0096672.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1340\A0096675.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1341\A0096720.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1342\A0096723.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1344\A0096724.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1345\A0096729.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1347\A0096775.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1347\A0096791.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1348\A0096806.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1349\A0098812.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1349\A0098813.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0099000.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0099017.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0099021.EXE (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1353\A0100058.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100074.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100078.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100079.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100080.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100081.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100082.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100084.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100085.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1354\A0100086.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100118.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100119.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100120.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100121.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100135.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1355\A0100136.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100308.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100309.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100310.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100311.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100313.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100314.com (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100316.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100317.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100318.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100319.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100322.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{E35F7DCA-5BD1-4ABA-8353-6FE38401F7D7}\RP1358\A0100337.EXE (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\dci.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\dcis.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\dciz.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\irc.com.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\sexy.com.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\usb.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\usb2.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\usb22.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\usbg22.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\service.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\winudspm.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\avserv.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\efcATNHw.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\mlJYpOeC.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\pmnKdAqp.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\rqRJAQJA.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\rqRJAqQI.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\vtUlJccC.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\vtUlLCst.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\yayaArrS.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Documents and Settings\Ville\usb2.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qoMedDVP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.





    Ja tässä uusin HJT:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:09:31, on 24.6.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\sistray.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\LVComsX.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://plaza.fi
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Sonera] "C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" /P Sonera
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    --
    End of file - 5101 bytes
     
  8. yaht

    yaht Regular member

    Joined:
    Dec 6, 2005
    Messages:
    2,261
    Likes Received:
    0
    Trophy Points:
    46
    Hyvä sitten :D

    ******************************************
    Kirjoita windowsin käynnistävalikon suorita-kenttään ComboFix.exe /u paina OK
    ***************************************************************************

    Järjestelmän palauttamisen poistaminen käytöstä
    Voit poistaa järjestelmän palauttamisen käytöstä seuraavasti:

    1.Napsauta Käynnistä-painiketta, napsauta Oma tietokone -kuvaketta hiiren kakkospainikkeella ja valitse sitten Ominaisuudet.

    2.Valitse Järjestelmän palauttaminen -välilehti.

    3.Valitse Poista järjestelmän palauttaminen käytöstä -valintaruutu (tai Poista järjestelmän palauttaminen käytöstä kaikissa asemissa -valintaruutu) ja valitse sitten OK.

    4.Valitse Kyllä, kun näyttöön tulee kehote järjestelmän palauttamisen poistamisesta käytöstä.

    Lataa CCleaner tästä

    - Asennuksessa poista merkki/rasti kohdasta "asenna Yahoo! toolbar/työkalupalkki".
    - Asennuksen jälkeen aukaise CCleaner.
    - Valitse vasemmalta pystyrivistä Options.
    - Valitse viereisestä pystyrivistä Settings.
    - Language kohtaan valitse Suomi.

    - Käynnistä CCleaner.
    - Valitse Valinnat.
    - Paina Lisäasetukset.
    - Ota ruksi pois kohdasta "Poista vain yli 48 tuntia vanhat tiedostot Windowsin tilapäiskansioista".

    Puhdistaja

    - Valitse vasemmalta pystyrivistä Puhdistaja.
    - Paina alhaalta Tutki.
    Nyt CCleaner tutkii, mitä voidaan poistaa (tempit, cookiessit jne.).
    - Kun tutkiminen on valmis, paina Aja CCleaner.
    Nyt CCleaner poistaa löydetyt tempit, cookiessit jne.

    Rekisterin virheiden korjaus

    - Valitse vasemmalta pystyrivistä Rekisteri.
    - Paina alhaalta Etsi rekisterin virheitä.
    - Kun etsintä on valmis ja olet varma, että haluat korjata ne rivit jotka ovat merkattuja, niin paina Korjaa valitut rekisterin virheet.
    - Sinulta kysytään "haluatko varmuuskopioida muutokset rekisteriin", paina Kyllä. Tallenna varmuuskopio vaikka "Omat tiedostot" -kansioon.
    - Klikkaa uudesta aukeavasta ikkunasta Korjaa kaikki valitut virheet.
    - Saat vielä varmistus kysymyksen, paina Ok.
    - Kun virheet on korjattu, paina Sulje.

    Nyt voit suljea CCleanerin painamalla oikealta ylhäältä punaista rastia.

    Javan päivitys ja välimuistin tyhjennys:

    1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
    2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
    Niissä pitäisi olla seuraava kuva vieressä:[​IMG]

    3. Valitse kaikki entiset Java versiosi ja valitse Poista.
    4. Asenna uusin Java päivitys seuraavasta linkistä..
    5. Käynnistä kone uudelleen asennuksen jälkeen:

    http://java.sun.com/javase/downloads/index.jsp

    Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u6

    Paina Download

    Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se.

    6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).

    7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia.

    (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa.
    Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle).

    8. Varmista että kaikki kaksi valintaa ovat rastitettuja:

    *Applications and Applets

    *Trace and Log Files

    Ja paina OK -nappia

    9. Klikkaa OK "Temporary Files Settings" -ikkunassasi.

    10. Klikkaa OK jättääksesi Java asetusikkunasi.

    No niin ja lopuksi skannaa viellä tuolla Malwarebytesillä niin katsotaan ettei ole tullt takaisin noit mörkkejä.
     
  9. luettelo

    luettelo Member

    Joined:
    Jun 18, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11

    Nyt on kaikki tehty mitä käsketty, eikä anti-malwarella löytynyt enää mitään.
    Olisko se nyt niinku putsattu? Vai pitääkö vielä jotain tehdä?

    Kiitoksia älyttömän paljon. En olisi itse saanut koskaan konettani käyttökuntoon.

    Nyt se Javan (disc space) liukusäädin on siinä keskikohdassa. Onks se siinä hyvä, vai pitääkö sitä vielä siirrellä?

    Tässä tämä anti-malware:

    Malwarebytes' Anti-Malware 1.18
    Tietokantaversio: 885

    20:22:32 24.6.2008
    mbam-log-6-24-2008 (20-22-32).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|)
    Tarkistetut kohteet: 81639
    Kulunut aika: 21 minute(s), 44 second(s)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 0
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 0
    Saastuneita tiedostoja: 0

    Saastuneita muistiprosesseja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita tiedostoja:
    (Haitallisia kohteita ei löydetty)
     

Share This Page