Veljen kone sekaisin spywaresta. HJT apua kaivataan.

Discussion in 'Virukset ja haittaohjelmat' started by Kaakatus, Sep 1, 2006.

  1. Kaakatus

    Kaakatus Regular member

    Joined:
    Jun 29, 2005
    Messages:
    1,776
    Likes Received:
    0
    Trophy Points:
    46
    Veli asenteli jotain kummallista kamaa koneelleen ja tulos on tämä. Pop uppeja hyppii ruudulle jotka ilmoittavat koneen olevan saastunut etc. Ewidolla ja koneen virustorjunnalla (nod 32) scannailin, mutta eipä mitään oikeastaan löytäneet. Tuota hjt-logia katsellessa ihmettelin sen pituutta. Ja hjt on asennettu c:\hijackthis\hijackthis.exe.

    EDIT: Ajoin vielä eScanninkin, mutta ei auttanut.

    Logfile of HijackThis v1.99.1
    Scan saved at 22:32:58, on 1.9.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\PCODEC\isamonitor.exe
    C:\Program Files\PCODEC\pmsngr.exe
    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\PCODEC\pmmon.exe
    C:\Program Files\PCODEC\isamini.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pelimaailma.org/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\PCODEC\isaddon.dll
    O3 - Toolbar: Protection Bar - {fe2d25c1-c1db-4b5e-9390-af1cb5302f32} - C:\Program Files\PCODEC\iesplugin.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
     
    Last edited: Sep 1, 2006
  2. Jupsu

    Jupsu Active member

    Joined:
    Dec 30, 2005
    Messages:
    1,459
    Likes Received:
    2
    Trophy Points:
    68
    Lataa SmitfraudFix
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:

    Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
    Postita tämän tekstitiedoston sisältö viestiketjuusi.
     
  3. Kaakatus

    Kaakatus Regular member

    Joined:
    Jun 29, 2005
    Messages:
    1,776
    Likes Received:
    0
    Trophy Points:
    46
    Ikävä tuottaa pettymystä, mutta kerkesin jo kiireissäni forkata kovon, joten tämä ketju tuli turhaksi.
     
  4. Jupsu

    Jupsu Active member

    Joined:
    Dec 30, 2005
    Messages:
    1,459
    Likes Received:
    2
    Trophy Points:
    68
    selvä.. no pää asia että pöpö on poissa..:)

    EDIT: muista päivittää java.. ainakin uossa lokissa java on IKIVANHA..
     
    Last edited: Sep 2, 2006

Share This Page