Elikkä eilen imuroin maximagamesin pelin Lost Island,mutta siitä tulikin jonkinlainen virus koneelle. Avast,Sygate, ja spybot hävisivät kuin tuhka tuuleen,ja kun yritin asentaa niitä uudelleen niin eivät asenna exe tiedostoja ollenkaan eli eivät toimi. Kokeilin muitakin virus ja palomuureja ja aina sama juttu. Muut ohjelmat kyllä toimivat. Mistähän kyse ja auttaako muu kuin asentaa XP uudestaan
kokeile tuota ensin ja laita loki siintä Escan Ohjeet tuolla sivulla. http://koti.mbnet.fi/pattaya1/escanmwav.htm lataa tuosta http://www.spywareinfo.dk/download/mwav.exe päivitä tuosta http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat laita täpit merkkauksien mukaan http://koti.mbnet.fi/pattaya1/eScan6.jpg scannaa jos ala luukkuun tulee jotain niin kopioi se näin: Käytä komentoa Ctrl+A. Kopioi rivit komennolla Ctrl+C. Liitä rivit komennolla Ctrl+V. Laita virus log tänne. =================== Lataa TÄSTÄ HJTInstall.exe * Tallenna HJTInstall.exe työpöydällesi. * Tuplaklikkaa HJTInstall.exe-kuvaketta työpöydälläsi. * Oletuksena se asentaa itsensä hakemistoon C:\Program Files\Trend Micro\HijackThis. * Klikkaa Install. * Asennusohjelma luo HijackThis-kuvakkeen työpöydälle. * Kun asennus on valmis, se käynnistää HijackThisin. * Klikkaa Do a system scan and save a logfile-painiketta. Ohjelma aloittaa skannauksen ja lokin pitäisi avautua Muistioon. * Klikkaa ensin "Muokkaa > Valitse kaikki" sitten "Muokkaa > Kopioi" kopioidaksesi koko lokin sisällön. * Liitä lokin sisältö seuraavaan vastaukseesi. * ÄLÄ käytä Analyse This-nappulaa, sen löydöt ovat vaarallisia väärinymmärrettyinä. * ÄLÄ fixaa HijackThis-ohjelmalla vielä mitään. Suurin osa sen löydöistä ovat joko harmittomia tai jopa tarpeellisia.
Tässä olis tää Escan File C:\WINDOWS\system32\chkdsk.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\system32\ntoskrnl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\Program Files\Registry Mechanic\Update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB890859\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB893756\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB894391\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB896358\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB896423\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB896428\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB898461\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB899587\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB899591\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB900485\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB900725\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB901017\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB901214\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB902400\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB904706\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB904942\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB905414\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB905749\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB908519\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB908531\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB910437\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB911164\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB911280\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB911562\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB911927\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB913580\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB914388\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB914389\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB915865\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB916595\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB917344\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB917422\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB917953\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB918118\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB918439\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB919007\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB920213\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB920670\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB920683\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB920685\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB920872\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB921503\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB922582\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB922819\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB923414\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB923694\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB923980\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB924191\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB924270\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB924496\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB925902\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB926255\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB926436\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB927779\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB927802\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB927891\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB928090\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB928255\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB928843\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB929123\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB929969\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB930178\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB930916\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB931261\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB931768-IE7\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB931784\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB931836\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB932168\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB933360\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB933566-IE7\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB935448\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB935839\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB935840\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB936021\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB937143-IE7\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB938828\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$hf_mig$\KB938829\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\SoftwareDistribution\Download\aba121595894c0d28a37a62774aabdeb\update\update.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\system32\dllcache\chkdsk.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\WINDOWS\system32\dllcache\ntoskrnl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File D:\BitCometImut\Dzwonki Mp3\Mlns Zelmerlöw - Cara mia.mp3.bc! infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File D:\EmuleImut\Car Thief 5.1.0.4.zip infected by "Trojan-Downloader.Win32.Bagle.du" Virus. Action Taken: File Deleted. File D:\EmuleImut\Crooked Money 1.3.0.1.zip infected by "Trojan-Downloader.Win32.Bagle.du" Virus. Action Taken: File Deleted. File D:\Softat\PCTools Registry Mechanic 6.0.0.780-Keygen.rar infected by "Trojan-Downloader.Win32.LoadAdv.gen" Virus. Action Taken: File Deleted. File D:\System Volume Information\_restore{B3E0FA7E-6A4C-4891-A6BB-76483875F598}\RP238\A0038455.exe infected by "Trojan-Downloader.Win32.Bagle.dv" Virus. Action Taken: File Deleted.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:25:53, on 7.9.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\lg_fwupdate\fwupdate.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Kaspersky\mwavscan.com C:\Kaspersky\kavss.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1189128805234 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by141fd.bay141.hotmail.msn.com/activex/HMAtchmt.ocx O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (file missing) O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- End of file - 6002 bytes