1. Tämä sivusto käyttää keksejä (cookie). Jatkamalla sivuston käyttämistä hyväksyt keksien käyttämisen. Lue lisää.

Virukset "vundo" ja "lop" miten pois?

Viestiketju Virukset ja haittaohjelmat -osiossa. Ketjun avasi clowny 25.01.2009.

Viestiketjun tila:
Viestiketju on suljettu.
  1. clowny

    clowny Member

    Liittynyt:
    16.11.2005
    Viestejä:
    16
    Kiitokset:
    0
    Pisteet:
    11
    Terve!

    Koneelta löyty tommoset virukset vundo ja lop ja lisäksi 5 objectia mitkä AVG laittoi changed statukseen. Avg yritti parantaa virukset mutta tuloksena oli (2 files healed, 0 success, 2 error)
    Asensin ton Malmwarebytesin, scannasin koneen ja poistin löytyneet kurat. Tässä malmwaren loki:

    Malwarebytes' Anti-Malware 1.33
    Tietokantaversio: 1654
    Windows 5.1.2600 Service Pack 2

    25.1.2009 22:11:18
    mbam-log-2009-01-25 (22-11-18).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|)
    Tarkistetut kohteet: 96002
    Kulunut aika: 18 minute(s), 4 second(s)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 8
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 3
    Saastuneita tiedostoja: 41

    Saastuneita muistiprosesseja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia:
    HKEY_CLASSES_ROOT\AppID\{0507fdde-f3b7-49f5-9e8f-c557e991f39b} (Adware.Hotbar) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    C:\Documents and Settings\Isk\Application Data\SpamBlockerUtility_Icons (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Perttu\Application Data\SpamBlockerUtility_Icons (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Perttu\Application Data\SpamBlocker (Adware.Hotbar) -> Quarantined and deleted successfully.

    Saastuneita tiedostoja:
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040864.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040865.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040866.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040867.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040868.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040869.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040870.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040871.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040872.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040873.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040874.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040880.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040883.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040890.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040891.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040892.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040895.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040897.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040905.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040906.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040908.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040910.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040911.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040912.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D9174CDA-9704-4261-A2D5-E45457AD5ADA}\RP416\A0040914.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Isk\Application Data\SpamBlockerUtility_Icons\wallpapere1.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Isk\Application Data\SpamBlockerUtility_Icons\Jamster2.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Isk\Application Data\SpamBlockerUtility_Icons\Registryrepair.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Perttu\Application Data\SpamBlockerUtility_Icons\wallpapere1.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Perttu\Application Data\SpamBlockerUtility_Icons\Jamster2.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Perttu\Application Data\SpamBlockerUtility_Icons\Registryrepair.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\BM251a25c3.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\BM251a25c3.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Perttu\Työpöytä\Free PC Wallpapers.lnk (Rogue.Link) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Perttu\Työpöytä\Repair Your Registry.lnk (Rogue.Link) -> Quarantined and deleted successfully.
    C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> Quarantined and deleted successfully.

    Asensin myös ton hijackin, laitanko lokia siitä tulemaan?
    Jos joku viitsisi autella, kiitos etukäteen.
     
  2.  
Viestiketjun tila:
Viestiketju on suljettu.

Jaa tämä sivu