Eli ajoin tällä koneella malwarebytesin, joka löysi 117 vihua ja ie kuulemma pomputtaa(pomputti?) ikkunoita auki itsekseen. Alla malware logi ja sen jälkeen kone käynnistetty ja otettu hjt-logi. Kone todella hidas. Malwarebytes' Anti-Malware 1.17 Tietokantaversio: 849 12:49:29 2008-06-12 mbam-log-6-12-2008 (12-49-29).txt Tarkistustyyppi: Täysi tarkistus (C:\|) Tarkistetut kohteet: 145859 Kulunut aika: 2 hour(s), 22 minute(s), 37 second(s) Saastuneita muistiprosesseja: 0 Saastuneita muistimoduuleja: 3 Saastuneita rekisteriavaimia: 13 Saastuneita rekisteriarvoja: 5 Saastuneita rekisterikohteita: 2 Saastuneita hakemistoja: 0 Saastuneita tiedostoja: 94 Saastuneita muistiprosesseja: (Haitallisia kohteita ei löydetty) Saastuneita muistimoduuleja: C:\WINDOWS\system32\ungmpawo.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\xxywTKaY.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\xxyyayxx.dll (Trojan.FakeAlert) -> Unloaded module successfully. Saastuneita rekisteriavaimia: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4b1ceb99-b70d-4f5a-808f-8782dae58c14} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{4b1ceb99-b70d-4f5a-808f-8782dae58c14} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{487c9905-26a8-42c8-8033-c58ad3d2aec3} (Trojan.FakeAlert) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{487c9905-26a8-42c8-8033-c58ad3d2aec3} (Trojan.FakeAlert) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyyayxx (Trojan.FakeAlert) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Saastuneita rekisteriarvoja: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4bdb5e18 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{487c9905-26a8-42c8-8033-c58ad3d2aec3} (Trojan.FakeAlert) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows svchost (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSN (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM48e86d84 (Trojan.Agent) -> Delete on reboot. Saastuneita rekisterikohteita: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\xxywtkay -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\xxywtkay -> Quarantined and deleted successfully. Saastuneita hakemistoja: (Haitallisia kohteita ei löydetty) Saastuneita tiedostoja: C:\WINDOWS\system32\asenrwhf.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\fhwrnesa.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bhduusqc.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cqsuudhb.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\opnnlIXQ.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\QXIlnnpo.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\QXIlnnpo.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\qoMcaxXN.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\NXxacMoq.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\NXxacMoq.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ungmpawo.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\owapmgnu.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xxywTKaY.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\YaKTwyxx.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\YaKTwyxx.ini2 (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\yayyYPgG.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\GgPYyyay.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\GgPYyyay.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xxyyayxx.dll (Trojan.FakeAlert) -> Delete on reboot. C:\Documents and Settings\Marrun juttuja\Local Settings\Temp\eraseme_41131.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Documents and Settings\Marrun juttuja\Local Settings\Temporary Internet Files\Content.IE5\3KF2ZB4X\bot[1].exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Documents and Settings\Marrun juttuja\Local Settings\Temporary Internet Files\Content.IE5\3KF2ZB4X\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Marrun juttuja\Local Settings\Temporary Internet Files\Content.IE5\3KF2ZB4X\kb713501[1] (Trojan.LowZones) -> Quarantined and deleted successfully. C:\Documents and Settings\Marrun juttuja\Local Settings\Temporary Internet Files\Content.IE5\3KF2ZB4X\setup[1].exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Documents and Settings\Marrun juttuja\Local Settings\Temporary Internet Files\Content.IE5\TB5H81I3\bot[1].exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Documents and Settings\Marrun juttuja\Local Settings\Temporary Internet Files\Content.IE5\UDC8KGH4\css4[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Marrun juttuja\Local Settings\Temporary Internet Files\Content.IE5\UDC8KGH4\css4[3] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Paula\Local Settings\Temporary Internet Files\Content.IE5\6J45X1UJ\bot[1].exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP854\A0393458.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP855\A0394444.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP855\A0397461.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP856\A0398474.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398525.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398528.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398539.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398543.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398548.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398553.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398554.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398556.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP857\A0398557.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398575.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398577.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398588.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398598.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398599.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398600.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398601.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398608.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398610.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398631.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398634.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP858\A0398635.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP859\A0398657.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP859\A0398658.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP859\A0398659.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP859\A0398670.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399700.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399705.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399706.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399707.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399708.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399715.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399717.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399729.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399732.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399736.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399739.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399740.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399741.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399742.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399749.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399751.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399760.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399763.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399764.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399784.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399785.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399786.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP861\A0399787.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP862\A0399796.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP863\A0399822.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP863\A0400826.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP864\A0403851.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{A50E7FFE-C7AF-48DC-82C8-8C96FB23AEF7}\RP865\A0404851.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\eaifsekt.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\WINDOWS\system32\knadyfsy.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\WINDOWS\system32\otxohceo.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\WINDOWS\system32\qwdtnrgb.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tgbhskqk.exe (Trojan.LowZones) -> Quarantined and deleted successfully. C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vwfujbap.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\sjxhwrpw.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:26, on 2008-06-12 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE C:\WINDOWS\system32\bgsvcgen.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\WINDOWS\system32\HPConfig.exe C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\F-Secure\Common\FSMB32.EXE C:\Program Files\F-Secure\Common\FCH32.EXE C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\carpserv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Winamp3\winampa.exe C:\Program Files\F-Secure\Common\FSM32.EXE C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Sensior\Bin\Reader.exe C:\Program Files\Java\j2re1.4.2_11\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe C:\Program Files\OpenOffice.org1.0.1\program\soffice.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: {3f1c75e5-7558-f20a-a9a4-67c13737d6ea} - {ae6d7373-1c76-4a9a-a02f-85575e57c1f3} - C:\WINDOWS\system32\wbnjpufr.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [Pinnacle WebUpdater] "C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe O4 - HKLM\..\Run: [Sensior Reader] C:\Program Files\Sensior\Bin\Start Reader.bat O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_11\bin\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Error Safe] "C:\Program Files\Error Safe Free\ers.exe" /scan O4 - HKCU\..\Run: [PMCS] "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [VMCL] E:\\VMC_PBStarter.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 1.0.1.lnk = C:\Program Files\OpenOffice.org1.0.1\program\quickstart.exe O4 - Global Startup: IEEE802.11b WLAN Card Utility.lnk = C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_11\bin\npjpi142_11.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_11\bin\npjpi142_11.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game10.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe -- End of file - 9163 bytes
Poista käytöstä järjestelmän palautus ohje: http://support.microsoft.com/kb/310405/fi Mene Windowsin ControlPaneliin (Ohjauspaneli) ja sieltä Lisää / Poista sovellus Etsi ja poista ohjelma jonka nimessä on: Error Safe Free Fixaa Hijacthis:llä seuraavat rivit O4 - HKCU\..\Run: [Error Safe] "C:\Program Files\Error Safe Free\ers.exe" /scan Javan päivitys ja välimuistin tyhjennys: 1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa. 2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... ) Niissä pitäisi olla seuraava kuva vieressä: 3. Valitse kaikki entiset Java versiosi ja valitse Poista. 4. Asenna uusin Java päivitys seuraavasta linkistä.. 5. Käynnistä kone uudelleen asennuksen jälkeen: http://java.sun.com/javase/downloads/index.jsp Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u6 Paina Download Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se. 6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi). 7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia. (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa. Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle). 8. Varmista että kaikki kaksi valintaa ovat rastitettuja: *Applications and Applets *Trace and Log Files Ja paina OK -nappia 9. Klikkaa OK "Temporary Files Settings" -ikkunassasi. 10. Klikkaa OK jättääksesi Java asetusikkunasi. Postaa uusi hijackthis logi.
Ohjeet toteutettu, uus hjt. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:35, on 2008-06-12 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\carpserv.exe C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE C:\WINDOWS\system32\bgsvcgen.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\WINDOWS\system32\HPConfig.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\F-Secure\Common\FSMB32.EXE C:\Program Files\Winamp3\winampa.exe C:\Program Files\F-Secure\Common\FCH32.EXE C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Common\FSM32.EXE C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe C:\Program Files\OpenOffice.org1.0.1\program\soffice.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: {3f1c75e5-7558-f20a-a9a4-67c13737d6ea} - {ae6d7373-1c76-4a9a-a02f-85575e57c1f3} - C:\WINDOWS\system32\wbnjpufr.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [Pinnacle WebUpdater] "C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe O4 - HKLM\..\Run: [Sensior Reader] C:\Program Files\Sensior\Bin\Start Reader.bat O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PMCS] "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [VMCL] E:\\VMC_PBStarter.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 1.0.1.lnk = C:\Program Files\OpenOffice.org1.0.1\program\quickstart.exe O4 - Global Startup: IEEE802.11b WLAN Card Utility.lnk = C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game10.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe -- End of file - 9137 bytes
1. Lataa Combofix.exe työpöydällesi jommastakummasta linkistä: Combofix.exe Combofix.exe Avaa Muistio ja kopioi/liitä Lainaus: laatikon sisältö sinne: Tallenna nimellä CFScript (itse asiassa combofix tunnistaa tuon vaikka tiedostopääte ei olisi edes .txt). Sitten raahaa ja pudota CFScript ComboFix.exeen kuten alla.(Älä klikkaa) Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen. Käynnistä kone uudelleen, jos niin pyydetään ja lähetä combofix.txt-tiedoston sisältö tänne. Sammuta selain ja muut ohjelmat Fixin ajaksi. (ei virustorjuntaa) Käynnistä HijackThis:ja Scan ja ruksaa seuraavat punaisella listatut tiedostot sekä poista ne.(fix Chekked) O2 - BHO: {3f1c75e5-7558-f20a-a9a4-67c13737d6ea} - {ae6d7373-1c76-4a9a-a02f-85575e57c1f3} - C:\WINDOWS\system32\wbnjpufr.dll Tyhjennä roskakori ja käynnistä koneesi uudelleen. Postita tänne seuraavat lokit: * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta) * (C:\ComboFix.txt) raportti *
ComboFix-logi ja uusi hjt. Piti fixata seuraava rivi :O2 - BHO: {3f1c75e5-7558-f20a-a9a4-67c13737d6ea} - {ae6d7373-1c76-4a9a-a02f-85575e57c1f3} - C:\WINDOWS\system32\wbnjpufr.dll Tuota riviä ei kuitenkaan enään löytynyt...alla logit ComboFix 08-06-10.5 - sami office 2008-06-12 15:02:11.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.138 [GMT 3:00] Running from: C:\Documents and Settings\sami office\Työpöytä\ComboFix.exe Command switches used :: C:\Documents and Settings\sami office\Työpöytä\CFScript.txt * Created a new restore point * Resident AV is active WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: C:\WINDOWS\system32\wbnjpufr.dll . (((((((((((((((((((((((((((((((((((((( Muut poistot )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BM48e86d84.xml C:\WINDOWS\pskt.ini C:\WINDOWS\system32\btonimot.dll C:\WINDOWS\system32\dfritkbw.dll C:\WINDOWS\system32\dxfxarhi.ini C:\WINDOWS\system32\egMmmUvw.ini2 C:\WINDOWS\system32\exiutvki.dll C:\WINDOWS\system32\ffjglmwd.dll C:\WINDOWS\system32\fntqukne.dll C:\WINDOWS\system32\hcepivuk.dll C:\WINDOWS\system32\hnnqdwhh.ini C:\WINDOWS\system32\huvnqkxh.dll C:\WINDOWS\system32\ioykahny.dll C:\WINDOWS\system32\kytteywg.dll C:\WINDOWS\system32\ljnjsips.dll C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\mubtmlkp.dll C:\WINDOWS\system32\mvcnvqnl.dll C:\WINDOWS\system32\oalitjth.dll C:\WINDOWS\system32\pabjufwv.ini C:\WINDOWS\system32\qolcpvki.dll C:\WINDOWS\system32\sjxhwrpw.dll C:\WINDOWS\system32\srgmvsqh.dll C:\WINDOWS\system32\tucxvfet.ini C:\WINDOWS\system32\txridfuh.dll C:\WINDOWS\system32\ungmpawo.dll C:\WINDOWS\system32\uwtgipua.dll C:\WINDOWS\system32\wbnjpufr.dll C:\WINDOWS\system32\vwfujbap.dll C:\WINDOWS\system32\xxywTKaY.dll C:\WINDOWS\system32\xxyyayxx.dll C:\WINDOWS\system32\YaKTwyxx.ini C:\WINDOWS\system32\YaKTwyxx.ini2 . ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-12 to 2008-06-12 ))))))))))))))))) . 2008-06-12 14:26 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-06-12 14:24 . 2008-06-12 14:26 <KANSIO> d-------- C:\Program Files\Java 2008-06-12 14:24 . 2008-06-12 14:24 <KANSIO> d-------- C:\Program Files\Common Files\Java 2008-06-12 13:22 . 2008-06-12 13:22 <KANSIO> d-------- C:\Program Files\Trend Micro 2008-06-12 10:24 . 2008-06-12 10:24 <KANSIO> d-------- C:\Documents and Settings\sami office\Application Data\Malwarebytes 2008-06-12 10:23 . 2008-06-12 10:23 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-06-12 10:23 . 2008-06-12 10:23 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-06-12 10:23 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-06-12 10:23 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-06-11 12:10 . 2008-06-11 12:10 157,184 --a------ C:\WINDOWS\system32\pheoyakl.dll 2008-06-10 21:37 . 2008-06-10 21:37 268 --ah----- C:\sqmdata00.sqm 2008-06-10 21:37 . 2008-06-10 21:37 244 --ah----- C:\sqmnoopt00.sqm 2008-06-10 21:37 . 2008-06-10 21:37 172 --ah----- C:\sqmnoopt01.sqm 2008-06-10 21:37 . 2008-06-10 21:37 160 --ah----- C:\sqmdata01.sqm 2008-06-08 13:22 . 2008-06-08 13:22 100,352 --a------ C:\WINDOWS\system32\njiyaier.dll 2008-06-03 00:21 . 2008-06-03 00:21 97,116 --a------ C:\WINDOWS\DC5177176.zip . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-02 19:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom 2008-04-23 06:56 66,008 ----a-w C:\Documents and Settings\sami office\Application Data\GDIPFONTCACHEV1.DAT 2008-04-18 16:03 --------- d-----w C:\Documents and Settings\Marrun juttuja\Application Data\LimeWire 2006-11-04 12:39 67,552 ----a-w C:\Documents and Settings\Marrun juttuja\Application Data\GDIPFONTCACHEV1.DAT 2006-05-27 12:53 56 --sh--r C:\WINDOWS\system32\BC9F139FCC.sys . (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„ [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 02:12 15360] "PMCS"="C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" [ ] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 20:46 68856] "VMCL"="E:\\VMC_PBStarter.exe" [ ] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CARPService"="carpserv.exe" [2003-05-21 15:35 4608 C:\WINDOWS\system32\carpserv.exe] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-02-26 16:25 180316] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-14 17:29 290816] "PreloadApp"="c:\hp\drivers\printers\photosmart\hphprld.exe" [2001-12-12 07:05 36864] "srmclean"="C:\Cpqs\Scom\srmclean.exe" [2001-07-25 00:34 36864] "Display Settings"="C:\Program Files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 06:26 45056] "QT4HPOT"="C:\Program Files\HPQ\One-Touch\OneTouch.EXE" [2003-01-31 01:53 106496] "AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28 684032] "WinampAgent"="C:\Program Files\Winamp3\winampa.exe" [2002-07-23 19:58 12288] "F-Secure Manager"="C:\Program Files\F-Secure\Common\FSM32.exe" [2002-06-06 12:52 106571] "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-16 02:41 163840] "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ] "PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [ ] "Pinnacle WebUpdater"="C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" [ ] "PMCRemote"="C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [ ] "Sensior Reader"="C:\Program Files\Sensior\Bin\Start Reader.bat" [2006-06-06 17:02 223] "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32 53248] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-16 09:55 1838592] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-15 02:12 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [ ] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\WINDOWS\\system32\\sessmgr.exe"= "C:\\WINDOWS\\system32\\ntvdm.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= R0 sonypvl2;sonypvl2;C:\WINDOWS\system32\drivers\sonypvl2.sys [2003-07-25 15:02] R1 sonypvf2;sonypvf2;C:\WINDOWS\system32\drivers\sonypvf2.sys [2003-08-20 10:51] R1 sonypvt2;sonypvt2;C:\WINDOWS\system32\drivers\sonypvt2.sys [2003-08-20 10:44] R2 BackWeb Client - 7681197;F-Secure BackWeb;C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [2006-09-29 12:54] R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys [2002-04-23 14:23] R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSgk.sys [2002-05-22 15:52] R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys [2002-04-23 14:23] R2 FSpm;F-Secure Policy Manager;C:\Program Files\F-Secure\Common\FSPM.SYS [2002-06-06 12:52] R3 ALiIRDA;ALi Infrared Device Driver;C:\WINDOWS\system32\DRIVERS\aliirda.sys [2001-12-17 14:54] R3 CALIAUD;Conexant AMC 3D Environmental Audio;C:\WINDOWS\system32\drivers\caliaud.sys [2004-02-17 17:58] R3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys [2004-02-17 17:59] R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\system32\DRIVERS\DP83815.SYS [2002-08-29 03:00] R3 WLPC;IEEE802.11b WLAN PC Card v3.0 Driver;C:\WINDOWS\system32\DRIVERS\WLPCN51.sys [2002-09-05 18:25] S1 sonypvd2;sonypvd2;C:\WINDOWS\system32\DRIVERS\sonypvd2.sys [2003-06-24 10:29] S3 USB28xxBGA;Pinnacle PCTV DVB-T USB Stick;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2005-11-22 20:04] S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2005-11-22 20:04] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40fa52f1-e3d1-11dc-b063-00a0c5b13105}] \Shell\AutoRun\command - E:\VMC_PBStarter.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{562e4870-3ecf-11dc-afd1-000d9d5ec0bb}] \Shell\AutoRun\command - E:\VMC_PBStarter.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2548f82-1900-11dc-afb7-000d9d5ec0bb}] \Shell\AutoRun\command - E:\VMC_PBStarter.exe *Newly Created Service* - PCANDIS5 . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-12 15:19:21 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe?????M??2?2?4?9??????? ??3B?????????????T?B? ????M? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\bgsvcgen.exe C:\WINDOWS\system32\CTSVCCDA.EXE C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\fsgk32.exe C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\WINDOWS\system32\HPConfig.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\TEMP\bwgo0000f2f7.exe C:\Program Files\F-Secure\Common\FSMA32.exe C:\Program Files\F-Secure\Common\FSMB32.exe C:\Program Files\F-Secure\Common\fch32.exe C:\Program Files\F-Secure\Common\FAMEH32.exe C:\Program Files\F-Secure\Common\FNRB32.exe C:\Program Files\F-Secure\Common\FIH32.exe C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\Program Files\Sensior\Bin\Reader.exe C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe C:\Program Files\OpenOffice.org1.0.1\program\soffice.exe C:\WINDOWS\system32\imapi.exe . ************************************************************************** . Completion time: 2008-06-12 15:27:39 - machine was rebooted [sami office] ComboFix-quarantined-files.txt 2008-06-12 12:27:13 Pre-Run: 4,496,408,576 tavua vapaana Post-Run: 6,361,915,392 tavua vapaana 186 --- E O F --- 2008-03-27 07:25:50 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:37:54, on 12.6.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\carpserv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Winamp3\winampa.exe C:\Program Files\F-Secure\Common\FSM32.EXE C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Sensior\Bin\Reader.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE C:\WINDOWS\system32\bgsvcgen.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\WINDOWS\system32\HPConfig.exe C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\OpenOffice.org1.0.1\program\soffice.exe C:\Program Files\F-Secure\Common\FSMB32.EXE C:\Program Files\F-Secure\Common\FCH32.EXE C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [Pinnacle WebUpdater] "C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe O4 - HKLM\..\Run: [Sensior Reader] C:\Program Files\Sensior\Bin\Start Reader.bat O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PMCS] "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [VMCL] E:\\VMC_PBStarter.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 1.0.1.lnk = C:\Program Files\OpenOffice.org1.0.1\program\quickstart.exe O4 - Global Startup: IEEE802.11b WLAN Card Utility.lnk = C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game10.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe -- End of file - 9040 bytes
Lataa Atribunen ATF Cleaner Ohjeet: Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman. Main:n alla valitse: Select All Klikkaa Empty Selected valintaa. Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Jos käytät Operaa selaimenasi Klikkaa Opera yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa taas. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Klikkaa Exit päävalikosta sulkeaksesi ohjelman. Skannaa viellä uudestaan Malwarebytesillä.
ATF cleaner ajettu ja samoin malware. Ei löytänyt mitään enää, alkaisko oleen kunnossa ..vielä hjt-logi Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:20:29, on 13.6.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE C:\WINDOWS\system32\bgsvcgen.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\WINDOWS\system32\HPConfig.exe C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\F-Secure\Common\FSMB32.EXE C:\Program Files\F-Secure\Common\FCH32.EXE C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\WINDOWS\system32\carpserv.exe C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Winamp3\winampa.exe C:\Program Files\F-Secure\Common\FSM32.EXE C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe C:\Program Files\OpenOffice.org1.0.1\program\soffice.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elisa.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [Pinnacle WebUpdater] "C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe O4 - HKLM\..\Run: [Sensior Reader] C:\Program Files\Sensior\Bin\Start Reader.bat O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PMCS] "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [VMCL] E:\\VMC_PBStarter.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 1.0.1.lnk = C:\Program Files\OpenOffice.org1.0.1\program\quickstart.exe O4 - Global Startup: IEEE802.11b WLAN Card Utility.lnk = C:\Program Files\Wireless\IEEE802.11b WLAN Card Utility\WLPCCfg.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game10.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe -- End of file - 8982 bytes
Fixaa seuraavat rivit Hijackthis:llä O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) Rekisterin voisit alla olevalla ohjelmalla puhdistaa ja tämän jälkeen päivittää Windowsia menemällä http://windowsupdate.microsoft.com/ sivulle IE:llä (Internet Explorer). Lataa: RegSeeker.zip työpöydälle: Pura zip C:\RegSeeker\ kansioon. Sieltä käynnistät RegSeeker.exe ohjelman. Oikeasa yläkulmassa on Languages.... linkki, josta valitset Suomenkielen. Vasemmasta alakulmasta ruksit Luo vrmuuskopio ja sitten linkki Puhdista rekisteri Ruksit kaikkiin muihin kohtiin paitsi "Käyttökelvottomat.." sitten "OK" (odotat hetken). Ruutuun ilmestyy lista epäkelvoista rekisterimerkinnöistä, jotka alapalkista Valitse kohdasta klikkaat Valitse kaikki jolloin valitut saavat keltaisen pohjavärin. Alapalkin Toiminnot linkistä klikkaat Poista valitut kohteet Ponnahdusikkunaan "Kaikki valitut kohteet poistetaan ? vastaat "OK". Seuraavaan Ponnahdusikkunaan "Varmuuskopiot" vastaat "OK". Klikaa vasemmalta Lopeta RegSeeker ja käynnistä koneesi uudelleen.