Sain tänään jonkun vieraan ohjelman vahingossa koneelleni.En löytänyt sitä,että olisin voinut poistaa.Ohjelma oli "Security Tools"Löysin palomuurista ohjelman,joka oli Leak Test.Luultavammin on sama ohjelma.Hälytyksiä alkoi tämän jälkeen tuleemaan,kun tuo ohjelma pääsi koneelle.Ajoin kaikilla,mikä oli mahdollista.Tässä on logit HiJack,Avira ja malwarebytes.Ajoin vielä läpi Ad-Aware ohjelmalla.Muutamia päiviä ollut vaikeuksia saada sivustot auki samaan tapaan kun ennen.Tässäpä tietoa.Kuitenkin tässä tuo logi:
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 22:45:32, on 1.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)
Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriavaimia:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriarvoja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)
Saastuneita hakemistoja:
C:\Documents and Settings\All Users\Application Data\36550423 (Rogue.Multiple) -> No action taken.
Saastuneita tiedostoja:
C:\Program Files\COMODO\COMODO Internet Security\Quarantine\A0038119.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\All Users\Application Data\36550423\36550423.exe (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\xxxxxxxx\Käynnistä-valikko\Ohjelmat\Security Tool.LNK (Rogue.SecurityTool) -> No action taken.
Avira AntiVir Premium
Report file date: 1. huhtikuuta 2010 19:47
Scanning for 1953293 virus strains and unwanted programs.
The program is running as an unrestricted full version.
Online services are available:
Licensee : xxxxxxxxxxxxxxxx
Serial number : xxxxxxxxxxxxx
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : xxxxxxxxxxxxxx
Configuration settings for the scan:
Jobname.............................: avguard_async_scan
Configuration file..................: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\AVGUARD_4bf3abc4\guard_slideup.avp
Logging.............................: low
Primary action......................: repair
Secondary action....................: quarantine
Scan master boot sector.............: on
Scan boot sector....................: off
Process scan........................: on
Scan registry.......................: off
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: high
Start of the scan: 1. huhtikuuta 2010 19:47
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'Ad-Aware.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'KHALMNPR.EXE' - '1' Module(s) have been scanned
Scan process 'AVWEBGRD.EXE' - '1' Module(s) have been scanned
Scan process 'avmailc.exe' - '1' Module(s) have been scanned
Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
Scan process 'Sup_SmartRAM.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'VEngine.exe' - '1' Module(s) have been scanned
Scan process 'cfp.exe' - '1' Module(s) have been scanned
Scan process 'TimounterMonitor.exe' - '1' Module(s) have been scanned
Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
Scan process 'IoctlSvc.exe' - '1' Module(s) have been scanned
Scan process 'MSCamS32.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'lxctcoms.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'avshadow.exe' - '1' Module(s) have been scanned
Scan process 'fsssvc.exe' - '1' Module(s) have been scanned
Scan process 'CTsvcCDA.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'schedul2.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'AAWService.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
Scan process 'cmdagent.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
Starting the file scan:
Begin scan in 'C:\System Volume Information\_restore{F5C053B1-61E0-402B-8008-7E462DB5566F}\RP425\A0058715.exe'
C:\System Volume Information\_restore{F5C053B1-61E0-402B-8008-7E462DB5566F}\RP425\A0058715.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '49a16fc3.qua'.
Begin scan in 'C:\System Volume Information\_restore{F5C053B1-61E0-402B-8008-7E462DB5566F}\RP425\A0058716.exe'
C:\System Volume Information\_restore{F5C053B1-61E0-402B-8008-7E462DB5566F}\RP425\A0058716.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '51364065.qua'.
End of the scan: 1. huhtikuuta 2010 19:48
Used time: 01:07 Minute(s)
The scan has been done completely.
0 Scanned directories
52 Files were scanned
2 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
2 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
50 Files not concerned
2 Archives were scanned
0 Warnings
2 Notes
The scan results will be transferred to the Guard.