afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > virus iskenyt. hjt & mbam logit.
Keskustelualueet
Keskustelualueet
Virus iskenyt. HJT & Mbam logit.
krizu7
Junior Member
21. toukokuuta 2011 @ 00:32
Linkki tähän viestiin
Eli, windows xp sp3 on ruvennut tekemään sellaista että mikään ei tunnu toimivan kun koneen käynnistää normaalisti, taskbar jää jumiin ja Avast väittää että kaikki moduulit on poissa käytöstä. Vikasietotilassa kaikki muu toimii paitsi Mozilla Firefox ...
Myös omat tiedostot avautuu aina kun koneen käynnistää normaalisti.
LOG:
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 0:32:50, on 21.5.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe
O4 - Startup: Spotify .lnk = C:\Program Files\Spotify\spotify.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Lisää tämä blogiin - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Lisää tämä blogiin tuotteessa Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: BecHelperService - Unknown owner - C:\Program Files\Mobiililaajakaista\Mobiililaajakaista\BecHelperService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe (file missing)
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - Firebird Project - C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - Firebird Project - C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Google-päivityspalvelu (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Windows Media Playerin verkkojakamispalvelu (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
--
End of file - 8299 bytes
MBAM
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Tietokantaversio: 6628
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
21.5.2011 1:29:57
mbam-log-2011-05-21 (01-29-57).txt
Tarkistustyyppi: Täysi tarkistus (C:\|)
Tarkistettuja kohteita: 358726
Kulunut aika: 48 minuutti(a), 29 sekunti(a)
Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 2
Saastuneita rekisteriarvoja: 0
Saastuneita rekisterikohteita: 0
Saastuneita kansioita: 0
Saastuneita tiedostoja: 47
Saastuneita muistiprosesseja:
(Ei haitallisia kohteita)
Saastuneita muistimoduuleja:
(Ei haitallisia kohteita)
Saastuneita rekisteriavaimia:
HKEY_CURRENT_USER\SOFTWARE\Turkojan (Backdoor.Turkojan) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.
Saastuneita rekisteriarvoja:
(Ei haitallisia kohteita)
Saastuneita rekisterikohteita:
(Ei haitallisia kohteita)
Saastuneita kansioita:
(Ei haitallisia kohteita)
Saastuneita tiedostoja:
c:\WINDOWS\servicepackfiles\i386\notepad.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
c:\documents and settings\Kristian\local settings\Temp\dclogs.sys (Stolen.Data) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1812\A0327538.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0329904.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0329905.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0331018.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0331022.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0331023.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0331027.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0331029.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0331049.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0331990.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0332073.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1817\A0332074.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333230.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333231.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333232.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333263.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333279.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333344.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333345.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333347.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333349.exe (Backdoor.Daromec) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333350.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333351.exe (Backdoor.Daromec) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333353.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333354.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333355.bat (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333358.bat (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333359.bat (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333360.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333361.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333364.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333366.exe (Backdoor.Daromec) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333368.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333369.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333370.exe (Backdoor.Daromec) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333408.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333409.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333411.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1819\A0333413.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1821\A0340286.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1821\A0340287.dll (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1821\A0340288.exe (Backdoor.Turkojan) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1821\A0342423.exe (Backdoor.Daromec) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1821\A0342424.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully.
c:\system volume information\_restore{214986c9-2d86-4d74-8dfd-f9201943c32c}\RP1821\A0342425.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 21. toukokuuta 2011 @ 21:12
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > virus iskenyt. hjt & mbam logit.