Popuppeja jatkuvasti. Mitä voisi tehdä? F-Secure 2008 herjaa AdWare.Win32.Virtumonde -nimisestä vakoiluohjelmasta, mutta ei saa sitä pysyvästi poistettua. Mitä tehdä?
Hjt + mbam logit käskettiin laittamaan tänne. Kiitos kaikesta avusta!
Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)
Saastuneita tiedostoja:
C:\WINDOWS\system32\jkkHBSKE.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\cvkaifsb.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Saana\Local Settings\Temporary Internet Files\Content.IE5\H72DPN46\kb767887[1] (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Saana\Local Settings\Temporary Internet Files\Content.IE5\H72DPN46\picture561.JPG_www.msn-images[1].0om (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Saana\Local Settings\Temporary Internet Files\Content.IE5\K6YXIS2H\kb713501[1] (Trojan.LowZones) -> Delete on reboot.
C:\Documents and Settings\Saana\Local Settings\Temporary Internet Files\Content.IE5\K6YXIS2H\kb767887[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DF2650A7-D821-4337-AF1B-9C68AD18C17D}\RP505\A0473650.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DF2650A7-D821-4337-AF1B-9C68AD18C17D}\RP505\A0473736.0om (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DF2650A7-D821-4337-AF1B-9C68AD18C17D}\RP505\A0473737.0xe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DF2650A7-D821-4337-AF1B-9C68AD18C17D}\RP506\A0474762.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\winudspm.0xe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bysynidj.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fiqeurkk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hhyannhb.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sxjcruna.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tsdvneln.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yikskhpc.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
_____
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:01:12, on 2.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\dwwin.exe
Tallenna nimellä CFScript (itse asiassa combofix tunnistaa tuon vaikka tiedostopääte ei olisi
edes .txt).
Sitten raahaa ja pudota CFScript ComboFix.exeen kuten alla.(Älä klikkaa)
Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
Käynnistä kone uudelleen, jos niin pyydetään ja lähetä combofix.txt-tiedoston sisältö tänne.
Sammuta selain ja muut ohjelmat Fixin ajaksi. (ei virustorjuntaa)
Käynnistä HijackThis:ja Scan ja ruksaa seuraavat punaisella listatut tiedostot sekä poista ne.(fix Chekked)
O2 - BHO: (no name) - {06E12C36-760F-4D92-8509-5E5DBF12C423} - C:\WINDOWS\system32\ljJdBqrq.dll (file missing)
O2 - BHO: (no name) - {71DA537B-7F72-4011-ACAA-707F70A4EF9A} - C:\WINDOWS\system32\jkkHBSKE.dll (file missing)
O2 - BHO: {99bb4fe1-e010-3539-4fd4-f3a6860d9fea} - {aef9d068-6a3f-4df4-9353-010e1ef4bb99} - C:\WINDOWS\system32\cvkaifsb.dll (file missing)
O4 - HKLM\..\Run: [Windows UDP Control] winudspm.exe
O20 - Winlogon Notify: ljJdBqrq - ljJdBqrq.dll (file missing)
Tyhjennä roskakori ja käynnistä koneesi uudelleen.
Postita tänne seuraavat lokit: * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta)
* (C:\ComboFix.txt) raportti
*