Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)
Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriavaimia:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79ae735f-9663-4b92-9602-39eb563fa30c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byxwtsp (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{79ae735f-9663-4b92-9602-39eb563fa30c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{81705d67-3f73-4983-859b-97d0922e5abe} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3935B537-3E6D-04ED-ABB3-ACB16A699E3B} (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{81705d67-3f73-4983-859b-97d0922e5abe} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{79ae735f-9663-4b92-9602-39eb563fa30c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
Saastuneita rekisteriarvoja:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\94a97af4 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{81705d67-3f73-4983-859b-97d0922e5abe} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{79ae735f-9663-4b92-9602-39eb563fa30c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{f0d4f88e-e1f8-460f-a41c-6cfb7f73af79} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{735e980d-45d2-4777-af82-9923d3c8d3ae} (Trojan.Zlob) -> Quarantined and deleted successfully.
Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)
Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)
Saastuneita tiedostoja:
C:\WINDOWS\system32\byxwtsp.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Omistaja\Local Settings\Temp\murxbnfb.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\etmbjohj.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\srbukokl.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\pauxtrud.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\hsssrlbh.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\cgasbkqe.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\ciphpvmy.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\jqvadgwe.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\ukiyyuby.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\vahaoxqs.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\yacfcmek.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\dfonvfyw.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\ofibrewm.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\qfpvmcxj.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\nnrfdncc.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\rlvewyjw.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\xjxalall.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\fvpfwxqb.0ll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\knoquiyd.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\ebykdnuy.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\uetylfqx.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\vfxnnucb.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\gybqfnmh.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\ijbcnhxe.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\qwahxdhu.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\qynnigyt.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\pytwcabh.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\ouwhhbbk.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\oxmcqbrn.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\emtehlpl.0ll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\nibxtkvj.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\amjpmwkn.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\xofxmhct.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\vppcjvoe.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\trkiilra.0ll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\ttovewel.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Omistaja\Local Settings\Temp\hcqkwkpf.0ll (Trojan.Vundo) -> Delete on reboot.
C:\Program Files\AVG\AntivirusGold 4.3\AntivirusGold 4.3.exe (Rogue.AstrumAntivirus) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ulacmbfx.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM979a4968.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM979a4968.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Omistaja\Suosikit\Online Security Test.url (Rogue.Link) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:50:50, on 22.2.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
1.Lataa Combofix.exe työpöydällesi yhdestä linkistä:
Combofix1 Combofix2
älä asenna palautus consolia 2. Tuplaklikkaa Combofix.exe tiedostoa ja seuraa ohjeistuksia.
3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.