Koneelta loytyi ekassa scannauksessa noin 100 trojan saastuttamaa filea. Malewabyte logi ohessa. Nyt ei enaan skannerit loyda mitaan... olen skannanut safemode ja normaalisti.
Muuten kone nayttaa toimivan ihan suht ok mut Windows vaittaa seuraavaa...
You may be a victim of software counterfeiting. This copy of windows did not pass genuine Windows validation.
Koneen mukana on tullut Windows mutta mitaan Cd ei ole tai muutakaan tietoa asiasta.
Siis onko mitaan tehtavissa.
Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 5.1.2600 Service Pack 2
Memory Processes Infected:
C:\Documents and Settings\Saurabh\winlogon.exe (Trojan.Downloader) -> Unloaded process successfully.
Memory Modules Infected:
C:\WINDOWS\system32\jfxibvc.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\msxm192z.dll (Trojan.Agent) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36e69ce1-91aa-479e-aa9e-fe58f78771ca} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vfkkhjuo (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{36e69ce1-91aa-479e-aa9e-fe58f78771ca} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{18b0e5c2-99cb-11cf-ayx5-00401c648513} (Generic.Bot.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pzcesaku (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\pzcesaku (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pzcesaku (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{36e69ce1-91aa-479e-aa9e-fe58f78771ca} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\6to4 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\netcard (Rootkit.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegedit (Hijack.Regedit) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556 (Backdoor.Bot) -> Quarantined and deleted successfully.
Files Infected:
c:\WINDOWS\system32\jfxibvc.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\iuhi64.exe (Generic.Bot.H) -> Delete on reboot.
C:\jnvcbaox.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\yaewfl.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\d56tdrf2z44.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Saurabh\Local Settings\Temp\749.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Local Settings\Temp\239.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243336035-3055115375-381863305-1553\vslmq.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0561137935-6806760125-378334292-6565\wnzip32.exe (Trojan.Dropper) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-2518538986-1433761309-669742937-9525\wnzip32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\shell.fne (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\com.run (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eAPI.fne (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\RegEx.fnr (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556\Desktop.ini (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556\pqlmq.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\glaide32.sys (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\scvhost.exe (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\scvhost.exe (Backdoor.Bot) -> Delete on reboot.
C:\Documents and Settings\Administrator\winlogon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\winlogon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Saurabh\winlogon.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\User\winlogon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netcard.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dp1.fne (Autorun.Worm) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\internet.fne (Autorun.Worm) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\og.dll (Autorun.Worm) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\og.EDT (Autorun.Worm) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spec.fne (Autorun.Worm) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ul.dll (Autorun.Worm) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msxm192z.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\lyusoqm.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Documents and Settings\Saurabh\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\Documents and Settings\User\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:47:55 PM, on 8/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Koitin netissa vahvistaa Windowsin mutta herjaa minulle että product Key ei tunnisteta ja että on laiton versio.
Kun läppäri on hankittu niin siinnä oli XP valmiina niin ei luulisi että on laiton versio. Kone on kyllä aika apuri Lenovo mutta kumminkin luulisi siinä olevan aito XP sisällä.
Mitä konsteja minulla voisi olla nyt. Minulla ei ole itsellä kuin Vista orginal Windows.
Ja tästä että kone olisi puhdan... niin juu eipä ole =) Vaikka sain kerran puhtaat raportit niin ajattelin scannata varmuudeksi ja löydöksiä oli tietenkin. Koitin myös mennä nettiin ajamaan online Kaspe... mutta ei suostu rullaamaan läpi. Hakee päivitykset melkein loppuu ja sitten herjaa että ei voida hakea enempää ja siihen koko homma sen osalta tyssäsi.