afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > iexplore.exe  
											 
											
												
	 
											
											
						 				 	
	
		
		
			
		
		
	 
												  
												
													
	
		
			Keskustelualueet
			Keskustelualueet
		 
		
			
				
					
						
			
			
		
					
				
			 
		
	 
														
															
															
	
			
			
				
					iexplore.exe
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								M4dred
							
							
								Junior Member
								
									
								
							
							 
							 
						 
						23. toukokuuta 2012 @ 21:09  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Tämmönen haittaohjelma on löytänyt tiensä mun koneelle, ei siis tosiaan ole tuota varsinaista ohjelmaa koko koneella.
 
 Sen verran jo tiiän että kaverilla on rootkit jossainpäin koneella kun ei manuaalipoisto vaikuta mitenkään. On koetettu windows offline defenderiä, combofixiä (aina jumittanut), malwaree, otl, super antispywaree, spybot  S&D:tä, CCleaneria, aswMBRää, TDSSkilleriä ja vaikka mitä. Nyt tarttis sitä kuuluisaa apua jo tämän perkeleen kanssa.
 
 iexplore siis monistaa itteänsä ja vie about 50 megaa muistii / prosessi. 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								1pertti
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 
						23. toukokuuta 2012 @ 21:19  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								M4dred
							
							
								Junior Member
								
									
								
							
							 
							 
						 
						23. toukokuuta 2012 @ 21:42  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Jeps, runnaan tuon A-Squaredin ja postaan HJT-login niin kattoos onko tää romu jo puhdas.
 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Mainos
							 
						 
						 
					 
					
						
							
							  
								
							
						 
					 
				
				
				
					
						
							
								M4dred
							
							
								Junior Member
								
									
								
							
							 
							 
						 
						24. toukokuuta 2012 @ 01:31  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Nonni, tuolla ohjelmalla katosi ainakin meikäläisen ongelmat. Kiitoksia pirusti. Antaisin pokaalin jos olisi sillä 4pv on tän paskan kans nyt tapeltuna. Postaan tuon HJT  login jos siellä ois jotaki mikä pistää silmään jotaki muita, meikäläistä ei.
 
 
 Logfile of Trend Micro HijackThis  v2.0.4
 Scan saved at 1:30:54, on 24.5.2012
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Unable to get Internet Explorer version!
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 C:\Program Files\Bonjour\mDNSResponder.exe
 C:\Program Files\Java\jre6\bin\jqs.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\RunDll32.exe
 C:\WINDOWS\system32\RUNDLL32.EXE
 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
 C:\Program Files\Common Files\Java\Java Update\jusched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\WINDOWS\System32\wbem\wmiapsrv.exe
 C:\Documents and Settings\PASKA\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\PASKA\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\PASKA\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\PASKA\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
 C:\WINDOWS\system32\msiexec.exe
 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
 C:\Program Files\AVAST Software\Avast\setup\avast.setup
 C:\Program Files\AVAST Software\Avast\AvastUI.exe
 C:\Documents and Settings\PASKA\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
 C:\Documents and Settings\PASKA\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
 C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
 
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8118
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O1 - Hosts: 255.255.255.255 easyanticheat.se # misleading site
 O1 - Hosts: 255.255.255.255 www.easyanticheat.se # misleading site
 O1 - Hosts: 255.255.255.255 easyanticheat.com # misleading site
 O1 - Hosts: 255.255.255.255 www.easyanticheat.com # misleading site
 O1 - Hosts: 255.255.255.255 easyanticheat.org # misleading site
 O1 - Hosts: 255.255.255.255 www.easyanticheat.org # misleading site
 O2 - BHO: Adobe PDF  Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
 O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
 O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
 O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
 O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
 O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
 O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
 O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
 O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
 O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\PASKA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [LicenseValidator] C:\Documents and Settings\PASKA\Application Data\Identities\{86E5292A-16A3-4794-B29A-71E688C71BE8}\LicenseValidator.exe
 O4 - HKUS\S-1-5-21-746137067-1637723038-839522115-1009\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'postgres')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 O8 - Extra context menu item: E&xport to Microsoft  Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: Lisää tämä blogiin - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
 O9 - Extra 'Tools' menuitem: &Lisää tämä blogiin tuotteessa Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra button: Skype  Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O9 - Extra 'Tools' menuitem: Skype  Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot  - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra button: NordicBet - {17F033BE-1D45-4883-ADA4-EF09E96B0FAD} - C:\Microgaming\Poker\NordicBetMPP\MPPoker.exe (file missing) (HKCU)
 O12 - Plugin  for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - 
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows...b?1199833428046 
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup...b?1199833680984 
 O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) - 
 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s...ash/swflash.cab 
 O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab 
 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
 O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
 O18 - Filter hijack: text/html - {574940E0-1B7A-4881-8FA3-1E809714B156} - (no file)
 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
 O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
 O23 - Service: Apple  Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 O23 - Service: avast! Antivirus  - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
 O23 - Service: Bonjour-palvelu (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
 O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
 O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
 O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
 O23 - Service: iPod-palvelu (iPod  Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Java Quick Starter  (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
 O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
 O23 - Service: NVIDIA Display Driver  Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
 O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe
 O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
 O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
 O23 - Service: ServiceLayer - Nokia  - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: SupportSoft RemoteAssist - Unknown owner - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (file missing)
 O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
 O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
 O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
 O23 - Service: Windows Media  Playerin verkkojakamispalvelu (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
 
 --
 End of file - 12158 bytes
 
							
						 
						
						
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > iexplore.exe