Eli tarvis taas apua samaan vanhaan asiaan. Kone on pirun hidas.
tässä olis hijack loki ja karspersky raportti
Logfile of HijackThis v1.99.1
Scan saved at 23:12:53, on 12.2.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Monday, February 12, 2007 9:17:39 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 12/02/2007
Kaspersky Anti-Virus database records: 267092
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Scan Statistics
Total number of scanned objects 46903
Number of viruses found 2
Number of infected objects 2 / 0
Number of suspicious objects 0
Duration of the scan process 01:36:19
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\EXITCURBINSIDENOUN\License 2 bows Object is locked skipped
C:\Documents and Settings\All Users\Application Data\EXITCURBINSIDENOUN\regseach.exe Infected: Trojan.Win32.Obfuscated.bt skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-02-12_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Sivuhistoria\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\The Aras\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\The Aras\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\The Aras\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\The Aras\Local Settings\Sivuhistoria\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Aras\Local Settings\Temp\Free Download Manager\tic2.tmp Object is locked skipped
C:\Documents and Settings\The Aras\Local Settings\Temp\Free Download Manager\tic20.tmp Object is locked skipped
C:\Documents and Settings\The Aras\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\The Aras\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Aras\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\The Aras\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{DFD76601-70A6-4C89-BEAA-583F34879080}\RP3\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\ysbactivex.dll Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_7d0.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Lataa tuosta Startup niminen ohjelma ja asenna se: http://www.mlin.net/files/StartupCPL.zip Ohjelma tulee näkyviin Ohjauspaneeliisin nimellä Startup. Sillä voit ottaa koneen
käynnistyksen yhteydessä käynnistyviä turhia ohjelmia pois. Esim: Adobe Reader Speed Launch,
Neron BgMonitor, Nero FilterCheck, iTunesHelper, Messenger, SoundMan, CTFMON, Winamp Agent,
Real Player Update (Real Sched), Quicktime yms.
Lataa tuosta CCleaner ja asenna se: http://ccleaner.com/download/downloadpage.aspx?1 Kun asennat tätä ohjelmaa niin älä asenna sen mukana tulevaa yahoo-toolbaria. Tämä ohjelma
etsii ja poistaa ns. turhia tiedostoja koneeltasi eli esim: temp tiedostot ja tällä saat myös
puhdistettua rekisterisi.
Lataa tuosta RegSeeker ja pura se: http://fileforum.betanews.com/download/RegSeeker/1035382760/1 Pura se haluamaasi kansioo ja käynnistä tiedosto nimeltä RegSeeker.exe. Ohjelma oikeassa yläkulmassa
näet painikkeen 'languages', paina sitä ja aseta kieleksi suomi! Sen jälkeen paina vasemmassa laidassa
olevaa painiketta 'Puhdista Rekisteri' ja sen jälkeen 'OK'. Odota että skannaus loppuu ja paina 'valitse'
ja sitten 'valitse kaikki'. Sitten klikkaat hiiren oikealla jotain ohjelman löytänyttä kohdetta ja paina
'poista valitut kohteet', hyväksy poisto, hyväksy varmuuskopionluonti ja käynnistä kone uudelleen. Jos
jotain ongelmia niin backupit saat palautettua 'varmuuskopiot' valikosta.
--
Kerroppa mikä tuo on?
O4 - HKCU\..\Run: [bike open] C:\DOCUME~1\THEARA~1\APPLIC~1\BARBMP~1\READMETHAT.exe
Ja sit suosittelen päivittämään ton javan. Mene käynnistä -> asetukset -> ohjauspaneeli -> Java -> Update välilehti ja painat update painiketta.
--
O17 - HKLM\System\CCS\Services\Tcpip\..\{42145DFB-0C9B-4349-9E70-EAE0DA0643ED}: NameServer = 85.255.114.53,85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2A62D41-82C4-48D2-8FF6-78E29A697E20}: NameServer = 85.255.114.53,85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\..\{C3906E15-31F7-4101-98DE-ABFDC2B140A5}: NameServer = 85.255.114.53,85.255.112.16
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16
O17 - HKLM\System\CS1\Services\Tcpip\..\{42145DFB-0C9B-4349-9E70-EAE0DA0643ED}: NameServer = 85.255.114.53,85.255.112.16
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16
O17 - HKLM\System\CS2\Services\Tcpip\..\{42145DFB-0C9B-4349-9E70-EAE0DA0643ED}: NameServer = 85.255.114.53,85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16
^ Sit jos joku viisas viel kertoo mitä nuo on?