Tein tuossa virustarkistuksen ja avast löysi yhden troijalaisen (Win32:Rbot) ja sai sen poistettua ilmoituksen mukaan, mutta tässä olisi hjt logi varmuuden välttämiseksi.
Kiitos etukäteen!
Logfile of HijackThis v1.99.1 Scan saved at 13:49:12, on 7.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Ohjelman käynnistyessä kysytään sallitaanko ActiveX -komponentin asentamisen Kasperskyltä, klikkaa Kyllä.
" Ohjelma käynnistyy ja aloittaa viimeisimpien tunnistetiedostojen lataamisen.
" Kun skanneri on asennettu ja tunnistetiedot ladattu, klikkaa Next.
" Klikkaa nyt asetuksia, Scan Settings " Tarkista asetuksista, että seuraavat ovat valittuina:
o Scan using the following Anti-Virus database:
+ Extended (Jos valittavissa, muuten valitse Standard)
o Scan Options:
+ Scan Archives + Scan Mail Bases " Klikkaa OK " Nyt valitse "select a target to scan" otsikon alta Oma Tietokone, My Computer " Skannaus vie aikaa, joten ole kärsivällinen. Kun skannaus on valmis saat ilmoituksen, jos koneesi on saastunut.
" Klikkaa nyt Save as Text-painiketta.
" Tallenna tiedosto työpöydällesi.
" Mikäli haluat jatkaa asian käsittelyä foorumissa niin kopioi tiedoston sisältö viestiisi.
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
G:\
Scan Statistics
Total number of scanned objects 76275
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 01:05:28
Infected Object Name Virus Name Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Sivuhistoria\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\cert8.db Object is locked skipped
C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\history.dat Object is locked skipped
C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\key3.db Object is locked skipped
C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\parent.lock Object is locked skipped
C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Tomi\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Application Data\Mozilla\Firefox\Profiles\ud95hfba.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Sivuhistoria\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Sivuhistoria\History.IE5\MSHist012007100720071008\index.dat Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Temp\~DF80BE.tmp Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Temp\~DF9BB3.tmp Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Temp\~DFEE46.tmp Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Temp\~DFF3C5.tmp Object is locked skipped
C:\Documents and Settings\Tomi\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tomi\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Tomi\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Taustasuojaus.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{78656D17-5547-42BE-BCA8-6E097CBC80DD}\RP281\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{56207350-FD4A-494A-A27C-81A4A346AFBA}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_598.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{78656D17-5547-42BE-BCA8-6E097CBC80DD}\RP281\change.log Object is locked skipped
Scan process completed.
1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
2. Valitse ominaisuudet
3. Valitse järjestelmän palauttaminen välilehti
4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
5. Paina Käytä
6. Paina ok
7. Sammuta ja käynnistä
8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
9. Käytä ja OK