Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:36:22, on 26.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Teen nämä kikat seuraavaksi, kun näytti monessa olevan
" näin...
1. Lataa combofix.exe työpöydällesi mistä tahansa alla olevasta linkistä:
Linkki 1
Linkki 2
Linkki 3
2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
3. Kun työkalu on valmis, se tuottaa lokin. (C:\ComboFix.txt)+ uusi hjt-loki Lähetä tämä loki viesti ketjuusi.
Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
"
En ymmärrä. Kun tuplaklikkaan ComboFix:iä, tulee vaan semmonen sininen command prompt ikkuna ja ei tapahtu mitään, vaikka antaa olla pitkäänkin. Ei ole jumissakaan, koska pystyy liikuttelemaan slaidia ylös/alas.
Tuossa vielä tommonen:
Kannattaisiko noita poistella jotenkin?
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, January 27, 2008 10:11:41 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/01/2008
Kaspersky Anti-Virus database records: 533594
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Statistics:
Total number of scanned objects: 221882
Number of viruses found: 1
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 10:32:01
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\Temp\CLML_AGENT_LOG1.txt Object is locked skipped
C:\WINDOWS\Temp\sqlite_ueKQHPStpUNqMj7 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\F-Secure\logs\FSMA\fsma.log Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Mauku\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\Perflib_Perfdata_9c8.dat Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\~DF432C.tmp Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\~DF444E.tmp Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\~DF8F9D.tmp Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\~DF9097.tmp Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\Perflib_Perfdata_140c.dat Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\Perflib_Perfdata_1450.dat Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temp\IMG241B.tmp Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Application Data\Acer Arcade\Log\Trace20080127.log Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Application Data\ApplicationHistory\ePower_DMC.exe.3ca0acde.ini.inuse Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Application Data\Microsoft\Windows Live Contacts\m.jurvanen@suomi24.fi\real\members.stg Object is locked skipped
C:\Documents and Settings\Mauku\Local Settings\Application Data\Microsoft\Windows Live Contacts\m.jurvanen@suomi24.fi\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Mauku\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Mauku\ntuser.dat Object is locked skipped
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLML_MAIN\CLML.db Object is locked skipped
C:\Program Files\DAEMON Tools\SetupDTSB.exe Object is locked skipped
C:\Program Files\Sonera Tietoturva\Common\policy.ipf Object is locked skipped
C:\Program Files\Sonera Tietoturva\Common\policy.bpf Object is locked skipped
C:\Program Files\Sonera Tietoturva\Anti-Virus\perf.dat Object is locked skipped
C:\Program Files\Sonera Tietoturva\Anti-Virus\fsqh.exe.Qrt.log Object is locked skipped
C:\Program Files\Sonera Tietoturva\Anti-Virus\dbupdate.log Object is locked skipped
C:\Program Files\Sonera Tietoturva\Anti-Virus\power.dat Object is locked skipped
C:\Program Files\Sonera Tietoturva\Anti-Virus\deleteme_msg.log Object is locked skipped
C:\Program Files\Sonera Tietoturva\FSAUA\program\fsaua.log Object is locked skipped
C:\Program Files\Sonera Tietoturva\FSAUA\program\fsaua.dbg Object is locked skipped
C:\Program Files\Sonera Tietoturva\FSAUA\fsbwupst.log Object is locked skipped
C:\System Volume Information\_restore{C174DC8D-D03B-4FB1-AE2D-E56D3A107BCF}\RP494\change.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
I:\Softat\Nero8\Nero PhotoShow Express\nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
I:\Softat\Nero8\Nero PhotoShow Express\nero_photoshow_express_5_setup.exe NSIS: infected - 1 skipped
I:\Softat\Nero8\Nero8.part10.rar/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
I:\Softat\Nero8\Nero8.part10.rar/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
I:\Softat\Nero8\Nero8.part10.rar/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
I:\Softat\Nero8\Nero8.part10.rar RAR: infected - 3 skipped
I:\Softat\Nero8\Toolbar.exe Object is locked skipped
I:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
Niissä pitäisi olla seuraava kuva vieressä:
3. Valitse kaikki entiset Java versiosi ja valitse Poista.
4. Asenna uusin Java päivitys seuraavasta linkistä..
5. Käynnistä kone uudelleen asennuksen jälkeen:
Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u4
Paina Download
Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se.
6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).
7.General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia.
(Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa.
Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle).
8. Varmista että kaikki kaksi valintaa ovat rastitettuja:
Applications and Applets
Trace and Log Files
Ja paina OK -nappia
9. Klikkaa OK "Temporary Files Settings" -ikkunassasi.
Huomaa: Tämä poistaa kaikki ladatut sovellukset ja appletit VÄLIMUISTISTA.