|
|
|
Keskustelualueet
Keskustelualueet
|
|
|
combofix ja malware -logit
|
|
|
just4play
Member
|
13. kesäkuuta 2008 @ 17:27 |
Linkki tähän viestiin
|
Malwarebytes' Anti-Malware 1.17
Tietokantaversio: 850
20:17:37 12.6.2008
mbam-log-6-12-2008 (20-17-37).txt
Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
Tarkistetut kohteet: 60224
Kulunut aika: 7 minute(s), 26 second(s)
Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 5
Saastuneita rekisteriarvoja: 1
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 7
Saastuneita tiedostoja: 328
Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)
Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriavaimia:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
Saastuneita rekisteriarvoja:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Messanger Control Center (Backdoor.Bot) -> Quarantined and deleted successfully.
Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)
Saastuneita hakemistoja:
C:\Casino (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\logs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\promo (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs (Adware.Casino) -> Quarantined and deleted successfully.
Saastuneita tiedostoja:
C:\WINDOWS\system32\rxnbraea.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aearbnxr.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\bot1.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\d.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\daf.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dchi.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dci.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dcis.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dciz.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dcsi.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dczi.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\ddc.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dsdc.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\fa.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\img.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\irc.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\jester.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\jestesr.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\profile.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\setup1.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\sexy.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\sxy.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\sxy1.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\exy.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\setup.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\setup1.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\sexy.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\Työpöytä\image23.JPG-www.msnimages.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\setup.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\wkssvr.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\byXNfCSj.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\cbXoOhec.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\enlspfyr.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\geBSKaxV.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\grxwbjoy.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\hurbwlku.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\kdontckj.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\kvkkxhwr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\ljflnnff.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\mgrmowlr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\objdslsv.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\qywsvypb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\urqPggdA.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\wcalbfqq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\xiyrcpxo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP336\A0018154.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP336\A0018162.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP337\A0018164.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0018196.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0018197.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0019194.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0019205.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019219.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019220.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019221.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019224.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP340\A0019245.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP340\A0020224.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP340\A0020231.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020236.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020238.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020240.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020249.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020251.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020563.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020595.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP342\A0020601.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP342\A0020612.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020619.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020621.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020623.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020624.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020626.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020628.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020629.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020632.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020637.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020639.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020640.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020643.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020647.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020651.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020656.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020657.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020659.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020686.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\mservice.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\winudspm.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\telecms.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\blackjack.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\browser.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\cacerts.crt (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\cam.cas (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\cardlib.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\common.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\countries.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\creditdebit.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\db.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\devlib.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\devlibcomm.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\filemap.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\fivecard.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\games.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\gsid.txt (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\id.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\INSTALL.LOG (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\languages.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\libeay32.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\licens.txt (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\modstatus.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\mp3dec.asi (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\mss32.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\msvcp71.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\msvcr71.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\navigator.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\omaha.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\options.cfg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\poker.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\poker.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sc.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\shfolder.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\srvmap.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\ssleay32.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\texas.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\UNWISE.EXE (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\update.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xml.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\zlib1.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\0.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\1.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\10.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\11.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\12.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\13.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\14.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\15.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\16.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\17.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\18.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\19.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\2.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\20.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\21.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\22.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\23.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\24.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\25.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\26.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\27.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\28.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\29.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\3.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\30.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\31.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\32.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\33.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\34.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\35.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\36.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\37.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\38.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\39.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\4.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\40.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\41.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\42.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\43.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\44.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\45.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\46.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\47.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\48.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\49.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\5.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\50.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\51.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\6.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\7.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\8.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\9.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\allin_popup.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\archive.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\archive_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\avatar.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\b.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\base.css (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\bkg.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\browserdetect.js (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_cashier.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_close.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_filters_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_filters_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_game.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_general.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_join.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_main.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_medium.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_minmax.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_sublevels_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_sublevels_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\caret.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\chatbubble.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\chips.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\decktype_settings.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\edit.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gamelimits1.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gamelimits2.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gamelimits3.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\game_summary.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gre_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand.html (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand_cursor.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\harrow.cur (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\headers_bkg.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\headers_text.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\history.html (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\history.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\history_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\input_additional.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\input_boxes.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\input_lists.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\language.xml (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\language.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\languages.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\language_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\main.js (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\main_bkg.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\main_listhi.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_bg.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_buttons.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_moneytext.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_timer.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_bottom.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_game_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_game_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_game_top.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_left.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_medium.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_moretables.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_texts.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_top.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\pointer.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cardback.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards_4c.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards_large.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards_large_4c.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_deckside.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_font_11p_bold.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_makechoice.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_pucks.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\pol_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\popups.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_actions.png (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_active.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_inactive.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_note.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_numbers.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\progress_ani.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\promo-test1.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\rus_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\sc_bkg8.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tabs_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tabs_cashier.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tabs_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\text.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\timeslider.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tur_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tx_bkg10.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tx_bkg5.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\user.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\user_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\white_line.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\win_graphics.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\xml.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\xml_decoder.js (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\promo\sundayspecial.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\c_button.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\c_chip.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\c_deal.mp3 (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\p_alert.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\p_checkknock.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\blackjack_game_panel.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\blackjack_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\common.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\creditdebit.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_clientspecific.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_creditdebit.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_game.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_general.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_mc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_navigator.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\fcs_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\fc_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\fc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\filemap.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\filerefs.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\gameclient.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\game_common.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\game_common_message.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\game_panel.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\gizmo.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\mc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\message.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\mtt_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\mtt_lobby.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\navigator.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\omaha_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\omaha_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\optdef.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\poker_limits.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\sc_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\sc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\tel_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\texas_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\texas_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\tournament_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\image011.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\images21.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\images84.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photo12.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photo93.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photos2007_16.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
ja vielä combofix logi
ComboFix 08-06-03.4 - Mane 2008-06-12 20:32:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.301 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript_used_2008-06-04@19.22.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMcb78c4fe.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\mcrh.tmp
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-12 to 2008-06-12 )))))))))))))))))
.
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:50 . 2008-06-12 19:50 <KANSIO> d-------- C:\WINDOWS\LastGood
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 --a------ C:\roffl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-06-03 18:32 . 2008-06-03 18:32 86,548 --a------ C:\setz.exe
2008-05-27 22:53 . 2008-06-01 19:46 86,502 --a------ C:\sexy.com
2008-05-27 16:59 . 2008-05-27 16:59 28,672 --a------ C:\gay.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-04_19.27.44.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-04 16:25:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-14 15:52:59 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
- 2008-02-16 09:02:36 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2008-04-21 07:02:46 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
- 2008-02-16 09:02:36 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2008-04-21 07:02:46 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2008-02-16 09:02:37 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll
+ 2008-04-21 07:02:47 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll
- 2008-02-16 09:02:36 1,023,488 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2008-04-21 07:02:46 1,023,488 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
- 2008-02-16 09:02:36 151,552 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2008-04-21 07:02:46 151,552 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
- 2008-02-16 09:02:37 1,055,232 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
+ 2008-04-21 07:02:47 1,055,232 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
- 2008-02-16 09:02:37 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-04-21 07:02:47 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-02-16 09:02:37 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-04-21 07:02:47 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-02-16 09:02:37 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-04-21 07:02:47 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-02-15 09:23:37 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2008-04-17 10:52:54 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
- 2008-02-16 09:02:38 250,880 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2008-04-21 07:02:47 250,880 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2008-02-16 09:02:38 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2008-04-21 07:02:47 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2008-02-16 09:02:38 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-04-21 07:02:47 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2008-02-16 22:32:40 3,080,704 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-04-21 07:02:49 3,080,704 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-02-16 09:02:39 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-04-21 07:02:49 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-02-16 09:02:39 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-04-21 07:02:49 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2008-02-16 09:02:39 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-04-21 07:02:50 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2008-02-16 09:02:39 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-04-21 07:02:50 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-10-29 22:43:51 1,288,192 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:15:43 1,288,192 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
- 2008-02-16 09:02:41 1,494,016 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2008-04-21 07:02:51 1,494,016 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
- 2008-02-16 09:02:41 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2008-04-21 07:02:51 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
- 2008-02-16 09:02:41 616,448 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-04-21 07:02:52 616,448 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-02-16 09:02:42 659,456 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-04-21 07:02:52 659,456 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2008-02-16 09:02:37 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-04-21 07:02:47 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-02-16 09:02:37 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-04-21 07:02:47 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-02-16 09:02:37 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-04-21 07:02:47 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2008-02-16 09:02:38 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2008-04-21 07:02:47 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2008-02-16 09:02:38 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2008-04-21 07:02:47 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
- 2008-02-16 09:02:38 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-04-21 07:02:47 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-29 23:35:11 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe
- 2008-02-16 22:32:40 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-04-21 07:02:49 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2008-02-16 09:02:39 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-04-21 07:02:49 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2008-02-16 09:02:39 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-04-21 07:02:49 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
- 2008-02-16 09:02:39 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-04-21 07:02:50 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
- 2008-02-16 09:02:39 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-04-21 07:02:50 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2008-02-16 09:02:41 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2008-04-21 07:02:51 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2008-02-16 09:02:41 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2008-04-21 07:02:51 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
- 2006-09-25 14:58:48 14,640 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:19:02 17,272 ------w C:\WINDOWS\system32\spmsg.dll
- 2008-02-16 09:02:41 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-04-21 07:02:52 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2008-02-15 23:03:12 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2008-04-17 11:03:44 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 13:22 86016]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-06 00:16 185632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-12 20:32:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-12 20:33:24
ComboFix-quarantined-files.txt 2008-06-12 17:33:14
ComboFix2.txt 2008-06-04 16:28:15
Pre-Run: 14,326,657,024 tavua vapaana
Post-Run: 14,327,308,288 tavua vapaana
213 --- E O F --- 2008-06-12 16:51:25
|
|
Hujo
Suspended permanently
|
13. kesäkuuta 2008 @ 17:38 |
Linkki tähän viestiin
|
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:
Lainaus: File::
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\is155400.exe
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\roffl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\setz.exe
C:\sexy.com
C:\gay.exe
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm
Tallenna se nimellä CFScript.txt
Sitten raahaa CFScript ComboFix.exeen kuten alla.

Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
===========
laita se hjt:n loki myös
Lataa TÄSTÄ HJTInstall.exe
* Tallenna HJTInstall.exe työpöydällesi.
* Tuplaklikkaa HJTInstall.exe-kuvaketta työpöydälläsi.
* Oletuksena se asentaa itsensä hakemistoon C:\Program Files\Trend Micro\HijackThis.
* Klikkaa Install.
* Asennusohjelma luo HijackThis-kuvakkeen työpöydälle.
* Kun asennus on valmis, se käynnistää HijackThisin.
* Klikkaa Do a system scan and save a logfile-painiketta. Ohjelma aloittaa skannauksen ja lokin pitäisi avautua Muistioon.
* Klikkaa ensin "Muokkaa > Valitse kaikki" sitten "Muokkaa > Kopioi" kopioidaksesi koko lokin sisällön.
* Liitä lokin sisältö seuraavaan vastaukseesi.
* ÄLÄ käytä Analyse This-nappulaa, sen löydöt ovat vaarallisia väärinymmärrettyinä.
* ÄLÄ fixaa HijackThis-ohjelmalla vielä mitään. Suurin osa sen löydöistä ovat joko harmittomia tai jopa tarpeellisia.
Voiko tietsikka koskaan toimia?
|
|
just4play
Member
|
13. kesäkuuta 2008 @ 18:04 |
Linkki tähän viestiin
|
ComboFix 08-06-03.4 - Mane 2008-06-13 17:59:45.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.318 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Mane\new.txt
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 --a------ C:\roffl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-06-03 18:32 . 2008-06-03 18:32 86,548 --a------ C:\setz.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 14:56:37 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 18:00:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-13 18:01:08
ComboFix-quarantined-files.txt 2008-06-13 15:00:58
ComboFix2.txt 2008-06-12 17:33:24
ComboFix3.txt 2008-06-04 16:28:15
Pre-Run: 14,277,386,240 tavua vapaana
Post-Run: 14,291,722,240 tavua vapaana
127 --- E O F --- 2008-06-12 16:51:25
ja sitten hjt-logi perään:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:01:59, on 13.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 3769 bytes
|
|
Hujo
Suspended permanently
|
13. kesäkuuta 2008 @ 18:13 |
Linkki tähän viestiin
|
laita koneelle virustorjunta ja palomuuri kuntoon
Linkki
==============
sitten uusi hjt:n loki
=============
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:
Lainaus: Lainaus:File::
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\is155400.exe
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\roffl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\setz.exe
C:\sexy.com
C:\gay.exe
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm
Tallenna se nimellä CFScript.txt
Sitten raahaa CFScript ComboFix.exeen kuten alla.

Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
tämänkään ajo ei onnistunut
Voiko tietsikka koskaan toimia?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 13. kesäkuuta 2008 @ 18:22
|
|
just4play
Member
|
13. kesäkuuta 2008 @ 19:40 |
Linkki tähän viestiin
|
Asensin avastin virustorjunnaksi. Nyt äsken tuli ilmoitus jostain troijan viruksesta win32 tiedostossa tai jotain...
tässä hjt ja combologi
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:37:08, on 13.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\virustorjuta_avast\aswUpdSv.exe
C:\Program Files\virustorjuta_avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\virustorjuta_avast\ashMaiSv.exe
C:\Program Files\virustorjuta_avast\ashWebSv.exe
C:\PROGRA~1\VIRUST~1\ashDisp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\VIRUST~1\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\virustorjuta_avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\virustorjuta_avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashWebSv.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 4390 bytes
ComboFix 08-06-03.4 - Mane 2008-06-13 19:30:34.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.291 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.
2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 --a------ C:\roffl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-06-03 18:32 . 2008-06-03 18:32 86,548 --a------ C:\setz.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 19:31:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-13 19:32:01
ComboFix-quarantined-files.txt 2008-06-13 16:31:54
ComboFix2.txt 2008-06-13 15:01:09
ComboFix3.txt 2008-06-12 17:33:24
ComboFix4.txt 2008-06-04 16:28:15
Pre-Run: 14,153,953,280 tavua vapaana
Post-Run: 14,212,198,400 tavua vapaana
140 --- E O F --- 2008-06-12 16:51:25
ymmärrystä - olen vasta-alkaja!
|
|
Hujo
Suspended permanently
|
13. kesäkuuta 2008 @ 19:59 |
Linkki tähän viestiin
|
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:
Lainaus: File::
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\roffl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\setz.exe
Tallenna se nimellä CFScript.txt
Sitten raahaa CFScript ComboFix.exeen kuten alla.

Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
Voiko tietsikka koskaan toimia?
|
|
just4play
Member
|
13. kesäkuuta 2008 @ 21:27 |
Linkki tähän viestiin
|
|
mikäs tässä nyt on teidän mielestä pielessä? mitä minä yritän poistaa?
|
|
just4play
Member
|
13. kesäkuuta 2008 @ 21:32 |
Linkki tähän viestiin
|
|
uusin combofix logi. en ole varma onko se tämä kun hukkasin tallentamani. toivottavasti lähetin oikean.
2007-07-30 21:18 0 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\Mane\new.txt.vir
2008-05-28 16:08 57344 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\urqOIxUL.dll.vir
2008-05-28 16:14 371712 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJCvwTM.dll.vir
2008-05-28 20:15 57344 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\hgGyawVM.dll.vir
2008-05-29 04:31 1463566 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\sysrmtqv.ini.vir
2008-05-29 04:32 126464 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\gagjgtiv.dll.vir
2008-05-29 04:41 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\xxywuSKD.dll.vir
2008-05-29 17:31 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\cbXRKEvW.dll.vir
2008-05-29 17:41 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqOHaXo.dll.vir
2008-05-29 19:44 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvSmkLD.dll.vir
2008-05-29 19:58 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJASjJC.dll.vir
2008-05-29 20:32 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mlJCUKcb.dll.vir
2008-05-29 21:35 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\nnnllMgh.dll.vir
2008-05-29 21:35 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\pmnkLBRJ.dll.vir
2008-05-29 21:41 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\vtUnmlIb.dll.vir
2008-05-29 22:04 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqQkKax.dll.vir
2008-05-29 23:00 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJCsRHx.dll.vir
2008-05-30 00:38 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\khfGyyxV.dll.vir
2008-05-30 17:49 1474380 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\esiwosrg.ini.vir
2008-05-30 17:50 125440 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\qoxvehim.dll.vir
2008-05-30 17:56 134144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jlsidkru.dll.vir
2008-05-30 17:57 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jkkJaawx.dll.vir
2008-05-30 19:09 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\opnnoMFV.dll.vir
2008-05-30 22:15 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jkkKcAPi.dll.vir
2008-05-31 12:46 1478778 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ncgaqedc.ini.vir
2008-05-31 17:51 126464 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jbbvcrqc.dll.vir
2008-06-01 11:48 1473880 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ullnkfuu.ini.vir
2008-06-01 17:53 126464 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mrxeoflb.dll.vir
2008-06-03 18:17 125952 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\hjspukuk.dll.vir
2008-06-03 18:17 1497200 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\qdbdvgsk.ini.vir
2008-06-03 18:32 86548 --a------ C:\Qoobox\Quarantine\C\WINDOWS\service.exe.vir
2008-06-04 19:06 3424 --a------ C:\Qoobox\Quarantine\C\bot.exe.vir
2008-06-04 19:07 1499881 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\oxpcryix.ini.vir
2008-06-04 19:22 391897 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\MTwvCJjl.ini.vir
2008-06-04 19:22 391897 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\MTwvCJjl.ini2.vir
2008-06-04 19:24 288 --a------ C:\Qoobox\Quarantine\F\autorun.inf.vir
2008-06-04 19:25 362670 --a------ C:\Qoobox\Quarantine\catchme2008-06-04_192505,60.zip
2008-06-04 19:26 294 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\aearbnxr.ini.vir
2008-06-04 19:32 97 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mcrh.tmp.vir
2008-06-11 18:04 22 --a------ C:\Qoobox\Quarantine\C\WINDOWS\pskt.ini.vir
2008-06-11 18:56 109836 --a------ C:\Qoobox\Quarantine\C\WINDOWS\BMcb78c4fe.xml.vir
2008-06-13 21:16 431 --a------ C:\Qoobox\Quarantine\catchme.log
|
|
just4play
Member
|
13. kesäkuuta 2008 @ 21:41 |
Linkki tähän viestiin
|
tässä taitaa olla oikea logi.
ComboFix 08-06-03.4 - Mane 2008-06-13 21:16:02.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.246 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.
2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-09-14 16:12 159232]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 21:16:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-13 21:17:33
ComboFix-quarantined-files.txt 2008-06-13 18:17:22
ComboFix2.txt 2008-06-13 16:32:02
ComboFix3.txt 2008-06-13 15:01:09
ComboFix4.txt 2008-06-12 17:33:24
ComboFix5.txt 2008-06-04 16:28:15
Pre-Run: 14,197,080,064 tavua vapaana
Post-Run: 14,191,308,800 tavua vapaana
139 --- E O F --- 2008-06-12 16:51:25
ymmärrystä - olen vasta-alkaja!
|
|
Hujo
Suspended permanently
|
13. kesäkuuta 2008 @ 22:09 |
Linkki tähän viestiin
|
Avaa Muistio ja kopioi/liitä lainauksen sisältö sinne:
Lainaus: File::
C:\WINDOWS\svchosl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
Tallenna se nimellä CFScript.txt
Sitten raahaa CFScript ComboFix.exeen kuten alla.

Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
Voiko tietsikka koskaan toimia?
|
|
just4play
Member
|
13. kesäkuuta 2008 @ 23:22 |
Linkki tähän viestiin
|
ComboFix 08-06-03.4 - Mane 2008-06-13 22:50:30.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.245 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.
2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-09-14 16:12 159232]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 22:51:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-13 22:51:56
ComboFix-quarantined-files.txt 2008-06-13 19:51:49
ComboFix2.txt 2008-06-13 18:17:34
ComboFix3.txt 2008-06-13 16:32:02
ComboFix4.txt 2008-06-13 15:01:09
ComboFix5.txt 2008-06-12 17:33:24
Pre-Run: 14,181,195,776 tavua vapaana
Post-Run: 14,173,708,288 tavua vapaana
139 --- E O F --- 2008-06-12 16:51:25
|
|
Hujo
Suspended permanently
|
13. kesäkuuta 2008 @ 23:29 |
Linkki tähän viestiin
|
ajas tuo Malwarebytes' Anti-Malware uudelleen
========================
Avaa Muistio ja kopioi/liitä lainauksen sisältö sinne:
Lainaus: File::
C:\is155400.exe
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm
Tallenna se nimellä CFScript.txt
Sitten raahaa CFScript ComboFix.exeen kuten alla.

sitten kun olet raahannut sen sinne kuten kuva osoittaa niin tulee sininen taulu hetkenpäästä paina 1 ja enter sitten anna ohjelman touhuta loppuun.
Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
Voiko tietsikka koskaan toimia?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 13. kesäkuuta 2008 @ 23:43
|
|
just4play
Member
|
14. kesäkuuta 2008 @ 00:34 |
Linkki tähän viestiin
|
ComboFix 08-06-03.4 - Mane 2008-06-14 0:29:52.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.203 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.
2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-09-14 16:12 159232]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 00:30:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-14 0:31:26
ComboFix-quarantined-files.txt 2008-06-13 21:31:19
ComboFix2.txt 2008-06-13 19:51:57
ComboFix3.txt 2008-06-13 18:17:34
ComboFix4.txt 2008-06-13 16:32:02
ComboFix5.txt 2008-06-13 15:01:09
Pre-Run: 14,164,586,496 tavua vapaana
Post-Run: 14,157,385,728 tavua vapaana
139 --- E O F --- 2008-06-12 16:51:25
JA VIELÄ MALWAREN LOGI
Malwarebytes' Anti-Malware 1.17
Tietokantaversio: 850
0:28:23 14.6.2008
mbam-log-6-14-2008 (00-28-23).txt
Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
Tarkistetut kohteet: 61475
Kulunut aika: 7 minute(s), 32 second(s)
Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 0
Saastuneita rekisteriarvoja: 0
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 0
Saastuneita tiedostoja: 3
Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)
Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriavaimia:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriarvoja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)
Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)
Saastuneita tiedostoja:
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP350\A0020884.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP350\A0020885.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP350\A0020886.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
ymmärrystä - olen vasta-alkaja!
|
|
Hujo
Suspended permanently
|
14. kesäkuuta 2008 @ 01:00 |
Linkki tähän viestiin
|
1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
2. Valitse ominaisuudet
3. Valitse järjestelmän palauttaminen välilehti
4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
5. Paina Käytä
6. Paina ok
7. Sammuta ja käynnistä
8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
9. Käytä ja OK
==============
Kirjoita windowsin käynnistävalikon suorita-kenttään ComboFix.exe /u paina OK
==============
Lataa OTMoveIt
OTMoveIt ja tallenna se työpöydällesi.
Tuplaklikkaa OTMoveIt.exe.
Klikkaa CleanUp!.
Valitse Yes kun kysytään "Begin cleanup Process?".
Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.
HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.
Voiko tietsikka koskaan toimia?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 14. kesäkuuta 2008 @ 01:06
|
|
just4play
Member
|
14. kesäkuuta 2008 @ 13:23 |
Linkki tähän viestiin
|
jostain syystä combofix ei käynnistynyt tuolla tavalla. ilmoitti ettei se ole asennettu. sitten tein kuitenkin ton vikan vaiheen niin ilmeisesti se poisti myös combofixin. nyt äsken avast ilmoitti että ssetup.exe sisältää jonkun troijan osan. avast poisti sen.
nyt en siis saanut combo logia. lataanko ohjelman uudelleen vai miten jatkan?
|
|
Hujo
Suspended permanently
|
14. kesäkuuta 2008 @ 13:35 |
Linkki tähän viestiin
|
|
1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
2. Valitse ominaisuudet
3. Valitse järjestelmän palauttaminen välilehti
4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
5. Paina Käytä
6. Paina ok
7. Sammuta ja käynnistä
8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
9. Käytä ja OK
==============
lataa combofix uudelleen ja uusi hjt:n loki
Voiko tietsikka koskaan toimia?
|
|
just4play
Member
|
14. kesäkuuta 2008 @ 17:07 |
Linkki tähän viestiin
|
ComboFix 08-06-12.2 - Mane 2008-06-14 17:03:02.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.266 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-14 to 2008-06-14 )))))))))))))))))
.
2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 17:03:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-14 17:04:34
ComboFix-quarantined-files.txt 2008-06-14 14:04:28
Pre-Run: 14,783,410,176 tavua vapaana
Post-Run: 14,784,884,736 tavua vapaana
115 --- E O F --- 2008-06-12 16:51:25
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:05:10, on 14.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\virustorjuta_avast\aswUpdSv.exe
C:\Program Files\virustorjuta_avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\virustorjuta_avast\ashMaiSv.exe
C:\PROGRA~1\VIRUST~1\ashDisp.exe
C:\Program Files\virustorjuta_avast\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\VIRUST~1\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\virustorjuta_avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\virustorjuta_avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashWebSv.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 4423 bytes
|
|
Hujo
Suspended permanently
|
14. kesäkuuta 2008 @ 17:21 |
Linkki tähän viestiin
|
Vielä kaksi
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:
Lainaus: File::
C:\is155400.exe
C:\WINDOWS\is154890.exe
Tallenna se nimellä CFScript.txt
Sitten raahaa CFScript ComboFix.exeen kuten alla.

Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
Voiko tietsikka koskaan toimia?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 14. kesäkuuta 2008 @ 17:22
|
|
just4play
Member
|
14. kesäkuuta 2008 @ 21:28 |
Linkki tähän viestiin
|
ComboFix 08-06-12.2 - Mane 2008-06-14 21:00:23.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.228 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-14 to 2008-06-14 )))))))))))))))))
.
2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 14:14 --------- d-----w C:\Documents and Settings\Mane\Application Data\Apple Computer
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 21:01:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-14 21:01:51
ComboFix-quarantined-files.txt 2008-06-14 18:01:43
ComboFix2.txt 2008-06-14 14:04:35
Pre-Run: 16,241,147,904 tavua vapaana
Post-Run: 16,234,868,736 tavua vapaana
118 --- E O F --- 2008-06-12 16:51:25
|
|
Hujo
Suspended permanently
|
14. kesäkuuta 2008 @ 21:33 |
Linkki tähän viestiin
|
siellä ne vielä on
Mites tän homman oikeen teet..
===================
yritetään kerran viel poijaat
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:
Lainaus: File::
C:\is155400.exe
C:\WINDOWS\is154890.exe
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm
Tallenna se nimellä CFScript.txt
Sitten raahaa CFScript ComboFix.exeen kuten alla.

Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
Nyt tuon punasella merkityn laitat tyhjään muistioon
käynnistä nappi >apuohjelmat > muistio
Kohde: työpöytä
sittten vasemmasta ylä reunasta tiedosto > tallenna nimellä tiedosto nimi: CFScript.txt
tallenusmuoto kaikki tiedostot
sitten raahaat sen kuvan osoitamalla tavalla
combofix työstää tulee sininen taulu paina numeroa 1 ja enter
Voiko tietsikka koskaan toimia?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 14. kesäkuuta 2008 @ 22:08
|
|
just4play
Member
|
14. kesäkuuta 2008 @ 22:06 |
Linkki tähän viestiin
|
|
niin, aika monta puhdistusta on jo tehty. mitäs noi tiedostot on mitä yritetään poistaa, voiko ne alkaa leviämään? mulla on ainakin sormi jo suussa.
ymmärrystä - olen vasta-alkaja!
|
|
Hujo
Suspended permanently
|
14. kesäkuuta 2008 @ 22:11 |
Linkki tähän viestiin
|
|
katos laitoin tohon ylös ohjetta
ne on sitä msn virusta
vielä sitä exe .. niin samaa sontaa koneella kohta lisää.
Voiko tietsikka koskaan toimia?
|
|
just4play
Member
|
15. kesäkuuta 2008 @ 00:56 |
Linkki tähän viestiin
|
kaikki tehty ohjeen mukaan.
ComboFix 08-06-12.2 - Mane 2008-06-15 0:52:43.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.226 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-14 to 2008-06-14 )))))))))))))))))
.
2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 14:14 --------- d-----w C:\Documents and Settings\Mane\Application Data\Apple Computer
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-15 00:53:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-15 0:54:12
ComboFix-quarantined-files.txt 2008-06-14 21:54:01
ComboFix2.txt 2008-06-14 18:01:52
ComboFix3.txt 2008-06-14 14:04:35
Pre-Run: 16,228,130,816 tavua vapaana
Post-Run: 16,221,413,376 tavua vapaana
119 --- E O F --- 2008-06-12 16:51:25
|
|
Hujo
Suspended permanently
|
15. kesäkuuta 2008 @ 01:04 |
Linkki tähän viestiin
|
|
C:\WINDOWS\is154890.exe
C:\is155400.exe
Poista noi käsin punasella merkatut
seurava vaihe formatointi
Voiko tietsikka koskaan toimia?
|
|
Mainos
|
  |
|
|
just4play
Member
|
15. kesäkuuta 2008 @ 01:19 |
Linkki tähän viestiin
|
|
poistin käsin ... haluatko jonkin login?
|
|