User Käyttäjä Salasana  
   
torstai 13.11.2025 / 21:05
Hae keskustelualueilta:        In English   Suomeksi   På svenska
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > combofix ja malware -logit
Näytä aiheet
 
Keskustelualueet
Keskustelualueet
combofix ja malware -logit
  Siirry:
 
Kirjoittaja Viesti
Sivu:12>
just4play
Member
_
13. kesäkuuta 2008 @ 17:27 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Malwarebytes' Anti-Malware 1.17
Tietokantaversio: 850

20:17:37 12.6.2008
mbam-log-6-12-2008 (20-17-37).txt

Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
Tarkistetut kohteet: 60224
Kulunut aika: 7 minute(s), 26 second(s)

Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 5
Saastuneita rekisteriarvoja: 1
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 7
Saastuneita tiedostoja: 328

Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)

Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)

Saastuneita rekisteriavaimia:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Saastuneita rekisteriarvoja:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Messanger Control Center (Backdoor.Bot) -> Quarantined and deleted successfully.

Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)

Saastuneita hakemistoja:
C:\Casino (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\logs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\promo (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs (Adware.Casino) -> Quarantined and deleted successfully.

Saastuneita tiedostoja:
C:\WINDOWS\system32\rxnbraea.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aearbnxr.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\bot1.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\d.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\daf.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dchi.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dci.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dcis.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dciz.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dcsi.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dczi.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\ddc.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\dsdc.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\fa.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\img.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\irc.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\jester.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\jestesr.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\profile.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\setup1.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\sexy.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\sxy.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\sxy1.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\exy.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\setup.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\setup1.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\sexy.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mane\Työpöytä\image23.JPG-www.msnimages.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\setup.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\wkssvr.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\byXNfCSj.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\cbXoOhec.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\enlspfyr.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\geBSKaxV.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\grxwbjoy.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\hurbwlku.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\kdontckj.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\kvkkxhwr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\ljflnnff.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\mgrmowlr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\objdslsv.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\qywsvypb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\urqPggdA.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\wcalbfqq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\xiyrcpxo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP336\A0018154.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP336\A0018162.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP337\A0018164.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0018196.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0018197.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0019194.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP338\A0019205.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019219.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019220.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019221.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP339\A0019224.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP340\A0019245.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP340\A0020224.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP340\A0020231.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020236.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020238.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020240.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020249.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020251.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020563.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP341\A0020595.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP342\A0020601.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP342\A0020612.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020619.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020621.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020623.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020624.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020626.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020628.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020629.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020632.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020637.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020639.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020640.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020643.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020647.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020651.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020656.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020657.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020659.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP343\A0020686.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\mservice.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\winudspm.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\telecms.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\blackjack.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\browser.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\cacerts.crt (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\cam.cas (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\cardlib.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\common.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\countries.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\creditdebit.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\db.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\devlib.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\devlibcomm.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\filemap.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\fivecard.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\games.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\gsid.txt (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\id.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\INSTALL.LOG (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\languages.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\libeay32.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\licens.txt (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\modstatus.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\mp3dec.asi (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\mss32.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\msvcp71.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\msvcr71.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\navigator.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\omaha.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\options.cfg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\poker.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\poker.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sc.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\shfolder.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\srvmap.lst (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\ssleay32.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\texas.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\UNWISE.EXE (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\update.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xml.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\zlib1.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\0.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\1.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\10.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\11.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\12.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\13.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\14.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\15.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\16.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\17.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\18.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\19.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\2.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\20.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\21.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\22.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\23.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\24.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\25.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\26.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\27.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\28.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\29.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\3.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\30.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\31.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\32.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\33.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\34.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\35.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\36.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\37.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\38.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\39.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\4.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\40.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\41.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\42.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\43.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\44.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\45.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\46.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\47.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\48.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\49.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\5.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\50.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\51.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\6.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\7.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\8.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\9.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\allin_popup.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\archive.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\archive_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\avatar.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\b.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\base.css (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\bkg.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\browserdetect.js (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_cashier.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_close.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_filters_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_filters_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_game.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_general.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_join.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_main.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_medium.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_minmax.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_sublevels_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\but_sublevels_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\caret.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\chatbubble.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\chips.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\decktype_settings.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\edit.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gamelimits1.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gamelimits2.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gamelimits3.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\game_summary.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\gre_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand.html (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand_cursor.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\hand_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\harrow.cur (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\headers_bkg.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\headers_text.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\history.html (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\history.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\history_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\input_additional.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\input_boxes.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\input_lists.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\language.xml (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\language.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\languages.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\language_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\main.js (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\main_bkg.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\main_listhi.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_bg.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_buttons.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_moneytext.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\navigator_timer.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_bottom.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_game_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_game_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_game_top.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_left.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_medium.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_moretables.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_texts.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\panel_top.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\pointer.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cardback.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards_4c.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards_large.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_cards_large_4c.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_deckside.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_font_11p_bold.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_makechoice.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\poker_pucks.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\pol_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\popups.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_actions.png (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_active.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_inactive.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_note.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\position_numbers.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\progress_ani.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\promo-test1.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\rus_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\sc_bkg8.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tabs_big.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tabs_cashier.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tabs_small.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\text.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\timeslider.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tur_font_11p_regular.xbf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tx_bkg10.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\tx_bkg5.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\user.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\user_ff.xsl (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\white_line.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\win_graphics.bmp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\xml.gif (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\data\xml_decoder.js (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\promo\sundayspecial.jpg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\c_button.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\c_chip.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\c_deal.mp3 (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\p_alert.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\sfx\p_checkknock.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\blackjack_game_panel.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\blackjack_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\common.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\creditdebit.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_clientspecific.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_creditdebit.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_game.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_general.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_mc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\ext_navigator.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\fcs_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\fc_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\fc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\filemap.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\filerefs.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\gameclient.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\game_common.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\game_common_message.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\game_panel.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\gizmo.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\mc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\message.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\mtt_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\mtt_lobby.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\navigator.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\omaha_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\omaha_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\optdef.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\poker_limits.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\sc_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\sc_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\tel_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\texas_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\texas_main.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\PAF Diamond Poker\xrs\tournament_join.xrs (Adware.Casino) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\image011.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\images21.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\images84.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photo12.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photo93.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photos2007_16.zip (Backdoor.Bot) -> Quarantined and deleted successfully.





ja vielä combofix logi

ComboFix 08-06-03.4 - Mane 2008-06-12 20:32:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.301 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript_used_2008-06-04@19.22.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BMcb78c4fe.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\mcrh.tmp

.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-12 to 2008-06-12 )))))))))))))))))
.

2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:50 . 2008-06-12 19:50 <KANSIO> d-------- C:\WINDOWS\LastGood
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 --a------ C:\roffl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-06-03 18:32 . 2008-06-03 18:32 86,548 --a------ C:\setz.exe
2008-05-27 22:53 . 2008-06-01 19:46 86,502 --a------ C:\sexy.com
2008-05-27 16:59 . 2008-05-27 16:59 28,672 --a------ C:\gay.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot@2008-06-04_19.27.44.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-04 16:25:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-14 15:52:59 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
- 2008-02-16 09:02:36 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2008-04-21 07:02:46 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
- 2008-02-16 09:02:36 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2008-04-21 07:02:46 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2008-02-16 09:02:37 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll
+ 2008-04-21 07:02:47 1,055,232 ----a-w C:\WINDOWS\system32\danim.dll
- 2008-02-16 09:02:36 1,023,488 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2008-04-21 07:02:46 1,023,488 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
- 2008-02-16 09:02:36 151,552 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2008-04-21 07:02:46 151,552 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
- 2008-02-16 09:02:37 1,055,232 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
+ 2008-04-21 07:02:47 1,055,232 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
- 2008-02-16 09:02:37 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-04-21 07:02:47 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-02-16 09:02:37 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-04-21 07:02:47 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-02-16 09:02:37 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-04-21 07:02:47 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-02-15 09:23:37 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2008-04-17 10:52:54 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
- 2008-02-16 09:02:38 250,880 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2008-04-21 07:02:47 250,880 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2008-02-16 09:02:38 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2008-04-21 07:02:47 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2008-02-16 09:02:38 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-04-21 07:02:47 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2008-02-16 22:32:40 3,080,704 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-04-21 07:02:49 3,080,704 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-02-16 09:02:39 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-04-21 07:02:49 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-02-16 09:02:39 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-04-21 07:02:49 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2008-02-16 09:02:39 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-04-21 07:02:50 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2008-02-16 09:02:39 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-04-21 07:02:50 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-10-29 22:43:51 1,288,192 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:15:43 1,288,192 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
- 2008-02-16 09:02:41 1,494,016 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2008-04-21 07:02:51 1,494,016 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
- 2008-02-16 09:02:41 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2008-04-21 07:02:51 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
- 2008-02-16 09:02:41 616,448 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-04-21 07:02:52 616,448 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-02-16 09:02:42 659,456 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-04-21 07:02:52 659,456 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2008-02-16 09:02:37 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-04-21 07:02:47 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-02-16 09:02:37 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-04-21 07:02:47 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-02-16 09:02:37 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-04-21 07:02:47 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2008-02-16 09:02:38 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2008-04-21 07:02:47 250,880 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2008-02-16 09:02:38 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2008-04-21 07:02:47 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
- 2008-02-16 09:02:38 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-04-21 07:02:47 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-29 23:35:11 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe
- 2008-02-16 22:32:40 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-04-21 07:02:49 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2008-02-16 09:02:39 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-04-21 07:02:49 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2008-02-16 09:02:39 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-04-21 07:02:49 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
- 2008-02-16 09:02:39 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-04-21 07:02:50 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
- 2008-02-16 09:02:39 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-04-21 07:02:50 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2008-02-16 09:02:41 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2008-04-21 07:02:51 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2008-02-16 09:02:41 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2008-04-21 07:02:51 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
- 2006-09-25 14:58:48 14,640 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:19:02 17,272 ------w C:\WINDOWS\system32\spmsg.dll
- 2008-02-16 09:02:41 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-04-21 07:02:52 616,448 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2008-02-15 23:03:12 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2008-04-17 11:03:44 357,888 ----a-w C:\WINDOWS\system32\xpsp3res.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 13:22 86016]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-06 00:16 185632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=


*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-12 20:32:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-12 20:33:24
ComboFix-quarantined-files.txt 2008-06-12 17:33:14
ComboFix2.txt 2008-06-04 16:28:15

Pre-Run: 14,326,657,024 tavua vapaana
Post-Run: 14,327,308,288 tavua vapaana

213 --- E O F --- 2008-06-12 16:51:25
Hujo
Suspended permanently
_
13. kesäkuuta 2008 @ 17:38 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:

Lainaus:
File::
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\is155400.exe
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\roffl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\setz.exe
C:\sexy.com
C:\gay.exe
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm




Tallenna se nimellä CFScript.txt

Sitten raahaa CFScript ComboFix.exeen kuten alla.



Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.

===========

laita se hjt:n loki myös

Lataa TÄSTÄ HJTInstall.exe

* Tallenna HJTInstall.exe työpöydällesi.
* Tuplaklikkaa HJTInstall.exe-kuvaketta työpöydälläsi.
* Oletuksena se asentaa itsensä hakemistoon C:\Program Files\Trend Micro\HijackThis.
* Klikkaa Install.
* Asennusohjelma luo HijackThis-kuvakkeen työpöydälle.
* Kun asennus on valmis, se käynnistää HijackThisin.
* Klikkaa Do a system scan and save a logfile-painiketta. Ohjelma aloittaa skannauksen ja lokin pitäisi avautua Muistioon.
* Klikkaa ensin "Muokkaa > Valitse kaikki" sitten "Muokkaa > Kopioi" kopioidaksesi koko lokin sisällön.
* Liitä lokin sisältö seuraavaan vastaukseesi.
* ÄLÄ käytä Analyse This-nappulaa, sen löydöt ovat vaarallisia väärinymmärrettyinä.
* ÄLÄ fixaa HijackThis-ohjelmalla vielä mitään. Suurin osa sen löydöistä ovat joko harmittomia tai jopa tarpeellisia.


Voiko tietsikka koskaan toimia?
just4play
Member
_
13. kesäkuuta 2008 @ 18:04 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
ComboFix 08-06-03.4 - Mane 2008-06-13 17:59:45.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.318 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Mane\new.txt

.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.

2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 --a------ C:\roffl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-06-03 18:32 . 2008-06-03 18:32 86,548 --a------ C:\setz.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 14:56:37 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=


.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 18:00:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-13 18:01:08
ComboFix-quarantined-files.txt 2008-06-13 15:00:58
ComboFix2.txt 2008-06-12 17:33:24
ComboFix3.txt 2008-06-04 16:28:15

Pre-Run: 14,277,386,240 tavua vapaana
Post-Run: 14,291,722,240 tavua vapaana

127 --- E O F --- 2008-06-12 16:51:25




ja sitten hjt-logi perään:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:01:59, on 13.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 3769 bytes
Hujo
Suspended permanently
_
13. kesäkuuta 2008 @ 18:13 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
laita koneelle virustorjunta ja palomuuri kuntoon

Linkki

==============

sitten uusi hjt:n loki

=============

Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:

Lainaus:
Lainaus:File::
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\is155400.exe
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\roffl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\setz.exe
C:\sexy.com
C:\gay.exe
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm



Tallenna se nimellä CFScript.txt

Sitten raahaa CFScript ComboFix.exeen kuten alla.




Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.

tämänkään ajo ei onnistunut

Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 13. kesäkuuta 2008 @ 18:22

just4play
Member
_
13. kesäkuuta 2008 @ 19:40 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Asensin avastin virustorjunnaksi. Nyt äsken tuli ilmoitus jostain troijan viruksesta win32 tiedostossa tai jotain...

tässä hjt ja combologi

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:37:08, on 13.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\virustorjuta_avast\aswUpdSv.exe
C:\Program Files\virustorjuta_avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\virustorjuta_avast\ashMaiSv.exe
C:\Program Files\virustorjuta_avast\ashWebSv.exe
C:\PROGRA~1\VIRUST~1\ashDisp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\VIRUST~1\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\virustorjuta_avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\virustorjuta_avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashWebSv.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 4390 bytes


ComboFix 08-06-03.4 - Mane 2008-06-13 19:30:34.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.291 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.

2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 --a------ C:\roffl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-06-03 18:32 . 2008-06-03 18:32 86,548 --a------ C:\setz.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]

.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 19:31:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-13 19:32:01
ComboFix-quarantined-files.txt 2008-06-13 16:31:54
ComboFix2.txt 2008-06-13 15:01:09
ComboFix3.txt 2008-06-12 17:33:24
ComboFix4.txt 2008-06-04 16:28:15

Pre-Run: 14,153,953,280 tavua vapaana
Post-Run: 14,212,198,400 tavua vapaana

140 --- E O F --- 2008-06-12 16:51:25


ymmärrystä - olen vasta-alkaja!
Hujo
Suspended permanently
_
13. kesäkuuta 2008 @ 19:59 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:

Lainaus:
File::
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\roffl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\setz.exe


Tallenna se nimellä CFScript.txt

Sitten raahaa CFScript ComboFix.exeen kuten alla.



Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.


Voiko tietsikka koskaan toimia?
just4play
Member
_
13. kesäkuuta 2008 @ 21:27 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
mikäs tässä nyt on teidän mielestä pielessä? mitä minä yritän poistaa?
just4play
Member
_
13. kesäkuuta 2008 @ 21:32 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
uusin combofix logi. en ole varma onko se tämä kun hukkasin tallentamani. toivottavasti lähetin oikean.

2007-07-30 21:18 0 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\Mane\new.txt.vir
2008-05-28 16:08 57344 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\urqOIxUL.dll.vir
2008-05-28 16:14 371712 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJCvwTM.dll.vir
2008-05-28 20:15 57344 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\hgGyawVM.dll.vir
2008-05-29 04:31 1463566 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\sysrmtqv.ini.vir
2008-05-29 04:32 126464 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\gagjgtiv.dll.vir
2008-05-29 04:41 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\xxywuSKD.dll.vir
2008-05-29 17:31 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\cbXRKEvW.dll.vir
2008-05-29 17:41 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqOHaXo.dll.vir
2008-05-29 19:44 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvSmkLD.dll.vir
2008-05-29 19:58 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJASjJC.dll.vir
2008-05-29 20:32 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mlJCUKcb.dll.vir
2008-05-29 21:35 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\nnnllMgh.dll.vir
2008-05-29 21:35 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\pmnkLBRJ.dll.vir
2008-05-29 21:41 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\vtUnmlIb.dll.vir
2008-05-29 22:04 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqQkKax.dll.vir
2008-05-29 23:00 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJCsRHx.dll.vir
2008-05-30 00:38 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\khfGyyxV.dll.vir
2008-05-30 17:49 1474380 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\esiwosrg.ini.vir
2008-05-30 17:50 125440 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\qoxvehim.dll.vir
2008-05-30 17:56 134144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jlsidkru.dll.vir
2008-05-30 17:57 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jkkJaawx.dll.vir
2008-05-30 19:09 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\opnnoMFV.dll.vir
2008-05-30 22:15 59392 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jkkKcAPi.dll.vir
2008-05-31 12:46 1478778 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ncgaqedc.ini.vir
2008-05-31 17:51 126464 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jbbvcrqc.dll.vir
2008-06-01 11:48 1473880 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ullnkfuu.ini.vir
2008-06-01 17:53 126464 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mrxeoflb.dll.vir
2008-06-03 18:17 125952 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\hjspukuk.dll.vir
2008-06-03 18:17 1497200 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\qdbdvgsk.ini.vir
2008-06-03 18:32 86548 --a------ C:\Qoobox\Quarantine\C\WINDOWS\service.exe.vir
2008-06-04 19:06 3424 --a------ C:\Qoobox\Quarantine\C\bot.exe.vir
2008-06-04 19:07 1499881 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\oxpcryix.ini.vir
2008-06-04 19:22 391897 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\MTwvCJjl.ini.vir
2008-06-04 19:22 391897 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\MTwvCJjl.ini2.vir
2008-06-04 19:24 288 --a------ C:\Qoobox\Quarantine\F\autorun.inf.vir
2008-06-04 19:25 362670 --a------ C:\Qoobox\Quarantine\catchme2008-06-04_192505,60.zip
2008-06-04 19:26 294 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\aearbnxr.ini.vir
2008-06-04 19:32 97 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mcrh.tmp.vir
2008-06-11 18:04 22 --a------ C:\Qoobox\Quarantine\C\WINDOWS\pskt.ini.vir
2008-06-11 18:56 109836 --a------ C:\Qoobox\Quarantine\C\WINDOWS\BMcb78c4fe.xml.vir
2008-06-13 21:16 431 --a------ C:\Qoobox\Quarantine\catchme.log
just4play
Member
_
13. kesäkuuta 2008 @ 21:41 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
tässä taitaa olla oikea logi.

ComboFix 08-06-03.4 - Mane 2008-06-13 21:16:02.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.246 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.

2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-09-14 16:12 159232]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]

.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 21:16:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-13 21:17:33
ComboFix-quarantined-files.txt 2008-06-13 18:17:22
ComboFix2.txt 2008-06-13 16:32:02
ComboFix3.txt 2008-06-13 15:01:09
ComboFix4.txt 2008-06-12 17:33:24
ComboFix5.txt 2008-06-04 16:28:15

Pre-Run: 14,197,080,064 tavua vapaana
Post-Run: 14,191,308,800 tavua vapaana

139 --- E O F --- 2008-06-12 16:51:25


ymmärrystä - olen vasta-alkaja!
Hujo
Suspended permanently
_
13. kesäkuuta 2008 @ 22:09 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Avaa Muistio ja kopioi/liitä lainauksen sisältö sinne:

Lainaus:
File::
C:\WINDOWS\svchosl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe


Tallenna se nimellä CFScript.txt

Sitten raahaa CFScript ComboFix.exeen kuten alla.



Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.


Voiko tietsikka koskaan toimia?
just4play
Member
_
13. kesäkuuta 2008 @ 23:22 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
ComboFix 08-06-03.4 - Mane 2008-06-13 22:50:30.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.245 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.

2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-09-14 16:12 159232]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]

.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 22:51:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-13 22:51:56
ComboFix-quarantined-files.txt 2008-06-13 19:51:49
ComboFix2.txt 2008-06-13 18:17:34
ComboFix3.txt 2008-06-13 16:32:02
ComboFix4.txt 2008-06-13 15:01:09
ComboFix5.txt 2008-06-12 17:33:24

Pre-Run: 14,181,195,776 tavua vapaana
Post-Run: 14,173,708,288 tavua vapaana

139 --- E O F --- 2008-06-12 16:51:25
Hujo
Suspended permanently
_
13. kesäkuuta 2008 @ 23:29 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
ajas tuo Malwarebytes' Anti-Malware uudelleen

========================


Avaa Muistio ja kopioi/liitä lainauksen sisältö sinne:

Lainaus:
File::
C:\is155400.exe
C:\Documents and Settings\Mane\setupa.exe
C:\WINDOWS\svchosl.exe
C:\ssetup.exe
C:\WINDOWS\is154890.exe
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm


Tallenna se nimellä CFScript.txt

Sitten raahaa CFScript ComboFix.exeen kuten alla.



sitten kun olet raahannut sen sinne kuten kuva osoittaa niin tulee sininen taulu hetkenpäästä paina 1 ja enter sitten anna ohjelman touhuta loppuun.

Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.


Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 13. kesäkuuta 2008 @ 23:43

just4play
Member
_
14. kesäkuuta 2008 @ 00:34 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
ComboFix 08-06-03.4 - Mane 2008-06-14 0:29:52.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.203 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-13 to 2008-06-13 )))))))))))))))))
.

2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 21:22 . 2008-06-03 22:58 86,548 --a------ C:\Documents and Settings\Mane\setupa.exe
2008-06-03 21:13 . 2008-06-03 21:13 49,156 -r-hs---- C:\WINDOWS\svchosl.exe
2008-06-03 18:53 . 2008-06-03 23:05 86,548 --a------ C:\ssetup.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-12_20.33.07,37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 16:48:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 16:27:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-13 16:27:28 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_588.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-09-14 16:12 159232]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 13:22 7700480 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]

.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 00:30:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-14 0:31:26
ComboFix-quarantined-files.txt 2008-06-13 21:31:19
ComboFix2.txt 2008-06-13 19:51:57
ComboFix3.txt 2008-06-13 18:17:34
ComboFix4.txt 2008-06-13 16:32:02
ComboFix5.txt 2008-06-13 15:01:09

Pre-Run: 14,164,586,496 tavua vapaana
Post-Run: 14,157,385,728 tavua vapaana

139 --- E O F --- 2008-06-12 16:51:25



JA VIELÄ MALWAREN LOGI

Malwarebytes' Anti-Malware 1.17
Tietokantaversio: 850

0:28:23 14.6.2008
mbam-log-6-14-2008 (00-28-23).txt

Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
Tarkistetut kohteet: 61475
Kulunut aika: 7 minute(s), 32 second(s)

Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 0
Saastuneita rekisteriarvoja: 0
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 0
Saastuneita tiedostoja: 3

Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)

Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)

Saastuneita rekisteriavaimia:
(Haitallisia kohteita ei löydetty)

Saastuneita rekisteriarvoja:
(Haitallisia kohteita ei löydetty)

Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)

Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)

Saastuneita tiedostoja:
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP350\A0020884.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP350\A0020885.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DDED2FC8-4D7B-4E9A-A384-34611FC9710F}\RP350\A0020886.exe (Backdoor.Bot) -> Quarantined and deleted successfully.


ymmärrystä - olen vasta-alkaja!
Hujo
Suspended permanently
_
14. kesäkuuta 2008 @ 01:00 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
2. Valitse ominaisuudet
3. Valitse järjestelmän palauttaminen välilehti
4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
5. Paina Käytä
6. Paina ok
7. Sammuta ja käynnistä
8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
9. Käytä ja OK

==============

Kirjoita windowsin käynnistävalikon suorita-kenttään ComboFix.exe /u paina OK

==============

Lataa OTMoveIt
OTMoveIt ja tallenna se työpöydällesi.

Tuplaklikkaa OTMoveIt.exe.
Klikkaa CleanUp!.
Valitse Yes kun kysytään "Begin cleanup Process?".
Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.

HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.


Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 14. kesäkuuta 2008 @ 01:06

just4play
Member
_
14. kesäkuuta 2008 @ 13:23 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
jostain syystä combofix ei käynnistynyt tuolla tavalla. ilmoitti ettei se ole asennettu. sitten tein kuitenkin ton vikan vaiheen niin ilmeisesti se poisti myös combofixin. nyt äsken avast ilmoitti että ssetup.exe sisältää jonkun troijan osan. avast poisti sen.

nyt en siis saanut combo logia. lataanko ohjelman uudelleen vai miten jatkan?
Hujo
Suspended permanently
_
14. kesäkuuta 2008 @ 13:35 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
2. Valitse ominaisuudet
3. Valitse järjestelmän palauttaminen välilehti
4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
5. Paina Käytä
6. Paina ok
7. Sammuta ja käynnistä
8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
9. Käytä ja OK

==============

lataa combofix uudelleen ja uusi hjt:n loki

Voiko tietsikka koskaan toimia?
just4play
Member
_
14. kesäkuuta 2008 @ 17:07 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
ComboFix 08-06-12.2 - Mane 2008-06-14 17:03:02.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.266 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-14 to 2008-06-14 )))))))))))))))))
.

2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]

*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 17:03:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-14 17:04:34
ComboFix-quarantined-files.txt 2008-06-14 14:04:28

Pre-Run: 14,783,410,176 tavua vapaana
Post-Run: 14,784,884,736 tavua vapaana

115 --- E O F --- 2008-06-12 16:51:25


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:05:10, on 14.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\virustorjuta_avast\aswUpdSv.exe
C:\Program Files\virustorjuta_avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\virustorjuta_avast\ashMaiSv.exe
C:\PROGRA~1\VIRUST~1\ashDisp.exe
C:\Program Files\virustorjuta_avast\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\VIRUST~1\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\virustorjuta_avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\virustorjuta_avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\virustorjuta_avast\ashWebSv.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 4423 bytes
Hujo
Suspended permanently
_
14. kesäkuuta 2008 @ 17:21 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Vielä kaksi

Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:

Lainaus:
File::
C:\is155400.exe
C:\WINDOWS\is154890.exe


Tallenna se nimellä CFScript.txt

Sitten raahaa CFScript ComboFix.exeen kuten alla.



Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.

Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 14. kesäkuuta 2008 @ 17:22

just4play
Member
_
14. kesäkuuta 2008 @ 21:28 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
ComboFix 08-06-12.2 - Mane 2008-06-14 21:00:23.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.228 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-14 to 2008-06-14 )))))))))))))))))
.

2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 14:14 --------- d-----w C:\Documents and Settings\Mane\Application Data\Apple Computer
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]

*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 21:01:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-14 21:01:51
ComboFix-quarantined-files.txt 2008-06-14 18:01:43
ComboFix2.txt 2008-06-14 14:04:35

Pre-Run: 16,241,147,904 tavua vapaana
Post-Run: 16,234,868,736 tavua vapaana

118 --- E O F --- 2008-06-12 16:51:25
Hujo
Suspended permanently
_
14. kesäkuuta 2008 @ 21:33 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
siellä ne vielä on

Mites tän homman oikeen teet..

===================

yritetään kerran viel poijaat


Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:

Lainaus:
File::
C:\is155400.exe
C:\WINDOWS\is154890.exe
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm



Tallenna se nimellä CFScript.txt

Sitten raahaa CFScript ComboFix.exeen kuten alla.



Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.

Nyt tuon punasella merkityn laitat tyhjään muistioon
käynnistä nappi >apuohjelmat > muistio

Kohde: työpöytä

sittten vasemmasta ylä reunasta tiedosto > tallenna nimellä tiedosto nimi: CFScript.txt

tallenusmuoto kaikki tiedostot

sitten raahaat sen kuvan osoitamalla tavalla

combofix työstää tulee sininen taulu paina numeroa 1 ja enter

Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 14. kesäkuuta 2008 @ 22:08

just4play
Member
_
14. kesäkuuta 2008 @ 22:06 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
niin, aika monta puhdistusta on jo tehty. mitäs noi tiedostot on mitä yritetään poistaa, voiko ne alkaa leviämään? mulla on ainakin sormi jo suussa.

ymmärrystä - olen vasta-alkaja!
Hujo
Suspended permanently
_
14. kesäkuuta 2008 @ 22:11 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
katos laitoin tohon ylös ohjetta

ne on sitä msn virusta
vielä sitä exe .. niin samaa sontaa koneella kohta lisää.

Voiko tietsikka koskaan toimia?
just4play
Member
_
15. kesäkuuta 2008 @ 00:56 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
kaikki tehty ohjeen mukaan.

ComboFix 08-06-12.2 - Mane 2008-06-15 0:52:43.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.226 [GMT 3:00]
Running from: C:\Documents and Settings\Mane\Työpöytä\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mane\Työpöytä\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-14 to 2008-06-14 )))))))))))))))))
.

2008-06-13 18:52 . 2008-06-13 18:54 <KANSIO> d-------- C:\Program Files\virustorjuta_avast
2008-06-13 17:41 . 2008-06-13 17:41 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Uniblue
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\Mane\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-12 19:54 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 19:54 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 19:54 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 19:48 . 2008-06-12 19:48 268 --ah----- C:\sqmdata09.sqm
2008-06-12 19:48 . 2008-06-12 19:48 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 18:59 . 2008-06-11 18:59 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 18:58 . 2008-06-11 18:58 268 --ah----- C:\sqmdata08.sqm
2008-06-11 18:58 . 2008-06-11 18:58 244 --ah----- C:\sqmnoopt08.sqm
2008-06-11 18:05 . 2008-04-14 18:52 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 18:05 . 2008-04-14 18:52 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 07:49 . 2008-06-11 07:49 268 --ah----- C:\sqmdata07.sqm
2008-06-11 07:49 . 2008-06-11 07:49 244 --ah----- C:\sqmnoopt07.sqm
2008-06-10 22:17 . 2008-06-10 22:17 268 --ah----- C:\sqmdata06.sqm
2008-06-10 22:17 . 2008-06-10 22:17 244 --ah----- C:\sqmnoopt06.sqm
2008-06-09 23:46 . 2008-06-09 23:46 268 --ah----- C:\sqmdata05.sqm
2008-06-09 23:46 . 2008-06-09 23:46 244 --ah----- C:\sqmnoopt05.sqm
2008-06-08 23:43 . 2008-06-08 23:43 268 --ah----- C:\sqmdata04.sqm
2008-06-08 23:43 . 2008-06-08 23:43 244 --ah----- C:\sqmnoopt04.sqm
2008-06-04 19:06 . 2008-06-04 19:06 3,424 --a------ C:\is155400.exe
2008-06-03 18:37 . 2008-06-03 21:14 4,217 --a------ C:\WINDOWS\is154890.exe
2008-05-25 12:21 . 2008-05-25 12:21 268 --ah----- C:\sqmdata03.sqm
2008-05-25 12:21 . 2008-05-25 12:21 244 --ah----- C:\sqmnoopt03.sqm
2008-05-23 23:02 . 2008-05-23 23:02 268 --ah----- C:\sqmdata02.sqm
2008-05-23 23:02 . 2008-05-23 23:02 244 --ah----- C:\sqmnoopt02.sqm

.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 14:14 --------- d-----w C:\Documents and Settings\Mane\Application Data\Apple Computer
2008-06-13 15:54 --------- d-----w C:\Program Files\virustorjuta_avast
2008-06-03 15:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-10 13:11 --------- d-----w C:\Program Files\PartyGaming
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 15:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.

(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\VIRUST~1\ashDisp.exe" [2008-05-16 02:19 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-09-14 16:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 13:22 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-06 00:16 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]

*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-12 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-15 00:53:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-15 0:54:12
ComboFix-quarantined-files.txt 2008-06-14 21:54:01
ComboFix2.txt 2008-06-14 18:01:52
ComboFix3.txt 2008-06-14 14:04:35

Pre-Run: 16,228,130,816 tavua vapaana
Post-Run: 16,221,413,376 tavua vapaana

119 --- E O F --- 2008-06-12 16:51:25
Hujo
Suspended permanently
_
15. kesäkuuta 2008 @ 01:04 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
C:\WINDOWS\is154890.exe
C:\is155400.exe

Poista noi käsin punasella merkatut

seurava vaihe formatointi

Voiko tietsikka koskaan toimia?
Mainos
_
__
 
_
just4play
Member
_
15. kesäkuuta 2008 @ 01:19 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
poistin käsin ... haluatko jonkin login?
 
Sivu:12>
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > combofix ja malware -logit
 

Apua ongelmiin: AfterDawnin keskustelualueet | AfterDawnin Vastaukset
Uutiset: IT-alan uutiset | Uutisia puhelimista
Musiikkia: MP3Lizard.com
Tuotearviot: Laitevertailu | Vertaa puhelimia | Vertaa kännykkäliittymiä
Pelit: Pelitiedostot, pelidemot ja trailerit
Ohjelmat: download.fi | AfterDawnin ohjelma-alueet
International: AfterDawn in English | Software downloads | Free, legal MP3s | AfterDawn på svenska
RSS -syötteet: AfterDawnin uutiset | Uusimmat ohjelmapäivitykset | Keskustelualueiden viestit
Tietoja: Tietoa AfterDawn Oy:stä | Mainosta sivuillamme | Sivuston käyttöehdot ja tietoja yksityisyydensuojasta
Ota yhteyttä: Lähetä palautetta | Ota yhteyttä mainosmyyntiimme
 
  © 1999-2025 AfterDawn Oy