afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > hjt & a2-lokit
Keskustelualueet
Keskustelualueet
Hjt & A2-lokit
Sakset
Junior Member
4. helmikuuta 2009 @ 16:50
Linkki tähän viestiin
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:29:45, on 4.2.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Avast4\ashChest.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\rs32net.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\E.tmp
C:\WINDOWS\Explorer.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\services.exe
C:\Program Files\Easy SpyRemover\EasySpyRemover.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\cmd.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\rs32net.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\services.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\services.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\a-squared Anti-Malware\a2start.exe
C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2wizard.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Avast4\ashSimpl.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fi.wikipedia.org/wiki/Wikipedia:Etusivu
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1004336348-413027322-725345543-1003\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-1004336348-413027322-725345543-1003 Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE (User '?')
O4 - Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutorunsDisabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: HP-leikekirja - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart -valitse - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: avast ! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
--
End of file - 7671 bytes
-----
a-squared Anti-Malware - Version 4.0
Last update: 4.2.2009 11:55:04
Scan settings:
Objects: Memory, Traces, Cookies, C:\, E:\
Scan archives: On
Heuristics: On
ADS Scan: On
Scan start: 4.2.2009 11:56:07
[580] C:\WINDOWS\system32\crypts.dll detected: Trojan-Spy.Finanz.J!IK
[1048] C:\WINDOWS\system32\wdfmgr.exe detected: Virus.Win32.Virut.q!IK
[20360] C:\WINDOWS\Explorer.exe detected: Trojan.Win32.Patched!IK
[20932] C:\WINDOWS\system32\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
[22348] C:\WINDOWS\system32\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
[23536] C:\WINDOWS\Explorer.exe detected: Trojan.Win32.Patched!IK
[14572] C:\WINDOWS\system32\NOTEPAD.EXE detected: Virus.Win32.Hupigon.MAP!IK
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run --> Services detected: Trace.Registry.SKL 1.0!A2
c:\windows\services.exe detected: Trace.File.Backdoor.Prorat.RC!A2
C:\Documents and Settings\MaijuR\Cookies\system@atdmt[2].txt detected: Trace.TrackingCookie.atdmt!A2
C:\Documents and Settings\MaijuR\Cookies\system@doubleclick[2].txt detected: Trace.TrackingCookie.doubleclick!A2
C:\Documents and Settings\MaijuR\Local Settings\Temp\44568.exe detected: Constructor.Win32.Agent.bm!IK
C:\Documents and Settings\MaijuR\Local Settings\Temp\ICD1.tmp\jinstall.exe detected: Virus.Win32.Bancos.AWF!IK
C:\Documents and Settings\MaijuR\Local Settings\Temp\rbSolnUpdateFIN.3.1.0.exe detected: Constructor.Win32.Agent.bm!IK
C:\Documents and Settings\MaijuR\Local Settings\Temporary Internet Files\Content.IE5\OVZ3IGPD\aad[1].txt detected: Trojan-Dropper.Win32.Agent.afvt!A2
C:\kill\WDM_A402\WDM\SoundMan.exe detected: Trojan-PWS.Win32.Sysrater!IK
C:\Program Files\DAEMON Tools Lite\daemon.exe detected: Virus.Win32.Agent.aj!IK
C:\Program Files\EMCO Malware Destroyer\Quarantine\MAIJU\NMC.LOGPOLE.C\Files\WINDOWS\system32.exe detected: Trojan-Spy.Finanz.J!IK
C:\Program Files\Google\Google Earth\googleearth.exe detected: Virus.Constructor.Win32.Joiner.bf!IK
C:\Program Files\InstallShield Installation Information\{9A200E68-D5F4-4E70-910F-2871753A0E2B}\Setup.exe detected: Virus.Win32.Tufik.A!IK
C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe detected: Virus.Win32.Virut.n!IK
C:\Program Files\Internet Explorer\iexplore.exe detected: Trojan-Banker.Win32.Banbra!IK
C:\Program Files\Jasc Software Inc\Paint Shop Pro 9\Paint Shop Pro 9.exe detected: Backdoor.Win32.Bifrose!IK
C:\Program Files\Java\jre1.6.0_02\bin\java.exe detected: Virus.Win32.Bancos.AWF!IK
C:\Program Files\Java\jre1.6.0_02\bin\javacpl.exe detected: Virus.Win32.Bancos.AWF!IK
C:\Program Files\Java\jre1.6.0_02\bin\javaw.exe detected: Virus.Win32.Bancos.AWF!IK
C:\Program Files\Java\jre1.6.0_02\bin\javaws.exe detected: Virus.Win32.Bancos.AWF!IK
C:\Program Files\Movie Maker\moviemk.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe detected: Virus.Win32.Virut.q!IK
C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe detected: Virus.Win32.Virut.q!IK
C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe detected: Virus.Win32.Virut.q!IK
C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe detected: Virus.Win32.Virut.q!IK
C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe detected: Virus.Win32.Virut.q!IK
C:\Program Files\NetMeeting\cb32.exe detected: Virus.Win32.Virut.n!IK
C:\Program Files\Outlook Express\msimn.exe detected: Email-Worm.Win32.Tanatos.B!IK
C:\Program Files\Outlook Express\wab.exe detected: Trojan-Dropper.Agent!IK
C:\Program Files\Outlook Express\wabmig.exe detected: Virus.Win32.Virut.q!IK
C:\Program Files\Windows Media Player\setup_wm.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\Program Files\Windows Media Player\wmplayer.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\Program Files\Windows Media Player\wmsetsdk.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\Program Files\Windows NT\hypertrm.exe detected: Virus.Win32.Virut.q!IK
C:\Program Files\Windows NT\Pinball\pinball.exe detected: Virus.Win32.Virut.n!IK
C:\Program Files\WinRAR\Uninstall.exe detected: Backdoor.Win32.PoeBot.A!IK
C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentsvr.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe detected: Trojan.Win32.Patched!IK
C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msiexec.exe detected: Virus.Win32.Virtob!IK
C:\WINDOWS\$NtServicePackUninstall$\admin.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\$NtServicePackUninstall$\agentsvr.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\$NtServicePackUninstall$\ahui.exe detected: Trojan.Win32.VB!IK
C:\WINDOWS\$NtServicePackUninstall$\alg.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\$NtServicePackUninstall$\asr_pfu.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\author.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\$NtServicePackUninstall$\blastcln.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\cfgwiz.exe detected: Virus.Win32.Virut!IK
C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
C:\WINDOWS\$NtServicePackUninstall$\comrereg.exe detected: Win32.Virut.R!IK
C:\WINDOWS\$NtServicePackUninstall$\dcomcnfg.exe detected: Win32.Virut.R!IK
C:\WINDOWS\$NtServicePackUninstall$\diantz.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\dllhost.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\dmadmin.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\explorer.exe detected: Trojan.Win32.Patched!IK
C:\WINDOWS\$NtServicePackUninstall$\fontview.exe detected: Virus.Win32.Zezal.a!IK
C:\WINDOWS\$NtServicePackUninstall$\fp98swin.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\helpctr.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\ie4uinit.exe detected: Virus.Win32.Virut!IK
C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe detected: Trojan-Banker.Win32.Banbra!IK
C:\WINDOWS\$NtServicePackUninstall$\imapi.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\ipconfig.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\locator.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\logon.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\logonui.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\magnify.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\$NtServicePackUninstall$\makecab.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\mmc.exe detected: Trojan-PWS.Win32.VB.ER!IK
C:\WINDOWS\$NtServicePackUninstall$\mnmsrvc.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\$NtServicePackUninstall$\mobsync.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\moviemk.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\WINDOWS\$NtServicePackUninstall$\mplay32.exe detected: Virus.Win32.DeadCode.b!IK
C:\WINDOWS\$NtServicePackUninstall$\mplayer2.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\$NtServicePackUninstall$\msiexec.exe detected: Virus.Win32.Virtob!IK
C:\WINDOWS\$NtServicePackUninstall$\msimn.exe detected: Email-Worm.Win32.Tanatos.B!IK
C:\WINDOWS\$NtServicePackUninstall$\mspaint.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\mtstocom.exe detected: Win32.Virut.R!IK
C:\WINDOWS\$NtServicePackUninstall$\net.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\$NtServicePackUninstall$\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK
C:\WINDOWS\$NtServicePackUninstall$\osk.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\pinball.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\$NtServicePackUninstall$\powercfg.exe detected: Virus.Win32.Socks.BA!IK
C:\WINDOWS\$NtServicePackUninstall$\progman.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
C:\WINDOWS\$NtServicePackUninstall$\rcimlby.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\rdshost.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe detected: Win32.Virtob.2!IK
C:\WINDOWS\$NtServicePackUninstall$\sessmgr.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\setup.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\shmgrate.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\shtml.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\skeys.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\smbinst.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\smi2smir.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\sndrec32.exe detected: Virus.Win32.DeadCode.b!IK
C:\WINDOWS\$NtServicePackUninstall$\spnpinst.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\ssmarque.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\ssmyst.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\svchost.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\tcptest.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\$NtServicePackUninstall$\upnpcont.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\ups.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\$NtServicePackUninstall$\vssvc.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\wab.exe detected: Trojan-Dropper.Agent!IK
C:\WINDOWS\$NtServicePackUninstall$\wabmig.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\wextract.exe detected: Constructor.Win32.Agent.bm!IK
C:\WINDOWS\$NtServicePackUninstall$\wiaacmgr.exe detected: Trojan-Spy.Win32.Banker.bkj!IK
C:\WINDOWS\$NtServicePackUninstall$\wmiadap.exe detected: Win32.Virtob.P!IK
C:\WINDOWS\$NtServicePackUninstall$\wmiapsrv.exe detected: Win32.Virtob.P!IK
C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtServicePackUninstall$\wscntfy.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtUninstallKB920213$\agentsvr.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\$NtUninstallKB922582$\fltmc.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\$NtUninstallKB938828$\explorer.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\dbupjauj.exe detected: Trojan-Downloader.Win32.Small!IK
C:\WINDOWS\explorer.exe detected: Trojan.Win32.Patched!IK
C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe detected: Virus.Constructor.Win32.Joiner.bf!IK
C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut2_407B9B5CDAC54F44A756B57CAB4E6A8B.exe detected: Virus.Constructor.Win32.Joiner.bf!IK
C:\WINDOWS\msagent\agentsvr.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK
C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}\setup_wm.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfmgr.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}\wmplayer.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe detected: Virus.Win32.VB.dl!IK
C:\WINDOWS\ServicePackFiles\i386\admin.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\ServicePackFiles\i386\agentsvr.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\ServicePackFiles\i386\ahui.exe detected: Trojan.Win32.VB!IK
C:\WINDOWS\ServicePackFiles\i386\alg.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\ServicePackFiles\i386\author.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\ServicePackFiles\i386\cfgwiz.exe detected: Virus.Win32.Virut!IK
C:\WINDOWS\ServicePackFiles\i386\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
C:\WINDOWS\ServicePackFiles\i386\dmadmin.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\explorer.exe detected: Trojan.Win32.Patched!IK
C:\WINDOWS\ServicePackFiles\i386\fontview.exe detected: Virus.Win32.Zezal.a!IK
C:\WINDOWS\ServicePackFiles\i386\fp98swin.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\fpsrvadm.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\ServicePackFiles\i386\ie4uinit.exe detected: Virus.Win32.Virut!IK
C:\WINDOWS\ServicePackFiles\i386\iexplore.exe detected: Trojan-Banker.Win32.Banbra!IK
C:\WINDOWS\ServicePackFiles\i386\ilasm.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\ServicePackFiles\i386\imapi.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\ipconfig.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\lang\imjpdct.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\ServicePackFiles\i386\lang\imjputy.exe detected: Virus.Win32.SillyW.1459!IK
C:\WINDOWS\ServicePackFiles\i386\locator.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\logon.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\logonui.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\magnify.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\ServicePackFiles\i386\migwiza.exe detected: Win32.Virtob.2!IK
C:\WINDOWS\ServicePackFiles\i386\mmc.exe detected: Trojan-PWS.Win32.VB.ER!IK
C:\WINDOWS\ServicePackFiles\i386\mnmsrvc.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\ServicePackFiles\i386\mobsync.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\moviemk.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\WINDOWS\ServicePackFiles\i386\mplay32.exe detected: Virus.Win32.DeadCode.b!IK
C:\WINDOWS\ServicePackFiles\i386\msiexec.exe detected: Virus.Win32.Virtob!IK
C:\WINDOWS\ServicePackFiles\i386\msimn.exe detected: Email-Worm.Win32.Tanatos.B!IK
C:\WINDOWS\ServicePackFiles\i386\mspaint.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\net.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\ServicePackFiles\i386\ngen.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\ServicePackFiles\i386\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK
C:\WINDOWS\ServicePackFiles\i386\osk.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\pinball.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\ServicePackFiles\i386\powercfg.exe detected: Virus.Win32.Socks.BA!IK
C:\WINDOWS\ServicePackFiles\i386\progman.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
C:\WINDOWS\ServicePackFiles\i386\rcimlby.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\rundll32.exe detected: Win32.Virtob.2!IK
C:\WINDOWS\ServicePackFiles\i386\sessmgr.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\shmgrate.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\shtml.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\sndrec32.exe detected: Virus.Win32.DeadCode.b!IK
C:\WINDOWS\ServicePackFiles\i386\ss3dfo.scr detected: Virus.Win32.Zezal.a!IK
C:\WINDOWS\ServicePackFiles\i386\ssmarque.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\ssmyst.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\tcptest.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\ServicePackFiles\i386\ups.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\ServicePackFiles\i386\vssvc.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\wab.exe detected: Trojan-Dropper.Agent!IK
C:\WINDOWS\ServicePackFiles\i386\wabmig.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\ServicePackFiles\i386\wextract.exe detected: Constructor.Win32.Agent.bm!IK
C:\WINDOWS\ServicePackFiles\i386\wiaacmgr.exe detected: Trojan-Spy.Win32.Banker.bkj!IK
C:\WINDOWS\ServicePackFiles\i386\wmiadap.exe detected: Win32.Virtob.P!IK
C:\WINDOWS\ServicePackFiles\i386\wmiapsrv.exe detected: Win32.Virtob.P!IK
C:\WINDOWS\SOUNDMAN.EXE detected: Trojan-PWS.Win32.Sysrater!IK
C:\WINDOWS\system32\ahui.exe detected: Trojan.Win32.VB!IK
C:\WINDOWS\system32\alg.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\system32\chkntfs.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\cidaemon.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\cmd.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
C:\WINDOWS\system32\convert.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\crypts.dll detected: Trojan-Spy.Finanz.J!IK
C:\WINDOWS\system32\dllcache\bckgzm.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\cb32.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\system32\dllcache\chkntfs.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\chkrzm.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\cidaemon.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\convert.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\hrtzzm.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\imjpdct.exe detected: Win32.Cadoiac.A!IK
C:\WINDOWS\system32\dllcache\imjputy.exe detected: Virus.Win32.SillyW.1459!IK
C:\WINDOWS\system32\dllcache\isignup.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\system32\dllcache\mplay32.exe detected: Virus.Win32.DeadCode.b!IK
C:\WINDOWS\system32\dllcache\rsmui.exe detected: Virus.Win32.Virut!IK
C:\WINDOWS\system32\dllcache\rsvp.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\rvsezm.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\setup_wm.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\WINDOWS\system32\dllcache\shvlzm.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\dllcache\sol.exe detected: Trojan.Win32.Agent!IK
C:\WINDOWS\system32\dllcache\twunk_32.exe detected: Trojan-Clicker.Win32.NetBuie.H!IK
C:\WINDOWS\system32\dllcache\wmplayer.exe detected: Trojan-Downloader.Win32.Banload!IK
C:\WINDOWS\system32\dmadmin.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\drivers\ndisio.sys detected: Trojan-Dropper.Win32.Tofsee!IK
C:\WINDOWS\system32\fontview.exe detected: Virus.Win32.Zezal.a!IK
C:\WINDOWS\system32\ie4uinit.exe detected: Virus.Win32.Virut!IK
C:\WINDOWS\system32\imapi.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\ipconfig.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\java.exe detected: Virus.Win32.Bancos.AWF!IK
C:\WINDOWS\system32\javaw.exe detected: Virus.Win32.Bancos.AWF!IK
C:\WINDOWS\system32\javaws.exe detected: Virus.Win32.Bancos.AWF!IK
C:\WINDOWS\system32\locator.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\logon.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\logonui.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\magnify.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\system32\mmc.exe detected: Trojan-PWS.Win32.VB.ER!IK
C:\WINDOWS\system32\mnmsrvc.exe detected: Virus.Win32.Virut.n!IK
C:\WINDOWS\system32\mobsync.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\mplay32.exe detected: Virus.Win32.DeadCode.b!IK
C:\WINDOWS\system32\msiexec.exe detected: Virus.Win32.Virtob!IK
C:\WINDOWS\system32\mspaint.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\NeroCheck.exe detected: Trojan.Win32.Patched!IK
C:\WINDOWS\system32\net.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\system32\notepad.exe detected: Virus.Win32.Hupigon.MAP!IK
C:\WINDOWS\system32\osk.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\powercfg.exe detected: Virus.Win32.Socks.BA!IK
C:\WINDOWS\system32\progman.exe detected: Trojan-Spy.Win32.Banker.ciy!IK
C:\WINDOWS\system32\rcimlby.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\rsmui.exe detected: Virus.Win32.Virut!IK
C:\WINDOWS\system32\rsvp.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\rundll32.exe detected: Win32.Virtob.2!IK
C:\WINDOWS\system32\sessmgr.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\shmgrate.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\sndrec32.exe detected: Virus.Win32.DeadCode.b!IK
C:\WINDOWS\system32\sol.exe detected: Trojan.Win32.Agent!IK
C:\WINDOWS\system32\ss3dfo.scr detected: Virus.Win32.Zezal.a!IK
C:\WINDOWS\system32\ssmarque.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\ssmyst.scr detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\ups.exe detected: Virus.Win32.Virut.ak!IK
C:\WINDOWS\system32\usmt\migwiza.exe detected: Win32.Virtob.2!IK
C:\WINDOWS\system32\vssvc.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\wbem\wmiadap.exe detected: Win32.Virtob.P!IK
C:\WINDOWS\system32\wbem\wmiapsrv.exe detected: Win32.Virtob.P!IK
C:\WINDOWS\system32\wdfmgr.exe detected: Virus.Win32.Virut.q!IK
C:\WINDOWS\system32\wextract.exe detected: Constructor.Win32.Agent.bm!IK
C:\WINDOWS\system32\wiaacmgr.exe detected: Trojan-Spy.Win32.Banker.bkj!IK
C:\WINDOWS\Temp\28FE.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\3590.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\542A.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\5606.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\920B.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\A13E.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\A32E.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\B042.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\D431.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\E9E4.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\FA11.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\FBBE.tmp detected: Backdoor.Win32.KeyStart!IK
C:\WINDOWS\Temp\VRT4D.tmp detected: Trojan-Downloader.Win32.Injecter!IK
C:\WINDOWS\twunk_32.exe detected: Trojan-Clicker.Win32.NetBuie.H!IK
Scanned
Files: 276487
Traces: 711950
Cookies: 124
Processes: 55
Found
Files: 265
Traces: 2
Cookies: 2
Processes: 7
Registry keys: 0
Scan end: 4.2.2009 14:10:01
Scan time: 2:13:54
-----
En tehnyt tuolla A2:sellakaan vielä mitään kun sen verran kriittisen
näköisiä tiedostoja sieltä löytyi, enkä niistä mitään ymmärrä.
Sakset
Junior Member
4. helmikuuta 2009 @ 17:06
Linkki tähän viestiin
Ainiin ja Avast siirsi undname.exe ja windres.exe -tiedostot system32-kansiosta "virus chestiin",
eikä niitä saa palautettua sieltä.
Hujo
Suspended permanently
4. helmikuuta 2009 @ 17:11
Linkki tähän viestiin
joo niin näyttää olevan että exe tiedostot saastuneet.
Kai sulla on Käyttöjärjestelmä cd ja tarvittavat muutkin cd
tallessa jos kone viskasee voltin takaperin kerien kierteellä.
Eikä meinaan inahdakkaan mihkään suuntaan.
En vielä ainakaan kokonaan nielase tuon a2 löytöjä
Kumpaa virustorjuntaa käytät
avastia vai avg8
Poista toinen
===============
Lataa Atribunen ATF Cleaner
Ohjeet;
Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman.Main:n alla valitse: Select All
Klikkaa Empty Selected valintaa.
Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All
Klikkaa Empty Selected valintaa.
HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
Jos käytät Operaa selaimenasi Klikkaa Opera yläpuolelta ja valitse: Select All
Klikkaa Empty Selected valintaa taas.
HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
Klikkaa Exit päävalikosta sulkeaksesi ohjelman.
Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi)
===============
Lataa Tästä Ccleaner
CCleaner v 2.14.750.- Standard Build, ÄLÄ aseenna Yahoo toolbaria!
Asennuksessa poista merkki/rasti kohdasta "asenna Yahoo! toolbar/työkalupalkki".
Asennuksen jälkeen aukaise CCleaneri .
Valitse vasemmalta pystyrivistä Options .
Valitse viereisestä pystyrivistä Settings .
Language kohtaan valitse Suomi .
Puhdistaja
Valitse vasemmalta pystyrivistä Puhdistaja .
Paina alhaalta Tutki .
Nyt CCleaneri tutkii, mitä voidaan poistaa (tempit, cookiessit jne.).
Kun tutkiminen on valmis, paina Aja CCleaner .
Nyt CCleaneri poistaa löydetyt tempit, cookiessit jne.
Rekisterin virheiden korjaus
Valitse vasemmalta pystyrivistä Rekisteri .
Paina alhaalta Etsi rekisterin virheitä .
Kun etsintä on valmis ja olet varma, että haluat korjata ne rivit jotka ovat merkattuja, niin paina Korjaa valitut rekisterin virheet .
Sinulta kysytään "haluatko varmuuskopioida muutokset rekisteriin", paina Kyllä . Tallenna varmuuskopio vaikka "Omat tiedostot " -kansioon.
Klikkaa uudesta aukeavasta ikkunasta Korjaa kaikki valitut virheet .
Saat vielä varmistus kysymyksen, paina Ok .
Kun virheet on korjattu, paina Sulje .
Nyt voit sulkea CCleanerin painamalla oikealta ylhäältä punaista rastia .
================
sammuta ja käynnistä
================
Voiko tietsikka koskaan toimia?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 4. helmikuuta 2009 @ 17:22
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > hjt & a2-lokit