Elikkäpäs. Sain alkuviikosta ilmeisesti mesestä tai torrentista viiruksen joka polveilee useita eri muotoja (svchost, joku xy touhu, winud jutut), kahtelin tarkkaan miten nuo pirulaiset saa pois rekisteristä ja sainkin ne poistettua käyttämällä esim. hijack, spy bottia, winshock xp hommia. Silti tämä perkele tulee vain takaisin, entistä vahvempana.
Jo valmiiksi, tässä on hijackin "analyysi" jos siitä on apua.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:28, on 2008-06-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
F:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
F:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
F:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
F:\Program Files\F-Secure\Common\FSMA32.EXE
F:\Program Files\F-Secure\Common\FSMB32.EXE
F:\Program Files\F-Secure\Anti-Virus\fssm32.exe
F:\Program Files\F-Secure\Common\FCH32.EXE
F:\WINDOWS\system32\nvsvc32.exe
F:\PROGRA~1\PPO\BAANA1~1.SP1\app\pppoeservice.exe
F:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
F:\Program Files\F-Secure\Common\FAMEH32.EXE
F:\Program Files\F-Secure\Common\FNRB32.EXE
F:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
F:\Program Files\F-Secure\Common\FIH32.EXE
F:\Program Files\F-Secure\Anti-Virus\fsav32.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\F-Secure\Common\FSM32.EXE
F:\Program Files\Real\RealPlayer\RealPlay.exe
F:\WINDOWS\SOUNDMAN.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\F-Secure\FSGUI\fsguiexe.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\OpenOffice.org 2.3\program\soffice.exe
F:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
F:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
F:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
F:\Program Files\Winamp\winamp.exe
F:\Program Files\Last.fm\LastFM.exe
F:\PROGRA~1\PPO\BAANA1~1.SP1\app\EnterNet.exe
F:\WINDOWS\service.exe
F:\WINDOWS\system32\rundll32.exe
F:\WINDOWS\system32\rundll32.exe
F:\WINDOWS\system32\rundll32.exe
F:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE
F:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - F:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.wcreplays.com"); (F:\Documents and Settings\JUHA NURMENNIEMI\Application Data\Mozilla\Profiles\default\l9ptuavq.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://F:\Program Files\Netscape\Netscape 6\searchplugins\SBWeb_01.src"); (F:\Documents and Settings\JUHA NURMENNIEMI\Application Data\Mozilla\Profiles\default\l9ptuavq.slt\prefs.js)
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.exe -on
O4 - HKLM\..\Run: [F-Secure Manager] "F:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "F:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [RealTray] F:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSUSBRG] F:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [EM_EXEC] F:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [BMa3c9a0d4] Rundll32.exe "F:\WINDOWS\system32\yyxyfmbl.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = F:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm595YYFI
O8 - Extra context menu item: &Winamp Search - F:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: f:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1098979086445
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c356.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zango/ie/bridge-c356.cab?6e214b1070662729071b008b35c64779a83d2eebb7c2333879d14edaa31bb60aa45a41eaabcd6422e439fba9ac96f9ce426ab7efb6f169ceb99c2a5c7e:844a4f713710b4d6fd84c831d43d35df
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} -
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - F:\Program Files\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Unknown owner - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (file missing)
O23 - Service: attrib - Unknown owner - F:\WINDOWS\attrib.exe (file missing)
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - Unknown owner - F:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - F:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - F:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - F:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - F:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - F:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - F:\PROGRA~1\PPO\BAANA1~1.SP1\app\pppoeservice.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - F:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 8719 bytes
Kiitos hänelle joka osaisi auttaa, turhauttaa että yhden viiruksen tappamiseen tarvitaan 100 ohjelmaa. :S
Viirus owns me.
Divinesia
3
794
Vastaukset
- Tantta32
bma3c9a0d4
- se on varmaa
Atk open kanssa
kuinka sen menetelmät putsaa tän koneen. - LInuxForEver
Microsoftintuotteita ei puhtaaksi saa. Voisit kokeilla vaihtaa käyttöjärjestelmää johonkin muuhun :D
Ketjusta on poistettu 0 sääntöjenvastaista viestiä.
Luetuimmat keskustelut
Mies vinkkinä sulle
Jos pyytäisit kahville tai ihan mihin vaan, niin lähtisin varmasti välittämättä muista1018053- 1075657
- 2795003
- 494943
- 763727
- 542940
- 642667
Olet oikeasti ollut
Niin tärkeä mulle ja kaikki meidän väliltä on pilattu ei yksistään sinun toiminnalla vaan minun myös.222508Kuuluu raksutus tänne asti kun mietit
Pelkäätkö että särjen sydämesi vai mikä on? En mä niin tekisi mies koskaan 😘292442- 422358