hjt-loki kunnossa?

Judetin

Tarvitsisin apua tuon lokin tulkitsemisessa että mitkä siin on virustyyppisiä prosesseja:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:08:36, on 7.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Lavasoft\aawservice.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
D:\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
D:\TimeLeft3\TimeLeft.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools] "d:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BMbbd3fcba] Rundll32.exe "C:\WINDOWS\system32\npgtqsro.dll",s
O4 - HKLM\..\Run: [b8e0cf26] rundll32.exe "C:\WINDOWS\system32\occhonbo.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Rainlendar.lnk = D:\Rainlendar\Rainlendar.exe
O4 - Startup: TimeLeft.lnk = D:\TimeLeft3\TimeLeft.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160580028207
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Lavasoft\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - D:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe

--
End of file - 5545 bytes

15

536

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • Fix.fix

      aloitetaas tuosta 22 kaliperilisellä

      Lataa VundoFix.exe
      http://www.atribune.org/ccount/click.php?id=4 työpöydällesi.

      •   Tupla-klikkaa VundoFix.exe ajaaksesi sen.
      •   Klikkaa Scan for Vundo valintaa.
      •   Kun skannaus on valmis, klikkaa Remove Vundo valintaa.
      •   Sinulta kysytään haluatko poistaa filut - klikkaa YES.
      •   Kun olet klikannut yes, työpöytäsi tyhjenee kun se alkaa poistamaan Vundoa.
      •   Kun se on valmis, fiksi ilmoittaa käynnistäväsi koneesi uudelleen, klikkaa OK.
      •   Postita C:\vundofix.txt lokin sekä tuoreen HijackThis lokin sisältö.


      Huomaa: Se on mahdollista että VundoFix löysi tiedoston jota se ei pystynyt poistamaan.
      Tässä tilanteessa, VundoFix ajaa itsensä rebootissa, seuraa vain yläpuolelle olevia ohjeita alkaen kohdasta "Klikkaa Scan for Vundo valintaa." kun VundoFix ilmaantuu uudelleenkäynnistyksen yhteydessä.

      • Judetin

        poistaahan tuo vundo vain nuo haitalliset eikä muuta?


      • Fix.fix
        Judetin kirjoitti:

        poistaahan tuo vundo vain nuo haitalliset eikä muuta?

        on vasta alussa.


      • Judetin
        Fix.fix kirjoitti:

        on vasta alussa.

        was found. eli ei löytänyt mitään toi vundofix, mitäs seuraavaksi?


      • Judetin
        Fix.fix kirjoitti:

        on vasta alussa.

        Mitähän pitäisi seuraavaksi tehdä kun ei toi vundofix löytänyt mitään, mutta kone on silti jumissa? Auttakaa kiitos :)


      • FixFix
        Judetin kirjoitti:

        Mitähän pitäisi seuraavaksi tehdä kun ei toi vundofix löytänyt mitään, mutta kone on silti jumissa? Auttakaa kiitos :)

        Nyt tulee

        1.Lataa combofix.exe työpöydällesi yhdestä, kahdesta klinkistä:
        http://download.bleepingcomputer.com/sUBs/ComboFix.exe
        http://subs.geekstogo.com/ComboFix.exe

        2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
        3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
        Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.


      • Judetin
        FixFix kirjoitti:

        Nyt tulee

        1.Lataa combofix.exe työpöydällesi yhdestä, kahdesta klinkistä:
        http://download.bleepingcomputer.com/sUBs/ComboFix.exe
        http://subs.geekstogo.com/ComboFix.exe

        2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
        3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
        Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.

        Elikkäs ajoin tuon combofixin ja seuraavanlainen loki tuli:

        ComboFix 08-06-06.6 - Salosten kone 2008-06-07 20:33:18.1 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.606 [GMT 3:00]
        Running from: C:\Documents and Settings\Salosten kone\Työpöytä\ComboFix.exe
        * Created a new restore point

        [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
        .

        (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\WINDOWS\BMbbd3fcba.xml
        C:\WINDOWS\cookies.ini
        C:\WINDOWS\pskt.ini
        C:\WINDOWS\system32\cffyhphi.ini
        C:\WINDOWS\system32\dghtawsj.ini
        C:\WINDOWS\system32\dwwfkgyi.dll
        C:\WINDOWS\system32\gmjbxinf.ini
        C:\WINDOWS\system32\jkkICsqp.dll
        C:\WINDOWS\system32\ltcsboul.ini
        C:\WINDOWS\system32\mcrh.tmp
        C:\WINDOWS\system32\nduagcnx.dll
        C:\WINDOWS\system32\npgtqsro.dll
        C:\WINDOWS\system32\nwocdafi.dll
        C:\WINDOWS\system32\obnohcco.ini
        C:\WINDOWS\system32\occhonbo.dll
        C:\WINDOWS\system32\pqsCIkkj.ini
        C:\WINDOWS\system32\pqsCIkkj.ini2
        C:\WINDOWS\system32\qgiinabe.dll
        C:\WINDOWS\system32\rwxxxnld.dll
        C:\WINDOWS\system32\tsgcmial.dll
        C:\WINDOWS\system32\tuvUOHwu.dll
        C:\WINDOWS\system32\twhwjknw.ini
        C:\WINDOWS\system32\wabygbww.dll
        C:\WINDOWS\system32\vhrxqsdm.dll
        C:\WINDOWS\system32\wwbgybaw.ini
        C:\WINDOWS\system32\wvUOFyyX.dll

        .
        ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-07 to 2008-06-07 )))))))))))))))))
        .

        2008-06-07 17:51 . 2008-06-07 17:51      d--------   C:\VundoFix Backups
        2008-06-06 15:29 . 2008-02-22 02:33   69,632   --a------   C:\WINDOWS\system32\javacpl.cpl
        2008-06-03 00:21 . 2008-06-06 15:47      d--------   C:\Documents and Settings\All Users\Application Data\WLInstaller
        2008-06-02 15:56 . 2008-06-02 15:56      d--------   C:\Program Files\Trend Micro
        2008-06-01 10:58 . 2008-06-07 20:37   54,156   --ah-----   C:\WINDOWS\QTFont.qfn
        2008-06-01 10:58 . 2008-06-01 10:58   1,409   --a------   C:\WINDOWS\QTFont.for
        2008-05-10 20:17 . 2008-05-10 20:17      d--------   C:\Program Files\EA Sports

        .
        (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-06-07 17:36   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\Skype
        2008-06-06 12:29   ---------   d-----w   C:\Program Files\Java
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\ZoomBrowser EX
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\ZoomBrowser
        2008-05-21 10:21   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\uTorrent
        2008-05-10 11:47   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
        2008-05-01 23:39   ---------   d-----w   C:\Program Files\Pro Evolution Soccer 2008
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iTunes
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iPod
        2008-04-07 17:38   ---------   d-----w   C:\Program Files\QuickTime
        2008-04-02 15:10   22,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\PnkBstrK.sys
        2006-12-19 17:38   20,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\GDIPFONTCACHEV1.DAT
        .

        (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        REGEDIT4
        *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 02:12 15360]
        "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 11:12 139264]
        "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SoundMan"="SOUNDMAN.EXE" [2004-07-27 17:01 68096 C:\WINDOWS\SOUNDMAN.EXE]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
        "nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
        "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-20 12:21 262401]
        "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
        "DAEMON Tools"="d:\DAEMON Tools\daemon.exe" [2006-09-14 23:09 157592]
        "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
        "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-15 02:12 15360]
        "Nokia.PCSync"="D:\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
        C:\Program Files\MSN Messenger\msnmsgr.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
        --a------ 2007-03-23 13:20 227328 D:\Nokia\Nokia PC Suite 6\LaunchApplication.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
        --a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusDisableNotify"=dword:00000001
        "UpdatesDisableNotify"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "D:\\mIRC\\mirc.exe"=
        "D:\\Flatout2\\alkupFlatOut2.exe"=
        "D:\\Flatout2\\FlatOut2.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=
        "D:\\8ballclub\\8BallClub\\GameDirector.exe"=
        "C:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe"=
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"=

        R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 17:31]
        R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 20:36]

        .
        'Ajoitetut teht„v„t'-kansion sis„lt”
        "2008-01-26 07:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
        .
        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-06-07 20:38:11
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        ------------------------ Other Running Processes ------------------------
        .
        C:\WINDOWS\system32\rundll32.exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\Lavasoft\aawservice.exe
        D:\TimeLeft3\TimeLeft.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wscntfy.exe
        .
        **************************************************************************
        .
        Completion time: 2008-06-07 20:41:29 - machine was rebooted
        ComboFix-quarantined-files.txt 2008-06-07 17:41:26

        Pre-Run: 13,274,230,784 tavua vapaana
        Post-Run: 31,481,053,184 tavua vapaana

        144   --- E O F ---   2008-05-16 14:49:02



        Mitäs seuraavaksi? Kone jo näyttäisi toimivan paljon paremmin :) Onko vielä jotain mitä pitäisi tehdä?


      • FixFix
        Judetin kirjoitti:

        Elikkäs ajoin tuon combofixin ja seuraavanlainen loki tuli:

        ComboFix 08-06-06.6 - Salosten kone 2008-06-07 20:33:18.1 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.606 [GMT 3:00]
        Running from: C:\Documents and Settings\Salosten kone\Työpöytä\ComboFix.exe
        * Created a new restore point

        [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
        .

        (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\WINDOWS\BMbbd3fcba.xml
        C:\WINDOWS\cookies.ini
        C:\WINDOWS\pskt.ini
        C:\WINDOWS\system32\cffyhphi.ini
        C:\WINDOWS\system32\dghtawsj.ini
        C:\WINDOWS\system32\dwwfkgyi.dll
        C:\WINDOWS\system32\gmjbxinf.ini
        C:\WINDOWS\system32\jkkICsqp.dll
        C:\WINDOWS\system32\ltcsboul.ini
        C:\WINDOWS\system32\mcrh.tmp
        C:\WINDOWS\system32\nduagcnx.dll
        C:\WINDOWS\system32\npgtqsro.dll
        C:\WINDOWS\system32\nwocdafi.dll
        C:\WINDOWS\system32\obnohcco.ini
        C:\WINDOWS\system32\occhonbo.dll
        C:\WINDOWS\system32\pqsCIkkj.ini
        C:\WINDOWS\system32\pqsCIkkj.ini2
        C:\WINDOWS\system32\qgiinabe.dll
        C:\WINDOWS\system32\rwxxxnld.dll
        C:\WINDOWS\system32\tsgcmial.dll
        C:\WINDOWS\system32\tuvUOHwu.dll
        C:\WINDOWS\system32\twhwjknw.ini
        C:\WINDOWS\system32\wabygbww.dll
        C:\WINDOWS\system32\vhrxqsdm.dll
        C:\WINDOWS\system32\wwbgybaw.ini
        C:\WINDOWS\system32\wvUOFyyX.dll

        .
        ((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-05-07 to 2008-06-07 )))))))))))))))))
        .

        2008-06-07 17:51 . 2008-06-07 17:51      d--------   C:\VundoFix Backups
        2008-06-06 15:29 . 2008-02-22 02:33   69,632   --a------   C:\WINDOWS\system32\javacpl.cpl
        2008-06-03 00:21 . 2008-06-06 15:47      d--------   C:\Documents and Settings\All Users\Application Data\WLInstaller
        2008-06-02 15:56 . 2008-06-02 15:56      d--------   C:\Program Files\Trend Micro
        2008-06-01 10:58 . 2008-06-07 20:37   54,156   --ah-----   C:\WINDOWS\QTFont.qfn
        2008-06-01 10:58 . 2008-06-01 10:58   1,409   --a------   C:\WINDOWS\QTFont.for
        2008-05-10 20:17 . 2008-05-10 20:17      d--------   C:\Program Files\EA Sports

        .
        (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-06-07 17:36   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\Skype
        2008-06-06 12:29   ---------   d-----w   C:\Program Files\Java
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\ZoomBrowser EX
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\ZoomBrowser
        2008-05-21 10:21   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\uTorrent
        2008-05-10 11:47   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
        2008-05-01 23:39   ---------   d-----w   C:\Program Files\Pro Evolution Soccer 2008
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iTunes
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iPod
        2008-04-07 17:38   ---------   d-----w   C:\Program Files\QuickTime
        2008-04-02 15:10   22,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\PnkBstrK.sys
        2006-12-19 17:38   20,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\GDIPFONTCACHEV1.DAT
        .

        (((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        REGEDIT4
        *Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 02:12 15360]
        "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 11:12 139264]
        "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SoundMan"="SOUNDMAN.EXE" [2004-07-27 17:01 68096 C:\WINDOWS\SOUNDMAN.EXE]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
        "nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
        "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-20 12:21 262401]
        "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
        "DAEMON Tools"="d:\DAEMON Tools\daemon.exe" [2006-09-14 23:09 157592]
        "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
        "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-15 02:12 15360]
        "Nokia.PCSync"="D:\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
        C:\Program Files\MSN Messenger\msnmsgr.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
        --a------ 2007-03-23 13:20 227328 D:\Nokia\Nokia PC Suite 6\LaunchApplication.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
        --a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusDisableNotify"=dword:00000001
        "UpdatesDisableNotify"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "D:\\mIRC\\mirc.exe"=
        "D:\\Flatout2\\alkupFlatOut2.exe"=
        "D:\\Flatout2\\FlatOut2.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=
        "D:\\8ballclub\\8BallClub\\GameDirector.exe"=
        "C:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe"=
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"=

        R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 17:31]
        R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 20:36]

        .
        'Ajoitetut teht„v„t'-kansion sis„lt”
        "2008-01-26 07:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
        .
        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-06-07 20:38:11
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        ------------------------ Other Running Processes ------------------------
        .
        C:\WINDOWS\system32\rundll32.exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\Lavasoft\aawservice.exe
        D:\TimeLeft3\TimeLeft.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wscntfy.exe
        .
        **************************************************************************
        .
        Completion time: 2008-06-07 20:41:29 - machine was rebooted
        ComboFix-quarantined-files.txt 2008-06-07 17:41:26

        Pre-Run: 13,274,230,784 tavua vapaana
        Post-Run: 31,481,053,184 tavua vapaana

        144   --- E O F ---   2008-05-16 14:49:02



        Mitäs seuraavaksi? Kone jo näyttäisi toimivan paljon paremmin :) Onko vielä jotain mitä pitäisi tehdä?

        pääset liian helpolla ;D

        scannaa hjt:n loki uusi


      • Judetin
        FixFix kirjoitti:

        pääset liian helpolla ;D

        scannaa hjt:n loki uusi

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 20:57:32, on 7.6.2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
        D:\DAEMON Tools\daemon.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\Lavasoft\aawservice.exe
        D:\TimeLeft3\TimeLeft.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "d:\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Rainlendar.lnk = D:\Rainlendar\Rainlendar.exe
        O4 - Startup: TimeLeft.lnk = D:\TimeLeft3\TimeLeft.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160580028207
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Lavasoft\aawservice.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
        O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NBService - Nero AG - D:\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
        O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe

        --
        End of file - 6087 bytes


        Siinä olis hijackthis loki vielä, entäpä seuraavaksi? :D


      • FixFix
        Judetin kirjoitti:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 20:57:32, on 7.6.2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
        D:\DAEMON Tools\daemon.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\Lavasoft\aawservice.exe
        D:\TimeLeft3\TimeLeft.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "d:\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Rainlendar.lnk = D:\Rainlendar\Rainlendar.exe
        O4 - Startup: TimeLeft.lnk = D:\TimeLeft3\TimeLeft.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160580028207
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Lavasoft\aawservice.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
        O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NBService - Nero AG - D:\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
        O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe

        --
        End of file - 6087 bytes


        Siinä olis hijackthis loki vielä, entäpä seuraavaksi? :D

        huolen

        sammuta ja käynnistä

        scannaa ensin combofix loki
        sitten hjt:n loki uusi

        ja viimisenä alla oleva

        Lataa Malwarebytes' Anti-Malware työpöydällesi.
        http://www.besttechie.net/tools/mbam-setup.exe
        •   Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman.
        •   Lopuksi varmistu, että seuraavat on valittu: Update Malwarebytes' Anti-Malware ja Launch Malwarebytes' Anti-Malware ja sen jälkeen klikkaa Finish.
        •   Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version.
        •   Kun ohjelma on latautunut, valitse Perform full scan ja klikkaa Scan.
        •   Kun skanni on valmis, klikkaa OK ja sitten Show Results nähdäksesi tulokset.
        •   Varmistu, että kaikki on merkitty ja klikkaa Remove Selected.
        •   Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt
        •   Lähetä lokin sisältö seuraavassa viestissäsi.


      • Judetin
        FixFix kirjoitti:

        huolen

        sammuta ja käynnistä

        scannaa ensin combofix loki
        sitten hjt:n loki uusi

        ja viimisenä alla oleva

        Lataa Malwarebytes' Anti-Malware työpöydällesi.
        http://www.besttechie.net/tools/mbam-setup.exe
        •   Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman.
        •   Lopuksi varmistu, että seuraavat on valittu: Update Malwarebytes' Anti-Malware ja Launch Malwarebytes' Anti-Malware ja sen jälkeen klikkaa Finish.
        •   Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version.
        •   Kun ohjelma on latautunut, valitse Perform full scan ja klikkaa Scan.
        •   Kun skanni on valmis, klikkaa OK ja sitten Show Results nähdäksesi tulokset.
        •   Varmistu, että kaikki on merkitty ja klikkaa Remove Selected.
        •   Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt
        •   Lähetä lokin sisältö seuraavassa viestissäsi.

        ComboFix 08-06-06.6 - Salosten kone 2008-06-07 22:25:34.3 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.636 [GMT 3:00]
        Running from: C:\Documents and Settings\Salosten kone\Työpöytä\ComboFix.exe

        [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
        .

        ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-07 to 2008-06-07 )))))))))))))))))
        .

        2008-06-07 21:05 . 2008-06-07 21:11      d--------   C:\Program Files\Windows Live
        2008-06-07 21:05 . 2008-06-07 21:11      d--hsc---   C:\Program Files\Common Files\WindowsLiveInstaller
        2008-06-07 17:51 . 2008-06-07 17:51      d--------   C:\VundoFix Backups
        2008-06-06 15:29 . 2008-02-22 02:33   69,632   --a------   C:\WINDOWS\system32\javacpl.cpl
        2008-06-03 00:21 . 2008-06-07 21:04      d--------   C:\Documents and Settings\All Users\Application Data\WLInstaller
        2008-06-02 15:56 . 2008-06-02 15:56      d--------   C:\Program Files\Trend Micro
        2008-06-01 10:58 . 2008-06-07 22:24   54,156   --ah-----   C:\WINDOWS\QTFont.qfn
        2008-06-01 10:58 . 2008-06-01 10:58   1,409   --a------   C:\WINDOWS\QTFont.for
        2008-05-10 20:17 . 2008-05-10 20:17      d--------   C:\Program Files\EA Sports

        .
        (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-06-07 17:36   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\Skype
        2008-06-06 12:29   ---------   d-----w   C:\Program Files\Java
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\ZoomBrowser EX
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\ZoomBrowser
        2008-05-21 10:21   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\uTorrent
        2008-05-10 11:47   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
        2008-05-01 23:39   ---------   d-----w   C:\Program Files\Pro Evolution Soccer 2008
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iTunes
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iPod
        2008-04-07 17:38   ---------   d-----w   C:\Program Files\QuickTime
        2008-04-02 15:10   22,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\PnkBstrK.sys
        2008-04-02 15:10   107,888   ----a-w   C:\WINDOWS\system32\CmdLineExt.dll
        2008-03-25 04:51   621,344   ----a-w   C:\WINDOWS\system32\mswstr10.dll
        2008-03-25 04:51   166,688   ----a-w   C:\WINDOWS\system32\msjint40.dll
        2008-03-20 08:09   1,845,504   ----a-w   C:\WINDOWS\system32\win32k.sys
        2006-12-19 17:38   20,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\GDIPFONTCACHEV1.DAT
        .

        ((((((((((((((((((((((((((((( snapshot@2008-06-07_20.41.16.17 )))))))))))))))))))))))))))))))))))))))))
        .
        - 2008-06-07 17:37:29   2,048   --s-a-w   C:\WINDOWS\bootstat.dat
        2008-06-07 19:24:14   2,048   --s-a-w   C:\WINDOWS\bootstat.dat
        2008-06-07 18:11:16   29,926   ----a-r   C:\WINDOWS\Installer\{A9174A72-1B46-445B-B3CF-90ED2C63D83B}\MsblIco.Exe
        - 2008-06-07 13:57:58   63,664   ----a-w   C:\WINDOWS\system32\perfc009.dat
        2008-06-07 17:42:00   63,664   ----a-w   C:\WINDOWS\system32\perfc009.dat
        - 2008-06-07 13:57:58   77,646   ----a-w   C:\WINDOWS\system32\perfc00B.dat
        2008-06-07 17:42:00   77,646   ----a-w   C:\WINDOWS\system32\perfc00B.dat
        - 2008-06-07 13:57:58   406,464   ----a-w   C:\WINDOWS\system32\perfh009.dat
        2008-06-07 17:42:00   406,464   ----a-w   C:\WINDOWS\system32\perfh009.dat
        - 2008-06-07 13:57:58   381,580   ----a-w   C:\WINDOWS\system32\perfh00B.dat
        2008-06-07 17:42:00   381,580   ----a-w   C:\WINDOWS\system32\perfh00B.dat
        2007-10-18 08:31:46   51,224   ----a-w   C:\WINDOWS\system32\sirenacm.dll
        2006-06-05 11:14:28   479,232   ----a-w   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
        2006-06-05 11:14:28   548,864   ----a-w   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
        2006-06-05 11:14:28   626,688   ----a-w   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
        .
        (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        REGEDIT4
        *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 02:12 15360]
        "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 11:12 139264]
        "msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SoundMan"="SOUNDMAN.EXE" [2004-07-27 17:01 68096 C:\WINDOWS\SOUNDMAN.EXE]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
        "nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
        "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-20 12:21 262401]
        "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
        "DAEMON Tools"="d:\DAEMON Tools\daemon.exe" [2006-09-14 23:09 157592]
        "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
        "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-15 02:12 15360]
        "Nokia.PCSync"="D:\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

        C:\Documents and Settings\Salosten kone\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
        Rainlendar.lnk - D:\Rainlendar\Rainlendar.exe [2006-01-21 15:31:46 118784]
        TimeLeft.lnk - D:\TimeLeft3\TimeLeft.exe [2008-03-18 18:26:19 2045616]

        C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
        Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 12:01:04 83360]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
        C:\Program Files\MSN Messenger\msnmsgr.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
        --a------ 2007-03-23 13:20 227328 D:\Nokia\Nokia PC Suite 6\LaunchApplication.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
        --a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusDisableNotify"=dword:00000001
        "UpdatesDisableNotify"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "D:\\mIRC\\mirc.exe"=
        "D:\\Flatout2\\alkupFlatOut2.exe"=
        "D:\\Flatout2\\FlatOut2.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=
        "D:\\8ballclub\\8BallClub\\GameDirector.exe"=
        "C:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe"=
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

        R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 17:31]
        R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 20:36]

        *Newly Created Service* - CATCHME
        .
        'Ajoitetut tehtävät'-kansion sisältö
        "2008-01-26 07:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
        .
        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-06-07 22:27:58
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        Completion time: 2008-06-07 22:29:19
        ComboFix-quarantined-files.txt 2008-06-07 19:28:39
        ComboFix2.txt 2008-06-07 19:18:21
        ComboFix3.txt 2008-06-07 17:41:30

        Pre-Run: 31,324,786,688 tavua vapaana
        Post-Run: 31,312,408,576 tavua vapaana

        131   --- E O F ---   2008-05-16 14:49:02

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 22:31:40, on 7.6.2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
        D:\DAEMON Tools\daemon.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\TimeLeft3\TimeLeft.exe
        D:\Lavasoft\aawservice.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "d:\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Rainlendar.lnk = D:\Rainlendar\Rainlendar.exe
        O4 - Startup: TimeLeft.lnk = D:\TimeLeft3\TimeLeft.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160580028207
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Lavasoft\aawservice.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
        O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NBService - Nero AG - D:\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
        O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe

        --
        End of file - 6190 bytes





        Malwarebytes' Anti-Malware 1.15
        Tietokantaversio: 838

        23:06:51 7.6.2008
        mbam-log-6-7-2008 (23-06-51).txt

        Tarkistustyyppi: Täysi tarkistus (C:\|D:\|)
        Tarkistetut kohteet: 88004
        Kulunut aika: 23 minute(s), 57 second(s)

        Saastuneita muistiprosesseja: 0
        Saastuneita muistimoduuleja: 0
        Saastuneita rekisteriavaimia: 3
        Saastuneita rekisteriarvoja: 0
        Saastuneita rekisterikohteita: 0
        Saastuneita hakemistoja: 0
        Saastuneita tiedostoja: 9

        Saastuneita muistiprosesseja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita muistimoduuleja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita rekisteriavaimia:
        HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

        Saastuneita rekisteriarvoja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita rekisterikohteita:
        (Haitallisia kohteita ei löydetty)

        Saastuneita hakemistoja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita tiedostoja:
        C:\QooBox\Quarantine\C\WINDOWS\system32\jkkICsqp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\QooBox\Quarantine\C\WINDOWS\system32\wabygbww.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP418\A0040486.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP418\A0040603.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP420\A0040858.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP426\A0041294.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP428\A0041340.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP428\A0041349.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

        Vieläkö muuta :D ?


      • FixFix
        Judetin kirjoitti:

        ComboFix 08-06-06.6 - Salosten kone 2008-06-07 22:25:34.3 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.636 [GMT 3:00]
        Running from: C:\Documents and Settings\Salosten kone\Työpöytä\ComboFix.exe

        [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
        .

        ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-07 to 2008-06-07 )))))))))))))))))
        .

        2008-06-07 21:05 . 2008-06-07 21:11      d--------   C:\Program Files\Windows Live
        2008-06-07 21:05 . 2008-06-07 21:11      d--hsc---   C:\Program Files\Common Files\WindowsLiveInstaller
        2008-06-07 17:51 . 2008-06-07 17:51      d--------   C:\VundoFix Backups
        2008-06-06 15:29 . 2008-02-22 02:33   69,632   --a------   C:\WINDOWS\system32\javacpl.cpl
        2008-06-03 00:21 . 2008-06-07 21:04      d--------   C:\Documents and Settings\All Users\Application Data\WLInstaller
        2008-06-02 15:56 . 2008-06-02 15:56      d--------   C:\Program Files\Trend Micro
        2008-06-01 10:58 . 2008-06-07 22:24   54,156   --ah-----   C:\WINDOWS\QTFont.qfn
        2008-06-01 10:58 . 2008-06-01 10:58   1,409   --a------   C:\WINDOWS\QTFont.for
        2008-05-10 20:17 . 2008-05-10 20:17      d--------   C:\Program Files\EA Sports

        .
        (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-06-07 17:36   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\Skype
        2008-06-06 12:29   ---------   d-----w   C:\Program Files\Java
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\ZoomBrowser EX
        2008-05-29 20:58   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\ZoomBrowser
        2008-05-21 10:21   ---------   d-----w   C:\Documents and Settings\Salosten kone\Application Data\uTorrent
        2008-05-10 11:47   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
        2008-05-01 23:39   ---------   d-----w   C:\Program Files\Pro Evolution Soccer 2008
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iTunes
        2008-04-07 17:40   ---------   d-----w   C:\Program Files\iPod
        2008-04-07 17:38   ---------   d-----w   C:\Program Files\QuickTime
        2008-04-02 15:10   22,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\PnkBstrK.sys
        2008-04-02 15:10   107,888   ----a-w   C:\WINDOWS\system32\CmdLineExt.dll
        2008-03-25 04:51   621,344   ----a-w   C:\WINDOWS\system32\mswstr10.dll
        2008-03-25 04:51   166,688   ----a-w   C:\WINDOWS\system32\msjint40.dll
        2008-03-20 08:09   1,845,504   ----a-w   C:\WINDOWS\system32\win32k.sys
        2006-12-19 17:38   20,328   ----a-w   C:\Documents and Settings\Salosten kone\Application Data\GDIPFONTCACHEV1.DAT
        .

        ((((((((((((((((((((((((((((( snapshot@2008-06-07_20.41.16.17 )))))))))))))))))))))))))))))))))))))))))
        .
        - 2008-06-07 17:37:29   2,048   --s-a-w   C:\WINDOWS\bootstat.dat
        2008-06-07 19:24:14   2,048   --s-a-w   C:\WINDOWS\bootstat.dat
        2008-06-07 18:11:16   29,926   ----a-r   C:\WINDOWS\Installer\{A9174A72-1B46-445B-B3CF-90ED2C63D83B}\MsblIco.Exe
        - 2008-06-07 13:57:58   63,664   ----a-w   C:\WINDOWS\system32\perfc009.dat
        2008-06-07 17:42:00   63,664   ----a-w   C:\WINDOWS\system32\perfc009.dat
        - 2008-06-07 13:57:58   77,646   ----a-w   C:\WINDOWS\system32\perfc00B.dat
        2008-06-07 17:42:00   77,646   ----a-w   C:\WINDOWS\system32\perfc00B.dat
        - 2008-06-07 13:57:58   406,464   ----a-w   C:\WINDOWS\system32\perfh009.dat
        2008-06-07 17:42:00   406,464   ----a-w   C:\WINDOWS\system32\perfh009.dat
        - 2008-06-07 13:57:58   381,580   ----a-w   C:\WINDOWS\system32\perfh00B.dat
        2008-06-07 17:42:00   381,580   ----a-w   C:\WINDOWS\system32\perfh00B.dat
        2007-10-18 08:31:46   51,224   ----a-w   C:\WINDOWS\system32\sirenacm.dll
        2006-06-05 11:14:28   479,232   ----a-w   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
        2006-06-05 11:14:28   548,864   ----a-w   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
        2006-06-05 11:14:28   626,688   ----a-w   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
        .
        (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        REGEDIT4
        *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 02:12 15360]
        "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 11:12 139264]
        "msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SoundMan"="SOUNDMAN.EXE" [2004-07-27 17:01 68096 C:\WINDOWS\SOUNDMAN.EXE]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
        "nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
        "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-20 12:21 262401]
        "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
        "DAEMON Tools"="d:\DAEMON Tools\daemon.exe" [2006-09-14 23:09 157592]
        "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
        "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-15 02:12 15360]
        "Nokia.PCSync"="D:\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

        C:\Documents and Settings\Salosten kone\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
        Rainlendar.lnk - D:\Rainlendar\Rainlendar.exe [2006-01-21 15:31:46 118784]
        TimeLeft.lnk - D:\TimeLeft3\TimeLeft.exe [2008-03-18 18:26:19 2045616]

        C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
        Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 12:01:04 83360]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
        C:\Program Files\MSN Messenger\msnmsgr.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
        --a------ 2007-03-23 13:20 227328 D:\Nokia\Nokia PC Suite 6\LaunchApplication.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
        --a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusDisableNotify"=dword:00000001
        "UpdatesDisableNotify"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "D:\\mIRC\\mirc.exe"=
        "D:\\Flatout2\\alkupFlatOut2.exe"=
        "D:\\Flatout2\\FlatOut2.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
        "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=
        "D:\\8ballclub\\8BallClub\\GameDirector.exe"=
        "C:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe"=
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

        R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 17:31]
        R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 20:36]

        *Newly Created Service* - CATCHME
        .
        'Ajoitetut tehtävät'-kansion sisältö
        "2008-01-26 07:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
        .
        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-06-07 22:27:58
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        Completion time: 2008-06-07 22:29:19
        ComboFix-quarantined-files.txt 2008-06-07 19:28:39
        ComboFix2.txt 2008-06-07 19:18:21
        ComboFix3.txt 2008-06-07 17:41:30

        Pre-Run: 31,324,786,688 tavua vapaana
        Post-Run: 31,312,408,576 tavua vapaana

        131   --- E O F ---   2008-05-16 14:49:02

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 22:31:40, on 7.6.2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
        D:\DAEMON Tools\daemon.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\TimeLeft3\TimeLeft.exe
        D:\Lavasoft\aawservice.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "d:\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Rainlendar.lnk = D:\Rainlendar\Rainlendar.exe
        O4 - Startup: TimeLeft.lnk = D:\TimeLeft3\TimeLeft.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160580028207
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Lavasoft\aawservice.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
        O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NBService - Nero AG - D:\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
        O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe

        --
        End of file - 6190 bytes





        Malwarebytes' Anti-Malware 1.15
        Tietokantaversio: 838

        23:06:51 7.6.2008
        mbam-log-6-7-2008 (23-06-51).txt

        Tarkistustyyppi: Täysi tarkistus (C:\|D:\|)
        Tarkistetut kohteet: 88004
        Kulunut aika: 23 minute(s), 57 second(s)

        Saastuneita muistiprosesseja: 0
        Saastuneita muistimoduuleja: 0
        Saastuneita rekisteriavaimia: 3
        Saastuneita rekisteriarvoja: 0
        Saastuneita rekisterikohteita: 0
        Saastuneita hakemistoja: 0
        Saastuneita tiedostoja: 9

        Saastuneita muistiprosesseja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita muistimoduuleja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita rekisteriavaimia:
        HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

        Saastuneita rekisteriarvoja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita rekisterikohteita:
        (Haitallisia kohteita ei löydetty)

        Saastuneita hakemistoja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita tiedostoja:
        C:\QooBox\Quarantine\C\WINDOWS\system32\jkkICsqp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\QooBox\Quarantine\C\WINDOWS\system32\wabygbww.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP418\A0040486.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP418\A0040603.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP420\A0040858.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP426\A0041294.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP428\A0041340.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9E54A1EF-40B9-4537-8183-236EED6E093B}\RP428\A0041349.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

        Vieläkö muuta :D ?

        alkuun on päästy

        1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
        2. Valitse ominaisuudet
        3. Valitse järjestelmän palauttaminen välilehti
        4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
        5. Paina Käytä
        6. Paina ok
        7. Sammuta ja käynnistä
        8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
        9. Käytä ja OK


      • Judetin
        FixFix kirjoitti:

        alkuun on päästy

        1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
        2. Valitse ominaisuudet
        3. Valitse järjestelmän palauttaminen välilehti
        4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
        5. Paina Käytä
        6. Paina ok
        7. Sammuta ja käynnistä
        8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
        9. Käytä ja OK

        sitten? Onko vielä jotain mitä tehdä ;D


      • FixFix
        Judetin kirjoitti:

        sitten? Onko vielä jotain mitä tehdä ;D

        se oli siinä sitten

        Mites kone toimii


      • Judetin
        FixFix kirjoitti:

        se oli siinä sitten

        Mites kone toimii

        Vai että siinä oli, no hienoa. Tulipahan tehtyä, kone pyöriii mainiosti taas. Näkee selvästi että jotain todella tapahtui. Oli kone sen verran jumissa että...on noi ikäviä tollaset, mutta eiköhän tää tästä. Kiitos todella paljon avusta! Tiedän seuraavaksi kenen puoleen käänytä jos ongelmia vielä ilimenee.

        Kiitos!


    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. Kotkalainen Demari Riku Pirinen vangittu Saksassa lapsipornosta

      https://www.kymensanomat.fi/paikalliset/8081054 Kotkalainen Demari Riku Pirinen vangittu Saksassa lapsipornon hallussapi
      Kotka
      123
      3134
    2. Vanhalle ukon rähjälle

      Satutit mua niin paljon kun erottiin. Oletko todella niin itsekäs että kuvittelet että huolisin sut kaiken tapahtuneen
      Ikävä
      37
      2496
    3. Olen tosi outo....

      Päättelen palstajuttujen perusteella mitä mieltä minun kaipauksen kohde minusta on. Joskus kuvittelen tänne selkeitä tap
      Ikävä
      30
      2435
    4. Maisa on SALAKUVATTU huumepoliisinsa kanssa!

      https://www.seiska.fi/vain-seiskassa/ensimmainen-yhteiskuva-maisa-torpan-ja-poliisikullan-lahiorakkaus-roihuaa/1525663
      Kotimaiset julkkisjuorut
      111
      2159
    5. Oletko sä luovuttanut

      Mun suhteeni
      Ikävä
      114
      1700
    6. Hommaatko kinkkua jouluksi?

      Itse tein pakastimeen n. 3Kg:n murekkeen sienillä ja juustokuorrutuksella. Voihan se olla, että jonkun pienen, valmiin k
      Sinkut
      172
      1406
    7. Nurmossa kuoli 2 Lasta..

      Autokolarissa. Näin kertovat iltapäivälehdet juuri nyt. 22.11. Ja aina ennen Joulua näitä tulee. . .
      Seinäjoki
      26
      1345
    8. Aatteleppa ite!

      Jos ei oltaisikaan nyt NATOssa, olisimme puolueettomana sivustakatsojia ja elelisimme tyytyväisenä rauhassa maassamme.
      Maailman menoa
      291
      1239
    9. Mikko Koivu yrittää pestä mustan valkoiseksi

      Ilmeisesti huomannut, että Helenan tukijoukot kasvaa kasvamistaan. Riistakamera paljasti hiljattain kylmän totuuden Mi
      Kotimaiset julkkisjuorut
      279
      1231
    10. Onko se ikä

      Alkanut haitata?
      Ikävä
      62
      1077
    Aihe