ad-monitor kettuilee hijackthisille

Discussion in 'Virukset ja haittaohjelmat' started by joujouman, Sep 6, 2005.

  1. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    eli yritän poistaa hijackthisillä kaikenmoisia juttuja, mutta ad-monitor estää ne muutokset. eli tietääkö joku kuinka ne saisi sallittua?
     
  2. age007ti

    age007ti Guest

    mikä ohjelma on tuo ad-monitor, mistä olet asentanut sen

    mikä käyttis
    onko systeemin palautuspiste päällä
     
  3. Skedeejä

    Skedeejä Regular member

    Joined:
    Jul 26, 2004
    Messages:
    422
    Likes Received:
    0
    Trophy Points:
    26
    Tuo Ad-Monitor sisältyy Ad-Awaren Professional versioon. Kyseessä on reaaliaikainen tarkkailuohjelma. Koitas vaikka sammuttaa Ad-Monitor. (Yleensä kuvake tehtäväpalkissa).
     
  4. winxp

    winxp Member

    Joined:
    Jun 27, 2003
    Messages:
    45
    Likes Received:
    0
    Trophy Points:
    16


    Käsittääkseni Ad-Awaren Professional version sekä Ad-Aware Plus version tarkkailuohjelma on ainakin vielä nimeltään [bold]Ad-Watch.[/bold]

    Jos sulla on F-Secure Anti-Spyware niin sen tarkkailuohjelma taitaa olla nimeltään Ad-Monitor.

    F-Secure Anti-Spyware on siis lähes sama kuin alkuperäinen Lavasoftin Ad-Aware.

    https://verkkokauppa.f-secure.fi/cgi-bin/nph-cgi/~Jstex0000001/?Y999=PIF&Y184=&Y104=3
     
  5. Skedeejä

    Skedeejä Regular member

    Joined:
    Jul 26, 2004
    Messages:
    422
    Likes Received:
    0
    Trophy Points:
    26
    Joo eli sekotin nuo. Itselläni on F-Secure Internet Security ja sen mukana tullut Ad-Awaren versio, jossa todellakin on se Ad-Monitor. Ad-Watch oli sitten plussassa ja professionallissa. :)
     
  6. age007ti

    age007ti Guest

    asia harvinaaisen yksinkertainen

    verkko irti
    poistat f-securen kokonaan
    asennat sen uudestaan ilman tuota ad-monitoria

    kummalista on että f-securen sivut ei tunne koko sanaa ad-monitor
     
  7. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    noh kyllä tuon ad-monitorin aina saa pois päältä ja sitten se ei estä niitä mutta kyllä se olisi muuten hyvä ohjelma eli eikö niitä todellakaan saa sallittua millään niin että ad-monitoria voi pitää päällä ja tuosta käyttiksestä tarkottaako se windows XP:tä vai Intel Pentium 4:ä(eli noi on)
     
  8. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    f-secure anti-spyware on
     
  9. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    tietääkö joku mikä ad-monitorissa se sääntöeditori on?
     
  10. Skedeejä

    Skedeejä Regular member

    Joined:
    Jul 26, 2004
    Messages:
    422
    Likes Received:
    0
    Trophy Points:
    26
    Kokeilitko jo silleen, että sammutat sen Ad-Watchin ja sitten yrität poistaa HJ:llä niitä pöpöjä?
     
  11. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    joo olen, mutta sitten kun laittaa ad-monitorin päälle se palauttaa muutokset
     
  12. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    noni, ad-monitorissa oli automaattinen poisto päällä, mut nyt saan poistettua niitä
     
  13. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    onkos tämä nyt sitten aiva ok?

    Logfile of HijackThis v1.99.1
    Scan saved at 19:03:45, on 10.9.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Spyware\Ad-Monitor.exe
    C:\PROGRA~1\F-SECU~1\backweb\1245240\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure Internet Security\backweb\1245240\program\fsbwsys.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure Internet Security\backweb\1245240\Program\fspex.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
    C:\WINDOWS\System32\ScsiAccess.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
    C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
    C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
    C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguiexe.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    D:\Hijack This\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.teuva.fi/e/site
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [AWMON] "C:\Program Files\F-Secure Internet Security\Anti-Spyware\Ad-Monitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
    O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Näytä &Web-sivuluettelo... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'd:\ladatut\spyware removals\bps spyware & adware remover\apptoport.dll' missing
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab28578.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: F-Secure Internet Security 2005 OEM (BackWeb Plug-in - 1245240) - Unknown owner - C:\PROGRA~1\F-SECU~1\backweb\1245240\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\1245240\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
     
  14. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    eikös toi pitäisi poistaa? : O10 - Broken Internet access because of LSP provider 'd:\ladatut\spyware removals\bps spyware & adware remover\apptoport.dll' missing
     
  15. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    @joujouman: Sen voi poistaa, mutta 010-entryjä ei poisteta hijackthisin kautta, vaan lspfixillä. Ei ole pakollinen poistettava. Voin laittaa poisto-ohjeet, jos haluat :)
     
  16. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    eli mikä se ispfix on?
     
  17. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Ohjelma, jolla voit korjata virheellisiä winsockin asetuksia.

    Jos haluat korjata tuon rivin, tee näin.

    Hae LSPFix tuolta (joko se zippi tai sitten exe).
    http://cexx.org/lspfix.htm

    Tallenna se vaikka työpöydälle tai johonkin hakemistoon.

    Avaa LSPFix

    Laita rasti ruutuun, "I know what I’m doing".

    Klikkaa vasemmassa ruudussa olevaa apptoport.dll, siirrä se oikealla olevaan ruutuun nuolinäppäimellä, klikkaa "Remove" ja sulje LSPFix.

    Käynnistä kone uudestaan ja laita uusi hijackthis-loki.
     
  18. joujouman

    joujouman Member

    Joined:
    Feb 4, 2005
    Messages:
    83
    Likes Received:
    0
    Trophy Points:
    16
    mulla tuo apptpport.dll on jo oikeassa ikkunassa
     

Share This Page