löytäiskö joku tosta jotain? ite epäilen tota win32 wpclsp, mutta en oo viä uskaltanu tehdä mitään. koko ajan tulee ilmoituksia että: your computer is infected with spyware!! ja tehtäväpalkissa on sellanen pieni kolmio mitä klikkaamalla menee pc-cleanerin sivuille... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:46:24, on 21.4.2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\SiS VGA Utilities\SiSTray.exe C:\Windows\RtHDVCpl.exe C:\Windows\system32\taskeng.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\ProgramData\bghpznsq\ingfyryv.exe C:\Program Files\Option\GlobeTrotter Connect\GlobeTrotter Connect.exe C:\Program Files\FSC\Wireless Utility\WirelessSelector.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\Windows\system32\conime.exe C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fi.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.defaulthomepage.info R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll O1 - Hosts: ::1 localhost O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [SiSTray] %ProgramFiles%\SiS VGA Utilities\SiSTray.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [TouchPadHotKey] C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [bghpznsq] C:\ProgramData\bghpznsq\ingfyryv.exe O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu') O4 - Global Startup: GlobeTrotter Connect.lnk = C:\Program Files\Option\GlobeTrotter Connect\GlobeTrotter Connect.exe O4 - Global Startup: WirelessSelector.lnk = ? O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O13 - Gopher Prefix: O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/Unibet/FlashAX.cab O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: GtDetectSc - OptionNV - C:\Program Files\Option\GlobeTrotter Connect\GtDetectSc.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe -- End of file - 7972 bytes
1.Lataa combofix.exe työpöydällesi yhdestä linkistä: combofix1 combofix2 2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia. 3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi. Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen. ========== Lataa Malwarebytes' Anti-Malware työpöydällesi. 1. Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman. 2. Lopuksi varmistu, että seuraavat on valittu: Update Malwarebytes', Anti-Malwareja Launch Malwarebytes' Anti-Malware ja sen jälkeen klikkaaFinish. 3. Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version. 4. Kun ohjelma on latautunut, valitse Perform full scan ja klikkaa Scan. 5. Kun skanni on valmis, klikkaa OK ja sitten Show Results nähdäksesi tulokset. 6. Varmistu, että kaikki on merkitty ja klikkaa Remove Selected. 7. Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt 8. Lähetä lokin sisältö seuraavassa viestissäsi.
vedin sillä combofixillä koneen läpi ja tällästä löyty: jatkanko heti sillä toisella ohjelmalla? ComboFix 08-04-20.5 - Esprimo 2008-04-21 17:17:36.1 - NTFSx86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1035.18.159 [GMT 3:00] Running from: C:\Users\Esprimo\Downloads\lataukset\ComboFix.exe * Created a new restore point * Resident AV is active . (((((((((((((((((((((((((((((((((((((( Muut poistot )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Users\Esprimo\Desktopblackbird.jpg C:\Users\Esprimo\DesktopEditorFKWP1.5.exe C:\Users\Esprimo\DesktopEditorFKWP2.0.exe C:\Users\Esprimo\Desktopfilemanagerclient.exe C:\Users\Esprimo\Desktopfkwp1.5.exe C:\Users\Esprimo\Desktopfkwp2.0.exe C:\Users\Esprimo\Desktopfwebd.exe C:\Users\Esprimo\DesktopFWebdEditor.exe C:\Users\Esprimo\Desktopvirii . ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-03-21 to 2008-04-21 ))))))))))))))))) . 2008-04-21 15:44 . 2008-04-21 15:44 <KANSIO> d-------- C:\Program Files\Trend Micro 2008-04-19 10:52 . 2008-04-19 10:52 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\Nero 2008-04-19 10:44 . 2008-04-19 10:44 <KANSIO> d-------- C:\Users\All Users\Nero 2008-04-19 10:44 . 2008-04-19 10:44 <KANSIO> d-------- C:\ProgramData\Nero 2008-04-19 10:44 . 2008-04-19 10:49 <KANSIO> d-------- C:\Program Files\Common Files\Nero 2008-04-18 20:00 . 2008-04-18 20:00 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\BSplayer Pro 2008-04-18 20:00 . 2008-04-19 00:56 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\BSplayer 2008-04-18 20:00 . 2008-04-18 20:00 <KANSIO> d-------- C:\Program Files\Webteh 2008-04-17 17:50 . 2008-04-17 17:50 <KANSIO> d-------- C:\Program Files\Gabest 2008-04-17 17:39 . 2008-04-17 17:39 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\CyberLink 2008-04-17 17:25 . 2008-04-17 17:37 <KANSIO> d-------- C:\Users\All Users\CyberLink 2008-04-17 17:25 . 2008-04-17 17:37 <KANSIO> d-------- C:\ProgramData\CyberLink 2008-04-17 17:17 . 2001-03-08 18:30 24,064 --------- C:\Windows\System32\msxml3a.dll 2008-04-17 17:14 . 2008-04-17 17:16 <KANSIO> d-------- C:\Program Files\CyberLink 2008-04-14 18:02 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Searches 2008-04-14 18:01 . 2008-04-14 18:01 <KANSIO> dr------- C:\Users\Administrator\Contacts 2008-04-14 18:01 . 2008-04-14 18:01 <KANSIO> d-------- C:\Users\Administrator\AppData\Roaming\PC Suite 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Videos 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Saved Games 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Pictures 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Music 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Links 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Downloads 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> dr------- C:\Users\Administrator\Documents 2008-04-14 18:00 . 2008-04-14 18:02 <KANSIO> d--h----- C:\Users\Administrator\AppData 2008-04-14 18:00 . 2008-04-14 18:11 <KANSIO> d-------- C:\Users\Administrator 2008-04-14 18:00 . 2008-04-14 18:00 524,288 --ahs---- C:\Users\Administrator\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms 2008-04-14 18:00 . 2008-04-14 18:00 524,288 --ahs---- C:\Users\Administrator\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms 2008-04-14 18:00 . 2008-04-21 17:17 262,144 --ah----- C:\Users\Administrator\ntuser.dat.LOG1 2008-04-14 18:00 . 2008-04-14 18:00 65,536 --ahs---- C:\Users\Administrator\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf 2008-04-14 18:00 . 2008-04-14 18:00 0 --ah----- C:\Users\Administrator\ntuser.dat.LOG2 2008-04-14 17:52 . 2008-04-14 17:54 196,608 --a------ C:\Users\Esprimo\[ CD and DVD Appz ] Nero MPEG2 Video Codec Plugin.exe 2008-04-14 00:51 . 2008-04-14 00:51 <KANSIO> d-------- C:\MP_ROOT 2008-04-14 00:45 . 2008-04-14 00:45 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\Ahead 2008-04-13 18:36 . 2008-04-17 17:35 <KANSIO> d-------- C:\Program Files\DAEMON Tools 2008-04-13 18:36 . 2008-04-13 18:36 820 --a------ C:\DAEMON Tools.lnk 2008-04-13 18:29 . 2008-04-13 18:29 646,392 --a------ C:\Windows\System32\drivers\sptd.sys 2008-04-13 15:00 . 2008-04-13 15:56 22,281 --a------ C:\error.htm 2008-04-13 15:00 . 2008-04-13 15:54 845 --a------ C:\infect.htm 2008-04-12 17:29 . 2008-04-12 17:30 <KANSIO> d-------- C:\Program Files\Microsoft Silverlight 2008-04-11 07:46 . 2000-05-15 19:47 432,128 --a------ C:\Program Files\MRABBI.EXE 2008-04-11 07:46 . 1998-06-07 15:01 21,648 --a------ C:\Windows\system\CTL3DV2.DLL 2008-04-11 07:46 . 1998-07-31 15:01 19,904 --a------ C:\Program Files\_ISREG16.DLL 2008-04-11 07:46 . 2008-04-11 07:46 0 --a------ C:\Windows\PROTOCOL.INI 2008-04-11 07:45 . 2008-04-11 07:46 <KANSIO> d-------- C:\Program Files\JAELISTA 2008-04-11 07:45 . 2008-04-11 07:46 <KANSIO> d-------- C:\Program Files\HELPIT 2008-04-11 07:45 . 2008-04-11 07:46 <KANSIO> d-------- C:\Program Files\DATA 2008-04-11 07:45 . 1998-02-06 22:25 259,072 --a------ C:\Windows\UN16040B.EXE 2008-04-11 07:45 . 1995-07-13 19:43 26,768 --a------ C:\Windows\system\CTL3D.DLL 2008-04-11 06:09 . 2008-04-14 00:45 <KANSIO> d-------- C:\Temp 2008-04-11 05:25 . 2008-04-11 05:25 <KANSIO> d-------- C:\Program Files\Xilisoft 2008-04-11 01:52 . 2008-04-11 01:54 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\PC-Cleaner 2008-04-11 00:36 . 2008-04-11 00:36 <KANSIO> d-------- C:\Users\All Users\oxunstcz 2008-04-11 00:36 . 2008-04-11 00:36 <KANSIO> d-------- C:\Users\All Users\bghpznsq 2008-04-11 00:36 . 2008-04-11 00:36 <KANSIO> d-------- C:\ProgramData\oxunstcz 2008-04-11 00:36 . 2008-04-11 00:36 <KANSIO> d-------- C:\ProgramData\bghpznsq 2008-04-09 22:20 . 2008-02-15 02:19 944,184 --a------ C:\Windows\System32\winload.exe 2008-04-09 22:20 . 2008-02-19 08:10 620,088 --a------ C:\Windows\System32\ci.dll 2008-04-09 22:20 . 2008-02-29 09:39 371,712 --a------ C:\Windows\System32\srcore.dll 2008-04-09 22:20 . 2008-02-29 09:38 313,856 --a------ C:\Windows\System32\rstrui.exe 2008-04-09 22:20 . 2008-02-29 09:39 40,960 --a------ C:\Windows\System32\srclient.dll 2008-04-09 22:20 . 2008-02-29 09:51 19,000 --a------ C:\Windows\System32\kd1394.dll 2008-04-09 22:20 . 2008-02-29 09:38 16,384 --a------ C:\Windows\System32\srdelayed.exe 2008-04-09 22:20 . 2008-02-29 09:34 7,168 --a------ C:\Windows\System32\f3ahvoas.dll 2008-04-09 22:20 . 2008-02-29 09:35 6,656 --a------ C:\Windows\System32\kbd106n.dll 2008-04-09 17:13 . 2008-02-21 07:43 296,448 --a------ C:\Windows\System32\gdi32.dll 2008-04-09 17:10 . 2008-02-29 07:16 2,027,008 --a------ C:\Windows\System32\win32k.sys 2008-04-09 17:09 . 2007-12-16 14:42 83,968 --a------ C:\Windows\System32\dnsrslvr.dll 2008-04-09 17:09 . 2007-12-16 14:41 24,576 --a------ C:\Windows\System32\dnscacheugc.exe 2008-04-09 00:09 . 2008-04-09 00:09 <KANSIO> d-------- C:\Users\All Users\Winamp Toolbar 2008-04-09 00:09 . 2008-04-09 00:09 <KANSIO> d-------- C:\ProgramData\Winamp Toolbar 2008-04-09 00:09 . 2008-04-09 00:09 <KANSIO> d-------- C:\Program Files\Winamp Toolbar 2008-04-08 23:51 . 2007-03-08 02:51 129,784 --------- C:\Windows\System32\pxafs.dll 2008-04-08 23:50 . 2008-04-09 01:06 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\Winamp 2008-04-08 23:50 . 2008-04-09 00:10 <KANSIO> d-------- C:\Program Files\Winamp 2008-04-07 11:25 . 2008-04-11 07:45 <KANSIO> d-------- C:\Programs 2008-04-05 17:24 . 2008-04-05 18:14 <KANSIO> d-------- C:\Users\Esprimo\Phone Browser 2008-04-05 17:16 . 2008-04-05 17:16 168,846 --a------ C:\Users\Esprimo\AppData\Roaming\NMM-MetaData.db 2008-04-05 17:05 . 2008-04-08 19:13 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\Nokia Multimedia Player 2008-04-05 16:48 . 2008-04-05 16:57 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\Nokia 2008-04-02 19:48 . 2008-04-02 19:48 <KANSIO> d-------- C:\Program Files\MSXML 4.0 2008-04-02 00:16 . 2008-04-02 00:21 1,905 --a------ C:\Windows\diagwrn.xml 2008-04-02 00:16 . 2008-04-02 00:21 1,905 --a------ C:\Windows\diagerr.xml 2008-04-01 23:59 . 2008-04-19 10:44 <KANSIO> d-------- C:\Program Files\Nero 2008-04-01 23:59 . 2008-04-19 00:20 <KANSIO> d-------- C:\Program Files\Common Files\Ahead 2008-04-01 22:35 . 2008-04-20 20:41 98,310,591 --a------ C:\Windows\MEMORY.DMP 2008-04-01 22:25 . 2008-04-01 22:25 <KANSIO> d-------- C:\Program Files\AC3Filter 2008-04-01 22:25 . 2007-08-09 14:27 380,928 --a------ C:\Windows\System32\ac3filter.acm 2008-04-01 21:57 . 2008-04-01 21:57 <KANSIO> d-------- C:\Program Files\ffdshow 2008-04-01 21:57 . 2006-10-02 13:43 6,144 --a------ C:\Windows\System32\ff_acm.acm 2008-04-01 21:57 . 2006-10-02 13:44 5,120 --a------ C:\Windows\System32\ff_vfw.dll 2008-04-01 21:57 . 2006-08-05 12:06 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest 2008-04-01 20:55 . 2007-10-11 09:12 2,213,208 --a------ C:\Windows\System32\LEncMpg23.dll 2008-04-01 20:55 . 2007-10-04 12:40 263,512 --a------ C:\Windows\System32\LMVRGBxf.dll 2008-04-01 20:55 . 2007-10-04 12:43 218,456 --a------ C:\Windows\System32\LMOggMux.dll 2008-04-01 20:55 . 2007-10-04 12:42 161,112 --a------ C:\Windows\System32\lencmpga2.dll 2008-04-01 20:55 . 2007-10-04 12:39 161,112 --a------ C:\Windows\System32\LEncAC3.dll 2008-04-01 20:55 . 2007-10-04 12:40 140,632 --a------ C:\Windows\System32\LMVYUVxf.dll 2008-04-01 20:55 . 2007-10-09 09:47 83,288 --a------ C:\Windows\System32\LMMpg2Mx2.dll 2008-04-01 20:55 . 2007-10-04 12:42 75,096 --a------ C:\Windows\System32\LMMpg1Mx2.dll 2008-04-01 20:55 . 2007-10-04 12:39 71,000 --a------ C:\Windows\System32\LEncAC3Krn.dll 2008-04-01 20:54 . 2008-04-01 20:54 <KANSIO> d-------- C:\Program Files\LEAD Technologies, Inc 2008-04-01 20:54 . 2007-07-05 12:25 520,192 --a------ C:\Windows\System32\LtAct14n.dll 2008-04-01 20:54 . 2007-10-04 12:40 144,728 --a------ C:\Windows\System32\DSKernel2.dll 2008-04-01 20:54 . 2007-04-10 13:25 142,480 --a------ C:\Windows\System32\ltact.dll 2008-04-01 20:54 . 2006-03-08 05:11 65,536 --a------ C:\Windows\System32\ltserial.dll 2008-04-01 03:13 . 2008-04-01 03:13 139,264 --a------ C:\Windows\System32\Mpeg2Decoder.ax 2008-04-01 03:13 . 2008-04-01 03:13 94,208 --a------ C:\Windows\System32\Mpeg2Parser.ax 2008-03-31 23:56 . 2008-04-12 01:59 <KANSIO> d-------- C:\Windows\System32\FlashAX 2008-03-31 23:05 . 2008-03-31 23:05 <KANSIO> d-------- C:\Program Files\Common Files\Nokia 2008-03-31 23:04 . 2008-03-31 23:14 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\PC Suite 2008-03-31 23:04 . 2008-03-31 23:37 <KANSIO> d-------- C:\Users\All Users\PC Suite 2008-03-31 23:04 . 2008-03-31 23:37 <KANSIO> d-------- C:\ProgramData\PC Suite 2008-03-31 23:01 . 2006-05-29 08:26 50,688 --a------ C:\Windows\System32\nmwcdcls.dll 2008-03-31 23:00 . 2008-03-31 23:00 <KANSIO> d-------- C:\Users\All Users\Downloaded Installations 2008-03-31 23:00 . 2008-03-31 23:00 <KANSIO> d-------- C:\ProgramData\Downloaded Installations 2008-03-31 22:59 . 2008-03-31 22:59 <KANSIO> d-------- C:\Windows\Downloaded Installations 2008-03-31 22:59 . 2008-03-31 23:09 <KANSIO> d-------- C:\Program Files\Nokia 2008-03-31 22:59 . 2008-03-31 23:05 <KANSIO> d-------- C:\Program Files\Common Files\PCSuite 2008-03-31 21:52 . 2008-03-31 21:52 <KANSIO> d-------- C:\Windows\System32\Macromed 2008-03-31 21:27 . 2008-03-31 21:27 <KANSIO> d-------- C:\Windows\PCHEALTH 2008-03-31 21:17 . 2008-04-21 15:53 <KANSIO> d-------- C:\Users\Esprimo\AppData\Roaming\Microgaming 2008-03-31 21:17 . 2008-03-31 21:17 <KANSIO> d-------- C:\Microgaming 2008-03-31 20:23 . 2008-03-31 20:23 <KANSIO> d-------- C:\Program Files\DC++ 2008-03-31 19:11 . 2008-03-31 19:11 36 ---h----- C:\Windows\System32\swk.ini . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-11 04:47 25,114 ----a-w C:\Program Files\DEISL1.ISU 2008-04-09 23:53 --------- d-----w C:\Program Files\Windows Mail 2008-03-27 18:36 --------- d-----w C:\Program Files\Windows Photo Gallery 2008-03-27 18:36 --------- d-----w C:\Program Files\Windows Defender 2008-03-27 18:36 --------- d-----w C:\Program Files\Windows Collaboration 2008-03-27 18:36 --------- d-----w C:\Program Files\Windows Calendar 2008-03-27 12:04 --------- d-----w C:\Program Files\Windows Sidebar 2008-03-27 11:53 84,480 ----a-w C:\Windows\System32\INETRES.dll 2008-03-27 11:53 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys 2008-03-27 11:53 737,792 ----a-w C:\Windows\System32\inetcomm.dll 2008-03-27 11:53 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-03-27 11:53 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-03-27 11:53 216,632 ----a-w C:\Windows\system32\drivers\netio.sys 2008-03-27 11:53 2,048 ----a-w C:\Windows\System32\msxml6r.dll 2008-03-27 11:53 2,048 ----a-w C:\Windows\System32\msxml3r.dll 2008-03-27 11:53 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll 2008-03-27 11:53 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys 2008-03-27 11:53 1,327,104 ----a-w C:\Windows\System32\quartz.dll 2008-03-27 11:53 1,191,936 ----a-w C:\Windows\System32\msxml3.dll 2008-03-27 11:33 905,400 ----a-w C:\Windows\System32\winresume.exe 2008-03-27 11:31 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL 2008-03-27 11:31 8,704 ----a-w C:\Windows\System32\hcrstco.dll 2008-03-27 11:31 8,704 ----a-w C:\Windows\System32\hccoin.dll 2008-03-27 11:31 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys 2008-03-27 11:31 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys 2008-03-27 11:31 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys 2008-03-27 11:31 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys 2008-03-27 11:31 223,232 ----a-w C:\Windows\System32\WMASF.DLL 2008-03-27 11:31 2,048 ----a-w C:\Windows\System32\asferror.dll 2008-03-27 11:31 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys 2008-03-27 11:31 19,456 ----a-w C:\Windows\system32\drivers\usbohci.sys 2008-03-27 11:29 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll 2008-03-27 11:29 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2008-03-27 11:29 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll 2008-03-27 11:29 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll 2008-03-27 11:29 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2008-03-27 08:48 --------- d-sh--w C:\ProgramData\Työpöytä 2008-03-27 08:48 --------- d-sh--w C:\ProgramData\Tiedostot 2008-03-27 08:48 --------- d-sh--w C:\ProgramData\Suosikit 2008-03-27 08:48 --------- d-sh--w C:\ProgramData\Mallit 2008-03-27 08:48 --------- d-sh--w C:\ProgramData\Käynnistä-valikko 2008-03-27 08:44 174 --sha-w C:\Program Files\desktop.ini 2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll 2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll 2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2000-06-12 09:07 2,191 ----a-w C:\Program Files\LUEMUT.TXT 2000-06-12 09:01 23,399 ----a-w C:\Program Files\FAQ.TXT 1998-06-07 12:01 998,052 ----a-w C:\Program Files\MRABBI31.HLP 1998-06-07 12:01 36 ----a-w C:\Program Files\MRABBI31.INI 1998-06-07 12:01 148,233 ----a-w C:\Program Files\BIBLE.HLP 1998-03-19 21:06 529 ----a-w C:\Program Files\NIMETON.INI . (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}] 2008-03-20 01:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-20 01:36 1267040] [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2008-03-20 01:36 1267040] [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-27 14:52 1232896] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984] "bghpznsq"="C:\ProgramData\bghpznsq\ingfyryv.exe" [2008-04-11 00:36 102400] "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 13:48 157592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-23 15:41 1006264] "SiSTray"="C:\Program Files\SiS VGA Utilities\SiSTray.exe" [2007-08-14 14:29 552960] "RtHDVCpl"="RtHDVCpl.exe" [2007-08-09 20:26 4702208 C:\Windows\RtHDVCpl.exe] "Skytel"="Skytel.exe" [2007-08-03 14:22 1826816 C:\Windows\SkyTel.exe] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-10 20:48 869936] "TouchPadHotKey"="C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe" [2007-08-13 14:47 364544] "F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2007-05-25 16:12 183208] "F-Secure TNB"="C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2007-05-25 16:11 740208] "NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 01:12 2658304] "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 21:49 36352] "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 13:48 157592] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-06 18:37 69216] "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55 54832] "NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136] "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51 1836328] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ GlobeTrotter Connect.lnk - C:\Program Files\Option\GlobeTrotter Connect\GlobeTrotter Connect.exe [2008-01-10 15:51:02 864256] WirelessSelector.lnk - C:\Program Files\FSC\Wireless Utility\WirelessSelector.exe [2008-03-27 12:15:43 650752] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "LogonHoursAction"= 2 (0x2) "DontDisplayLogonHoursWarnings"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.avis"= ff_acm.acm "msacm.ac3filter"= ac3filter.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{E47752EA-08E8-487D-AEEE-0638619F6DB1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "TCP Query User{782EA554-8F43-4F78-B7A5-EA728778457F}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exeC++ "UDP Query User{0D4414A8-3613-4E48-ACD2-162E3C6AE911}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exeC++ "TCP Query User{4A0D6948-357E-4ADC-870D-BB958396703E}C:\\program files\\nero\\nero8\\nero showtime\\showtime.exe"= UDP:C:\program files\nero\nero8\nero showtime\showtime.exe:Nero ShowTime "UDP Query User{F81CC65E-ED11-4041-B6AD-722EB797B10D}C:\\program files\\nero\\nero8\\nero showtime\\showtime.exe"= TCP:C:\program files\nero\nero8\nero showtime\showtime.exe:Nero ShowTime [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys [2008-03-27 15:00] R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-05-25 16:09] R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-03-27 15:03] R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsvista.sys [2007-05-25 16:08] R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51] R2 GtDetectSc;GtDetectSc;"C:\Program Files\Option\GlobeTrotter Connect\GtDetectSc.exe" [2007-12-18 11:48] R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2008-03-26 06:48] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2007-05-25 16:08] R3 GT72NDISIPXP;GT 72 IP NDIS;C:\Windows\system32\DRIVERS\Gt51Ip.sys [2007-11-13 15:50] R3 GT72UBUS;GT 72 U BUS;C:\Windows\system32\DRIVERS\gt72ubus.sys [2007-10-09 12:53] R3 GTPTSER;GT PT SER;C:\Windows\system32\DRIVERS\gtptser.sys [2007-03-30 12:38] R3 SiS6350;SiS6350;C:\Windows\system32\DRIVERS\SISGRKMD.sys [2007-08-14 14:30] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSGB6.sys [2007-07-04 11:04] S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2007-05-25 16:09] S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2007-05-25 16:09] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3bcc2e64-ff1c-11dc-b173-806e6f6e6963}] \shell\AutoRun\command - E:\setup.exe AUTORUN=1 *Newly Created Service* - CATCHME . 'Ajoitetut tehtävät'-kansion sisältö "2008-04-21 12:01:49 C:\Windows\Tasks\Scheduled scanning task.job" - C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeQ /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-21 17:28:16 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-04-21 17:33:06 ComboFix-quarantined-files.txt 2008-04-21 14:32:59 Pre-Run: 51,885,051,904 tavua vapaana Post-Run: 52,632,035,328 tavua vapaana 299 --- E O F --- 2008-04-18 15:10:36
no niin tällästä infoo: olisko toi jo riittävä, poistin ne tartunnan saaneet tiedostot niin kuin neuvoit. Malwarebytes' Anti-Malware 1.11 Tietokantaversio: 665 Tarkistustyyppi: Täysi tarkistus (C:\|) Tarkistetut kohteet: 104554 Kulunut aika: 54 minute(s), 46 second(s) Saastuneita muistiprosesseja: 1 Saastuneita muistimoduuleja: 0 Saastuneita rekisteriavaimia: 8 Saastuneita rekisteriarvoja: 1 Saastuneita rekisterikohteita: 0 Saastuneita hakemistoja: 1 Saastuneita tiedostoja: 4 Saastuneita muistiprosesseja: C:\ProgramData\bghpznsq\ingfyryv.exe (Trojan.FakeAlert) -> Unloaded process successfully. Saastuneita muistimoduuleja: (Haitallisia kohteita ei löydetty) Saastuneita rekisteriavaimia: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\PC-Cleaner (Rogue.PC-Cleaner) -> Quarantined and deleted successfully. Saastuneita rekisteriarvoja: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bghpznsq (Trojan.FakeAlert) -> Quarantined and deleted successfully. Saastuneita rekisterikohteita: (Haitallisia kohteita ei löydetty) Saastuneita hakemistoja: C:\Users\Esprimo\AppData\Roaming\PC-Cleaner (Rogue.PC-Cleaner) -> Quarantined and deleted successfully. Saastuneita tiedostoja: C:\ProgramData\bghpznsq\ingfyryv.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\ProgramData\oxunstcz\wpuxoxev.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Users\Esprimo\AppData\Roaming\PC-Cleaner\log.dat (Rogue.PC-Cleaner) -> Quarantined and deleted successfully. C:\Users\Esprimo\AppData\Roaming\PC-Cleaner\settings.dat (Rogue.PC-Cleaner) -> Quarantined and deleted successfully.
Lataa Tästä Ccleaner CCleaner v2.05.555- Standard Build, ÄLÄ aseenna Yahoo toolbaria! laita asetukset näin: Valinnat --> Lisäasetukset --> Ota ruksi pois kohdasta Poista vain yli 48 tuntia vanhat tilapäistiedostot. aja Puhdistaja > tutki nappi > aja ccleaner nappi oikea alakulma aja Virheet > etsi rekisteri virheitä nappi > Korjaa rekisteri virheet. nappi
teenkö nyt ihan oikein, pitääkö ne saastuneet tiedostot ajaa yksitellen sillä napilla aja ccleanerilla? oon tehny sitä jo jonkin aikaa, eikä se tunnu edistyvän? jatkanko vaan?
oon nyt tehny sitä tunnin ajan ja se poistaa niitä väliaikaisia internet sivustoja eikä muuta, kuinka paljon niitä voi olla vai teenkö jotain väärin?
ajas tuolla Lataa Atribunen ATF Cleaner Ohjeet; Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman.Main:n alla valitse: Select All Klikkaa Empty Selected valintaa. Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Jos käytät Operaa selaimenasiKlikkaa Opera yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa taas. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Klikkaa Exit päävalikosta sulkeaksesi ohjelman. Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi)
no ajoin nyt sillä atfcleanerilla ja ei oo enää herjannu mistään. tosin kone kaatu tänään kerran mut se nyt voi olla jotain muutakin.kiitos!