Apuva Security toolbar 7.1 ja hirveesti popuppeja

Discussion in 'Virukset ja haittaohjelmat' started by Wiljami, Aug 7, 2007.

  1. Wiljami

    Wiljami Member

    Dec 14, 2002
    Juu kokeiltu on vikasietotilaa muttei auta. Huomasin muuten että tuolla windowsin kansiossa oli kanssa mafia kansio jossa oli uninstal.exe jonka sai poistettua mutta kansiota ei. Sitten huomasin kanssa että logissa

    2007-08-07 12:50 d-------- C:\WINDOWS\network diagnostic
    2007-08-04 23:23 d----c--- C:\WINDOWS\system32\DRVSTORE
    2007-08-02 18:39 C:\WINDOWS\Mafia
    2007-08-02 18:39 C:\Program Files\Mafia
    2007-07-29 14:37 52,736 --a------ C:\WINDOWS\ipuninst.exe
    2007-07-28 01:00 d-------- C:\DOCUME~1\Wiljami\APPLIC~1\Command & Conquer 3 Tiberium Wars

    noissa mafia riveissä ei ole samanlaisia juttuja edessä kuin noissa muissa riveissä eli d------ pläpläplää osaa. Tarkoittaako se jotain?
  2. Auttaja

    Auttaja Guest

    Uskosin sen tarkottavan että tiedostot ovat jollain tavalla vahingoittuneita ett niit ei pysty lukee...
  3. Wiljami

    Wiljami Member

    Dec 14, 2002
    Yritin vielä poistaa killboxilla mutta tulee tälläinen ilmoitus

    "PendingFileRenameOperations Registry Data has been Removed by External Process!"

    Mitäs tää meinaa?

    Ihme juttu kun ei saa poistettua.
  4. Wiljami

    Wiljami Member

    Dec 14, 2002
    Kansioihin pystyy laittamaan tiedostoja ja niitä pystyy käyttämään sekä poistamaan sieltä mutta kansiota ei.. tosi hassua.
  5. Auttaja

    Auttaja Guest

    Luo käynnistyslista

    * Avaa HiJackThis
    * Klikkaa "Configure" valintaa oikealla alhaalla
    * Klikkaa "Misc Tools"
    * Rastita 2 boxia boxin vierestä jossa lukee "Generate StartupList log"
    * Klikkaa valintaa "Generate StartupList log"
    * Kopioi ja liitä käynnistyslistasi muistiosta postiisi
  6. Wiljami

    Wiljami Member

    Dec 14, 2002
    StartupList report, 10.8.2007, 23:10:14
    StartupList version: 1.52.2
    Started from : C:\Documents and Settings\Wiljami\Omat tiedostot\HijackThis.EXE
    Detected: Windows XP SP2 (WinNT 5.01.2600)
    Detected: Internet Explorer v7.00 (7.00.6000.16473)
    * Using default options
    * Including empty and uninteresting sections
    * Showing rarely important sections

    Running processes:

    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
    C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
    C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
    C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
    E:\BitDefender plus v10\vsserv.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Wiljami\Omat tiedostot\HijackThis.exe


    Listing of startup folders:

    Shell folders Startup:
    [C:\Documents and Settings\Wiljami\Käynnistä-valikko\Ohjelmat\Käynnistys]
    desktop_minion4260671805.lnk = C:\Program Files\Codemasters Overlord Desktop Minion\desktop_minion.exe

    Shell folders AltStartup:
    *Folder not found*

    User shell folders Startup:
    *Folder not found*

    User shell folders AltStartup:
    *Folder not found*

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
    *No files*

    Shell folders Common AltStartup:
    *Folder not found*

    User shell folders Common Startup:
    *Folder not found*

    User shell folders Alternate Common Startup:
    *Folder not found*


    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINDOWS\system32\userinit.exe,

    *Registry key not found*

    [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    *Registry value not found*

    *Registry key not found*


    Autorun entries from Registry:

    NVIDIA nTune = "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
    JMB36X IDE Setup = C:\WINDOWS\JM\JMInsIDE.exe
    Logitech Utility = Logi_MwX.Exe
    BDMCon = e:\BITDEF~1\bdmcon.exe
    NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


    Autorun entries from Registry:

    *No values found*


    Autorun entries from Registry:

    *No values found*


    Autorun entries from Registry:

    *No values found*


    Autorun entries from Registry:

    *Registry key not found*


    Autorun entries from Registry:

    ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe


    Autorun entries from Registry:

    *No values found*


    Autorun entries from Registry:

    *Registry key not found*


    Autorun entries from Registry:

    *No values found*


    Autorun entries from Registry:

    *Registry key not found*


    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*


    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*


    Autorun entries in Registry subkeys of:



    Autorun entries in Registry subkeys of:
    *No subkeys found*


    Autorun entries in Registry subkeys of:
    *No subkeys found*


    Autorun entries in Registry subkeys of:
    *No subkeys found*


    Autorun entries in Registry subkeys of:
    *Registry key not found*


    Autorun entries in Registry subkeys of:



    Autorun entries in Registry subkeys of:
    *No subkeys found*


    Autorun entries in Registry subkeys of:
    *Registry key not found*


    Autorun entries in Registry subkeys of:
    *No subkeys found*


    Autorun entries in Registry subkeys of:
    *Registry key not found*


    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*


    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*


    File association entry for .EXE:

    (Default) = "%1" %*


    File association entry for .COM:

    (Default) = "%1" %*


    File association entry for .BAT:

    (Default) = "%1" %*


    File association entry for .PIF:

    (Default) = "%1" %*


    File association entry for .SCR:

    (Default) = "%1" /S


    File association entry for .HTA:

    (Default) = C:\WINDOWS\system32\mshta.exe "%1" %*


    File association entry for .TXT:

    (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1


    Enumerating Active Setup stub paths:
    HKLM\Software\Microsoft\Active Setup\Installed Components
    (* = disabled by HKCU twin)

    [<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] *
    StubPath = C:\WINDOWS\system32\ieudinit.exe

    StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

    [>{26923b43-4d38-484f-9b9e-de460746276c}] *
    StubPath = C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig

    [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] *
    StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

    [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
    StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

    [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

    [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
    StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

    [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

    [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

    [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

    [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

    [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

    [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
    StubPath = regsvr32.exe /s /n /i:U shell32.dll

    [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
    StubPath = C:\WINDOWS\system32\ie4uinit.exe -BaseSettings

    [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
    StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install


    Enumerating ICQ Agent Autostart apps:

    *Registry key not found*


    Load/Run keys from C:\WINDOWS\WIN.INI:

    load=*INI section not found*
    run=*INI section not found*

    Load/Run keys from Registry:

    HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
    HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=sockspy.dll


    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    SCRNSAVE.EXE=*Registry value not found*
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry value not found*
    HKLM\..\Policies: Shell=*Registry value not found*


    Checking for EXPLORER.EXE instances:

    C:\WINDOWS\Explorer.exe: PRESENT!

    C:\Explorer.exe: not present
    C:\WINDOWS\Explorer\Explorer.exe: not present
    C:\WINDOWS\System\Explorer.exe: not present
    C:\WINDOWS\System32\Explorer.exe: not present
    C:\WINDOWS\Command\Explorer.exe: not present
    C:\WINDOWS\Fonts\Explorer.exe: not present


    Checking for superhidden extensions:

    .lnk: HIDDEN! (arrow overlay: yes)
    .pif: HIDDEN! (arrow overlay: yes)
    .exe: not hidden
    .com: not hidden
    .bat: not hidden
    .hta: not hidden
    .scr: not hidden
    .shs: HIDDEN!
    .shb: HIDDEN!
    .vbs: not hidden
    .vbe: not hidden
    .wsh: not hidden
    .scf: HIDDEN! (arrow overlay: NO!)
    .url: HIDDEN! (arrow overlay: yes)
    .js: not hidden
    .jse: not hidden


    Verifying REGEDIT.EXE integrity:

    - Regedit.exe found in C:\WINDOWS
    - .reg open command is normal (regedit.exe %1)
    - Regedit.exe has no CompanyName property! It is either missing or named something else.
    - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
    - Regedit.exe has no FileDescription property! It is either missing or named something else.

    Registry check failed!


    Enumerating Browser Helper Objects:

    (no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}


    Enumerating Task Scheduler jobs:



    Enumerating Download Program Files:

    [WUWebControl Class]
    InProcServer32 = C:\WINDOWS\System32\wuweb.dll
    CODEBASE = http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1182366219515

    [Java Plug-in 1.6.0_02]
    InProcServer32 = C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab

    [Java Plug-in 1.6.0_02]
    InProcServer32 = C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab

    [Java Plug-in 1.6.0_02]
    InProcServer32 = C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


    Enumerating Winsock LSP files:

    NameSpace #1: C:\WINDOWS\System32\mswsock.dll
    NameSpace #2: C:\WINDOWS\System32\winrnr.dll
    NameSpace #3: C:\WINDOWS\System32\mswsock.dll
    NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll
    Protocol #1: C:\WINDOWS\system32\mswsock.dll
    Protocol #2: C:\WINDOWS\system32\mswsock.dll
    Protocol #3: C:\WINDOWS\system32\mswsock.dll
    Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #6: C:\WINDOWS\system32\mswsock.dll
    Protocol #7: C:\WINDOWS\system32\mswsock.dll
    Protocol #8: C:\WINDOWS\system32\mswsock.dll
    Protocol #9: C:\WINDOWS\system32\mswsock.dll
    Protocol #10: C:\WINDOWS\system32\mswsock.dll
    Protocol #11: C:\WINDOWS\system32\mswsock.dll
    Protocol #12: C:\WINDOWS\system32\mswsock.dll
    Protocol #13: C:\WINDOWS\system32\mswsock.dll


    Enumerating Windows NT/2000/XP services

    a347bus: system32\DRIVERS\a347bus.sys (system)
    a347scsi: System32\Drivers\a347scsi.sys (system)
    Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
    Adobe LM Service: "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" (manual start)
    Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
    AFD Networking Support -ympäristö: \SystemRoot\System32\drivers\afd.sys (system)
    Hälytys: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
    Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
    Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    1394 ARP -asiakasprotokolla: System32\DRIVERS\arp1394.sys (manual start)
    AsIO: system32\drivers\AsIO.sys (system)
    aslm75: \??\C:\WINDOWS\system32\drivers\aslm75.sys (system)
    ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (manual start)
    RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
    Standardi IDE/ESDI-kiintolevyohjain: System32\DRIVERS\atapi.sys (system)
    ATM ARP Client -protokolla: System32\DRIVERS\atmarpc.sys (manual start)
    Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
    Autodesk Licensing Service: "C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe" (autostart)
    AVG Anti-Spyware Driver: \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys (system)
    AVG Anti-Spyware Guard: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (autostart)
    AVG Anti-Spyware Clean Driver: System32\DRIVERS\AvgAsCln.sys (system)
    bdfdll: \??\E:\BitDefender plus v10\bdfdll.sys (manual start)
    BDFSDRV: \??\E:\BitDefender plus v10\bdfsdrv.sys (manual start)
    bdpredir: \??\E:\BitDefender plus v10\bdpredir.sys (system)
    BDRSDRV: \??\E:\BitDefender plus v10\bdrsdrv.sys (autostart)
    BitDefender Scan Server: "C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (autostart)
    BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##: "C:\Program Files\Bonjour\mDNSResponder.exe" (autostart)
    Tietokoneiden selaus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    catchme: \??\C:\DOCUME~1\Wiljami\LOCALS~1\Temp\catchme.sys (manual start)
    CD-ROM-ohjain: System32\DRIVERS\cdrom.sys (system)
    Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
    Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled)
    .NET Runtime Optimization Service v2.0.50727_X86: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (manual start)
    COM+-järjestelmäsovellus: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
    Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
    DHCP-asiakas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Levyohjain: System32\DRIVERS\disk.sys (system)
    Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
    dmboot: System32\drivers\dmboot.sys (disabled)
    Loogisen levyn hallinta -ohjain: System32\drivers\dmio.sys (system)
    dmload: System32\drivers\dmload.sys (system)
    Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
    DNS-asiakas: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
    Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
    DS1410D: \??\C:\WINDOWS\system32\drivers\ds1410d.sys (autostart)
    Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
    COM+-tapahtumajärjestelmä: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
    ewwgyccycpsb: system32\drivers\ewwgyccycpsb.sys (manual start)
    Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Levykeaseman ohjain: System32\DRIVERS\fdc.sys (manual start)
    FLEXnet Licensing Service: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" (manual start)
    Levykeasemaohjain: System32\DRIVERS\flpydisk.sys (manual start)
    FltMgr: system32\drivers\fltmgr.sys (system)
    Volume Manager -ohjain: System32\DRIVERS\ftdisk.sys (system)
    Yleinen paketinmääritys: System32\DRIVERS\msgpc.sys (manual start)
    Hardlock: \??\C:\WINDOWS\system32\drivers\hardlock.sys (autostart)
    Haspnt: \??\C:\WINDOWS\system32\drivers\Haspnt.sys (autostart)
    Microsoft UAA Bus Driver for High Definition Audio: System32\DRIVERS\HDAudBus.sys (manual start)
    Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    Microsoft HID -luokkaohjain: System32\DRIVERS\hidusb.sys (manual start)
    HTTP: System32\Drivers\HTTP.sys (manual start)
    HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
    i8042-näppäimistö ja PS/2-hiiriohjain: System32\DRIVERS\i8042prt.sys (system)
    CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
    CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\System32\imapi.exe (manual start)
    Service for Realtek HD Audio (WDM): system32\drivers\RtkHDAud.sys (manual start)
    Intel-suoritinohjain: System32\DRIVERS\intelppm.sys (system)
    Windowsin IPv6-palomuurin ohjain: system32\drivers\ip6fw.sys (manual start)
    IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
    IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
    IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
    IPSEC-ohjain: System32\DRIVERS\ipsec.sys (system)
    IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
    PnP ISA/EISA -väyläohjain: System32\DRIVERS\isapnp.sys (system)
    JMicron Hot-Plug Driver: System32\DRIVERS\JGOGO.sys (system)
    JRAID: System32\DRIVERS\jraid.sys (system)
    Näppäimistön luokkaohjain: System32\DRIVERS\kbdclass.sys (system)
    Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
    Palvelin: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Työasema: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Logitech HID/USB Mouse Filter Driver: System32\DRIVERS\LHidFlt2.Sys (manual start)
    Logitech USB Receiver device driver: System32\Drivers\LHidUsb.Sys (manual start)
    License Management Service ESD: "C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe" (manual start)
    BitDefender Desktop Update Service: "C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (autostart)
    TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
    Logitech Mouse Class Filter Driver: System32\DRIVERS\LMouFlt2.Sys (manual start)
    Messagcr: c:\temp\svchost.exe (disabled)
    Viestinvälitys: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    mental ray 3.5 Satellite (32-bit): E:\3DMaX\mentalray\satellite\raysat_3dsmax9_32server.exe (autostart)
    NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
    Hiiren luokkaohjain: System32\DRIVERS\mouclass.sys (system)
    Hiiren HID-ohjain: System32\DRIVERS\mouhid.sys (manual start)
    WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
    MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
    Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
    Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
    Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
    Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
    Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
    Microsoft-järjestelmänhallinnan BIOS-ohjain: System32\DRIVERS\mssmbios.sys (manual start)
    ATK0110 ACPI UTILITY: System32\DRIVERS\ASACPI.sys (manual start)
    NBService: E:\Nero Burning\Nero 7\Nero BackItUp\NBService.exe (manual start)
    Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
    NDIS Usermode I/O -protokolla: System32\DRIVERS\ndisuio.sys (manual start)
    Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
    NetBIOS-käyttöliittymä: System32\DRIVERS\netbios.sys (system)
    NetBIOS TCP/IP:n päällä: System32\DRIVERS\netbt.sys (system)
    Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled)
    Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
    Verkkokirjautuminen: %SystemRoot%\System32\lsass.exe (manual start)
    Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    1394-verkko-ohjain: System32\DRIVERS\nic1394.sys (manual start)
    NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    NT LM -suojaustuen toimittaja: %SystemRoot%\System32\lsass.exe (manual start)
    Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    nTune Service: C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe /StartService (autostart)
    nv: System32\DRIVERS\nv4_mini.sys (manual start)
    nvata: System32\DRIVERS\nvata.sys (system)
    NVIDIA nForce Networking Controller Driver: System32\DRIVERS\NVENETFD.sys (manual start)
    NVIDIA Network Bus Enumerator: System32\DRIVERS\nvnetbus.sys (manual start)
    NVR0Dev: \??\C:\WINDOWS\nvoclock.sys (manual start)
    NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
    IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
    IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
    VIA OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
    Rinnakkaisporttiohjain: System32\DRIVERS\parport.sys (manual start)
    PCI-väyläohjain: System32\DRIVERS\pci.sys (system)
    PCIIde: System32\DRIVERS\pciide.sys (system)
    Plug and Play: %SystemRoot%\system32\services.exe (autostart)
    IPSEC-palvelut: %SystemRoot%\System32\lsass.exe (autostart)
    WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
    Processor Driver: System32\DRIVERS\processr.sys (system)
    Profos: \??\e:\bitdefender plus v10\profos.sys (manual start)
    Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
    QoS-paketinajoitus: System32\DRIVERS\psched.sys (manual start)
    Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
    PxHelp20: System32\Drivers\PxHelp20.sys (system)
    Remote Access Auto Connection -ohjain: System32\DRIVERS\rasacd.sys (system)
    Remote Access Auto Connection -hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
    Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
    Suora rinnakkainen: System32\DRIVERS\raspti.sys (manual start)
    Rdbss: System32\DRIVERS\rdbss.sys (system)
    RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
    Terminal Server Device Redirector -ohjain: System32\DRIVERS\rdpdr.sys (manual start)
    Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
    Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
    Reititys ja etäkäyttö: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    Etärekisteri: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
    Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\System32\locator.exe (manual start)
    Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
    QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
    Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
    Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
    Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Secdrv: System32\DRIVERS\secdrv.sys (manual start)
    Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Serenum Filter -ohjain: System32\DRIVERS\serenum.sys (manual start)
    Sarjaporttiohjain: System32\DRIVERS\serial.sys (system)
    Internet Connection Sharing: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
    Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
    sptd: System32\Drivers\sptd.sys (system)
    Järjestelmän palautussuodatin -ohjain: System32\DRIVERS\sr.sys (system)
    Järjestelmän palauttaminen -palvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Srv: System32\DRIVERS\srv.sys (manual start)
    SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
    WIA (Windows Image Acquisition): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
    Ohjelmistoväyläohjain: System32\DRIVERS\swenum.sys (manual start)
    Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
    MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{E4942198-17AE-4D7A-B43A-3DC56CF2DFD6} (manual start)
    Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
    Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
    Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    TCP/IP-protokollaohjain: System32\DRIVERS\tcpip.sys (system)
    Päätelaiteohjain: System32\DRIVERS\termdd.sys (system)
    Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
    Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Telnet: C:\WINDOWS\System32\tlntsvr.exe (disabled)
    Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Trufos: \??\e:\bitdefender plus v10\trufos.sys (manual start)
    Microcode Update -ohjain: System32\DRIVERS\update.sys (manual start)
    Universal Plug & Play -laiteisäntä: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
    Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
    Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
    USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
    Microsoft USB Open Host Controller Miniport Driver: System32\DRIVERS\usbohci.sys (manual start)
    USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)
    VGA-näytönohjain: \SystemRoot\System32\drivers\vga.sys (system)
    Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
    BitDefender Virus Shield: "E:\BitDefender plus v10\vsserv.exe" /service (autostart)
    Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
    Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
    WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
    WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Kannettavan mediasoittimen sarjanumeropalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WMI-palvelun ohjainlaajennukset: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WMI resurssisovitin: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
    Windows Socket 2.0:n tukiympäristö ei-IFS-järjestelmiä varten: \SystemRoot\System32\drivers\ws2ifsl.sys (disabled)
    Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    BitDefender Communicator: "C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (autostart)
    Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


    Enumerating Windows NT logon/logoff scripts:
    *No scripts set to run*

    Windows NT checkdisk command:
    BootExecute = autocheck autochk *

    Windows NT 'Wininit.ini':
    PendingFileRenameOperations: *Registry value not found*


    Enumerating ShellServiceObjectDelayLoad items:

    PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
    CDBurn: C:\WINDOWS\system32\SHELL32.dll
    WebCheck: C:\WINDOWS\system32\webcheck.dll
    SysTray: C:\WINDOWS\System32\stobject.dll

    Autorun entries from Registry:

    *No values found*


    Autorun entries from Registry:

    *No values found*


    End of report, 34 243 bytes
    Report generated in 0.094 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
  7. Auttaja

    Auttaja Guest

  8. Wiljami

    Wiljami Member

    Dec 14, 2002
    Muuten toimi niinkuin sanoit mutta kansiot eivät poistuneet ja avenger.txt on tyhjä. Ohjelma loi jopa sen backup filun.

    Noudatin ohjeita niin kuin kirjoitit.
  9. Wiljami

    Wiljami Member

    Dec 14, 2002
    No voi hi**o.. kokeilin uudestaan ja tuli tälläinen

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:


    Script file located at: \??\C:\qpkdmqyx.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger


    Beginning to process script file:

    Folder C:\WINDOWS\Mafia not found!
    Deletion of folder C:\WINDOWS\Mafia failed!

    Could not process line:
    Status: 0xc0000034

    Folder C:\Program Files\Mafia not found!
    Deletion of folder C:\Program Files\Mafia failed!

    Could not process line:
    C:\Program Files\Mafia
    Status: 0xc0000034

    Completed script processing.


    Finished! Terminate.
  10. Auttaja

    Auttaja Guest

    Moi... eli sun kiintolevy on huonossa kunnossa.. eli jotain virheitä siellä.. anna vaan olla ne tiedostot.. ei ne maailmaa kaada... :)
  11. Wiljami

    Wiljami Member

    Dec 14, 2002
    Jeh no eihän ne kaada joo :) toivottavasti lähtevät kuitenkin sitten seuraavan kerran ku formatoin ja asennen windowsin uusiks.

    Kiitos avusta!

